[Rats] Re: Threat model and properties for remote attestation
Manu Fontaine <Manu@hushmesh.com> Thu, 13 August 2026 11:17 UTC
Return-Path: <manu@hushmesh.com>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 36F651291790C for <rats@mail2.ietf.org>; Thu, 13 Aug 2026 04:17:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786619849; bh=ZlqH96yGJ12Rl+oEKnndYpWFvxv1M2Az5vJQ69P8qic=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=yrxT4Gal8d5qJ/C9GWOeE+OvkgIQ6H+x+kmjxlbw4vsgD5NQ1KkLPrpVfo8b1/CgG RrAE0TwfIfwV4htSmAPhXzjQeWrM757SrAfWsCX2vJ1r1K/pvv32kXZuYAyNXD86ns 24mIihmAI/c3XOhjvKfmG2qY/+SH4awEMRot70+c=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=hushmesh.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pgMTeb7Zaow6 for <rats@mail2.ietf.org>; Thu, 13 Aug 2026 04:17:27 -0700 (PDT)
Received: from mail-ed1-x52e.google.com (mail-ed1-x52e.google.com [IPv6:2a00:1450:4864:20::52e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id B591F129178F6 for <rats@ietf.org>; Thu, 13 Aug 2026 04:17:27 -0700 (PDT)
Received: by mail-ed1-x52e.google.com with SMTP id 4fb4d7f45d1cf-6a0de062db5so3695440a12.1 for <rats@ietf.org>; Thu, 13 Aug 2026 04:17:27 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786619847; cv=none; d=google.com; s=arc-20260327; b=Ta/fwP2ndomU9BxyF5PqSXouYTDiMaVTnyOq4PD87RT9G7kmvPdsz/yFhrkxmtWiGD thtwJNVeO4HqhPL8hGtzJueRHjqMEgw369299H/RvuevKdwH7qlXHCFs6tBvAcHtxd/q NHCwhQXkmxhrFoCOsNWUw5DA1DZsTiU2WZL5tgQkX9j8WDEFEVKVnOP0IGi7w1V1ODfJ 9XZGBSfgzIYOrxUVG4pYFvVa+lSCZg0BMF9gHWh5MIh+/WdcriwI28yaaCVs7J6y9UyM dzY/Eo4p5ZT3RPnudxawdFY5YXNvAJuv2YY4kB6RllUVSDjAdbRB85UFyTuvLs4hg+i8 vHCw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=ZlqH96yGJ12Rl+oEKnndYpWFvxv1M2Az5vJQ69P8qic=; fh=GwmfhX9A9ShWtZUx3w8/9OfLMG6JD1jkt56L0pwVetA=; b=MEqmE/QFYbd8jUglhRdSjXK+j84tWets9NvLxOZXAesqXx9PdikcOuIf/vX5WBWD+s NQ7U2iM6hfCLGJoRYIZItNuJTas8J6rvF5d1jiCr0aStrOhBRewQIo/MwOMKrPsPwKJE U4Q4YoFHU8eJoDpaBUJxtJ8w3PQrh0ldp7j6HmDD3tD5ZYu4aieeVYMJTJkNDdWNDxlA /cje3rAazEAio4I7G+4yn7IglGPZLO2ag90+NTCqDsQA3AuUH4GybM1yKcD8bb/KMini 7JcOiQxUinZd+UsAbIlqrNCW1kmhCo+/dt5jD0E3F4SJPHwH/Mt6HFS27re8CHQ0aWlP fmWg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hushmesh.com; s=google; t=1786619847; x=1787224647; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ZlqH96yGJ12Rl+oEKnndYpWFvxv1M2Az5vJQ69P8qic=; b=MOJpCl4gnRM+uKkqR5LArnWqOKfHitnC8GCbw9pqUgXAzesDrWE6E1Qgvg+Wdi63M4 7HewsJctlRlIbQBzeXRyrebpGhPgNOgPRqtMcvzzpb7UxM4B5B1ZMU+ok3cqksWeu/Iz /vasgMgMmHYV05UBxrGRTnb6VfTe9QXGvqAfh7AxQ1/AdcPW2GHXaZJl5NaP6KMt7lv1 sA5RcZ27firgROR7xFtRm64RqUEZJTAqmIPZ+srUsFzBcx3CZQLyavxV6oAI3GC5+QMn Y5pMMC+qT2OlM/1MRDwKyewkPu6kOJwBQLr+QwsTs0EUFIjezKFywPXxsyyM+V6nmuOY