← cipherwake.io · All watchlists
Cipherwake watchlist

Domains Still Accepting RSA Fallback (Downgrade-Attackable)

Modern servers prefer ECDHE for forward secrecy, but many still accept RSA key exchange when an attacker manipulates the handshake. These domains are downgrade-attackable: a MITM forces RSA, harvested traffic from that session is decryptable with one stolen cert key. This finding is independent of quantum risk — it's a present-day exposure too.

# Domain Score Grade Sector Freshness
1 nordea.com 6.6 D verified 35h ago
2 energy.gov 6.5 D verified 35h ago
3 politico.com 6.2 D Global News & Media verified 35h ago
4 zoom.us 6.0 D verified 35h ago
5 sendgrid.com 6.0 D verified 35h ago
6 dwp.gov.uk 6.0 D verified 35h ago
7 ico.org.uk 6.0 D verified 35h ago
8 hyundai.com 6.0 D Global Automakers verified 35h ago
9 newrelic.com 6.0 D verified 35h ago
10 gov.uk 6.0 D verified 35h ago
11 ofsted.gov.uk 6.0 D verified 35h ago
12 apnews.com 6.0 D Global News & Media verified 35h ago
13 intercom.com 6.0 D verified 35h ago
14 twilio.com 6.0 D verified 35h ago
15 nyulangone.org 6.0 D verified 35h ago
16 honda.com 6.0 D verified 35h ago
17 rivian.com 6.0 D Global Automakers verified 35h ago
18 github.com 5.9 C verified 3h ago
19 stanfordhealthcare.org 5.8 C verified 35h ago
20 theguardian.com 5.8 C Global News & Media verified 35h ago
21 pennmedicine.org 5.8 C verified 35h ago
22 zendesk.com 5.7 C stale (6d old)
23 linear.app 5.7 C stale (6d old)
24 fbi.gov 5.7 C stale (6d old)
25 santander.com 5.7 C stale (6d old)

Don't want to be here?

Run the same scan we use for this ranking. See your specific findings, get the migration steps, and track the domain so you know when your score improves.

Updated nightly via Certificate Transparency log mining + active TLS probes. Public-surface measurements only — internal Blast Radius is typically 12–40× this score.
Methodology · Challenge a score · All sector leaderboards

Other watchlists