[Seat] Re: Updated Attacker Model in SEAT Use Cases Draft
Songbo Bu <bluedognull@gmail.com> Wed, 19 August 2026 01:28 UTC
Return-Path: <bluedognull@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D850412BFEDBE for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 18:28:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787102904; bh=2o+uxRJrOjFjxR3tJjgsfoGVKyyMQIuwgAyBGSqX7Lw=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=ElVtgPjXfztJn58B8XTpRvQ2Wr0hSSYRX2DmAMnBuE6po91Wh96xSsHLppFXGMuAy 2zcKc5drgBiTDWe/4YYjuLk+VuBIJOe30jszIgz7cRflz6L4Ac5X/JOnwD9QXZXszm G84j5yPqqHms655jUNk/LRWUpJ4ZfpAcxScQ5KzA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5p9Q5Zk8Jlvo for <seat@mail2.ietf.org>; Tue, 18 Aug 2026 18:28:24 -0700 (PDT)
Received: from mail-qv1-xf2b.google.com (mail-qv1-xf2b.google.com [IPv6:2607:f8b0:4864:20::f2b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2624C12BFEDB3 for <seat@ietf.org>; Tue, 18 Aug 2026 18:28:24 -0700 (PDT)
Received: by mail-qv1-xf2b.google.com with SMTP id 6a1803df08f44-8efbafa1bacso4059226d6.1 for <seat@ietf.org>; Tue, 18 Aug 2026 18:28:24 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787102898; cv=none; d=google.com; s=arc-20260327; b=IF6j2wskggWjPXjehvHL0iZORQp3n96ZjpZh+5sJcvtPSjBYmP2SDwWMchZ4zGF6Fo jUlhLsqJBR+Vxf348Vn+biRng5R/sCdE1bMmGvvr0U1OD/5GFNH+3J7HxhI0NViRX7Te 6sifTO4+dqGPniNyHAtlGRgUuBeMAlpzgGGLrBYemX/MxmvfxBOlusjZhjxPFgbIj+VV nVsE+RjeLTrrU8H5c8U7spaLWAzHHf50ILvel/z5pVg6hVI1MFb3Vao7AXk7p7btmTmM JbVBDOl0ntw39r9JRDUK3o7nM4U/AmZLXiGuzEKTcp9A99WKb1XpBYA0W/T7wUKf1aLL xdDQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=2o+uxRJrOjFjxR3tJjgsfoGVKyyMQIuwgAyBGSqX7Lw=; fh=ltGa5jPjDpTRY45qynPpVCXWZ99Iai7+xFly1WGX3Y0=; b=H4si9K3nQeqfWwFuTFPThumnUwr8Kwf/xVEk6e9P04tvmapMRysh5BJJS65BE8n0M9 jSScdIBKcRKrc8RJDNBTmOaC7V6zzYAp7JN3qFl6h8zytY7Dy3V66zjHFV0zdXmttx1g YYlv1Sbbr1TBVS55QhRhI/vX/UfKivxlF43PRQe1eWwBaCFw9/RqPflR0Px02lbs/bZ0 iLgEKdy38ydzVmXAyWFTZuTxqThg0tiRL8vyzS/cF0+tcOAuoF/N0S6cW+JYYWZUXyHb n0EJFw61Wt5QTj2/b0hZ30kDeyZWVn0emOxoV0Yhnqj+Q5INWC6S9pYGgjv+9laLZhfY 5W6Q==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787102898; x=1787707698; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=2o+uxRJrOjFjxR3tJjgsfoGVKyyMQIuwgAyBGSqX7Lw=; b=ax1o0EjtEgdh5abTrp5sGmadzv5n9d4VGQOHV/xJFPNBfIR5k/ZIi9Pc1mQJAiNALr r8Z00OGxLJ5czvMu1upsR+DK75EmRiWBV3+gd1FyTJaYsdw48xrTvvB8BHi7eEzOLpDd VfQ1tKN4CJXvGFt8NXDyh8KtRysdLyeQ8XUOmP5FRHxyjVFtJ6x8UcgAxinXZcuaqw+r X1L4bMLW53igkAREktUCgpUyLIs8AgQasZgEpVfz4tgFnFN1bh4v5YMcXLfpI0ROzjS/ DM146VQI8Puw2PMKrisTYa1n9/oHDcI0pl7MuyYA8ry+JNzAsfjKR5DtIpP9C4o5JRFe IWXg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787102898; x=1787707698; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=2o+uxRJrOjFjxR3tJjgsfoGVKyyMQIuwgAyBGSqX7Lw=; b=UHy16UIsrQ6oEAECEpfXT3D0IRJid5UJW3XItuubzoSrjZ9wS/tCYnxvm2SdMukBhc kd84CxVFrbIMlgbL4a8zzuaXvbcOcWgLwQj1i+IIjy1vVxcQNjujGZQ6Qhh5AJxPQZey JOM42uBAakFRFRakLozbavnQyMCxlb6zo6bCIcYzsUCS9ty4qurUpia+xbplLIXusx+e vhVrtrbwHyqZcrXXqoFcxGNH1l8KturgLfjOhdGR9uYCxLQZVuRedYAyZfZfX1d1U9Ky h2FjLWbHeobcBgUDb/3a/wxHBbXNkf018y7buPewjnUubLQCY1lMngD6owpOBGq00WmZ MHyw==
X-Gm-Message-State: AOJu0YxWo8CW0yGSEcole+VWrOqp3ip1znq2J4RkB9D46cWPM/05zVRh nz/5oJrMor8Qb4nixcrusryIpe+7wFAdKl8gLbvKDT/b5wBgORVPH3uslzgcH4lAsdk7xtd0mg8 29RdKbwY3BJni4bvxWNOwKEau25nsd2atD07pBgM=
X-Gm-Gg: AR+sD12F5JvDanA7KKM2U9MleuXlMmM/LWxEePXkCdVfQEG3on4H41o52qPGSxwhZKX QTBmRobRAJT7WRM80S59a10vre+R+jbgZrb1GOm/VZFjLaHSyV8uA59djPcN2vCVogf0Mj85WJu FWWRjE56ShT4qf9YoGEwQHWNb/HFtCzfJ5PGeitIYvBeV0YoUGfthK1Tng1JASVmAoG+1Eaz8Dm UEAvFoWBrBMDnmtQCvNg6FMAgSXVo2ip0GhK4u6aV/FEBIkcOzTTkkzAFCLVUMrEVAZmSdoEO3M Ttxp/dB57zJRnDU6Ds2xsUyyGH8fzqK+jShaBgoBB5ISXJdeWbJ0dYy9MTJ3DSBc9hdw5qi+r5c oiiN8j3ZVhXSGEW5BrybSckhmjLa2MmrJEWgUm8InzrNm5eLaYk1VATA=
