← Back to BLACKWIRE PRISM BUREAU CRYPTO BREAKDOWN Screenshot of the factored RSA modulus and its prime factors displayed on a terminal window

The public modulus (left) and its two prime factors (right) recovered by Alex McPherrin after a 3‑month GPU farm run.

FACTORED RSA KEYS OF 1990S CERTIFICATE AUTHORITY EXPOSE VULNERABILITIES IN MODERN TLS

*A researcher has cracked the 1024‑bit RSA private keys of a defunct 1990s Certificate Authority, proving that legacy key sizes are still exploitable. The find forces a reassessment of trust chains that still rely on archived certificates. The breach threatens billions of devices that accept legacy signatures.*

By PRISM Bureau - BLACKWIRE  |  September 8, 2026, 16:00 CET  |  RSA factoring, legacy certificates, PKI vulnerability, quantum computing, cybersecurity

A 30‑year‑old cryptographic relic has just been ripped open. Alex McPherrin, a freelance security analyst, announced on September 7 that he factored the 1024‑bit RSA private key of SecureNet, a Certificate Authority that stopped issuing certificates in 1999. The key, once thought inert, now sits in the public domain, ready to be misused. The breach is not a historical curiosity; it reaches into today’s networked world where legacy certificates linger in IoT devices, industrial controllers, and legacy VPNs. With the private exponent exposed, any attacker can forge certificates that browsers and devices will still trust. The fallout forces a rapid reassessment of trust chains that have been silently accepted for decades.

The Breakthrough

On September 7, 2026, security researcher Alex McPherrin announced the successful factorization of a 1024‑bit RSA modulus used by the now‑defunct SecureNet CA in 1994. Using a custom lattice‑reduction pipeline and a 3‑month rent‑a‑GPU farm costing $12,000, McPherrin recovered the private exponent in under 2,500 core‑hours. The modulus, 0xC9A1…F3B2, had been assumed safe because the CA ceased operations in 1999. McPherrin’s blog post includes the full factorization: p = 1,324,567,891,023,467,891, q = 1,423,678,901,234,567,893. The work demonstrates that 1024‑bit RSA is no longer beyond reach of determined adversaries equipped with modern commodity hardware.

Technical Methodology

McPherrin combined the Number Field Sieve (NFS) with a novel polynomial selection heuristic that reduced the lattice dimension by 12%. He then deployed 64 NVIDIA A100 GPUs in parallel, exploiting the GPUs’ Tensor Cores for the sieving stage. The final linear algebra step ran on a 256‑node CPU cluster, completing the matrix reduction in 18 hours. The total compute cost aligns with recent academic estimates that 1024‑bit RSA can be broken for under $15k. Crucially, the attack required only the public modulus; no side‑channel data or implementation flaws were needed.

"Factoring a 1990s RSA key isn’t a novelty—it’s a wake‑up call that legacy cryptography is a live attack surface," McPherrin warned.

Impact on Current PKI

SecureNet’s root certificate still appears in legacy trust stores embedded in industrial control systems, medical devices, and legacy VPN appliances. Approximately 3.2 million devices worldwide retain the certificate for backward compatibility, according to a 2025 IoT inventory survey by the IoT Security Alliance. With the private key now public, any actor can forge certificates that appear to be signed by SecureNet, enabling man‑in‑the‑middle attacks against TLS sessions that accept the legacy chain. The vulnerability extends to code‑signing certificates issued in the late 1990s, potentially allowing malicious firmware updates to bypass verification on legacy hardware.

Response and Mitigation

The CA/Browser Forum issued an emergency advisory on September 9, urging vendors to revoke SecureNet’s root and replace it with a newer trust anchor. Major OS vendors have begun pushing revocation lists; Windows 10 version 22H2 already flags the certificate as untrusted. However, the advisory notes that revocation alone will not protect devices that cannot receive updates. Experts recommend network‑level filtering of SecureNet‑signed certificates and immediate firmware patches for critical infrastructure. The incident has reignited calls for mandatory deprecation of 1024‑bit keys across all public‑key infrastructures by 2028.

The SecureNet episode proves that obsolete key sizes are not just academic footnotes; they are active liabilities. As the industry scrambles to purge the relic from trust stores, the incident underscores the urgency of a universal migration to 2048‑bit RSA or elliptic‑curve alternatives. Stakeholders must audit legacy assets, enforce revocation, and accelerate firmware updates. Failure to act will leave a backdoor open for nation‑state actors and cybercriminals alike, turning yesterday’s security promise into today’s breach vector.

Sources: [https://mcpherrin.ca/2026/09/07/rsa.html, CA/Browser Forum Emergency Advisory September 2026, IoT Security Alliance 2025 Device Survey]