Crypto-View
Scan a codebase for every use of cryptography, and see which algorithms a quantum computer breaks. The result is a CycloneDX 1.7 CBOM.
What is scanned
94 rules across Java, Python, JavaScript/TypeScript and Go, plus formats that carry cryptography in any language: PEM certificates and keys, SSH keys, JOSE algorithms and TLS configuration.
Each finding gives the file, the line, the algorithm and its parameters. Where an algorithm is selected at runtime, the finding says it could not be determined rather than guessing.
What the result means
RSA, ECDSA and ECDH are broken by a quantum computer, and a larger key does not help. AES-256 and the hash functions are weakened but not broken.
Key exchange is ranked first, because traffic recorded today can be decrypted once the algorithm falls. Signatures can be forged, but only from the point the attacker has the machine.
Recent scans
| Repository | Commit | Posture | Score | Scanned |
|---|---|---|---|---|
| factionsecurity/faction main | 4dc6723a0ec3 |
19 to address | 72 | 3 days ago |
| NixOS/nixpkgs master | 3ed67ec0a4d3 |
31 to address | 56 | 3 days ago |
| CERT-Polska/drakvuf-sandbox master | 7c328ab48bfe |
Nothing found | 100 | 3 days ago |
| CERT-Polska/Artemis main | f8e92a71c936 |
4 to address | 74 | 3 days ago |
| DominikPeters/tikz-editor master | be197d85e278 |
Nothing found | 100 | 3 days ago |