[Seat] Re: Updated Attacker Model in SEAT Use Cases Draft

Nathanael Ritz <nathanritz@gmail.com> Tue, 18 August 2026 15:53 UTC

Return-Path: <nathanritz@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D926812BC3CFE for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 08:53:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787068431; bh=nWoywLNR/rMx/6Mn/WuUgf2zpyPUtDg2s1RiUtDmnIc=; h=References:In-Reply-To:From:Date:Subject:To; b=x2aBqVpaU2gWmR+4ANxnxjDx774OMOR/Yw4UxHtHkJVovnYk0Oq3FuK8X70mPMiX0 Fx5aWVr5lzjxxd3crwKd4HY4XAg/Opu6Q8oQxOBB07yeN/9ymF276SpwsamxSCMYF+ KYFvVTt703tVhCaIACmUUbPaZ895SAHHdbyL7gqE=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kTMNLtvEPKqz for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 08:53:51 -0700 (PDT)
Received: from mail-ed1-x534.google.com (mail-ed1-x534.google.com [IPv6:2a00:1450:4864:20::534]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 1414A12BC3CF7 for <seat@ietf.org>; Tue, 18 Aug 2026 08:53:51 -0700 (PDT)
Received: by mail-ed1-x534.google.com with SMTP id 4fb4d7f45d1cf-6983d3dae7aso1896353a12.0 for <seat@ietf.org>; Tue, 18 Aug 2026 08:53:51 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787068430; cv=none; d=google.com; s=arc-20260327; b=IGebElCHFqgOVTTbVbRsCyfGPsLo2svy2/3gYVHwG9YsySaGM2fGHmXULZK66Losrd ICFvuE6HccDPUeaJnYmCXu+KURN7E+J4yYhh5OsH1bxNrjiwU6btqMMYjxlJgqQ3lggB 9Xwc9QNMHO1+pImvH9jeLm7fHsTyJ9owdFqOOjFxjfnXQZkxKDQF2cQisAIvqUqV2SvV ltRENAVORjYI2GSDLjAAWnJ2fKdagSjz7mLwIX1LQfibcfi/y5Oyv+miQlfr/t28Eb5U ep8//6xU7OTGqtqBG5iMvgmd0rAGeSvvmGy81lQiIbddH2Wg9z0qEzTAsTRY+avSM23f HC8w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=nWoywLNR/rMx/6Mn/WuUgf2zpyPUtDg2s1RiUtDmnIc=; fh=nonanup7af3odSacD+avaZXzPkTQ1Kb/ongJHX+6ikI=; b=TQulBf5MuOK6xlIXcqz1Qu4ZQOx/UT+QZSqkyym4eUrimbL14LH53sM01DNYxxD564 egOtTQxMoyxSBipvC5cf7lHUaoMgpy6sQzK8ctDdD3zDMQmw/xEoAZYdELB5EDi7QRUU 9g1imTLMN1t3EfvUDsUFrJ1wHONjA38ZmNlJkqnBp+TCH1kMvyJs6LpHOkW16/fnr4k6 7dhjapmgd5lEfWXKcQXBRAhWGv6b9iddwNfPDFDcfZLiTcFLMLruVi2OxKg83aDYtcxj 7/JJibNnEoX/u57pAHPx8DyMeAOzxq3X86bB8jHBQ8CM0Dt5fwQD7aRz6n6n2vaRV2xP 3jkQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787068430; x=1787673230; darn=ietf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=nWoywLNR/rMx/6Mn/WuUgf2zpyPUtDg2s1RiUtDmnIc=; b=JOeFD1+rOmZx6vMHKpHC6bjiYgRyR0OxDNLbpWH7It99xSIUw6FcYUZ7uDPJaMohSj 2fBjTJ59fKoNDV4kcc6iUS6lUWS4hWajkDW/dAqgk/Kh4DfqTS/2GGnJjqLsoKamaKRs logsNIdzbYxcal8MWuWcprAxx/fBIyyRa9eA7xTC9Rtj+npc7D4lCGBJfBjqrff2XJik /ndZeZsoHSo2tK0rlujhKBB1e5KSRXOUfkw3Q1pc5aM42fZDf1zoUeSZRsRjnc/CNbyj VHc7niHXS+ZZIYlJcS0J7gj2mk4tBuyHuoIoPnTJt2FHxc2/T41N/YAulOf22ptjgjro v9uw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787068430; x=1787673230; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=nWoywLNR/rMx/6Mn/WuUgf2zpyPUtDg2s1RiUtDmnIc=; b=RAfz4NgDsR1tSV9qftJuVJCFZpPqcaGzkcjhnvbIeJapC95RephRYWLkM/glU+X5AA SyMpaMzAaEygibYxDkzOsLF6RFRDM6ewW8MZgh2l7vn8G2iWqILeWin/bKRt1N9Wta9k a7Y0S9BDKP53Ebj4rwwQxgSclIVD5wW9ElcHiKFthGyuV4W1LAPQnXkujE0/5xMP/TGP oAw+ZFH4eN3hC7IjooxFlBiefXKAzYJrhEwz7wxbXMAcHKQ23QTDnJlKHrqDq0yJuypd Qzx9+2Sr2Gi8n7h6e2de4E4dS1XnqZJzxHvhp6w0sP4bObiKlxYPyiFPbBdzMhNgOAAR KenQ==
X-Gm-Message-State: AOJu0YzaAp5JdBnFXsoYfmZj//xYWC8U32wn0dKxaQ6r1askCRmdLtGA 1Gy+SmVyU6FPoJe6suQPVG2z0mV8Z7Xr/oW8l98hXrqikTpw3yVKczTyKHFfXS3V2haI622UMQB hu1Y1872GRmfE1iHElsxcp3YjbX8LPxJlvg0F
X-Gm-Gg: AR+sD13+Z37GTuWRnxelH6UAuNmkq3zR2MSK6x8IA/lq1Xoc6I2zqb44xTfu/yWr3EU s8zWk+AbXX6+iNk564wJJxS2AnnKFyVSKrJM2HAS9jA2gsGTxqcM14Mb73A4RRz1VRmLN65VB5u m6ls3ChuBCdvxosNyae7mmvrXFmeg5WitT2CwufZHiqcOK5CUyByEmqFw/7G/s78TealiHTKhRo 9rsJjbuF/pXNknN6RZl1mbsI8Quolnb0cyLAEg1zcTJ8w65zxB6PV/I/4uuVTu5oV7APk/RubsE vIc2xfPduyrn3tenLVqnUaCpVtegHvbycIZYA3XUXh8=
X-Received: by 2002:a17:907:d0d:b0:c20:fd32:d9f5 with SMTP id a640c23a62f3a-c218b186199mr468191166b.13.1787068429825; Tue, 18 Aug 2026 08:53:49 -0700 (PDT)
MIME-Version: 1.0
References: <CAFpG3gc1POcpcc0NCOFig=e1AgbeMpre2i++xdmXtQTpAp8vqA@mail.gmail.com> <CAK08nYaM7+2j7RgYduVRYEWkjGMYxeQNzHHWuPsbmP0hVDCC5A@mail.gmail.com> <CAFpG3gdvVTbUTCYGV7QWMM-YPctEk+oRL+jODshO3wLvAbPP7w@mail.gmail.com> <CAK08nYZkqacNmMMfyXYjGx-Nim__hA8O-VgsaMQ9D=E-rHq0Og@mail.gmail.com> <CAP3D6hLc-=yFdX8hqrimLTAsGRGtonhiW+oymBQ8g6jF8B56Cg@mail.gmail.com>
In-Reply-To: <CAP3D6hLc-=yFdX8hqrimLTAsGRGtonhiW+oymBQ8g6jF8B56Cg@mail.gmail.com>
From: Nathanael Ritz <nathanritz@gmail.com>
Date: Tue, 18 Aug 2026 09:53:35 -0600
X-Gm-Features: AcwNN1VigcOrd8quUsCEqEqho1PQ9vUYXlIwYA6P_c0I95FKcKhjVr4e0_X5tks
Message-ID: <CAHxYnaO+cJHzL3sT+ngZoUgBZJxXUcosT13muhUvrnESeOqSOQ@mail.gmail.com>
To: seat@ietf.org
Content-Type: multipart/alternative; boundary="000000000000f2f8960659544a97"
Message-ID-Hash: LPOID2APZRRCFNGPBS3VQ564HUEWTTZ5
X-Message-ID-Hash: LPOID2APZRRCFNGPBS3VQ564HUEWTTZ5
X-MailFrom: nathanritz@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Updated Attacker Model in SEAT Use Cases Draft
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/Zs7T47ABMoQASy5Xp2p8SUM_HTQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>

