[Seat] Re: Regarding symbolic analysis of draft-fossati-seat-early-attestation-06
Songbo Bu <bluedognull@gmail.com> Mon, 10 August 2026 07:19 UTC
Return-Path: <bluedognull@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id EB3FE1270075A for <seat@mail2.ietf.org>; Mon, 10 Aug 2026 00:19:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786346373; bh=7pVD4azDHQFpUkErpEKcLwo0K9YP7mv8n6RT6nM8s6M=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=gILDX+GwEvHUairI81xOJBo0g0B1xx9VKsNKxz/xMDWdY+R45yYetgF0OQXdIHSk4 r/kk7Pmqg9MN5A33D+ZGr/q7g0JZLT4B9+IQSY3ONGnY3eNu2/H5GCUnxnYZ785Pfk lFoXvHiBnld1nGYmIzBZIvkHzNYj+URmAdPgsML8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.088
X-Spam-Level:
X-Spam-Status: No, score=-1.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U6WbQ0QxNPn9 for <seat@mail2.ietf.org>; Mon, 10 Aug 2026 00:19:33 -0700 (PDT)
Received: from mail-qv1-xf31.google.com (mail-qv1-xf31.google.com [IPv6:2607:f8b0:4864:20::f31]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 53E4912700755 for <seat@ietf.org>; Mon, 10 Aug 2026 00:19:33 -0700 (PDT)
Received: by mail-qv1-xf31.google.com with SMTP id 6a1803df08f44-8fcc43c48f7so15591176d6.2 for <seat@ietf.org>; Mon, 10 Aug 2026 00:19:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786346373; cv=none; d=google.com; s=arc-20260327; b=S4TxszU13Wo+2wcpZ+CGjfLzLeIGUQV2AqAVsk3KmmWG92CcUJ8h8axgDiHpY9aeXA 5unnXJY88D2krgnvis2X80wK6s2UQwVtDx2icauC+sM5ogfO67ztXaNMOLPb8eYOnnhP RImlrYylxW8Y8+GmW4TGjHjjn9ekjcvRCYYI0MPL5mQKmhLj+JhQ9fSQrc++jtwSDVDy B6hqIcw/JhCfTeL4Vn8Rj4xYkXNgoN6M4ZWr3PMjz7f18DI6G2dZRPyhW+xXo9vxpWbh HJBIGYwUSfHZ6Mvvo0ZqaKAFo9o4iUGxOoZSlCTmzhGFl8q01/P6np/XmAM3bB8SfJBu 4mLg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=7pVD4azDHQFpUkErpEKcLwo0K9YP7mv8n6RT6nM8s6M=; fh=ltGa5jPjDpTRY45qynPpVCXWZ99Iai7+xFly1WGX3Y0=; b=P199jDZWiLLVtICPVwKx5FbrdQ6Bj6YpOhC6qNWOANRl5r7wNmAJIqvHvYPbKgF2yf WVcaWzfWZqsDVDlMXR1mNo4CYygv+Ch2AWmX3Aaz0yhdJx9xbJ3PyyuKw3ponOwmhE7W +WQ0ipb3MF8ygpnLRI+9sTbEO2fhRQwLNwBC3/uo2cJewoL5fKm75Hp/G7lUpGjYU65L iA56MJ9K7FF3oJ2ZQDuaEgrF0qQVS2SmZndO3gpeUm/4c5lOSD5I8jD+qtRyXNS3eLGm HPykWxasE8+pSJ/IalBMc0FIcLL8GGJ6iGjdHK2UZamq0QCbLm4NVhLbGeDKi1bBWd00 JRQw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786346373; x=1786951173; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=7pVD4azDHQFpUkErpEKcLwo0K9YP7mv8n6RT6nM8s6M=; b=aIO0YOBKEz1fSYrGnkbgvKQdAV0PdfcoOAG7RhoW8dRYr5tJOc35etibBWSBXXd1sq AyoaDgr1PcfZej5mvqONn3NVp2zw/1TRxh2frLB2SXoByhQ/wyjxJ/62B9HxxHV/kGEB syf7cTUDvTSdcJKJAGZ4zOvrA/h8kSRs8y7O/CR78PwNSpSFwyUXVMVpsVPVZYfZB8o8 2pfMTO/AcqgN5oxS9J4rNYezMVc4KpMxfc+XdxT9DfcS9itxmNO7FFXiRM0qbbNG5MKI ZUuRaIpBARyInhj22lfsCLGxLPUY5S8LbBFHPpWcOuIiOBfYiWhpQ2Zm7myuNPyR5DvA Dt0w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786346373; x=1786951173; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=7pVD4azDHQFpUkErpEKcLwo0K9YP7mv8n6RT6nM8s6M=; b=lqSZSfB0LHeYWctFwhSRJ2sTsk9aDLkLow8VLZKg+s0Ylkf13UW+mX7gjmA6rnuD3r UmJ6Utr8jmw3k3CmPNhLlJbQQOWM5yWan6t3EK8sJClE+r7IdUw8PHyWs/hsZ6uhL47F qmZU7scD4UDqnYJ1sggrVz7t6cyiOblKJ3Yhc9hiNXCQmH836G5bu0KkkBCn5jARs74n jdmvuTJYf1l45t3jmDswG1aSsoTBx2FunCYbh8Q6rXvnNkwI+TIt37Z401K2ANAPWV8f fdOoe2W6HcL9k/M2AbfQWuJtL2JTXJKc58J2FzOze1FyuDna9wTf3Yz50Qa2NmFWGjOa cgnw==
