[Seat] Re: Updated Attacker Model in SEAT Use Cases Draft

Chengxin Huang <aurestarnull@gmail.com> Tue, 18 August 2026 13:16 UTC

Return-Path: <aurestarnull@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6552A12BA293B for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 06:16:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787058976; bh=HaJtwFBuBhoxKqk4C1al2O1EqmDZfGHiEDyqw8C+vIQ=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=HEO6ZMMUc1WaMcoscvlF34JBBxby+pRvIP1bhOe+1ChowtrDba3Qi03yhCi8AHod8 eoNNSvPdAkcrle+QuE1fbuH5/vzdB6FkWRbl72yiMIhZUQ/Ltt5UGpdoFyPovPJE07 WfdjnLJPl+y+Jjc5g7UzuSggu9brTRR6yxDIyoHc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.988
X-Spam-Level:
X-Spam-Status: No, score=-1.988 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_BOUND_DIGITS_15=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 52p1zOjQMD-G for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 06:16:15 -0700 (PDT)
Received: from mail-pj1-x102a.google.com (mail-pj1-x102a.google.com [IPv6:2607:f8b0:4864:20::102a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CC14A12BA2932 for <seat@ietf.org>; Tue, 18 Aug 2026 06:16:15 -0700 (PDT)
Received: by mail-pj1-x102a.google.com with SMTP id 98e67ed59e1d1-38d489b6b71so4679492a91.0 for <seat@ietf.org>; Tue, 18 Aug 2026 06:16:15 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787058975; cv=none; d=google.com; s=arc-20260327; b=LYYSmO2tVVcK+/XHdHUc3I4P3iNqnU9p4UoR8TiLHRgHyQWS4pnt8bAA6TSb553kc2 5hIRCEOqv7c5UyWQBqsr1+ylfy7WHCh5R/53hxOFcOb1RFp7F0KCBBsQVuJvghA7GX+1 zPySv+3jyQZ8ID1mFqgm1L4BAK8U+5w3b4yVDQ3Yo/FkiCB0tNdfAD3vmZCCAxhjrT8i IQ8SAuD9G6dd/zqD//ozP3X9zfx4w2cWM7o9o8hNQt5cp0Q6vfJ1l2/vdfwBo+M+D8Ut cAqk0I075/dejm8aQatMNzkHM12oUoU7ivOUAdF9gGDGuRxmkuvaHCP2qb4Fgh/0jYU2 J7AQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=HaJtwFBuBhoxKqk4C1al2O1EqmDZfGHiEDyqw8C+vIQ=; fh=HAmqswYJ8kySjaQtGOefMCkCUHlu1c/4MWfkTua4WDk=; b=b4QZA6L21IjtXN4PyW5Zy6a0wiP8Xa4X4O/gigq4CCI/+62gFuDdjPvkzPlcTJNU2x mQTRgroNlawdd/a0f8JHp3Bm1yVJguxNfP/dAe6iLmsiAZXMgGC9sHZtwbLMuldyhjcT 4a0etCnjLW+0Y37kxc9zAcaqAEwooBH+AuxQSnZbikuYj1Fr4X0Wh3Ojcr2jwXrz7eFz zJA1rHVYhfY3HKoE+0wLHvTxQEq+3Yf1ibc7YPvjfaQnEPfA3bsHHu5wS5itl3FvXuwq Rh21355yUw9wA4QLfhi/jtptlQYqhmQw+zh1LABsfW2eCxH9Clw5kZIY/Kmy4ALlSEI/ IbGw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787058975; x=1787663775; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HaJtwFBuBhoxKqk4C1al2O1EqmDZfGHiEDyqw8C+vIQ=; b=KQlDFchUZMRCG/+1zBj2JmPEXmCvRXK0otaYpFpWx+5UlghBUBjyp5aFX7h9rP+Ss7 yctzaW+f8/mwlf7U3MDIhQaWWVjdZ8uY9Oc4BKM1WTEPmb4GIN69KNIq8AXUGfrUSX56 yqw9S/KA75wKQn2MLSUO7RSx9W7lvynElLhdv19O4+8qS4JB9ofiXL+h55H0mNWxllYk 