[Seat] Re: A Note on Allowing Vulnerability Reporting on the SEAT List

Chengxin Huang <aurestarnull@gmail.com> Wed, 02 September 2026 04:23 UTC

Return-Path: <aurestarnull@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 87D541338C9FA for <seat@mail2.ietf.org>; Tue, 1 Sep 2026 21:23:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788323037; bh=HxidMTHUzpjvZ07eFDKqQT9u4WY5ZcCnJQkvTRSfbyQ=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=eyrwJ9fi+0QyTAiS4HCiVaGmx7PKk17nWWIxbLJ1U1PDizgQQalAIGN2krEIqfDUh eWbGBiYIuX+kqjVsq2/14KLqVekF1zCHAhy0nLyXIlONlKg1MY9mbMYxNArFwrNxRV W5savSzoIA2uky9JUWLRWCYhia3ET6ve7KQOG0jQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uKMxAKMrzd7Z for <seat@mail2.ietf.org>; Tue, 1 Sep 2026 21:23:56 -0700 (PDT)
Received: from mail-pl1-x630.google.com (mail-pl1-x630.google.com [IPv6:2607:f8b0:4864:20::630]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CE09E1338C9F3 for <seat@ietf.org>; Tue, 1 Sep 2026 21:23:56 -0700 (PDT)
Received: by mail-pl1-x630.google.com with SMTP id d9443c01a7336-2cace91f112so5452465ad.0 for <seat@ietf.org>; Tue, 01 Sep 2026 21:23:56 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788323036; cv=none; d=google.com; s=arc-20260327; b=BKlHOuf+wL3MZ4Clzwc2lMSu4/6WSEzZPSBFIBjXcAqIdsWlLQvTBReF50MlIeNUSg 0jOkly2/1Wc8JbgaFds32goc2n87fnnlRTN1xc9GBBMv5YiRxZdjEqqHSBK70Nwua4GN s0dvaFka8DMwk63T830hAixu4Lptx7A1+PkS7LHfYYToyM2ZcTLv3yITszN9IKVjFMQn Tn4MDxac6wKzxhCfus9umL0Yw6FoRj7Wa3Lx0/17G7ffvjAXb2/dmkJxEYODSby6GaVB pOIhLOORoAYI7K2lJTRVm9ytqPlCcyCoEzt3dbmKDaJkNI70iZ11JUVpEH/Pkdje2fk3 b8ag==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=HxidMTHUzpjvZ07eFDKqQT9u4WY5ZcCnJQkvTRSfbyQ=; fh=aEILN/VGLbOaRIuekYGgiQMh1Af3RrIDyEWOTaJJtAU=; b=Rp9mQO8JO7/tI0GENatyOt8ZtUZZbk/L8yckNLmiBHYrzPGfKKbDL35lLKS5LwpAdz Dhth4nVhNnS8SjW33CwpCrL2p6oJcRKP2QyKDSGXttKECrwL3600f22UXdmxR1U4QJUm UIvfDB2gb6BJ2F6F7u9EsIJTGWu/5pPLNpyoUEyyY3bhVvc/wkR26TE0gEB8oZSAEOSn qfwKK5G/CHQZrKgjZoNn4zQHLlwVbYQGW1v8/mwHw46OyhHtaj3+lGeL7/IWeVgcwN8v Fy+Si1nP+Vehc342W7LxrJB1TPdyLu94dlvkuhbAhMQFErb7F4FQuceCzyeJvbA+Vny5 CMDA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788323036; x=1788927836; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HxidMTHUzpjvZ07eFDKqQT9u4WY5ZcCnJQkvTRSfbyQ=; b=ck5bLKzBI0SVmuqgzeEZ1FOSRnkBSrswiXxXPJ6V0nsG6VBmtIE4sSmZrTbPjwiO0o LIYTTcNcB2De60gNSPth0hkhhUSGvDu4Zp3+OTG2kNwShd6/ElqGzOxpnetYeJmFbfWq mD0exKPaoELuoWoExz8IxLL03SfW7jv/b6MJEoV38Uh6mu7dTfH4kmSI57pD/zO3mV9h KU4roWsGPRQZwjMSn++wPeEDxXS32oTkuxFx26jT/gC1dJIxQPC45Nz4xHlFvV8/TiiV AOeiZ8oDiDRTiip41L6PdSHrYQHeFa6wxLFgkwbjRpSVcO0qGTL1F0c303fGJ7LkNjmZ s3PQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788323036; x=1788927836; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=HxidMTHUzpjvZ07eFDKqQT9u4WY5ZcCnJQkvTRSfbyQ=; b=FBM/8DsZzfXZMQxF6gkXUhx6ba73VXNI1kWKxI77yBl+9bVrCS0qsQzhrIU4j2HRvi UPAlBR4NqurLEGeR+FWC4zbB3AdAhy9i3PGMdoRKEVSiw0/5DvluJTW//7S1vuiTV/Jg /x53mxRYQKifnVL1Ot0nhi04q2UC9d8OFaxlNRNasy6IRfjoSRRjBWHH/wt2s0XXrwRp 87406tYS8FSdm2I28Jby5cHKoTH90VMnWBXpINBobyLQVeWGQwHakz5dYzKnm6jp9QKF tpenOe/RGnrY2FOMYK1NqQN4gbyl+XMX/2pGdis0fI8uGpVw240xt/B5zH3KBPH9E+Qr mTDw==
X-Gm-Message-State: AFuF++mWTE3CPINM07DR11UZWMPQURPdsfqEw+FKyHvXBW7ljtkLh7LI RnZhFRHCgQKMfzH72F63tDuA35SXlsmmDE0lQjLhRhKSvm0wPFpnchGjJqEQLz+j5TzYkiJ0Z4e o5OoQ8JwBJ5EqjucKYDWqCXWoQxClfSkZ4nz1
X-Gm-Gg: AYBFou06S0/sbnoSU4jn4AbhU//ZMhXMlHk34rLkeg5f38zBMfkjR9tTiEXWDiq1mvH XXDYaqfc/ipOwNbV58WJUTb1tq6AQWzidWzxVDFEHB+qepAiiFV2ohEjRKPCmO0Fjblziyc4IMG 3a0YoMZWGnvHZ/ayFUsSOLPpdmHGSBb4/gYUM6D2gTbuAOBx9G+uhL2zImCPUWSa60eb9JmVJ+T 6y90pLYeSzJHjpFiuW1iKHDRbBdvm9qbFeMU8pGylnzW1tOAmattYNvnS5jBVJQYeJDmE+GyVbJ 1CrX06EifhVEZ8dRFP+rKc2srsFD8nqGMS5lHkwjuxvRfptV3Z9nhUWl+WiuRGt8F6Uf6Vr9+Hk nA8DabQ/wbIK4XBVmVysQhCv++Ik0ah2zjQon1eVEzJREiPYwIQvAZB6A6Lss
X-Received: by 2002:a17:90b:2e50:b0:398:b426:ca4b with SMTP id 98e67ed59e1d1-39aee1a9994mr3229168a91.22.1788323035707; Tue, 01 Sep 2026 21:23:55 -0700 (PDT)
MIME-Version: 1.0
References: <CADmRJY4d6rTWsFPDqzYJz9rX8SwtXmarT+NW8GhKhO2hiHr_qA@mail.gmail.com>
In-Reply-To: <CADmRJY4d6rTWsFPDqzYJz9rX8SwtXmarT+NW8GhKhO2hiHr_qA@mail.gmail.com>
From: Chengxin Huang <aurestarnull@gmail.com>
Date: Wed, 02 Sep 2026 12:23:26 +0800
X-Gm-Features: AcwNN1XxlsXQil4KXs3cxajfz5Z0yVFMQGL2VTgbxRqXE1W6i9kXi8ZowlYhtTY
Message-ID: <CAP3D6hL4XtwCGWOWT6f490hAvBtCmpyjWjrnyE05yZ7e38ZtXw@mail.gmail.com>
To: Steve <zhijieluo1022@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000497c08065a7867fb"
Message-ID-Hash: 6TWDRH3DEPF4243CLQT7IOJQSHHUDD5U
X-Message-ID-Hash: 6TWDRH3DEPF4243CLQT7IOJQSHHUDD5U
X-MailFrom: aurestarnull@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-seat.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "seat@ietf.org" <seat@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: A Note on Allowing Vulnerability Reporting on the SEAT List
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>

