I've factored the RSA keys of a Certificate Authority from the 90s
- ID
- 22274
- Status
- summarized
- Published
- 08 Sep 2026, 9:16 AM
- Fetched
- 10 Sep 2026, 8:34 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://mcpherrin.ca/2026/09/07/rsa.html
- Source URL
- https://hnrss.org/best
Summary
- Score
- 4.5
- Created
- 10 Sep 2026, 8:35 AM
- Tags
- Audience
- developersai_ml_learners
What happened
Matthew McPherrin factored two 512-bit RSA root CA keys from the defunct Canadian CA E-Certify, shipped in Netscape 4.51 in March 1999. He used Claude Code to extract old root certificates from browser archives on archive.org, then ran CADO-NFS on a Ryzen 9 5950X, taking 32 and 29 hours respectively to recover the private keys.
Why it matters
This is a historical crypto exercise, not a live threat—512-bit RSA was deprecated over a decade ago and these roots were removed by 2002. The practical takeaway for builders is that Claude Code can automate tedious extraction tasks from legacy binary formats, and that factoring 512-bit RSA is now a weekend job on consumer hardware, reinforcing why minimum key-size standards exist.
Discussion angle
How Claude Code was used as a bulk extraction tool for legacy certificate formats—and whether that workflow pattern (LLM-assisted parsing of old binary/archive data) generalizes to other reverse-engineering or data-recovery tasks builders face.