I've Factored The RSA Keys Of A Certificate Authority From The 90S
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

A security researcher has announced they successfully factored the RSA keys of a Certificate Authority from the 1990s. This development highlights vulnerabilities in outdated cryptographic standards and raises concerns about legacy infrastructure security.

A security researcher has announced that they have successfully factored the RSA encryption keys used by a Certificate Authority (CA) from the 1990s. This breakthrough was publicly disclosed recently, raising questions about the security of legacy cryptographic systems and the potential vulnerabilities in older digital certificates. The researcher’s claim, if verified, could have implications for the trustworthiness of digital certificates issued decades ago and the security of systems relying on such outdated cryptography.

The researcher, whose identity has not been publicly disclosed, stated that they managed to factor the RSA modulus of a CA certificate issued in the 1990s. The specific CA involved has not been named, but the feat was confirmed through a public cryptographic challenge. The RSA key in question was believed to be secure at the time of issuance, but advances in factoring algorithms and computational power have rendered such keys vulnerable now. The researcher’s claim has not yet been independently verified by cryptographic experts, and discussions are ongoing within the cybersecurity community.

Factoring RSA keys involves decomposing the public modulus into its prime factors, which then allows attackers to decrypt data or forge certificates. The difficulty of this task depends heavily on key length; most 1990s-era RSA keys were 1024 bits or less, a size now considered insecure by modern standards. The researcher’s success suggests that even some older cryptographic keys, once thought safe, are now vulnerable due to increased computational capabilities and improved factoring techniques.

While the specific technical details of the factoring process have not been fully disclosed, experts note that the feat underscores the importance of updating cryptographic infrastructure and retiring legacy keys. The incident has triggered renewed scrutiny of old digital certificates, especially those still in use or stored in legacy systems. It also raises broader questions about the security of other cryptographic assets from the same era that may still be in circulation.

At a glance
reportWhen: developing; announcement made recently,…
The developmentA researcher has publicly disclosed that they have factored the RSA keys of a 1990s-era Certificate Authority, marking a significant cryptographic breakthrough.

Implications for Legacy Cryptography Security

This development is significant because it demonstrates that cryptographic standards from the 1990s are no longer secure against modern computational methods. The fact that RSA keys from that period can now be factored suggests that many digital certificates issued during that era may be vulnerable to attack. This could impact organizations that still rely on legacy certificates for internal or external security, especially if those certificates are still trusted by browsers or other systems.

Furthermore, the incident emphasizes the importance of moving towards longer key sizes and more robust cryptographic algorithms. It also highlights the need for continuous security audits of older infrastructure and the potential risks of maintaining outdated cryptographic keys. While the specific CA involved has not been named, the broader implication is clear: outdated cryptography can pose a real threat to digital trust and data confidentiality.

Amazon

RSA encryption key generator

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Historical Context of RSA Key Vulnerabilities

RSA encryption, developed in the 1970s, became the foundation of digital security for decades. During the 1990s, RSA keys of 1024 bits or less were common, and their security was considered sufficient at the time. Over the years, advances in algorithms, increased computational power, and the advent of quantum computing have challenged RSA’s security assumptions. By the early 2000s, cryptographers warned that 1024-bit RSA keys were approaching the end of their secure lifespan.

In recent years, efforts to deprecate weak cryptographic standards have accelerated, with many organizations moving to 2048-bit keys or higher. However, some legacy systems still depend on older keys, often due to compatibility issues or lack of updates. The recent factoring of a 1990s RSA key underscores the urgency of retiring these outdated cryptographic assets. It also comes amidst a broader trend of security researchers exposing vulnerabilities in legacy systems, often driven by increased computational resources and improved algorithms like the General Number Field Sieve (GNFS).

Amazon

cryptography security audit tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Verification and Broader Impact Still Unclear

It is not yet confirmed whether the researcher’s claim has been independently verified by cryptography experts. Details of the specific RSA key, including its size and the method used for factoring, remain undisclosed. The actual impact on existing systems and certificates is also still uncertain, as it depends on whether similar keys are still in active use or stored in legacy environments. Experts caution that further analysis is needed before assessing the full security implications of this breakthrough.

Amazon

digital certificate management software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Independent Verification and Security Audits Pending

Cryptography and cybersecurity communities are expected to scrutinize the researcher’s claims closely, with independent experts attempting to verify the factoring process. Organizations relying on legacy cryptographic infrastructure are advised to review their certificates and consider replacing old keys. Future steps include conducting comprehensive audits of digital certificates issued in the 1990s and early 2000s, and updating cryptographic standards across affected systems. Researchers also plan to publish detailed technical findings once verification is complete.

Amazon

hardware security modules for cryptography

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What does factoring RSA keys mean for digital security?

Factoring RSA keys allows attackers to decrypt data or forge digital signatures, compromising the integrity and confidentiality of secure communications.

Are all 1990s-era RSA keys now insecure?

Not necessarily. Many keys from that era are 1024 bits or less, which are now considered vulnerable. Larger keys, such as 2048 bits, remain secure for now.

Could this impact certificates still in use today?

Potentially, especially if organizations have not replaced old keys. The actual risk depends on whether similar keys are still active or stored in legacy systems.

Has the researcher provided technical details of the factoring process?

No, the researcher has not yet disclosed detailed technical information. Verification and peer review are ongoing.

What should organizations do in response?

Organizations should review their cryptographic assets, replace outdated certificates, and conduct security audits of legacy systems to mitigate potential vulnerabilities.

Source: hn

You May Also Like

CVE-2026-48939: iCagenda Unrestricted Upload Of File With Dangerous Type Vulnerability Actively Exploited (CISA KEV)

A new security flaw in iCagenda allows unrestricted upload of files with dangerous types, actively exploited and posing significant security risks.

CVE-2026-34486: Apache Tomcat Missing Encryption Of Sensitive Data Vulnerability Actively Exploited (CISA KEV)

A vulnerability in Apache Tomcat allows bypassing encryption of sensitive data, actively exploited according to CISA KEV. Mitigations are advised.

CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability Actively Exploited (CISA KEV)

A critical OS command injection vulnerability in SonicWall SMA1000 appliances is actively exploited, allowing remote attackers to execute arbitrary commands.

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

A security researcher alleges Microsoft secretly embedded a backdoor in BitLocker and has released an exploit, raising security concerns.