Dear chairs,

I agree with Steve and want to add my two cents too. I think if someone
finds a vulneability in attested TLS deployment maintained for 3.5 years,
it is relevant and welcome input for SEAT WG. I believe it should not be
given a warning, rather welcomed. It helps us all synchronise, learn from
the pitfalls and improve our mental and formal models.

I don't see anything promotional in the report or the email. As far as I
can tell right now, both GHSAs appear to be genuine and technical.

About the comments of WG individual, it is not "high-severity flaw".
Anything above 8.9 is critical-severity [cvss] and this one is 9.1. Yes,
the charter says "will allow per-connection freshness" and "will also
describe a minimum subset of properties" but what will get us there is
exactly this kind of vulnerability analysis. Conflating "aware of risk" as
broad as the charter statement and actually finding a vulnerability in a
concrete real-world implementation is a category error. I kindly ask the WG
individual not to equate their opinion to the WG opinion.

Best regards,
Chengxin Huang

[cvss] https://nvd.nist.gov/vuln-metrics/cvss

On Wed, Sep 2, 2026 at 9:55 AM Steve <zhijieluo1022@gmail.com> wrote:

> Dear SEAT chairs,
>
> I am not seeking to reopen the discussion but just to share my two cents
> here. The most valuable and practically actionable information that I and
> CSA-GCR have obtained so far from this working group is the practical CVEs
> and ProVerif artifacts that Sardar et al. have shared on list. With all due
> respect, I want to kindly ask that such reporting be allowed and welcomed
> on list.
>
> My rationale is the following:
> 1. Both advisories explicitly state [draft-fossati-seat-early-attestation].
> 2. It actually adds information because it is not only the claim of
> authors but rather statement and approval of cocos maintainers.
> 3. It is not clear to me what "SEAT working group's active specification
> work" and "working group's active work items" actually represent. There is
> no SEAT working group adopted draft for specification. My understanding is
> that use-cases will not contain specification.
> 4. Technically, the only difference between TLS's
> [draft-fossati-tls-attestation] and SEAT's
> [draft-fossati-seat-early-attestation] is the binder and re-attestation.
>
> This is not a request for the Working Group to adopt, validate or discuss
> the recent vulnerability report, but just that such reporting may be
> allowed because it is very helpful for us. In my humble opinion, such
> reporting rather deserves welcome, and surely not warning.
>
> Best regards,
>
> Steve Luo
>
> Research Analyst, Cloud Security Alliance (CSA-GCR)
>
>
> [draft-fossati-seat-early-attestation]
> https://datatracker.ietf.org/doc/draft-fossati-seat-early-attestation/06/
> [draft-fossati-tls-attestation]
> https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/
> _______________________________________________
> Seat mailing list -- seat@ietf.org
> To unsubscribe send an email to seat-leave@ietf.org
>