CryptoCensus: Cryptographic Posture and Post-Quantum Readiness of Docker Hub

Resumo


Under a draft schedule from the National Institute of Standards and Technology (NIST), affected systems would stop using Rivest–Shamir–Adleman (RSA) and elliptic-curve cryptography after 2035. Traffic recorded today can be decrypted once a sufficiently large quantum computer exists. How far published container images have moved toward standardized post-quantum algorithms has not been openly measured. CryptoCensus gives every repository in a 12,716,568-repository crawl the same chance of selection. We scan 11,962 images and catalog 4,211,380 certificates and key files. 100% are quantum-vulnerable and 0 are post-quantum. Although 801 images (about one in fifteen) include a library that supports post-quantum algorithms, none contains a post-quantum key or certificate. The images also contain weak cryptography. 43% of certificates outside trust-store paths use Secure Hash Algorithm 1 (SHA-1) or Message-Digest Algorithm 5 (MD5) signatures, 512-bit RSA keys remain, and 36 private keys in operational paths recur across distinct images. Docker Hub images have yet to begin their post-quantum transition, even where supporting libraries are installed.

Referências

Almeida de Jesus, J., Amaral, L. H. V., and Bonifácio, R. (2025). Cryptographic API misuses in industry: A case study on prevalence and remediation. In Proc. SBSeg Estendido, pages 417–425. SBC.

Bäumer, F., Brinkmann, M., Radoy, M., Schwenk, J., and Somorovsky, J. (2025). On the security of SSH client signatures. In Proc. CCS, pages 4619–4633.

CycloneDX (2024). Cryptography Bill of Materials (CBOM). [link]. Standardized as ECMA-424.

Dahlmanns, M., Sander, C., Decker, R., and Wehrle, K. (2023). Secrets revealed in container images: An Internet-wide study on occurrence and impact. In Proc. ASIA CCS, pages 797–811.

Docker, Inc. (2025). The World’s Largest Container Registry. [link].

Durumeric, Z., Adrian, D., Mirian, A., Bailey, M., and Halderman, J. A. (2015). A search engine backed by Internet-wide scanning. In Proc. CCS, pages 542–553.

Durumeric, Z., Kasten, J., Bailey, M., and Halderman, J. A. (2013). Analysis of the HTTPS certificate ecosystem. In Proc. IMC, pages 291–304.

Heninger, N., Durumeric, Z., Wustrow, E., and Halderman, J. A. (2012). Mining your Ps and Qs: Detection of widespread weak keys in network devices. In Proc. USENIX Security, pages 205–220.

Holz, R., Braun, L., Kammenhuber, N., and Carle, G. (2011). The SSL landscape: A thorough analysis of the X.509 PKI using active and passive measurements. In Proc. IMC, pages 427–444.

Kapelinski, C. and Kreutz, D. (2026a). A multi-scanner census of the Linux operating-system base images of Docker Hub. In SBSeg 2026. SBC.

Kapelinski, C. and Kreutz, D. (2026b). A uniform random-sample security measurement of Docker Hub images. In SBSeg 2026. SBC.

Kapelinski, C., Machado, B., and Kreutz, D. (2026). Vulnerabilities, secrets and misconfiguration in the highest-exposure Docker Hub images. arXiv preprint arXiv:2608.02669.

Liu, P., Ji, S., Fu, L., Lu, K., Zhang, X., Lee, W.-H., Lu, T., Chen, W., and Beyah, R. (2020). Understanding the security risks of Docker Hub. In Proc. ESORICS, pages 257–276.

Meli, M., McNiece, M. R., and Reaves, B. (2019). How bad can it Git? Characterizing secret leakage in public GitHub repositories. In Proc. NDSS.

Moody, D., Perlner, R., Regenscheid, A., Robinson, A., and Cooper, D. (2024). Transition to Post-Quantum Cryptography Standards. [link]. NIST IR 8547, initial public draft.

Mosca, M. (2018). Cybersecurity in an era with quantum computers: Will we be ready? IEEE Security & Privacy, 16(5):38–41.

NIST (2022). Transitioning away from SHA-1 for all applications. [link].

NIST (2024). Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography. [link].

OpenSSL Library (2025). OpenSSL 3.5 Final Release. [link].

Ott, D., Paterson, K., and Moreau, D. (2023). Where is the research on cryptographic transition and agility? Commun. ACM, 66(4):29–32.

Proos, J. and Zalka, C. (2003). Shor’s discrete logarithm quantum algorithm for elliptic curves. Quantum Information & Computation, 3(4):317–344.

SandboxAQ (2025). Introducing Open Cryptography: A Public Resource for Assessing Cryptographic Risk in Open-Source Software. [link].

Shi, H., Ying, L., Chen, L., Duan, H., Liu, M., and Xue, Z. (2025). Dr. Docker: A large-scale security measurement of Docker image ecosystem. In Proc. ACM Web Conf. (WWW), pages 2813–2823.

Shor, P. W. (1997). Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput., 26(5):1484–1509.

Shu, R., Gu, X., and Enck, W. (2017). A study of security vulnerabilities on Docker Hub. In Proc. CODASPY, pages 269–280.

Silverthorne, V. and Hendrick, S. (2025). Cloud Native 2024: Approaching a Decade of Code, Cloud, and Change. [link].

Sosnowski, M., Wiedner, F., Hauser, E., Steger, L., Schoinianakis, D., Gallenmüller, S., and Carle, G. (2023). The performance of post-quantum TLS 1.3. In Proc. CoNEXT Companion, pages 19–27.

Stevens, M., Bursztein, E., Karpman, P., Albertini, A., and Markov, Y. (2017). The first collision for full SHA-1. In Proc. CRYPTO, pages 570–596.

Strauss, J., Upadhyay, K., Siddique, A. B., Baggili, I., and Farooq, U. (2025). Assessing and enhancing quantum readiness in mobile apps. arXiv:2506.00790. Poster, IEEE S&P.

Turner, S. and Chen, L. (2011). Updated security considerations for the MD5 message-digest and the HMAC-MD5 algorithms. Technical Report RFC 6151, Internet Engineering Task Force.

Valenta, L., Cohney, S., Liao, A., Fried, J., Bodduluri, S., and Heninger, N. (2016). Factoring as a service. In Proc. Financial Cryptography, pages 321–338.

Westerbaan, B. (2025). State of the post-quantum Internet in 2025. [link].

Wist, K., Helsem, M., and Gligoroski, D. (2021). Vulnerability analysis of 2500 Docker Hub images. In Proc. SAM, pages 307–327. Springer.

Zerouali, A., Mens, T., Robles, G., and González-Barahona, J. M. (2019). On the relation between outdated Docker containers, severity vulnerabilities, and bugs. In Proc. IEEE SANER, pages 491–501.
Publicado
01/09/2026
KAPELINSKI, Cristhian; KREUTZ, Diego. CryptoCensus: Cryptographic Posture and Post-Quantum Readiness of Docker Hub. In: WORKSHOP DE TRABALHOS DE INICIAÇÃO CIENTÍFICA E DE GRADUAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 456-468. DOI: https://doi.org/10.5753/sbseg_estendido.2026.29735.

Artigos mais lidos do(s) mesmo(s) autor(es)

<< < 3 4 5 6 7 8 9 10 11 12 > >>