I was the product manager with responsibility for root certificates in the Netscape 4.51 browser. It's crazy to see someone factor it 25 years later. Just to reply to some people in the comments. Yes, we knew export grade encryption was weak - that was the point - that the NSA could decrypt it - and the govt. required us to do it anyway. FWIW - we had the goal of expanding the list of root authorities in the 4.5x rel…
Fascinating! My involvement in this space starts much later, so it’s always interesting to hear from folks involved at the time. The rumours about monetizing the root program is one I’ve heard repeated but never anything concrete. These days with the CA/Browser forum, CCADB, and openly run root programs from Mozilla, Chrome and others, this is all much better documented than what went on in the early days, so I defin…
Re: I've factored the RSA keys of a Certificate Authority from the 90s
#131At the time there were two root programs, Microsoft's and Netscape's. To get into them, for Microsoft you had to go through a painful third-party audit process, SAS 70 from memory, for Netscape you turned up in Mountain View with a suitcase full of cash (this was the informal description of the process). It cost about the same for both programs, again from memory $0.5M each.