Reference
Standards, estimates and the model
Every number this application produces comes from one of the tables below. If a row is wrong, the app is wrong, and the citation is right there so you can check it.
Transition dates
112-bit public key
2030
Deprecated after this year: RSA-2048, P-224, 1024-bit finite-field DH.
All quantum-vulnerable public key
2035
Disallowed after this year, including the 128-bit-and-above levels.
112-bit-level symmetric
2030
3DES and SHA-1-family primitives go here.
Source: NIST IR 8547 ipd, Transition to Post-Quantum Cryptography Standards. Dates are read from the published transition tables; this app does not interpret them.
Scoring table
35 primitives, each with the NIST comparable classical strength, the security it retains against a quantum adversary, how broken it already is, and what replaces it.
| Primitive | Family | Classical | Quantum | Already weak | NIST deprecate | NIST disallow | Replace with |
|---|---|---|---|---|---|---|---|
| RSA-1024 | signature-public | 80 | 0 | 1.00 | 2030 | 2035 | ML-KEM-768 (FIPS 203)(FIPS 203, 2y) |
| RSA-2048 | kex-public | 112 | 0 | 0.10 | 2030 | 2035 | ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y) |
| RSA-3072 | kex-public | 128 | 0 | 0.02 | — | 2035 | ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y) |
| RSA-4096 | kex-public | 152 | 0 | 0.01 | — | 2035 | ML-KEM-1024 (FIPS 203), hybrid with X25519(FIPS 203, 3y) |
| RSA-2048 signature | signature-public | 112 | 0 | 0.10 | 2030 | 2035 | ML-DSA-65 (FIPS 204)(FIPS 204, 3y) |
| ECDSA P-224 | signature-public | 112 | 0 | 0.35 | 2030 | 2035 | ML-DSA-44 (FIPS 204)(FIPS 204, 3y) |
| ECDSA P-256 | signature-public | 128 | 0 | 0.05 | — | 2035 | ML-DSA-65 (FIPS 204)(FIPS 204, 3y) |
| ECDSA P-384 | signature-public | 192 | 0 | 0.03 | — | 2035 | ML-DSA-65 (FIPS 204)(FIPS 204, 3y) |
| ECDH P-256 | kex-public | 128 | 0 | 0.05 | — | 2035 | ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y) |
| ECDH P-384 | kex-public | 192 | 0 | 0.03 | — | 2035 | ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y) |
| Finite-field Diffie-Hellman 2048 | kex-public | 112 | 0 | 0.15 | 2030 | 2035 | ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y) |
| Ed25519 | signature-public | 128 | 0 | 0.02 | — | 2035 | ML-DSA-65 (FIPS 204)(FIPS 204, 4y) |
| X25519 | kex-public | 128 | 0 | 0.02 | — | 2035 | ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 2y) |
| ML-KEM-512 | kex-public | 128 | 128 | 0.00 | — | — | Keep ML-KEM-512(FIPS 203, 0y) |
| ML-KEM-768 | kex-public | 192 | 192 | 0.00 | — | — | Keep ML-KEM-768(FIPS 203, 0y) |
| ML-DSA-44 | signature-public | 128 | 128 | 0.00 | — | — | Keep ML-DSA-44(FIPS 204, 0y) |
| ML-DSA-65 | signature-public | 192 | 192 | 0.00 | — | — | Keep ML-DSA-65(FIPS 204, 0y) |
| SLH-DSA-SHA2-128s | signature-public | 128 | 128 | 0.00 | — | — | Keep SLH-DSA-SHA2-128s(FIPS 205, 0y) |
| MD5 | hash | 0 | 0 | 1.00 | — | — | SHA-256(FIPS 180-4, 1y) |
| SHA-1 | hash | 80 | 30 | 0.90 | — | 2030 | SHA-256 or SHA-384(FIPS 180-4, 1y) |
| SHA-256 | hash | 128 | 128 | 0.00 | — | — | Keep SHA-256(FIPS 180-4, 0y) |
| SHA-384 | hash | 192 | 192 | 0.00 | — | — | Keep SHA-384(FIPS 180-4, 0y) |
| HMAC-SHA-256 | mac | 128 | 128 | 0.00 | — | — | Keep HMAC-SHA-256(FIPS 198-1, 0y) |
| HMAC-SHA-1 | mac | 80 | 40 | 0.75 | — | 2030 | HMAC-SHA-256(FIPS 198-1, 1y) |
| AES-128 | symmetric-cipher | 128 | 64 | 0.05 | — | — | AES-256-GCM(FIPS 197 + SP 800-38D, 1y) |
| AES-256 | symmetric-cipher | 256 | 128 | 0.00 | — | — | Keep AES-256-GCM(FIPS 197 + SP 800-38D, 0y) |
| DES | symmetric-cipher | 56 | 28 | 1.00 | — | 2030 | AES-256-GCM(FIPS 197 + SP 800-38D, 1y) |
| 3DES | symmetric-cipher | 112 | 56 | 0.80 | — | 2030 | AES-256-GCM(FIPS 197 + SP 800-38D, 1y) |
| RC4 | stream-cipher | 0 | 0 | 1.00 | — | 2030 | ChaCha20-Poly1305 or AES-256-GCM(SP 800-38D / RFC 8439, 1y) |
| ChaCha20-Poly1305 | stream-cipher | 256 | 128 | 0.00 | — | — | Keep ChaCha20-Poly1305(RFC 8439, 0y) |
