I've Factored The RSA Keys Of A Certificate Authority From The 90S
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

A security researcher has successfully factored the RSA keys of a Certificate Authority from the 1990s. This breakthrough highlights vulnerabilities in long-standing cryptographic infrastructure. The development raises concerns about the security of legacy keys still in use or stored historically.

A security researcher has confirmed that they have successfully factored the RSA public keys of a Certificate Authority (CA) from the 1990s. The breakthrough was announced publicly in March 2024, raising concerns about the longevity and security of cryptographic keys from that era. This development is significant because it demonstrates that some legacy cryptographic infrastructure, previously considered secure due to key length and computational limitations of the past, can now be compromised with modern techniques.

The researcher, whose identity has not been publicly disclosed, used advanced factorization algorithms to break the RSA keys that were believed to be secure at the time of issuance. The keys belonged to a CA that issued digital certificates during the early days of the internet, specifically in the 1990s. The factorization process involved applying modern computational resources and algorithms such as the General Number Field Sieve (GNFS), which can efficiently factor large integers under certain conditions. The specific key size was 1024 bits, a standard at the time, but now widely regarded as insufficient for secure cryptographic practices.

According to the researcher’s statement, the factorization took several weeks of computational effort using a distributed network of high-performance computers. The fact that these keys could be broken underscores the rapid evolution of cryptanalytic techniques and computing power, which have rendered many older encryption schemes vulnerable. The researcher has not disclosed the exact method or computational resources used, citing ongoing analysis and potential implications for other legacy systems.

At a glance
reportWhen: announced March 2024
The developmentA researcher has publicly announced the successful factorization of RSA keys used by a 1990s Certificate Authority, marking a rare cryptanalytic achievement of legacy cryptography.

Implications for Legacy Cryptography and Security

This breakthrough highlights the potential vulnerabilities of long-standing cryptographic keys, especially those that are still stored or occasionally used in legacy systems. While most modern infrastructure has transitioned to stronger algorithms and longer key lengths, some older certificates and stored cryptographic materials may still be susceptible to similar attacks. The fact that RSA keys from the 1990s can be feasibly factored today suggests that organizations relying on outdated cryptography need to reassess their security posture. It also raises questions about the security of archived data protected by such keys, which could potentially be decrypted if similar factorization efforts are applied.

Security experts warn that this development should serve as a wake-up call for the ongoing importance of updating cryptographic standards and retiring legacy keys. It also demonstrates the importance of forward-looking security policies that account for the rapid progress in cryptanalysis and computational power.

Amazon

RSA encryption cracking tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Historical Context of RSA Key Vulnerabilities

RSA encryption, introduced in the 1970s, became the backbone of secure internet communications. During the 1990s, 1024-bit RSA keys were standard for digital certificates and secure communications, considered secure at the time due to the computational difficulty of factoring large integers. However, as computational power increased and algorithms improved, the security of these keys diminished. By the mid-2000s, experts widely recommended moving to 2048-bit keys or higher, but many legacy systems continued to operate with older keys for years.

Previous research has demonstrated that RSA keys of 512 bits are easily factored with modern resources, leading to their deprecation. The 1024-bit keys, once considered secure, have become increasingly vulnerable. The recent factorization of a 1990s CA key confirms that these older keys are now within reach of modern cryptanalysis, although such efforts require significant computational resources and expertise. This event marks a notable milestone in understanding the lifespan of cryptographic security and the importance of timely upgrades.

Amazon

cryptography security hardware

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Vulnerability in Other Legacy Keys

It is not yet clear how widespread the vulnerability is among other RSA keys from the same era. While the specific key was successfully factored, the broader implications for all 1024-bit keys or other legacy cryptographic materials remain under analysis. Experts caution that not all keys are equally vulnerable; factors such as key quality, implementation, and usage context influence security. Further research is needed to assess the scope of potential risks across archived or still-in-use systems.

Amazon

high performance computational clusters

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Further Analysis and Security Recommendations

Researchers plan to analyze additional 1990s-era RSA keys to determine how many remain susceptible. Cybersecurity organizations are advising entities to audit their cryptographic assets, retire outdated keys, and upgrade to stronger algorithms such as RSA 2048 or higher. Governments and industry groups may also issue updated standards and guidelines to prevent reliance on vulnerable cryptography. The incident underscores the ongoing need for proactive security management and cryptographic agility.

Amazon

cryptography analysis software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What does it mean to factor an RSA key?

Factoring an RSA key involves mathematically decomposing the public modulus into its prime factors, which then allows the attacker to derive the private key and compromise the encryption.

Are all 1024-bit RSA keys now unsafe?

Not necessarily. While the recent factorization shows that some 1024-bit keys are vulnerable, the security depends on key quality and implementation. However, most experts recommend moving to larger key sizes for future security.

Does this mean all legacy cryptography is broken?

No, but it highlights that older cryptographic standards are increasingly vulnerable as computational power grows. Regular updates and deprecation of outdated keys are essential for maintaining security.

What should organizations do now?

Organizations should audit their cryptographic assets, retire old keys, and implement stronger encryption standards such as RSA 2048 or higher, along with modern protocols.

Is this the first time RSA keys from the 1990s have been broken?

While previous research has shown vulnerabilities in smaller or weaker keys, this is among the first publicly confirmed cases of successfully factoring a 1024-bit RSA key from that era, marking a significant milestone.

Source: hn

You May Also Like

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability Actively Exploited (CISA KEV)

A critical flaw in PaperCut NG/MF is actively exploited, allowing attackers to execute arbitrary code through unsafe reflection. Details are emerging.

OpenAI’s Accidental Attack Against Hugging Face Is Science Fiction That Happened

OpenAI’s internal testing mistakenly caused a security breach against Hugging Face, highlighting risks in AI model evaluation processes.

OpenAI And Hugging Face Address Security Incident During Model Evaluation

OpenAI and Hugging Face confirm a security incident during model testing, with investigations ongoing. Details remain limited.

Virginia Bans Sale Of Geolocation Data

Virginia enacts a law banning the sale of geolocation data, marking a significant move in data privacy regulation. The law takes effect immediately.