X-Gm-Message-State: AOJu0Yy2q9fS3NLDutU8+uMqxqv7i7qDfRpEfXxGSB7dxX3P6WZttaBF 295qRizXcY0cB8Dj+eWiHrN61jHyr7v34ClgdqZNq0xjyVoimaAcwCpDP8xYwE/DWoDPjAYdtzx rWGsrEGV6M5x5S4VyJh+1A8/EypOtFkA=
X-Gm-Gg: AR+sD13+OjEZWaBSWTAuzEPfJdYyn8XwHHX9tKF7GtKGov8psElLyGXJw6yIYSIgnfs qa4v7egX/SdbQtdwS4f7vTm2jeEvMAay20rY7qQsd+twbjzlTxK5d0zDLj2R4QDLUXk6FJm95ET I+C/Q+MUSeV/LN3665p06wMQnwqWVsVLM5PhIlttFHrUL1nsIyKeI08dii7PtbsIFfK4hRUmJpA w8TB2C/JvZsrsoO1n1gnCqj4ew49gikrhDgVVCpGW/bkgRYwdxCc7sW8BR1OWhROv48MmCEUdcD 30KA++vMpoIP7K3SmyM9mr5VRa0L30LUAWa18uHSdJS8f1nZ5RLGySRfwbZK6IHs7qfa6/m0QWR xEx/sbr7YgoEu
X-Received: by 2002:a0c:f099:0:b0:908:8f6e:52be with SMTP id 6a1803df08f44-9088f6e5917mr381950766d6.15.1786346372128; Mon, 10 Aug 2026 00:19:32 -0700 (PDT)
MIME-Version: 1.0
References: <178592625332.1174.15715227575457159982@dt-datatracker-54dc84885d-8d5gh> <VI0PR07MB11371696F052D3CC97C2DBBB5ABD32@VI0PR07MB11371.eurprd07.prod.outlook.com> <CAFpG3gcTVg0DJWb28E25EnH1CjUxe_y8T2HrKFFaCp2ouAPHpQ@mail.gmail.com> <f477291c-970c-47be-9692-b217ee1c204e@tu-dresden.de> <CAFpG3gfR4RxVNrO655aU_eYDnbm00OFixFuGqSvUkgn1aBu-Yw@mail.gmail.com> <VI0PR08MB115658E2E506025EA0864F8D18AD22@VI0PR08MB11565.eurprd08.prod.outlook.com> <CAK08nYZKVXUrgQ+e_nGaMEGF05BJ7bXTkxV2jba-uw=zfXnNVw@mail.gmail.com> <CAHxYnaOE-97sw941TvQc=MO_ygqVsdOxmk3Si6QVby8RfWJRXg@mail.gmail.com> <CAHxYnaNhHLG-1jkmqmtdjOeO5cx07AqyyesaD9PKdx1p8LYqJQ@mail.gmail.com> <ea848091-37e8-421e-af9d-22a624fd36a7@tu-dresden.de> <4d22aeeb-aac6-4d47-b8df-c2243b2df44f@tu-dresden.de> <CAK08nYZyPNEvU6ECEJ98iG+1J_MmsROk_-3mw88fNYMHJvXTXw@mail.gmail.com> <CAHxYnaOF18cQ2UchgRbn9k7oHuJ5hmuv6aQ5DNB-p-RmUHSdEw@mail.gmail.com> <CAK08nYYYVWKH0dAeS=Gi-MYr1R3_eCg99==Xx3ufmaBxrkdEjw@mail.gmail.com> <CAHxYnaOx1YshSJ7YTYkdbe42X6NLYtw1AHTcopdhY5Jim=6OBA@mail.gmail.com>
In-Reply-To: <CAHxYnaOx1YshSJ7YTYkdbe42X6NLYtw1AHTcopdhY5Jim=6OBA@mail.gmail.com>
From: Songbo Bu <bluedognull@gmail.com>
Date: Mon, 10 Aug 2026 15:19:20 +0800
X-Gm-Features: AUfX_mw-nG63FUD8d4cB8oPlra1_Wm0MvawbN0ElaMqZA0Nx5dWRqwFbGDUzMAw
Message-ID: <CAK08nYbpZFuCmoKs2SoO7VcGtOS6QrypJ04g+ufTqBKOZ9PvQg@mail.gmail.com>
To: Nathanael Ritz <nathanritz@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000f4e25f0658ac2c64"
Message-ID-Hash: G5AG2LCGKB44YXXMDSKHGBAFMEE5HAAA
X-Message-ID-Hash: G5AG2LCGKB44YXXMDSKHGBAFMEE5HAAA
X-MailFrom: bluedognull@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: seat@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Regarding symbolic analysis of draft-fossati-seat-early-attestation-06
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>