DVHw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786619847; x=1787224647; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=ZlqH96yGJ12Rl+oEKnndYpWFvxv1M2Az5vJQ69P8qic=; b=fcYOhNWFxYuckYRAWIrDexogkKUkWN/ToCpokIzHZIw/8eQl5kdD+PuhsD/LJTW7N8 uBgtd+poOvK53t/RXiYOMXhFctN0O/Ft+RyL6xFNkPFgJ3Kls9BESplBtV9ItLRjtnCq xib2409JLiwwmlXB6W1JMNlV/J0RPJyjg3AEj9aSUP7O+AWQ0fYRh1vmMMGYuelMue47 mxyNjkDT9Ad1RcrnBtibgH7RchzBH7ofY7OqrV4/IlLLFw6EeWfSosb9ZUrH4V4Cdykf E/aWhbZAKiVmvNh4uep2gVqsVP+LuKdPWlIjA1iiTo3u+lDnJ5gb3wZGNhxnGtA8RlJS R7RQ==
X-Forwarded-Encrypted: i=1; AHgh+Rq5cUQ15q5HdgcwX+SrwBytQ32GyfMzrNiWEOn6TYhFuwW7/oxQiQSILg5DJUoBj1Sm+Bj0@ietf.org
X-Gm-Message-State: AOJu0YxmroHMWXrzioBkVmqHKHyYP5GCmvr1ghPDrQYuHQ2hj+smrF7e bWRXqhsyf1oU+uvRspfYXkQ4kpJG3X4WqXmuX60Kb1IFT+J4GuwwiM//Nnv4kl+OUz+FkOVmQnN DYgYbeH1GSHggQtysypWGI7ct/pJHB1LbJCv1dDC10w==
X-Gm-Gg: AR+sD11DIRuaMI9WrgmKWcQaq670uNezqSDrKS0CMAVzkR6qX5CaJHaYp+ZHuRBPaPv sd5V5ugNOKPXtn1fxiF2dOW+P+liyv1ik+SBnklTHXCsq0qdX/idPdDRMiaxu1BBLqZoKOPONkM BTxUH+Cj1kf+uPQHjah+P1QOtynErUg2nCfFU5pij2dxJDHYv9Eoyk59VwW6x496p6hvV6s/UV/ 1QKPOv+VizA5JvyY1Y+7skuVfpLMXC5BrKRvcdo//OBvbiPautTKSTM2q3eF7enGBnrQ6dVH69r fH3SXXT7GH2xn1ktsYmZOWgWVRVHVzUG1/HB2/PALCEL+qUCE6NA1zoOCAXK+Z1+eOgrE9TLmWP eNHEUZ4eaF6BhJb3TRmgH/XKuEKrT5bqIaEDhV1dUVPAtHtxAPnBZpaygoegOv+HVOqXuOAIMZB 9R2Mc9G8uWH75i3h2i
X-Received: by 2002:a05:6402:1f0d:b0:69f:2c1d:d83c with SMTP id 4fb4d7f45d1cf-6a3807300f1mr2783562a12.21.1786619846583; Thu, 13 Aug 2026 04:17:26 -0700 (PDT)
MIME-Version: 1.0
References: <fcec2ef9-4881-48a8-ba45-83e2b9110f3c@tu-dresden.de> <CAHxYnaMimQXVxaNLw89fnyUHUYfArcFeAjkEKnXp8h3w2+JoOg@mail.gmail.com> <CAEEbLAZ3zdgL_9i-h6Hxf_Mth6mNY188TN4QW9s2MceXax_0Tg@mail.gmail.com> <CAHxYnaM5gs_389oN0xOtbcwnL5nsRb0Op6hb3dCadi=sY_kdWg@mail.gmail.com> <CAK08nYZgvmjKv74ChRPoM-MbiR-GhuUhZr1aCPJFCKWtN1cF=w@mail.gmail.com> <CAHxYnaMDYhkZGvnSOgZfSvtUtfUfLAS3sydQok4R0c9fmF-VQw@mail.gmail.com> <CAEEbLAa21eKKemkT7KN_yWkLH0NeCDHP2Uz8aHPZiyMckQcYAQ@mail.gmail.com> <b19cc65f-1005-453b-b2f7-14784dd3fdf8@tu-dresden.de> <CAK08nYZ-OYPapNxOq6Aw7j4XXF85COh4sruBe4Uh3GCa74hv0g@mail.gmail.com> <CAHxYnaM2No9++gcvEVzR19ZdVS63iA80FqHEqs7z-ASk0S_aAw@mail.gmail.com> <CAObGJnNosSB9idBB=19QgEUMSFjERX=wS2Y6raB7HPvEYYaskg@mail.gmail.com>
In-Reply-To: <CAObGJnNosSB9idBB=19QgEUMSFjERX=wS2Y6raB7HPvEYYaskg@mail.gmail.com>
From: Manu Fontaine <Manu@hushmesh.com>
Date: Thu, 13 Aug 2026 07:17:16 -0400
X-Gm-Features: AUfX_mzWvs4uwmJOyG1K8ZzkFqUsV54gEpul8VJW9VqMs69shFOMpN1a0AK_1ss
Message-ID: <CAHu=PL3DFdpfpQk3q9MykZCrgd55UAOOAuRTUbLL+zJxO3L2xA@mail.gmail.com>
To: Thomas Fossati <tho.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000004df4fb0658ebd994"
Message-ID-Hash: 5VJFFHWPZ56IG7BQJ2CVVCSHFUNN2QYN
X-Message-ID-Hash: 5VJFFHWPZ56IG7BQJ2CVVCSHFUNN2QYN