X-Received: by 2002:a05:6214:418b:b0:908:8f97:7d8c with SMTP id 6a1803df08f44-90c5e6c92b0mr12732376d6.4.1787102897256; Tue, 18 Aug 2026 18:28:17 -0700 (PDT)
MIME-Version: 1.0
References: <CAFpG3gc1POcpcc0NCOFig=e1AgbeMpre2i++xdmXtQTpAp8vqA@mail.gmail.com> <CAK08nYaM7+2j7RgYduVRYEWkjGMYxeQNzHHWuPsbmP0hVDCC5A@mail.gmail.com> <CAFpG3gdvVTbUTCYGV7QWMM-YPctEk+oRL+jODshO3wLvAbPP7w@mail.gmail.com> <CAK08nYZkqacNmMMfyXYjGx-Nim__hA8O-VgsaMQ9D=E-rHq0Og@mail.gmail.com> <CAP3D6hLc-=yFdX8hqrimLTAsGRGtonhiW+oymBQ8g6jF8B56Cg@mail.gmail.com> <CAHxYnaO+cJHzL3sT+ngZoUgBZJxXUcosT13muhUvrnESeOqSOQ@mail.gmail.com>
In-Reply-To: <CAHxYnaO+cJHzL3sT+ngZoUgBZJxXUcosT13muhUvrnESeOqSOQ@mail.gmail.com>
From: Songbo Bu <bluedognull@gmail.com>
Date: Wed, 19 Aug 2026 09:28:05 +0800
X-Gm-Features: AcwNN1VMQrCbSD9arQ9U77nyH1NZPGV0FAM5YO5SdzaAyRVxwckIJyxVATjavjc
Message-ID: <CAK08nYZF2zftx3T1Gj7mGN8-5YcoL3akmfsY3-ODBDbojtdvuQ@mail.gmail.com>
To: Nathanael Ritz <nathanritz@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000005e3d4806595c51a2"
Message-ID-Hash: 3XKRSICAVEJODJXE4POT2ZHFFZM2CWTM
X-Message-ID-Hash: 3XKRSICAVEJODJXE4POT2ZHFFZM2CWTM
X-MailFrom: bluedognull@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: seat@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Updated Attacker Model in SEAT Use Cases Draft
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>
Nathanael, Thank you. I want to provide a concrete proof. Davyd Okaianchenko has developed the "concrete, runnable Proof of Concept (PoC) for the attack" for CVE-2026-33697: https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/. I think it is not at all difficult to develop. Several news in China have confirmed exploit in the wild. Best, Songbo Nathanael Ritz <nathanritz@gmail.com> 于2026年8月18日周二 23:53写道: > Hi, some comments inline with [NR]: > > On Tue, 18 Aug 2026 at 07:16, Chengxin Huang <aurestarnull@gmail.com> > wrote: > >> [SNIP] I agree with Songbo that CVE-2026-33697 must be added. I also >> suggest to add a pointer to [Edgeless] advisory in attacker model. Both are >> wildly exploited and I don't see how proposed text covers both. >> > > On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote: > >> [...] On CVE-2026-33697: This is already exploited in the wild. >>> >> > [NR]: Despite repeated assersions of 'wild exploitation', SEAT recently > had another independent researcher stop by and specifically state that that > they "have not, however, been able to find a publicly available, concrete exploitation > trace or proof-of-concept demonstrating how the attack > can be carried out against the actual CoCoS implementation." [0] My own > search has found a specific PoC for specific regressions related to new CVE > candidates including a post-TLS authenticator handshake example [1], but > such concrete tooling seems to appear in isolation. Finally, I think it's > also worth noting that NIST [2] appears to give CVE-2026-33697 an > exploitability score of 1.0 [3] and it appears Github suggests an > exploitability score of 1.1 for the same [4]. > > On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote: > >> Therefore, please make it explicit in the threat model. I don't think >>> "cross-connection replay" is a standard term in the literature. I think >>> CVE-2026-33697 is related to relay and not "cross-connection replay". >>> Therefore, as a first step, making it explicit