[Seat] Re: Updated Attacker Model in SEAT Use Cases Draft

Nathanael Ritz <nathanritz@gmail.com> Wed, 19 August 2026 02:29 UTC

Return-Path: <nathanritz@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8950B12C05783 for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 19:29:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787106580; bh=j5fdA67QPsmIwxxLOJWKMjpk7Ba6at0xRxCsGJNKyh4=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=BMybP6M7s9nXFFv2+ftTkKjja7qN+aeYobC+oIcingSCXuGaGJ98FN4UeVypXtI4c tqvgd/PrNVXqzaq+i1d1CGYMeYGHElewxF3+idvU3lc4TDj0c202x4kEu+Gn92hnOO NG5GRGtNwp7U+5LUoRC40K1N2S5bQzHd7z522UE4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.087
X-Spam-Level:
X-Spam-Status: No, score=-2.087 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ijq2CdcaAynI for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 19:29:39 -0700 (PDT)
Received: from mail-pl1-x62b.google.com (mail-pl1-x62b.google.com [IPv6:2607:f8b0:4864:20::62b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id B5BD712C0577C for <seat@ietf.org>; Tue, 18 Aug 2026 19:29:39 -0700 (PDT)
Received: by mail-pl1-x62b.google.com with SMTP id d9443c01a7336-2d5cad1a6baso4233775ad.3 for <seat@ietf.org>; Tue, 18 Aug 2026 19:29:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787106573; cv=none; d=google.com; s=arc-20260327; b=dU3co22SL5aDQ0tV77AxtC5jJLD3943a2pAt4uL55Uu5L6KxzOX9nxfZ5pqZ1DHyB/ 1t+rPysvGpGBTtTFwXWs35piZvCsE4CrOsfGmzz/ZZk8oRor1B7n4lviOaKsX2hg9jOV GbHClrpk/f8n92GBIdv0OK42zQrZVfaW+z/43FpkLfQorrX3ltf0nR7UPxiKdaXMiu+w aE9JhRrqIYkJZaILJ4kJUm5uaN3CdMJUvg419vHxRy2w/8JFGL3XcUkKGYNgmHQ54U1Y pZ5X4tWr9ISNASPNpRXp4FXYfW4cuSnW0gtLkAZvoaAFO/jFpNm+0CjS9aOm4cGkj/ga vAdg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=j5fdA67QPsmIwxxLOJWKMjpk7Ba6at0xRxCsGJNKyh4=; fh=KwvdXt8FdG/tG+1+avIGuVI4z7A4xIoVcx0clDtACBw=; b=ZTjz7UHbmv2J6i301iR87GpC3XSZA75np3B0F9CJWf6EqzlIJ+niKUih2wa7JZRnLQ vsMbMOFUAtb7jVQwWZbFTwgoi24uCNzj4LuT1fqMg4zZp/UQQc36SevRMqR8TL5xgo2y X4sTpSuo2BecnitSyIyNoSganhQajesGYALh0IHLCaMSysPQN4A0Cj8FTPMnV6qe5wIG oKPXBHzSUje2Y34Ajdl2YzDbc2ewopAlKj9xkkiLDEKfJubqf7j3a9Oa6reREO/SsXG0 FoB/0fA3B/UtihuYVhaMeF2DYcnrBMcTkYgn5DP2wSCzovo/JW7pzPrqgWVSJfU6ypad ECtA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787106573; x=1787711373; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=j5fdA67QPsmIwxxLOJWKMjpk7Ba6at0xRxCsGJNKyh4=; b=PiLSPIzjlLVYajrQQcGn0ukgwn/mwxxweOleopG8K+IC5CRXs8PI63BDtN+bvLnols PxgRq0pPFiTPJ9N8EiCP3awguV/briXaDWXv8IwAsbUNCD+rVFwDl9Jkcteq5HkvOF8i 4RtBLyIVVbFoeiIrTPeUu/esOUjZA5hUG1tzNO5i4KSNG+uoOLr6TdFc/zif4ikSA6DI 8do8jkgyteMDue0cytxc+noxNFU5+UXpiDr4HDf8nWKyGA49n5OffRspA7QqBnRe2+uf