X-MailFrom: manu@hushmesh.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-rats.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Nathanael Ritz <nathanritz@gmail.com>, Songbo Bu <bluedognull@gmail.com>, rats <rats@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Rats] Re: Threat model and properties for remote attestation
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/q7fpqaXdXsJ-uqpmu0_Co1OY69Y>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>
On Thu, Aug 13, 2026, 4:23 AM Thomas Fossati <tho.ietf@gmail.com> wrote: What confidential computing can achieve (if properly deployed) is... > Thomas, you tie what Confidential Computing capabilities to conventional deployment assumptions. When dealing with a technology that inherently shrinks the attack and trust surfaces of a hardware+software actor by orders of magnitude, the North Star should be to explore, design, and standardize a system around it that minimizes the degradation of that initial security posture, i.e. the entire system should be built the same way. From that idealistic blueprint, you can decide where current reality forces compromises. If RATS WG took such a complete system design perspective, it would see that there is a path that minimizes trust dependencies beyond what you state is possible. We know because we do operate a recursive and hierarchical network of "verifiers of verifiers", entirely built on CC, that does not have some of the trust dependencies you implicitly assume cannot be removed. I know that's not how the RATS WG works, and unfortunately it may lead some folks to conclude that CC has limitations that are, in fact, imposed by legacy deployment approaches, not the technology itself. Thanks, M
- [Rats] Re: Threat model and properties for remote… Nathanael Ritz
- [Rats] Re: Threat model and properties for remote… Thomas Fossati
- [Rats] Re: qualifying "confidential computing" (w… Ned Smith IETF
- [Rats] Re: Threat model and properties for remote… Manu Fontaine
- [Rats] Re: qualifying "confidential computing" (w… Manu Fontaine
- [Rats] Re: qualifying "confidential computing" (w… Nathanael Ritz
- [Rats] qualifying "confidential computing" (was: … Thomas Fossati
- [Rats] Re: qualifying "confidential computing" (w… Henri Sirkkavaara
- [Rats] Re: qualifying "confidential computing" (w… Manu Fontaine
- [Rats] Re: qualifying "confidential computing" (w… Thomas Fossati
- [Rats] Re: qualifying "confidential computing" (w… Nathanael Ritz
- [Rats] Re: qualifying "confidential computing" (w… Manu Fontaine
- [Rats] Re: qualifying "confidential computing" (w… Henri Sirkkavaara
- [Rats] Re: qualifying "confidential computing" (w… Michael Richardson
- [Rats] Re: Threat model and properties for remote… Mandyam, Giridhar
- [Rats] Re: qualifying "confidential computing" (w… Ned Smith IETF