in the draft is useful for >>> further discussion. >>> >> > [NR]: If we are uncertain if we think CVE-2026-33697 is related to relay > and not 'cross-connection replay' or not, I suggest such details get > narrowed down before being put into the draft. Based on the sources, I > believe we should consider the practical impact of "Key Exchange without > Entity Authentication" and "Origin Validation Error" from first principles. > This is not because these are new risks, but because they are well > established in prior literature and represent long-standing concerns for > secure transport protocols. The mailing list is the right place to continue > these discussions. > > On Tue, Aug 18, 2026 at 4:09 PM Songbo Bu <bluedognull@gmail.com> wrote: > >> [SNIP] On cross-connection replay handling: I think we can agree on >>> desired handling in this draft and solutions can then implement this. >>> >> > tirumal reddy <kondtir@gmail.com> 于2026年8月18日周二 14:26写道: > >> On cross-connection replay: how a solution detects and handles it (abort >> or otherwise) is a separate discussion for the solution drafts, not this >> document. >> > [NR]: As such, I agree with Tiru on the direction with this. > > Cheers, > Nathanael > > [0] > https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/ > > [1] https://github.com/B1ueD0g/cocos-cve-regression-evidence > > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-33697 > > [3] > https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-33697&vector=AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N&version=3.1&source=NIST > > [4] > https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-33697&vector=AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N&version=3.1&source=GitHub,%20Inc > . > > > _______________________________________________ > Seat mailing list -- seat@ietf.org > To unsubscribe send an email to seat-leave@ietf.org >
- [Seat] Updated Attacker Model in SEAT Use Cases D… tirumal reddy
- [Seat] Graceful fallback? (Was: Updated Attacker … Nathanael Ritz
- [Seat] Re: Graceful fallback? (Was: Updated Attac… tirumal reddy
- [Seat] Re: Graceful fallback? (Was: Updated Attac… Yaron Sheffer
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Songbo Bu
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… tirumal reddy
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Songbo Bu
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Chengxin Huang
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Nathanael Ritz
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Yaron Sheffer
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Songbo Bu
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Song Haowen
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Nathanael Ritz
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Songbo Bu
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Steve
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Ionut Mihalcea
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Nathanael Ritz
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Nathanael Ritz
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Songbo Bu
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Katapulta Pultalowska
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Chengxin Huang
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Nathanael Ritz
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Chengxin Huang
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Yaron Sheffer
- [Seat] Re: Updated Attacker Model in SEAT Use Cas… Ionut Mihalcea