R1s+b4SwyBS9TZW1EiRPmNhyBcFyM/dl2e+53YLUNPNUuuuDNhw64FK6fabtszi0Dqj0 Acjw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787106573; x=1787711373; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=j5fdA67QPsmIwxxLOJWKMjpk7Ba6at0xRxCsGJNKyh4=; b=KHzIE5WWVCJfPLrWzzHtEVglVxwt5FrW5NkYnt15NlLrgLrHKyToYNyzjQCnLDaVV2 Ib+kP2gUbXYcnDIjMu7tFf4qztf+VI9eXaOUqqdUO+ACzWMvSBOlxLO1DV4owMTF9rih f6sdR28hjzNbJor9xXEQy7KU9+G2emVcHcKFu/UlbMwdNQctdXrB7uVTr9GmcHg3EBXJ FsYntnRerQ+fJSlPMxMtdlAxXCisrA07a+HjTg+mHnYdncGB7v7wR5LrfxxgdLZpmz8F 2xCOeKdaBIhuzSJ+4gb1GqBfFp8CYa3xvy3Abk4hQXaszcguqw7A81+F8bWZtYKGXHBk zFxg==
X-Gm-Message-State: AOJu0Ywm8vYW5el1SwiT4AAMZhZga3YJWDItXSH4udtHOoDBLfhC08pp X6m630y/djVjMDVAvJRDQ8qfFGL3oUVNJhNN9ZhJ4dMjiVh53k+ZHxyy+cZkpFrNIY9EquuHU/6 6Cs+axsjC3WPKydPM51XTGn26D+Il/Wk=
X-Gm-Gg: AR+sD13f5F1vJqgKbU6V49DpRiI7aaJhbr062pdH+biD/Tw+6DGCfImVTKeAFr7mTuK W0A0XtKGyUKd8KkH3yMymhcbbJrJ9VCvdmNZZ1VbhURDHv4Kvhj1WKdpgwpKkGLbu9LYSNU6n8p i9XmvkGeCOUloKPhV2tV4/2Y685AeAhDk4eu832Rp59+AcaHVpgPbT6mSZjGbuunyaYcsbvkCO9 OwonPHRDsCX2AWr2heICNAhu6o7+ZK5TyySH9ZrarYjZuab1I4x6LVhfoZxUOd8oacUGIZ8q7VR qaep0sLD4x2AT6gUx4DYkXLIR/EWG8J07W2s3navRg8=
X-Received: by 2002:a17:90b:35d0:b0:38d:f94d:4c6e with SMTP id 98e67ed59e1d1-395810b5a0amr2652490a91.17.1787106572468; Tue, 18 Aug 2026 19:29:32 -0700 (PDT)
MIME-Version: 1.0
References: <CAFpG3gc1POcpcc0NCOFig=e1AgbeMpre2i++xdmXtQTpAp8vqA@mail.gmail.com> <CAK08nYaM7+2j7RgYduVRYEWkjGMYxeQNzHHWuPsbmP0hVDCC5A@mail.gmail.com> <CAFpG3gdvVTbUTCYGV7QWMM-YPctEk+oRL+jODshO3wLvAbPP7w@mail.gmail.com> <CAK08nYZkqacNmMMfyXYjGx-Nim__hA8O-VgsaMQ9D=E-rHq0Og@mail.gmail.com> <CAP3D6hLc-=yFdX8hqrimLTAsGRGtonhiW+oymBQ8g6jF8B56Cg@mail.gmail.com> <CAHxYnaO+cJHzL3sT+ngZoUgBZJxXUcosT13muhUvrnESeOqSOQ@mail.gmail.com> <CAK08nYZF2zftx3T1Gj7mGN8-5YcoL3akmfsY3-ODBDbojtdvuQ@mail.gmail.com>
In-Reply-To: <CAK08nYZF2zftx3T1Gj7mGN8-5YcoL3akmfsY3-ODBDbojtdvuQ@mail.gmail.com>
From: Nathanael Ritz <nathanritz@gmail.com>
Date: Tue, 18 Aug 2026 20:29:21 -0600
X-Gm-Features: AcwNN1U_kau82ILc_GB8rDWaUT3YIqqBz4z7oDCiyIWouRvk-ep0a2MppKm2OwA
Message-ID: <CAHxYnaOv4HCn4X6Oexdbpp=0jYj3i02mBAOjOWK1a=wpNdfUig@mail.gmail.com>
To: Songbo Bu <bluedognull@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000006d858f06595d2c92"
Message-ID-Hash: JDL3YWVYD4LWGUG5OCX6HN24GY2ZSXYG
X-Message-ID-Hash: JDL3YWVYD4LWGUG5OCX6HN24GY2ZSXYG
X-MailFrom: nathanritz@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: seat@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Updated Attacker Model in SEAT Use Cases Draft
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/VLf850IncIpuDMCz74Srw-Ot_IU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>

