[Seat] Re: [Ufmrg] Re: Re: Comments on formal analysis of relay attacks in attested TLS (CVE-2026-33697)
Dr Küçük Oxford University DPhil Computer S cience <dr.kucuk@oxfordalumni.org> Tue, 04 August 2026 18:43 UTC
Return-Path: <dr.kucuk@oxfordalumni.org>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 268321239AF63 for <seat@mail2.ietf.org>; Tue, 4 Aug 2026 11:43:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785869011; bh=nH0ynRImxjwRdsrMlIXhCZu9aqbPTMwZaqOQd6vG1Pg=; h=From:Subject:Date:Cc:To; b=jbeq3Nxlx/F2B8QJ/FC1vzzWsT1vw1zj02sm5DltlUtwDc5b/EHdpZoKq0jOx8oq2 u3lOTS8qwIKCXPNPhWKTJwStcixgj5pXTfHVWYf6+q45SHRqHJ154vI13Ofh64HEHq iM6iK9mxEz2QlVjl1wi/41FA077Rxp6EPgkwch0s=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=oxfordalumni.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LXljYFIjpjJV for <seat@mail2.ietf.org>; Tue, 4 Aug 2026 11:43:30 -0700 (PDT)
Received: from mta02.prd.rdg.aluminati.org (mta02.prd.rdg.aluminati.org [94.76.243.215]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E283A1239AF5C for <seat@ietf.org>; Tue, 4 Aug 2026 11:43:29 -0700 (PDT)
Received: from mta02.prd.rdg.aluminati.org (localhost [127.0.0.1]) by mta02.prd.rdg.aluminati.org (Postfix) with ESMTP id 4hF2Vd4q5Nz12n9 for <seat@ietf.org>; Tue, 4 Aug 2026 18:43:21 +0000 (UTC)
Authentication-Results: mta02.prd.rdg.aluminati.org; dkim=pass (2048-bit key; unprotected) header.d=oxfordalumni.org header.i=@oxfordalumni.org header.a=rsa-sha256 header.s=dkim header.b=MiQ78itG; dkim-atps=neutral
Received: from localhost (localhost [127.0.0.1]) by mta02.prd.rdg.aluminati.org (Postfix) with ESMTP id 4hF2Vd4gk0zMp; Tue, 4 Aug 2026 18:43:21 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=oxfordalumni.org; h=x-mailer:date:date:message-id:subject:subject:mime-version :from:from:received:received; s=dkim; t=1785868999; bh=nH0ynRImx jwRdsrMlIXhCZu9aqbPTMwZaqOQd6vG1Pg=; b=MiQ78itGAJGvYTe8oeL1vdkU0 8gAcLuLmVsw1fck9em2zXGvsc1XgZBKS9LUiNCguJqPRGNbIjuTKMUOEmlNd900O MIKzll8QdFeULsSa9bMjuC/DzByF4W90bqkmk1wPfoGWczAa52Au0O5xZEOtMa+u Tf621xuMkSS9PnaA/9vJqwcop5p2Fh/z33vmxHztmQ4g1WW4YtTYbpX3/mg+cAjO ia93a2InMtR73Zbnfj4RuEF/gL5nnhFrA2lOw/qVcTIFXQkRM5f7/yi1TIeYQFm1 v3D7SiQeihAfScWoT7BAIRJJbvVEHnVghd0EQlYHoXeZXV07AgxODkFug+wKA==
X-Quarantine-ID: <xkTRI_HNsZrb>
X-Virus-Scanned: Debian amavisd-new at mta02.prd.rdg.aluminati.org
Received: from mta.aluminati.local ([127.0.0.1]) by localhost (mta02.prd.rdg.aluminati.org [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id xkTRI_HNsZrb; Tue, 4 Aug 2026 18:43:19 +0000 (UTC)
Received: from smtpclient.apple (mob-194-230-148-63.cgn.sunrise.net [194.230.148.63]) by svc01-1.prd.rdg.aluminati.org (Postfix) with ESMTPSA id 4hF2VZ3bPpzFpTZ; Tue, 4 Aug 2026 18:43:18 +0000 (UTC)
From: Dr Küçük Oxford University DPhil Computer S cience <dr.kucuk@oxfordalumni.org>
Content-Type: multipart/alternative; boundary="Apple-Mail=_73C9DD4E-541F-476A-9F30-6CFA336563C2"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.700.51.1.1\))
Message-Id: <B27A940A-112D-4696-BB3D-A63F93BCD40D@oxfordalumni.org>
Date: Tue, 04 Aug 2026 20:42:57 +0200
To: seat@ietf.org
X-Mailer: Apple Mail (2.3864.700.51.1.1)
Message-ID-Hash: C4O7BWYXMUS5MOGPSQDAIMKCRNHE4YRH
X-Message-ID-Hash: C4O7BWYXMUS5MOGPSQDAIMKCRNHE4YRH
X-MailFrom: dr.kucuk@oxfordalumni.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Dr Küçük Oxford University DPhil Computer Sci ence <dr.kucuk@oxfordalumni.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: [Ufmrg] Re: Re: Comments on formal analysis of relay attacks in attested TLS (CVE-2026-33697)
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>