1w44BCTSA6EbF/pqDYCbujHI6nHv0y7WrvUMXg0xmQQ2rASF+2IucCscrZS8gL3DkNFv lyAOlu8uPwfqUbpmQMRZTZAaVZ+thIFq4H54OD9piu+Ka+ZS6DHy6h0fe7qxWulEk+y2 Cz2Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787058975; x=1787663775; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=HaJtwFBuBhoxKqk4C1al2O1EqmDZfGHiEDyqw8C+vIQ=; b=mPFVywY5RlhblarZsHgf6E/cGIy/B7cljIVlaB7Ehj7FigbZKK/niUER/79hMqjY0P RB2WFdlw4E6r2PGYIxJqZX9T64hicqtZkri71a/mE1mQPA3K2u55O+ysEb5s/DmJ/zHm m5s5cKCNxGZrNc4UVWQv2Gua5prYQa887iQidvwUID+m6kgunK3/9W7rMPxJ7ZsM/bL9 yToYvrrQH35y8Xb+8CW1BWcatPve/QMKDFZVFq8ueYyQikf2O8/ucaxlIzc0F//bGZgn eMYCFLKwZ/jFBd/EFTCb3QXy07mQWKHDTLaYZm3dxJ0AxacEHmtlgQDQU3vcFsfqujor jm4A==
X-Forwarded-Encrypted: i=1; AHgh+RqlC5V40J/kcxd8SuTHkysc7hBx2on3MJHtYBUS8HYkiq02l+w3pIXhciaJLbki+FAQP00g@ietf.org
X-Gm-Message-State: AOJu0YyntbwbPTENXPDmQOVijq2mICFvxxJCNCJiUPbRZPHEATsrBhvb 9Y50di2rC0SKSQ/HkA1/Kk2YR/XzbMJpYjBUTXD8tPEZqSCcGS9WsRqPNhjpYIcj1DnWopFGy8D 33AKl+sUOKTv6ja/xTvSviMjOw1rPqqBrNzQWNk5/gw==
X-Gm-Gg: AR+sD11OPsbsp2LMckWXmDcF/K7jcAYc2ysSmrxKZzyG3nRaMwz5qCwbdX1ZMKCvbw3 k5IxTFHuATvPD/rkMs+f8XImZUoNc9d+6J07C0GbH+ggGUJ0U3qhQUk9J85K1S7J7D8vfTFOfMm 3OiqtiUJeYyai7DBaw6w1Egj2flnumlsBuKuszCSVqrH/1mi/84loczz2wS8Y2DC6uGCl+xVcXC BgWGn8CQp+SwIVHhcB6/P69b61uhwDkg9o8pGFXSGjhDTvKNmkAi+mocUS0TVIQHM+1DqgKoVlX 4/RqmG32ExkueNpteeQhpzwq5OeP+Deoo/INWvxFd56QiYg=
X-Received: by 2002:a17:90b:314a:b0:395:5404:95 with SMTP id 98e67ed59e1d1-3955a79c987mr10120330a91.12.1787058974768; Tue, 18 Aug 2026 06:16:14 -0700 (PDT)
MIME-Version: 1.0
References: <CAFpG3gc1POcpcc0NCOFig=e1AgbeMpre2i++xdmXtQTpAp8vqA@mail.gmail.com> <CAK08nYaM7+2j7RgYduVRYEWkjGMYxeQNzHHWuPsbmP0hVDCC5A@mail.gmail.com> <CAFpG3gdvVTbUTCYGV7QWMM-YPctEk+oRL+jODshO3wLvAbPP7w@mail.gmail.com> <CAK08nYZkqacNmMMfyXYjGx-Nim__hA8O-VgsaMQ9D=E-rHq0Og@mail.gmail.com>
In-Reply-To: <CAK08nYZkqacNmMMfyXYjGx-Nim__hA8O-VgsaMQ9D=E-rHq0Og@mail.gmail.com>
From: Chengxin Huang <aurestarnull@gmail.com>
Date: Tue, 18 Aug 2026 21:16:02 +0800
X-Gm-Features: AcwNN1WbBv14aGw7i4SEEdxgNfYmZNoWkIqjYARGnCKIkGOHUDhuIBIZ5HjDS0E
Message-ID: <CAP3D6hLc-=yFdX8hqrimLTAsGRGtonhiW+oymBQ8g6jF8B56Cg@mail.gmail.com>
To: Songbo Bu <bluedognull@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000006242360659521742"
Message-ID-Hash: OX4CSEI3L3XNMXB4CKGSH3QCXVBDPKQW
X-Message-ID-Hash: OX4CSEI3L3XNMXB4CKGSH3QCXVBDPKQW
X-MailFrom: aurestarnull@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tirumal reddy <kondtir@gmail.com>, seat@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Updated Attacker Model in SEAT Use Cases Draft
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>