Hi, some comments inline with [NR]:

On Tue, 18 Aug 2026 at 07:16, Chengxin Huang <aurestarnull@gmail.com> wrote:

> [SNIP] I agree with Songbo that CVE-2026-33697 must be added. I also
> suggest to add a pointer to [Edgeless] advisory in attacker model. Both are
> wildly exploited and I don't see how proposed text covers both.
>

On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote:

> [...] On CVE-2026-33697: This is already exploited in the wild.
>>
>
[NR]: Despite repeated assersions of 'wild exploitation', SEAT recently had
another independent researcher stop by and specifically state that that
they "have not, however, been able to find a publicly available,
concrete exploitation
trace or proof-of-concept demonstrating how the attack
can be carried out against the actual CoCoS implementation." [0] My own
search has found a specific PoC for specific regressions related to new CVE
candidates including a post-TLS authenticator handshake example [1], but
such concrete tooling seems to appear in isolation. Finally, I think it's
also worth noting that NIST [2] appears to give CVE-2026-33697 an
exploitability score of 1.0 [3] and it appears Github suggests an
exploitability score of 1.1 for the same [4].

On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote:

> Therefore, please make it explicit in the threat model. I don't think
>> "cross-connection replay" is a standard term in the literature. I think
>> CVE-2026-33697 is related to relay and not "cross-connection replay".
>> Therefore, as a first step, making it explicit in the draft is useful for
>> further discussion.
>>
>
[NR]: If we are uncertain if we think CVE-2026-33697 is related to relay
and not 'cross-connection replay' or not, I suggest such details get
narrowed down before being put into the draft. Based on the sources, I
believe we should consider the practical impact of "Key Exchange without
Entity Authentication" and "Origin Validation Error" from first principles.
This is not because these are new risks, but because they are well
established in prior literature and represent long-standing concerns for
secure transport protocols. The mailing list is the right place to continue
these discussions.

On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote:

> [SNIP] On cross-connection replay handling: I think we can agree on
>> desired handling in this draft and solutions can then implement this.
>>
>
tirumal reddy <kondtir@gmail.com> 于2026年8月18日周二 14:26写道:

> On cross-connection replay: how a solution detects and handles it (abort
> or otherwise) is a separate discussion for the solution drafts, not this
> document.
>
[NR]: As such, I agree with Tiru on the direction with this.

Cheers,
Nathanael

[0] https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/

[1] https://github.com/B1ueD0g/cocos-cve-regression-evidence

[2] https://nvd.nist.gov/vuln/detail/CVE-2026-33697

[3]
https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-33697&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&version=3.1&source=NIST

[4]
https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-33697&vector=AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N&version=3.1&source=GitHub,%20Inc
.