The case attributes to the author of mcpherrin.ca a claim to have factored the RSA keys of a certificate authority from the 1990s. The supplied search results explain RSA factorization and how root certificates anchor trust, but none directly documents this claimed recovery or identifies the author, CA, key sizes, or method. They also do not establish that these historical keys remain trusted, so any present-day need to retire them is conditional rather than demonstrated.
The claim is at most an illustration of the signing-key assumptions behind Scott’s Cryptographic Trust concept, not an established challenge to his provenance architecture or an identified dependency in his projects. The supplied material neither verifies the recovery nor establishes continuing trust in the keys; the radar’s other signing-key stories do not track this development.
queries asked of Scott's wikis
- legacy PKI trust anchors certificate retirement
- cryptographic key lifecycle rotation migration
- software signing provenance historical signature trust
- TLS certificate validation trust store dependencies
2026-09-10T18:59:58Z
The review horizon has elapsed without substantive evidence beyond testimony about historical weak-key recovery, and no concrete follow-up is expected. The case has faded rather than been disproved: neither a live trust exposure nor a consequential AI-tooling result is established.
2026-09-08T18:24:47Z
The refreshed discussion is repetitive amplification, not independent confirmation of key recovery or evidence of a currently trusted affected CA. Historical 512-bit weakness remains the bounded interpretation; incidental AI-written code adds no consequential tooling result for Scott.
2026-09-08T12:32:28Z
The refreshed discussion adds no independent verification or live trust dependency, leaving this a bounded historical weak-key recovery claim rather than a demonstrated modern-PKI risk. Repeated commentary, including incidental AI-generated implementation details, does not change Scott’s decisions or justify frequent review.
2026-09-08T10:27:08Z
The comment refresh adds no substantive evidence beyond the existing historical weak-key recovery claim; neither independent verification nor a currently trusted affected certificate is established. The AI-generated implementation discussion remains incidental, with no new consequence for Scott’s tooling or security decisions.
2026-09-08T09:29:16Z
The refreshed discussion remains amplification of a historical weak-key recovery claim, without independent verification or an identified live trust dependency. Speculation about stronger RSA and AI-generated implementation details adds no demonstrated modern-PKI risk or consequential AI-tooling result for Scott.
2026-09-08T06:31:50Z
The refreshed comments add no independent recovery verification or evidence that the historical CA remains trusted; the case still concerns reportedly weak legacy keys, not a demonstrated modern PKI exposure. Discussion of AI-written implementation material does not establish a consequential agent-tooling result.
2026-09-08T05:26:27Z
The refreshed comments remain amplification of historical 512-bit key recovery, not a new verification or an identified present-day trust exposure. Neither speculation about stronger RSA nor concerns about unverified LLM-generated material change the case’s bounded security significance.
2026-09-08T04:23:17Z
The refreshed discussion remains commentary on historical weak-key recovery, not independent verification or evidence of a live trust dependency. Questions about the factoring method and unverified LLM output leave validation gaps open without establishing that the core recovery claim is false.
2026-09-08T03:25:17Z
The refreshed discussion adds no independent validation or live trust dependency; this remains a historical weak-key recovery claim rather than evidence of modern PKI exposure. References to AI-generated implementation material do not establish a consequential AI-tooling development for Scott.
2026-09-08T02:25:51Z
Discussion now describes a 512-bit certificate and a linked implementation, making this more concrete but still reader testimony rather than independent verification. The apparent significance remains historical weak-key recovery; neither modern RSA exposure nor continued trust in the recovered CA keys is established.
2026-09-08T02:25:18Z
grounded: novel/low — The claim is at most an illustration of the signing-key assumptions behind Scott’s Cryptographic Trust concept, not an established challenge to his provenance a
2026-09-08T02:22:45Z
case created — A concrete historical key-recovery claim warrants a bounded security case distinct from RSA-260, without implying exposure in modern PKI.