Crypto-View

wultra/powerauth-crypto

ef7f0b8e76b4 (18 hours ago) → 469da6a2fb80 (5 hours ago)

Measure Before After Change
Readiness score 15 15 -
Findings to address 51 73 +22
Key establishment 10 2 -8
Files scanned 171 287 +116

Added

Present in the later scan and not in the earlier one.

Finding Assessment Before After
EC Classical key material handled through the JCA · java.keyfactory Quantum-vulnerable 0 4
EC Classical key pair generated through the JCA · java.keypairgenerator Quantum-vulnerable 0 2
EC Named elliptic curve requested · java.eccurve Quantum-vulnerable 0 1
EC Named elliptic curve requested · java.eccurve Quantum-vulnerable 0 1
ML-DSA-65 Post-quantum algorithm through BouncyCastle · java.bouncycastle.pqc Quantum-safe 0 6
ML-KEM-768 Post-quantum algorithm through BouncyCastle · java.bouncycastle.pqc Quantum-safe 0 4
ML-KEM-768 Classical public-key cipher through the JCA · java.cipher Quantum-safe 0 2
ML-KEM-768 Classical key pair generated through the JCA · java.keypairgenerator Quantum-safe 0 1

Resolved

Present in the earlier scan and gone in the later one.

Finding Assessment Before After
ECDH Named elliptic curve requested · java.eccurve Quantum-vulnerable 4 0
ECDH Classical key material handled through the JCA · java.keyfactory Quantum-vulnerable 4 0
ECDSA Classical signature algorithm through the JCA · java.signature Quantum-vulnerable 3 0
HMAC Message authentication code through the JCA · java.mac Quantum-safe 2 0

Count changed

The same finding, in a different number of places.

Finding Assessment Before After
ECDSA Elliptic-curve cryptography through BouncyCastle · java.bouncycastle.ec Quantum-vulnerable 8 16
AES Cipher transformation named away from the call · java.transformation Reduced margin 6 13
SHA-256 Hash algorithm through the JCA · java.messagedigest Reduced margin 7 2
AES Key material constructed for a named algorithm · java.keyspec Reduced margin 2 1
unknown Key material constructed for a named algorithm · java.keyspec Could not be determined 1 10
unknown Key pair algorithm chosen at runtime · java.keypairgenerator.variable Could not be determined 2 6
unknown Non-cryptographic randomness near key material · java.random.insecure Could not be determined 15 13
CSPRNG Random number generation · java.rng Quantum-safe 1 4
HMAC Key material constructed for a named algorithm · java.keyspec Quantum-safe 1 2

Unchanged

7 findings appear in both scans, in the same number of places. Each scan's own report lists them.