Dear all, I have reviewed the paper intra-handshake.fail, the accompanying draft (draft-intra-handshake-fail-01), and the artifacts of the formal analysis of relay attacks in attested TLS at commit 8ba77c5. I would like to strongly support this work and share a few comments. First, this paper has genuinely moved the field forward. The formal treatment of relay attacks in attested TLS gives the community a much stronger foundation for reasoning about these designs. The vulnerabilities existed for several years, yet manual testing, intuition, and audits had not discovered them. Second, the practical impact is significant: all vendors of intra-handshake attestation have acknowledged the attacks and have either published security advisories or archived the affected repositories (see Section 4: https://www.ietf.org/archive/id/draft-intra-handshake-fail-01.html#section-4) In addition, the vulnerable draft draft-fossati-tls-attestation has been withdrawn by its authors (see abstract and introduction: https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/10/) Third, the severity assessment speaks for itself — this is the highest-scored CVE in the history of Confidential Computing (see Section 5: https://www.ietf.org/archive/id/draft-intra-handshake-fail-01.html#section-5) Fourth, regarding the concerns raised by Nathanael in the recent thread (https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/) I found the authors' clarifications convincing and I support their responses. In my reading, the concerns do not identify a concrete gap in the formal analysis. Given the substantial body of work already established by Sardar et al. over the past decade, I believe the working group is better served by building on that foundation than by developing a parallel approach from scratch, and I would encourage collaboration toward that end. Finally, a question for the authors of the hybrid proposals (draft-fossati-seat-early-attestation and draft-ritz-seat-facts): which specific security property, as modeled in ProVerif, can the hybrid proposals achieve that post-handshake attestation alone cannot? A precise statement of this distinguishing property would help the working group evaluate whether the added complexity of the hybrid approach is justified. Thank you to the paper authors for this important contribution and for promptly addressing working group feedback. Best regards, Dr Küçük DPhil Oxford University https://www.cs.ox.ac.uk/people/dr.kucuk/ x-ETH Zürich dr.kucuk@oxfordalumni.org
- [Seat] Relay Attacks in Intra-handshake Attestati… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Iman Schrock
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Давид Nunhausen
- [Seat] Re: [Ufmrg] Re: Re: Comments on formal ana… rachid bouziane
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: [Ufmrg] Re: Re: Comments on formal ana… Dr Küçük Oxford University DPhil Computer S cience
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Nancy Cam-Winget (ncamwing)
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Nathanael Ritz
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Paul Wouters
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Nathanael Ritz
- [Seat] Comments on formal analysis of relay attac… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Steve
- [Seat] Re: Comments on formal analysis of relay a… Chengxin Huang
- [Seat] Re: [Ufmrg] Re: Comments on formal analysi… Song Haowen
- [Seat] Re: Comments on formal analysis of relay a… Mark Novak
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Mark Novak
- [Seat] Re: Comments on formal analysis of relay a… camilo ayerbe
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: [Ufmrg] Re: Re: Comments on formal ana… Salz, Rich
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… camilo ayerbe
- [Seat] Re: Comments on formal analysis of relay a… Song Haowen
- [Seat] Re: Comments on formal analysis of relay a… Chengxin Huang
- [Seat] Re: [Ufmrg] Re: Re: Comments on formal ana… Salz, Rich
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: [Ufmrg] Re: Re: Comments on formal ana… Steve
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Paul Wouters