On Tue, Aug 18, 2026 at 7:28 PM Songbo Bu <bluedognull@gmail.com> wrote:

> Nathanael,
>
> Thank you. I want to provide a concrete proof. Davyd Okaianchenko has
> developed the "concrete, runnable Proof of Concept (PoC) for the attack"
> for CVE-2026-33697:
> https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/.
> I think it is not at all difficult to develop.
>
> Several news in China have confirmed exploit in the wild.
>
> Best,
> Songbo
>

First, the CVE description itself states that “exploitation requires the
attacker to first extract the ephemeral TLS private key, which is possible
through physical access to the server hardware, transient execution
attacks, or side-channel attacks.”

Second, the CVSS 3.1 vector indicates both “AV:L”, indicating the attack
vector is local and “AC:H”, which indicates attack complexity is high.

Third, it’s worth noting that the CVSS measures severity, not risk [*]. And
finally, again from the CVE description, it states clearly what the problem
actual was: “Because the attestation evidence is bound to the ephemeral key
but not to the TLS channel, possession of that key is sufficient to relay
or divert the attested TLS session.”

So, based on that, we should not expect a software demonstration of the
exploit to be hard to develop in a home lab. However, it appears it is another
thing altogether to actually succeed against a real CVM on real hardware.
In any case, all individual I-Ds proposed to the SEAT WG propose binders
that all tie directly to the per-session TLS channel already — complete
with available matching models that demonstrate their effectiveness against
the high severity impact that CVE-2026-33697 would represent under a
real-world hardware-based attack.

Cheers,
Nathanael

[*]
https://www.first.org/cvss/user-guide#CVSS-Base-Score-CVSS-B-Measures-Severity-not-Risk



>
>
> Nathanael Ritz <nathanritz@gmail.com> 于2026年8月18日周二 23:53写道:
>
>> Hi, some comments inline with [NR]:
>>
>> On Tue, 18 Aug 2026 at 07:16, Chengxin Huang <aurestarnull@gmail.com>
>> wrote:
>>
>>> [SNIP] I agree with Songbo that CVE-2026-33697 must be added. I also
>>> suggest to add a pointer to [Edgeless] advisory in attacker model. Both are
>>> wildly exploited and I don't see how proposed text covers both.
>>>
>>
>> On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote:
>>
>>> [...] On CVE-2026-33697: This is already exploited in the wild.
>>>>
>>>
>> [NR]: Despite repeated assersions of 'wild exploitation', SEAT recently
>> had another independent researcher stop by and specifically state that that
>> they "have not, however, been able to find a publicly available,
>> concrete exploitation trace or proof-of-concept demonstrating how the
>> attack
>> can be carried out against the actual CoCoS implementation." [0] My own
>> search has found a specific PoC for specific regressions related to new CVE
>> candidates including a post-TLS authenticator handshake example [1], but
>> such concrete tooling seems to appear in isolation. Finally, I think it's
>> also worth noting that NIST [2] appears to give CVE-2026-33697 an
>> exploitability score of 1.0 [3] and it appears Github suggests an
>> exploitability score of 1.1 for the same [4].
>>
>> On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote:
>>
>>> Therefore, please make it explicit in the threat model. I don't think
>>>> "cross-connection replay" is a standard term in the literature. I think
>>>> CVE-2026-33697 is related to relay and not "cross-connection replay".
>>>> Therefore, as a first step, making it explicit in the draft is useful for
>>>> further discussion.
>>>>
>>>
>> [NR]: If we are uncertain if we think CVE-2026-33697 is related to relay
>> and not 'cross-connection replay' or not, I suggest such details get
>> narrowed down before being put into the draft. Based on the sources, I
>> believe we should consider the practical impact of "Key Exchange without
>> Entity Authentication" and "Origin Validation Error" from first principles.
>> This is not because these are new risks, but because they are well
>> established in prior literature and represent long-standing concerns for
>> secure transport protocols. The mailing list is the right place to continue
>> these discussions.
>>
>> On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote:
>>
>>> [SNIP] On cross-connection replay handling: I think we can agree on
>>>> desired handling in this draft and solutions can then implement this.
>>>>
>>>
>> tirumal reddy <kondtir@gmail.com> 于2026年8月18日周二 14:26写道:
>>
>>> On cross-connection replay: how a solution detects and handles it (abort
>>> or otherwise) is a separate discussion for the solution drafts, not this
>>> document.
>>>
>> [NR]: As such, I agree with Tiru on the direction with this.
>>
>> Cheers,
>> Nathanael
>>
>> [0]
>> https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/
>>
>> [1] https://github.com/B1ueD0g/cocos-cve-regression-evidence
>>
>> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-33697
>>
>> [3]
>> https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-33697&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&version=3.1&source=NIST
>>
>> [4]
>> https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-33697&vector=AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N&version=3.1&source=GitHub,%20Inc
>> .
>>
>>
>> _______________________________________________
>> Seat mailing list -- seat@ietf.org
>> To unsubscribe send an email to seat-leave@ietf.org
>>
>