I-D Action: draft-intra-handshake-fail-04.txt

[email protected] Sun, 09 Aug 2026 04:46:40 -0700
Newsgroups gmane.ietf.announce
Message-ID <178627600045.287746.14002714233531076993@dt-datatracker-559c48c7fb-9llwz>
Internet-Draft draft-intra-handshake-fail-04.txt is now available.

   Title:   Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)
   Author:  Muhammad Usama Sardar
   Name:    draft-intra-handshake-fail-04.txt
   Pages:   24
   Dates:   2026-08-09

Abstract:

   The draft aims to provide technical details of CVE-2026-33697
   (https://www.cve.org/CVERecord?id=CVE-2026-33697) and EUVD-2026-16488
   (https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488), which is
   substantial technical evidence of how *intra*-handshake attestation
   fails in practice, even _without physical access_. Moreover, since
   continuous attestation is generally required, *intra*-handshake
   attestation adds *unnecessary complexity*. The results are backed by
   the research [Intra-handshake.fail] and the artifacts
   [Intra-handshake.fail-repo] in state-of-the-art tool, ProVerif, under
   Apache-2.0 license for reproducibility, and have been acknowledged by
   the relevant stakeholders.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-intra-handshake-fail/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-intra-handshake-fail-04.html

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-intra-handshake-fail-04

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]