Hello everyone,

My feedback is not welcomed on SEAT but I agree with Songbo that
CVE-2026-33697 must be added. I also suggest to add a pointer to [Edgeless]
advisory in attacker model. Both are wildly exploited and I don't see how
proposed text covers both. Making both explicit will help ensure everybody
agrees what is talked about and constructively move forward, following the
[advice] of Dr. Schmieg. If we don't account for the wild exploits in the
attacker model, nobody will use the SEAT protocol we are designing.

Best regards,

Chengxin Huang

[Edgeless]
https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h

[advice]
https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/

On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote:

> Tiru,
>
> Thank you for the answers. I want to followup more narrowly.
>
> The link between the following is missing:
> Threat model => Security goals
>
> The following section is missing:
> Formal properties
>
> On cross-connection replay handling: I think we can agree on desired
> handling in this draft and solutions can then implement this.
>
> On CVE-2026-33697: This is already exploited in the wild. Therefore,
> please make it explicit in the threat model. I don't think
> "cross-connection replay" is a standard term in the literature. I think
> CVE-2026-33697 is related to relay and not "cross-connection replay".
> Therefore, as a first step, making it explicit in the draft is useful for
> further discussion.
>
> Best,
> Songbo
>
> tirumal reddy <kondtir@gmail.com> 于2026年8月18日周二 14:26写道:
>
>> Hi Songbo,
>>
>> Right now the focus is to capture all the relevant threat vectors. Formal
>> properties come later, after the WG concludes on the attacker model, attack
>> vectors and security requirements.
>>
>> On cross-connection replay: how a solution detects and handles it (abort
>> or otherwise) is a separate discussion for the solution drafts, not this
>> document.
>> On CVE-2026-33697: it is an instance of the cross-connection and relay
>> class already covered in the PR. What is it you would like to see
>> covered about it in the draft ?
>>
>> Best Regards,
>> -Tiru
>>
>> On Tue, 18 Aug 2026 at 07:39, Songbo Bu <bluedognull@gmail.com> wrote:
>>
>>> Tiru,
>>>
>>> Thank you. I have one narrow suggestion and two questions.
>>>
>>> I think the draft's flow could be:
>>>
>>> Threat model => Security goals => Formal properties
>>>
>>> The draft does not currently state the desired behavior when the
>>> server attempts a "cross-connection replay." Should the connection be
>>> aborted?
>>>
>>> How is CVE-2026-33697 covered by the threat model?
>>>
>>> Best,
>>> Songbo
>>>
>> _______________________________________________
> Seat mailing list -- seat@ietf.org
> To unsubscribe send an email to seat-leave@ietf.org
>