Nathanael, Thank you. You have skipped some of my questions. So please narrowly answer them all. You haven't explained the rationale on your statements for draft-fossati-seat-early-attestation-06 and binder7. You also haven't answered about vulnerability CVE-2026-33697. Leaving the model untouched and using `rdata = (log_SH, pubEK)` which abstractly models section 5.1.1 of this draft with ProVerif v2.05 on the commit `819bb7f20ac458b27c9be2c91cce1e72b8b5f4f7` gives me G1=true, G2=true, G3=false. Are you claiming that you get G3=true? About Meta's binder, Meta and others may not be offended with it but that is not my question. My question is technical. How can a very reputed cybersecurity firm miss "niaeve binders" in their "extensive security review"? In your opinion, is the binder in draft-fossati-seat-early-attestation-06 also "niaeve binders"? You also haven't answered my questions in https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/. Best, Songbo Nathanael Ritz <nathanritz@gmail.com> 于2026年8月10日周一 11:26写道: > Hi, > > On Sun, 9 Aug 2026 at 20:59, Songbo Bu <bluedognull@gmail.com> wrote: > >> [snip] My understanding is that `selfsign` is self-signed certificate for >> the >> key generated within the TEE. Evidence cannot be transmitted as it is >> in TLS 1.3, so a self-signed certificate is generated. Could you >> clarify what sense it would make to check the self-signed certificate >> at client-side? What needs to be checked before gate release is the >> signature using AK and that is correctly there in my reading >> ( >> https://github.com/muhammad-usama-sardar/intra-handshake.fail/blob/819bb7f20ac458b27c9be2c91cce1e72b8b5f4f7/binder1/tls-lib-simple.pvl#L682 >> ). >> > > The symbolic `selfsign` parameter is a redundant modeling bug. Within the > CRT message of Usama's model, the Evidence is conveyed in the `quote` > parameter. The ephemeral signing key is the `pubEK` parameter. However, as > mentioned before, outside of introducing a modeling artifact, its presence > is generally harmless. I say this because as one may have already seen, a > query like "Property G-C2: Composition Property for Relay attack," already > demonstrates that using the CH...SH checkpoint successfully mitigates > CVE-2026-33697/EUVD-2026-16488 -- even with the modeling bug left > untouched. > > On Sun, 9 Aug 2026 at 20:59, Songbo Bu <bluedognull@gmail.com> wrote: > >> I don't think it is helpful to downplay someone's work by calling it >> "niaeve binders". Do you really believe that tall companies like Meta >> are using what you call as "niaeve binders"? According to section 8 of >> intra-handshake.fail paper, that has gone through "extensive security >> review" ( >> https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf >> ) >> by a cybersecurity firm "Trail of Bits". In my search, Trail of Bits >> appears to be a very reputed firm. Do you really believe that a very >> reputed cybersecurity firm missed "niaeve binders" in their "extensive >> security review"? >> > > Absolutely. Funny, Usama asked me the exact same thing a few weeks ago > [0]. The answer to that same question remains unchanged [1]: "I highly > doubt [anyone] will be offended, if that's what you might be concerned > about." > > Secure systems get better with a healthy dose of collaboration between > both red teams (finding attacks) and blue teams (constructively