[Seat] Re: Comments on formal analysis of relay attacks in attested TLS (CVE-2026-33697)
Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Tue, 28 July 2026 20:37 UTC
Return-Path: <muhammad_usama.sardar@tu-dresden.de>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6014E1200BC51 for <seat@mail2.ietf.org>; Tue, 28 Jul 2026 13:37:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785271025; bh=BHKe6szAdH/xtW4xVs7ybhpPb6mutNkXIucB9ITQ6QM=; h=Date:Subject:To:CC:References:From:In-Reply-To; b=Ws5UCN2tAlbEXypbCq4ymBU+GtfR5J5N8SXjzkNac7HGjkIsQJonZcNpzIvU2tIBx c4GnEnh7tEyvFuhYrSqoKW2n9MHrdraebcOekmGIZfQXE0NjGs410PWUI4syGyjnaj xuPNiBL+jG9tYB1iXOhzxqdDEXlQeEJMqgSyDQ8o=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=tu-dresden.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lm0UkJkiW1ba for <seat@mail2.ietf.org>; Tue, 28 Jul 2026 13:37:04 -0700 (PDT)
Received: from mailout3.zih.tu-dresden.de (mailout3.zih.tu-dresden.de [141.30.67.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 49C671200BC3F for <seat@ietf.org>; Tue, 28 Jul 2026 13:37:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:In-Reply-To:From:References:CC:To :Subject:MIME-Version:Date:Message-ID:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=kXZXdQv/7/bvB5WMElAzppu2JpiXMagdHeIgVGHoA18=; b=c5vo86MjEokfPQ1WI2r5++U4P6 BmLvN/KE827+ImWONcpUwLRS9/7NeGh0fuxLHinpSnviV19PWQFzSNBV/Z7xw01r1HdQEO60qxIf6 XGmxU+kkh7EXnHxnYTjkjH9gbfqyFMNZ+Ny3d6XbZrbn5yCdk+rJ1hxauW6qG+fGCB7KMPE2fJh40 oy/oM2GgL30Okjq20LbMaOC5XxwhXZCezPak9io2exjDNzsCj9ZhrnHafZHOBB78vN7i17owmIclg g0TK3hLeTu6T0i6JrqeIQ5TwIKCDEI8AdKMfhzTFzyB+Z4KU7RVzXscKr84gnPH8eqRK99D8f9ogR C4YX9PNw==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout3.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1wooXr-001xVU-1p; Tue, 28 Jul 2026 22:37:03 +0200
Received: from [10.12.5.228] (141.76.13.149) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Tue, 28 Jul 2026 22:36:51 +0200
Message-ID: <9371184b-d6c1-44fa-b184-58811946ca55@tu-dresden.de>
Date: Tue, 28 Jul 2026 22:36:49 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Nathanael Ritz <nathanritz@gmail.com>, "seat@ietf.org" <seat@ietf.org>
References: <5f361893-bc32-4737-9578-fdb3ad7be3f9@tu-dresden.de> <9F03163D-B0F9-40DD-A4AB-69C151B872D6@aiven.io> <c4a0c433-173d-44ac-bd48-eed642a674d3@tu-dresden.de> <CAHxYnaOBMnPp7EiRLNYWX8AQDc2zYoBL226nfeBiPXsyii7Now@mail.gmail.com> <CAHxYnaOFWQBLf0Pn8bY=CMx7ytSEkTbvj7xp-s0GCHJohRh5xg@mail.gmail.com> <MRWPR02MB1208667A0653CF2C6B141933DB7CD2@MRWPR02MB12086.eurprd02.prod.outlook.com> <76b504ae-5692-4f31-a9d2-025974b12339@tu-dresden.de> <MRWPR02MB1208652B214687BB93253F1D2B7CD2@MRWPR02MB12086.eurprd02.prod.outlook.com> <5fb42c5c-825b-472b-8455-ce893011ade5@tu-dresden.de> <MRWPR02MB12086E888B91ECDB72D4B230AB7CC2@MRWPR02MB12086.eurprd02.prod.outlook.com> <CAHxYnaPYKJ_jdbVXraoXQootU4KeaSsmE8Dh0r=RLkZUqcaFqg@mail.gmail.com> <CAHxYnaOovbOJkp_og6rzs05hw_3zUKPWaufr5tukCaxizQY7FA@mail.gmail.com> <CAHxYnaNtzCqEm19r+0pwRZCWKykXHiWLXK_DsaSU9D+mqkf3sw@mail.gmail.com>
Content-Language: en-US
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
In-Reply-To: <CAHxYnaNtzCqEm19r+0pwRZCWKykXHiWLXK_DsaSU9D+mqkf3sw@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms050302050009080801090806"
X-ClientProxiedBy: MSX-T415.msx.ad.zih.tu-dresden.de (172.26.35.135) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout3.zih.tu-dresden.de
Message-ID-Hash: 5ZXDXP3LYYSXVCYPNJPXHHKADXMWHJX6
X-Message-ID-Hash: 5ZXDXP3LYYSXVCYPNJPXHHKADXMWHJX6
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "ufmrg@irtf.org" <ufmrg@irtf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Comments on formal analysis of relay attacks in attested TLS (CVE-2026-33697)
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/c_xAHR3E-wBSDSkiidThYu6om64>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>
Hi Nathanael,
Markus kindly clarified what he would like to see in more detail. Could
you please do the same to help keep this discussion more focused? Here
is my understanding of the points where you disagree:
1. While the paper [6] claims it 'may not be possible' to achieve level
3 binding in intra-handshake attestation, you believe it is
possible. Setting aside what you model and prove is correct or not,
I don't see how this contradicts the claim 'may not be possible' in
the paper.
