Shorstop LogoshorstopCryptographic Inventory for a Post-Quantum World

RustCrypto/RSA

Branch
master
Commit
4a6006f
Committed
2026-05-15
Scanned
2026-08-29, 21:10
text scan · 33 of 74 files · submodules not scannedWhat was scanned

Scanner Shorstop 0.2.0 · text scan

Coverage 33 source files scanned of 74 in the repository; 11 skipped in test, vendored and build directories. What is excluded

Submodules this repository uses git submodules. Their contents are not included in the downloaded archive and were not scanned.

Findings are starting points for investigation, not a security assessment. How scanning works

Total Cryptographic Assets

330

Files Impacted

29

Quantum-Vulnerable Assets

60%

198 of 330

Deprecated after 2030, disallowed after 2035 — NIST IR 8547

Quantum-Safe Assets

15%

49 of 330

NIST-approved: FIPS 203 ML-KEM, 204 ML-DSA, 205 SLH-DSA

Quantum Readiness

Categories:

Post-Quantum Cryptography: NIST-approved PQC (Kyber, Dilithium, SPHINCS+)
Quantum-Safe Classical: Symmetric/hash with 256+ bit security (AES-256, SHA-256)
Quantum-Resistant Uncertain: Needs validation (AES-128, XMSS, some hash functions)
Quantum-Vulnerable: Broken by Shor's algorithm (RSA, ECDSA, DH)
Classically Weak: Broken TODAY (MD5, SHA-1, DES, RC4)
Unknown: Generic names, unidentifiable algorithms

By Algorithm Type

Algorithm Types:

Block Cipher: Symmetric encryption (AES, DES, ChaCha20)
Hash Function: One-way digest (SHA-256, MD5, BLAKE2)
Digital Signature: Asymmetric signing (RSA, ECDSA, Dilithium)
Message Authentication: MAC codes (HMAC, CMAC, Poly1305)
Key Derivation: KDF functions (PBKDF2, Argon2, HKDF)
Public Key Encryption: Asymmetric encryption (RSA, Kyber)
Public Key Cipher: Public key cryptography (RSA, ElGamal)
Key Exchange: Key agreement (ECDH, X25519, Kyber-KEM)
Authenticated Encryption: Combined encryption+MAC (AES-GCM, ChaCha20-Poly1305)
Extendable-Output Function: Variable-length output (SHAKE128, SHAKE256)
Other: Miscellaneous or unclassified algorithms

By Purpose

Purpose Types:

Encryption: Protect data confidentiality
Decryption: Recover original data
Digital Signing: Prove authenticity and integrity
Signature Verification: Validate digital signatures
Key Generation: Create cryptographic keys
Key Agreement: Establish shared secrets
Hashing: Generate message digests
Other: Miscellaneous or unclassified operations

Cryptographic Assets

Export

Cryptographic Bill of Materials (CycloneDX)

NamePrimitiveFunctionsFile:LineRisk
SHA-1-digesthashdigestsrc/algorithms/oaep.rs:14
Classically weak
SHA-1-digesthashdigestsrc/algorithms/pss.rs:34
Classically weak
SHA-1-digesthashdigestsrc/algorithms/pss.rs:109
Classically weak
SHA-1-digesthashdigestsrc/algorithms/pss.rs:180
Classically weak
SHA-1-digesthashdigestsrc/oaep.rs:37
Classically weak
SHA-1-digesthashdigestsrc/oaep.rs:66
Classically weak
SHA-1-digesthashdigestsrc/oaep.rs:110
Classically weak
SHA-1-digesthashdigestsrc/oaep.rs:123
Classically weak
SHA-1-digesthashdigestsrc/oaep.rs:333
Classically weak
SHA-1-digesthashdigestsrc/oaep.rs:380
Classically weak
Page 1 of 33
Shorstop reports automated source-code findings for investigation. Matches can include example code, commented-out code and non-production usage, and should be reviewed in context. Test directories, vendored dependencies and build output are not scanned. A Shorstop scan is not a substitute for a formal security assessment. How scanning worksFound an incorrect result? Report it.