[{"data":1,"prerenderedAt":135},["ShallowReactive",2],{"blog-index":3},[4],{"id":5,"title":6,"author":7,"authorTitle":8,"authorUrl":8,"body":9,"canonical":8,"category":95,"date":96,"description":97,"draft":98,"extension":99,"faqs":100,"findingsSource":8,"howto":8,"howtoTitle":8,"image":107,"keyFindings":8,"meta":108,"modified":96,"navigation":109,"path":110,"pullquote":8,"recommendations":8,"references":111,"related":8,"seo":121,"signposts":8,"slug":122,"stats":123,"stem":126,"tags":127,"tldr":133,"__hash__":134},"blog\u002Fresources\u002Fblog\u002Fseven-places-quantum-crypto-hides.md","The Seven Places Quantum-Vulnerable Cryptography Hides","ArcQubit Team",null,{"type":10,"value":11,"toc":88},"minimark",[12,17,21,25,72,76,79],[13,14,16],"h2",{"id":15},"the-answer-up-front","The answer, up front",[18,19,20],"p",{},"Quantum-vulnerable cryptography does not live in one place. It is scattered across seven distinct surfaces of a modern software stack, and the reason most organizations underestimate their exposure is simple: the tool they use inspects one surface and reports it clean, while the other six go unexamined.",[13,22,24],{"id":23},"the-seven-surfaces","The seven surfaces",[26,27,28,36,42,48,54,60,66],"ol",{},[29,30,31,35],"li",{},[32,33,34],"strong",{},"Source code."," Hardcoded algorithms, key sizes, and cipher suites written directly into your application.",[29,37,38,41],{},[32,39,40],{},"Dependencies."," Cryptography pulled in transitively through libraries you never audited.",[29,43,44,47],{},[32,45,46],{},"SBOMs and CBOMs."," The declared inventory, which is only as accurate as the process that generated it.",[29,49,50,53],{},[32,51,52],{},"Certificates."," TLS and code-signing certificates whose signature algorithms quietly age into risk.",[29,55,56,59],{},[32,57,58],{},"Infrastructure."," Load balancers, service meshes, and managed services terminating cryptography outside your code.",[29,61,62,65],{},[32,63,64],{},"Binaries."," Compiled artifacts where the algorithm is baked in and invisible to a source scan.",[29,67,68,71],{},[32,69,70],{},"Runtime tokens."," JWTs, session tokens, and signed payloads generated and verified live in production.",[13,73,75],{"id":74},"why-single-surface-tools-mislead","Why single-surface tools mislead",[18,77,78],{},"A scanner that reads only source code will pass a repository whose real exposure lives in a five-year-old certificate or a vendored binary. The clean report is worse than no report, because it creates false confidence. Credible discovery has to span all seven surfaces at once.",[18,80,81,82,87],{},"Run ",[83,84,86],"a",{"href":85},"\u002Fqucode","QuCode"," to see where quantum-vulnerable cryptography actually lives in your stack.",{"title":89,"searchDepth":90,"depth":90,"links":91},"",2,[92,93,94],{"id":15,"depth":90,"text":16},{"id":23,"depth":90,"text":24},{"id":74,"depth":90,"text":75},"Security","2026-07-08","Quantum-vulnerable cryptography hides across seven surfaces of your stack. Here is the field guide, and why single-surface scanners leave you exposed.",false,"md",[101,104],{"q":102,"a":103},"What does it mean for cryptography to be quantum-vulnerable?","It means the algorithm can be broken by a sufficiently large quantum computer. RSA and ECC are the primary examples, because Shor's algorithm defeats the math they rely on.",{"q":105,"a":106},"Why isn't one cryptographic scanner enough?","Because vulnerable cryptography appears on seven different surfaces, from source code to runtime tokens. A scanner that only reads source misses certificates, binaries, and dependencies entirely.","\u002Fassets\u002Fblog\u002Fseven-places-quantum-crypto-hides.png",{},true,"\u002Fresources\u002Fblog\u002Fseven-places-quantum-crypto-hides",[112,115,118],{"label":113,"url":114},"NIST FIPS 203","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Ffips\u002F203\u002Ffinal",{"label":116,"url":117},"Executive Order 14412 (2026)","https:\u002F\u002Fwww.whitehouse.gov\u002Fpresidential-actions\u002F2026\u002F06\u002Fsecuring-the-nation-against-advanced-cryptographic-attacks\u002F",{"label":119,"url":120},"UK NCSC: Timelines for migration to post-quantum cryptography","https:\u002F\u002Fwww.ncsc.gov.uk\u002Fguidance\u002Fpqc-migration-timelines",{"title":6,"description":97},"seven-places-quantum-crypto-hides",[124,125],"Most cryptographic scanning tools inspect a single surface, leaving the other six unexamined (ArcQubit, 2026).","Government mandates worldwide set post-quantum migration deadlines between 2030 and 2035 (U.S. EO 14412, EU roadmap, UK NCSC).","resources\u002Fblog\u002Fseven-places-quantum-crypto-hides",[128,129,130,131,132],"post-quantum cryptography","cryptographic discovery","cryptographic inventory","SBOM","primer","Quantum-vulnerable cryptography hides across seven distinct surfaces, and most scanning tools inspect only one of them.","devewd3D-ZCRZoF6aIF2LDusIhAGU4k6BfirgHA-ON0",1784747239437]