AI Weekly Malaysia

Back to items Summaries

I've factored the RSA keys of a Certificate Authority from the 90s

ID
22274
Status
summarized
Published
08 Sep 2026, 9:16 AM
Fetched
10 Sep 2026, 8:34 AM
Provider
Hacker News
Category
dev-community
Original URL
https://mcpherrin.ca/2026/09/07/rsa.html
Source URL
https://hnrss.org/best

Summary

Score
4.5
Created
10 Sep 2026, 8:35 AM
Tags
Audience
developersai_ml_learners

What happened

Matthew McPherrin factored two 512-bit RSA root CA keys from the defunct Canadian CA E-Certify, shipped in Netscape 4.51 in March 1999. He used Claude Code to extract old root certificates from browser archives on archive.org, then ran CADO-NFS on a Ryzen 9 5950X, taking 32 and 29 hours respectively to recover the private keys.

Why it matters

This is a historical crypto exercise, not a live threat—512-bit RSA was deprecated over a decade ago and these roots were removed by 2002. The practical takeaway for builders is that Claude Code can automate tedious extraction tasks from legacy binary formats, and that factoring 512-bit RSA is now a weekend job on consumer hardware, reinforcing why minimum key-size standards exist.

Discussion angle

How Claude Code was used as a bulk extraction tool for legacy certificate formats—and whether that workflow pattern (LLM-assisted parsing of old binary/archive data) generalizes to other reverse-engineering or data-recovery tasks builders face.

Top