2. We haven't yet seen a property that the hybrid construction (intra-
+ post-handshake attestation) /can/ satisfy, but post-handshake
attestation alone /cannot/ satisfy, unless you are implicitly
implying that level-3 binding cannot be achieved by post-handshake
attestation. Please clarify explicitly.
Is there something I have missed? As mentioned before to Markus, I
believe it is much more organized to have them answered in detailed
technical report. So more important than the discussion below is the
correction/addition/edits in above statements.
Also, I believe it will be more constructive to respond point by point
to [5] where you disagree, so we can do further working to share with
the WG/RG.
We will then work on it and share with the WG/RG.
On 28.07.26 20:51, Nathanael Ritz wrote:
> On Tue, 28 Jul 2026 at 10:00, Muhammad Usama Sardar
> <muhammad_usama.sardar@tu-dresden.de> wrote:
>
> This does not address any of the questions in [5] where your
> working was shown to be not correct, and these inaccuracies still
> remain here too.
>
> [NR}: I disagree, but the authors are welcome to cite my work and my
> words directly in relationship to any questions that are, in their
> opinion, left unanswered so that I can address them directly rather
> than guessing.
For example, our responses to your #2 in [5].
>
> For clarity, nothing has changed in the key schedule of TLS 1.3
> for quite long time (I think draft-20 which became RFC8446).
> Saying that RFC9846 is "new work" for key schedule is almost
> surely wrong. Maybe Ekr can confirm.
>
> [NR]: If it is being stated that I am suggesting RFC9846 includes 'new
> work for key schedule', please quote me directly, as I am currently
> unclear to what context and statements are being referenced to right now.
Thanks for clarifying. 'non-conformant Key Schedule' and then mention of
RFC 9846 §7.5 was unclear for #2 in [5]; it has stayed the same for
pretty much a decade. We believe that both points in your #2 about key
schedule are not valid and we justified it technically in [5], to which
we have seen no response.
Best regards,
Usama, Slava, and Jean-Marie
> [5]
> https://mailarchive.ietf.org/arch/msg/seat/dKVqaL8RJSQLonIEmtzrDYEXEAU/
>
> [6]
> https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS
- [Seat] Relay Attacks in Intra-handshake Attestati… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Давид Nunhausen
- [Seat] Re: [Ufmrg] Re: Re: Comments on formal ana… rachid bouziane
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Nancy Cam-Winget (ncamwing)
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Nathanael Ritz
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Paul Wouters
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Nathanael Ritz
- [Seat] Comments on formal analysis of relay attac… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… Steve
- [Seat] Re: Comments on formal analysis of relay a… Chengxin Huang
- [Seat] Re: [Ufmrg] Re: Comments on formal analysi… Song Haowen
- [Seat] Re: Comments on formal analysis of relay a… Mark Novak
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Mark Novak
- [Seat] Re: Comments on formal analysis of relay a… camilo ayerbe
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: [Ufmrg] Re: Re: Comments on formal ana… Salz, Rich
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Nathanael Ritz
- [Seat] Re: Comments on formal analysis of relay a… Songbo Bu
- [Seat] Re: Comments on formal analysis of relay a… camilo ayerbe
- [Seat] Re: Comments on formal analysis of relay a… Muhammad Usama Sardar
- [Seat] Re: Comments on formal analysis of relay a… Markus Rudy
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Muhammad Usama Sardar
- [Seat] Re: Relay Attacks in Intra-handshake Attes… Paul Wouters