Reading the bench
Reading the bench…Reading the bench
Reading the bench…post-quantum exposure desk · measured, not surveyed
A cryptographic inventory is a questionnaire, and questionnaires lie. Shorwatch reads the certificate a server is actually serving, checks how long that exact key has been sitting in public Certificate Transparency logs, and computes the date a quantum adversary breaks it — with every factor shown.
How a finding is produced
Shorwatch opens a real TLS connection and parses the SubjectPublicKeyInfo out of the DER. RSA modulus size, curve and algorithm OID are read from the bytes.
The exact SPKI fingerprint is matched against Certificate Transparency logs, which answers the only question a TLS probe cannot: since when has anyone been able to harvest this key?
Five weighted factors produce an exposure score and a projected quantum deadline. Every number is published, and the result is sealed with SHA-384.
Three jobs, done properly
Point at a host and get the key that is really in use, with its fingerprint and DER on record.
Set how long your data must stay secret and every deadline re-derives from the engine, so the first rotation is the one that actually matters.
Export an OpenSSL 3.5 hybrid configuration, a runbook with the deadline arithmetic, and a sealed JSON dossier.
Live sources, no API key required
node:tls against port 443 — the key comes off the socket, not a form
Cert Spotter issuances, matched by SPKI fingerprint
Google Public DNS, for CAA and address records
Shodan address exposure for the same host
Published anchors
RSA comparable security
1024→80, 2048→112, 3072→128, 4096→152 bits
NIST SP 800-57 Part 1 Rev. 5, Table 2Approved curve security
P-224/P-256→128, P-384→192, P-521→256 bits
NIST FIPS 186-5 and SP 800-57 Part 1 Rev. 5RSA-2048 factoring anchor
4098 logical / ~20,000,000 physical qubits in 8 h
Gidney & Eakerå, Quantum 5, 433 (2019)CRQ projection basis
2035 for RSA-2048, 7.7 years per modulus doubling
Interpolation anchored on the published RSA-2048 estimate aboveMigration lead time is a published assumption (3 years), not a measurement. Shorwatch reports measured facts and an explicitly published model. The cryptographically-relevant-quantum date is an order-of-magnitude educational projection, not a forecast, and nothing here is security advice. Validate every migration decision with your own cryptographic review and current standards guidance.