2026-10-11 17:11 UTC

The author of mcpherrin.ca claims to have factored a 1990s certificate authority’s RSA keys, demonstrating recovery of historical signing keys and the need to retire any trust still placed in them.

state: expiredheat: lowuncertainty: highnovelscott: lowrsa-factorization legacy-pki cryptography

What is this?

The case attributes to the author of mcpherrin.ca a claim to have factored the RSA keys of a certificate authority from the 1990s. The supplied search results explain RSA factorization and how root certificates anchor trust, but none directly documents this claimed recovery or identifies the author, CA, key sizes, or method. They also do not establish that these historical keys remain trusted, so any present-day need to retire them is conditional rather than demonstrated.

Why it matters to Scott

The claim is at most an illustration of the signing-key assumptions behind Scott’s Cryptographic Trust concept, not an established challenge to his provenance architecture or an identified dependency in his projects. The supplied material neither verifies the recovery nor establishes continuing trust in the keys; the radar’s other signing-key stories do not track this development.
queries asked of Scott's wikis
  • legacy PKI trust anchors certificate retirement
  • cryptographic key lifecycle rotation migration
  • software signing provenance historical signature trust
  • TLS certificate validation trust store dependencies

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnI've factored the RSA keys of a Certificate Authority from the 90sahlCVA511119
🟧 echo.blog ⭐The linked post is presented as: “I've factored the RSA keys of a Certificate Authority from the 90s.”mcpherrin.ca author——

Interpretation history

Decision trace