RC RANDOM CHAOS

I factored a root CA

Factoring a 1990s Certificate Authority's public key recovered its private signing key, showing that confidentiality resting on computational cost is not a control.

· 8 min read
I factored a root CA

I factored the RSA keys of a Certificate Authority issued in the 1990s. Working from public data alone, I recovered the private signing key. The secret that defined that authority is now reproducible outside of it. That key was never protected by secrecy. It was protected by the assumed cost of factoring its modulus, and that cost is now payable.

A Certificate Authority’s private key is the root of trust for every certificate it signs. Holding that key means holding the ability to produce signatures that validate as that authority. That capability now exists in hands that are not the CA’s. Whether any modern client still trusts this authority is not confirmed. Whether the root is still present in any trust store is not confirmed. The cryptographic result does not depend on either. The private key is recoverable, and that is a fixed condition, not an event.

This was not a break of an implementation. No system was accessed. No key was stolen from a vault or extracted from a hardware module. The public key was published, which is what public keys are for. The private key was computed from it. The point leadership needs to hold is narrow and exact: the secret half of this key pair was derivable from the half that was always meant to be public.

The observable behavior is simple. Given the CA’s public modulus, factoring returned its prime factors. From those factors, the private key reconstructs directly with no further information. The input was public certificate data. The output was the private key. Nothing about the CA’s infrastructure was touched, because factoring operates only on values that are already public.

What failed is the confidentiality of the private key. The secrecy of that key is the only property that separates a legitimate authority from anyone else who holds the same number. That separation did not hold. The private key is a deterministic function of public inputs, which means it was never confidential in any durable sense. It was unpublished, not protected.

State clearly what did not fail, because scope discipline matters here. The certificate format did not fail. The signature construction did not fail. The mathematics of RSA behaved exactly as specified. Whether any certificate was forged is not confirmed. Whether any relying party was deceived is not confirmed. Whether this authority remains in any active trust path is not confirmed. The confirmed failure is bounded: the private key of a 1990s Certificate Authority is recoverable from its public key.

RSA protects a private key on one condition. The public modulus must be infeasible to factor. When factoring that modulus becomes feasible, the private key is not secret. It is simply not yet written down. For this key, factoring the modulus was feasible with available computation. That is the entire mechanism. There is no second cause to identify.

The exact key length is not confirmed. Factorability establishes the necessary fact regardless: the modulus sat below the size that current computation can resolve. Whatever margin the key held when it was generated, that margin is now gone. A key’s resistance to factoring is fixed at the moment it is created. The computation available to attack it is not fixed. Those two values move against each other, and when they meet, the key’s confidentiality ends without anything being done to the key itself.

Nothing operational produced this outcome. There was no leaked credential, no misissued certificate, no compromised endpoint, no lapse by an operator. The key functioned as a valid RSA key throughout. Its security rested on an assumption about factoring cost, and that assumption was the component that expired. The key value was set once and never had to change for it to fail. The mathematics that protected it and the mathematics that now exposes it are identical. Only the price of factoring moved.

The mechanism is single and it sits outside the key. The private key’s confidentiality was never a stored property. It was the output of one arithmetic condition: the modulus resists factoring. That condition is not held inside the Certificate Authority. It is held by the state of available computation, which the CA does not own, cannot observe, and cannot adjust. When the modulus was factored from public data, no control the CA operated was defeated. A condition the CA depended on, and had no authority over, was satisfied. The confidentiality of the key was delegated by design to a variable that sits beyond the boundary of the authority relying on it.

This is why nothing had to be touched. The key value was fixed at generation and correct for its entire life. Whatever access controls surrounded the private key, their presence is not confirmed, and their state is not relevant to this outcome. Factoring does not interact with them. The one property that made the key an authority, the gap between its public and private halves, was defined by a number whose effective size falls as computation advances. The key did not weaken. The distance an attacker had to cover to reach it shrank until it was payable. Observed externally, the input was public and the output was the private key. There is no intermediate step a control could occupy, because the computation ran entirely on published values.

Define precisely what that means for enforcement. A control acts on something the defender holds: an access path, a credential, an execution context, a trust decision. Factoring acts on none of these. It consumes only the public key, which the CA is required to distribute for the system to function at all. There is no point at which the defender can intervene, because there is no interaction with the defender. The failure is not the breach of a boundary. It is the discovery that the boundary was arithmetic, and that the arithmetic was never enforced by the authority. It was assumed to be enforced by cost. Cost is not a control. Cost is a bet on an external variable.

The pattern generalizes only along that mechanism, not by analogy. Any secret whose confidentiality rests on the assumed cost of a computation, rather than on being withheld, has an expiration its holder does not set and cannot see. The holder controls whether the secret is published. The holder does not control the price of deriving it. Those are two distinct security properties, and this key demonstrates they were treated as one. The private key was unpublished, and unpublished was read as protected. The two are equivalent only while the derivation stays infeasible.

The same mechanism applies to every key pair of the same construction whose margin was fixed at creation and never revised. An RSA key sized against the computation of its generation carries that assumption for its entire deployed life. If the key is long lived, the assumption ages while the key does not move. Every such modulus already in circulation stands in the identical position: its confidentiality is a function of a factoring cost that moves in one direction. This is not a claim about which specific keys are now factorable, which is not confirmed for any key not tested. It is the structural point that the property protecting them is the same property that failed here, and it degrades toward zero margin.

The exposure sharpens for anything that acts as a root. A signing key that other parties trust does not only protect its own data. It authorizes signatures that validate as the authority. When the mechanism keeping that key secret expires, the meaning of every signature that key can produce expires with it. The failure does not stay contained to one secret. It reaches the trust anchored on the assumption that the secret would hold. A key whose margin was set once and left is a fixed value under attack by a quantity that only grows. The direction of that race is not in dispute, and the holder is not a participant in it.

State the position without softening. Confidentiality that depends on computational cost is not a stored secret. It is a countdown whose length was not measured and whose end will not be announced. This key reached the end. Treating an unpublished private key as a protected one is a design error whenever the only thing separating the two is a factoring assumption fixed at generation. The key was not protected. It was unpublished, and the derivation became affordable.

What must now be true is a boundary condition, not a repair for this key. This key is not recoverable to a secret state. A recovered private key is a permanent condition, not an incident to close. If this authority sits in any trust path, presence not confirmed, that path assigns authority to a key anyone holding the public value can reproduce. The requirement is structural. No root may derive its confidentiality from a factoring margin set once and never revised against the computation now available. Cryptographic strength must be treated as a value that decays, reviewed against current factoring capability on a defined interval, or it must be assumed already spent.

The final point for leadership is narrow. Nothing was stolen. Nothing was misconfigured in the sense of an operator error. A correct key, generated correctly, protected as designed, produced its own private half from its own public half, because that computation was always mathematically available and only recently affordable. If a system permits a secret to be computed from public data, that computation will be performed, by someone, on a schedule the defender does not set. The private key of this authority is recoverable. That is fixed. Everything downstream of trusting it must be treated as reproducible by anyone who reads the public record.

Share

Keep Reading

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.