Skip to content

Education

Where cryptography hides: an attack surface map for PQC migration

Teams that inventory only public HTTPS miss most of the long-tail crypto their auditors care about. This map shows where quantum-vulnerable algorithms hide.

Cryptographic attack surface map diagram.
What Makes Quantum Computers SO Powerful? Watch on YouTube

Attack surface layers

Internet-facing          Internal / partner           Embedded & supply chain
─────────────────        ─────────────────────        ─────────────────────────
HTTPS / API TLS          mTLS between services        Firmware signing (RSA)
CDN cert chains          LDAPS / database TLS         Secure boot keys
Email STARTTLS           VPN (IPsec, WireGuard)       IoT device certs
JWKS / OIDC keys         SSH host keys                Container image signatures

NIST IR 8547 expects organizations to discover crypto across the full estate. The NCCoE migration project publishes discovery guidance.

Common blind spots

  • OAuth/OIDC JWKS endpoints serving ECDSA keys for token signing
  • SMTP STARTTLS on notification and claims systems
  • Backup encryption using RSA-wrapped symmetric keys
  • Third-party SaaS where you control policy but not implementation

NIST's PQC overview and Palo Alto's Q-Day guide emphasize breadth over depth on a single domain.

Inventory approach

  1. External TLS baseline (fast, high signal).
  2. Expand to JWKS, SSH, and email from asset lists.
  3. Merge into CycloneDX CBOM with provenance tags.
  4. Re-scan on change cadence — see crypto drift blog.

This quarter

  1. Map your estate against the layers above; mark coverage gaps.
  2. Run external scan + manual JWKS/SSH checklist.
  3. Export CBOM and assign owners per finding category.

Continue on the Q-Day hub: CBOM guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.