• Sources: primary, discussion
  • Summary: A researcher ran CADO-NFS on a single Ryzen 9 5950X desktop to factor two 512-bit RSA certificate authority root keys that shipped in the Netscape 4.51 trust store. The two E-Certify root private keys were recovered in 32 hours and 29 hours. There is no live exposure: Netscape removed the roots in 2002, they expired on 2003-10-16, and using the recovered keys requires running Netscape 4.51 with the clock set back.
  • Why it matters: It puts a measured single-machine cost on RSA key sizes that once anchored browser trust stores, without touching any current trust store.

send feedback on this story