| PBKDF2-HMAC-SHA-256 | kdf | 128 | 128 | 0.20 | — | — | Argon2id or scrypt(RFC 9106 / RFC 7914, 1y) |
| PBKDF2-HMAC-SHA-1 | kdf | 80 | 40 | 0.60 | — | 2030 | Argon2id(RFC 9106, 1y) |
| bcrypt | password-hash | 128 | 128 | 0.00 | — | — | Keep bcrypt or move to Argon2id(OpenBSD bcrypt, 0y) |
| Argon2id | password-hash | 128 | 128 | 0.00 | — | — | Keep Argon2id(RFC 9106, 0y) |
| Math.random() for a secret | rng | 0 | 0 | 1.00 | — | — | crypto.randomBytes / secrets.token_bytes(FIPS 140-3 approved DRBG, 0.25y) |
Quantum resource estimates
Gidney & Ekerä closed form, RSA
logical qubits = 3n + 0.002 n lg n
Toffoli gates = 0.3 n³ + 0.0005 n³ lg n
| Modulus | Logical qubits | Toffolis |
|---|---|---|
| RSA-2048 | 6,189 | 2.62B |
| RSA-3072 | 9,287 | 8.87B |
| RSA-4096 | 12,386 | 21.03B |
At n = 2048 this yields 6,189 logical qubits, which is the figure the paper reports. The app converts logical to physical with a 3,232:1 ratio, taken from that paper's own 20-million-physical-qubit run, so the two numbers stay consistent with each other.
ECDLP, linear model
Published constructions for the elliptic-curve discrete logarithm problem are linear in the key length, so this app scales the anchor from Häner et al.: 2,124 logical qubits at 256 bits, or 8.297 logical qubits per key bit. No Toffoli figure is claimed, because the published counts for this problem span orders of magnitude depending on the construction.
P-256 → 2,124 · P-384 → 3,186 · P-521 → 4,323 logical qubits
These are literature estimates under stated assumptions, not predictions of a date. The app labels them as such everywhere they appear.
Engine hndl@1.0.0
Six weighted factors, summed to a 0-100 score and banded. The weights are constants in one file, and the same function runs in the browser, on the server, and inside the agent tools.
| Factor | Weight | Question it answers |
|---|---|---|
| Harvest-now-decrypt-later window | 0.26 | How long until ciphertext captured today is decryptable? |
| Quantum security strength | 0.22 | How many bits of security survive a quantum adversary? |
| Migration headroom | 0.18 | Is there still time to finish before NIST forbids it? |
| Classical weakness | 0.14 | Is it already broken without a quantum computer at all? |
| Dependency supply signal | 0.12 | Is the package maintained, and does it carry known advisories? |
| What this primitive protects | 0.08 | What depends on this key establishment or signature? |
Deadline arithmetic: work must start by H − (X + Y), where X is the years the data must stay confidential and Y is the migration lead time recorded against the replacement primitive. The chain is SHA-384.
Classifier nbc@1.0.0
A multinomial Naive Bayes model implemented in this repository. It has no weights file, calls no service and needs no key: it trains from a seed corpus of realistic call sites plus every correction a user teaches it, and the learned table is exportable. Training rows are sorted before counting so the model is deterministic.
Sources
- NIST IR 8547 ipd, Transition to Post-Quantum Cryptography Standards
- NIST SP 800-57 Part 1 Rev. 5, Key Management
- Gidney & Ekerå, How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits, Quantum 5, 433 (2021)
- Häner et al., Estimating the resource requirements of breaking ECC, PQCrypto 2020 / IACR ePrint 2020/1193
- FIPS 203, ML-KEM
- FIPS 204, ML-DSA
- FIPS 205, SLH-DSA
- Grover, A fast quantum mechanical algorithm for database search, FOCS 1996
- deps.dev package release metadata
- OSV published vulnerability records
- arXiv quant-ph / cs.CR current research
- NIST news standards announcements
This is an engineering aid, not an assurance or security advice. It does not certify a system as quantum-safe. Resource estimates are literature values under stated assumptions, not forecasts.
Ready to try it on your own code? Import a manifest.