guarding > and mitigating). Both are highly valuable to the community.To quote someone > else I spoke to in a discussion about this technology space, "it's all just > a gigantic work in progress." > > Cheers, > Nathanael > > >> >> Best, >> Songbo >> > > [0] > https://github.com/CCC-Attestation/attested-tls-poc/pull/58#discussion_r3580301451 > > [1] > https://github.com/CCC-Attestation/attested-tls-poc/pull/58#discussion_r3580393272 > > _______________________________________________ > Seat mailing list -- seat@ietf.org > To unsubscribe send an email to seat-leave@ietf.org >
- [Seat] FW: New Version Notification for draft-fos… tirumal reddy
- [Seat] Re: FW: New Version Notification for draft… Muhammad Usama Sardar
- [Seat] Re: FW: New Version Notification for draft… Nathanael Ritz
- [Seat] Re: FW: New Version Notification for draft… tirumal reddy
- [Seat] Re: FW: New Version Notification for draft… tirumal reddy
- [Seat] Re: FW: New Version Notification for draft… Ionut Mihalcea
- [Seat] Re: FW: New Version Notification for draft… Songbo Bu
- [Seat] Re: FW: New Version Notification for draft… tirumal reddy
- [Seat] Re: FW: New Version Notification for draft… Songbo Bu
- [Seat] Re: FW: New Version Notification for draft… Iman Schrock
- [Seat] Re: FW: New Version Notification for draft… Ionut Mihalcea
- [Seat] Re: FW: New Version Notification for draft… tirumal reddy
- [Seat] Re: FW: New Version Notification for draft… Songbo Bu
- [Seat] Re: FW: New Version Notification for draft… tirumal reddy
- [Seat] Re: FW: New Version Notification for draft… Song Haowen
- [Seat] Re: FW: New Version Notification for draft… Ionut Mihalcea
- [Seat] Re: FW: New Version Notification for draft… Steve
- [Seat] Re: FW: New Version Notification for draft… Nathanael Ritz
- [Seat] Re: FW: New Version Notification for draft… Chengxin Huang
- [Seat] Re: FW: New Version Notification for draft… Nathanael Ritz
- [Seat] Re: FW: New Version Notification for draft… Songbo Bu
- [Seat] Re: FW: New Version Notification for draft… Chengxin Huang
- [Seat] Re: FW: New Version Notification for draft… Ionut Mihalcea
- [Seat] Re: FW: New Version Notification for draft… Chengxin Huang
- [Seat] Re: FW: New Version Notification for draft… Songbo Bu
- [Seat] Re: FW: New Version Notification for draft… Ionut Mihalcea
- [Seat] Re: FW: New Version Notification for draft… Nathanael Ritz
- [Seat] Regarding symbolic analysis of draft-fossa… Nathanael Ritz
- [Seat] Re: Regarding symbolic analysis of draft-f… Muhammad Usama Sardar
- [Seat] Re: Regarding symbolic analysis of draft-f… Muhammad Usama Sardar
- [Seat] Re: Regarding symbolic analysis of draft-f… Songbo Bu
- [Seat] Re: Regarding symbolic analysis of draft-f… Nathanael Ritz
- [Seat] Re: Regarding symbolic analysis of draft-f… Songbo Bu
- [Seat] Re: Regarding symbolic analysis of draft-f… Nathanael Ritz
- [Seat] Re: Regarding symbolic analysis of draft-f… Songbo Bu
- [Seat] Re: Regarding symbolic analysis of draft-f… Nathanael Ritz
- [Seat] Re: FW: New Version Notification for draft… Songbo Bu