I-D Action: draft-intra-handshake-fail-04.txt
[email protected] Sun, 09 Aug 2026 04:46:40 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178627600045.287746.14002714233531076993@dt-datatracker-559c48c7fb-9llwz> |
Internet-Draft draft-intra-handshake-fail-04.txt is now available. Title: Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming) Author: Muhammad Usama Sardar Name: draft-intra-handshake-fail-04.txt Pages: 24 Dates: 2026-08-09 Abstract: The draft aims to provide technical details of CVE-2026-33697 (https://www.cve.org/CVERecord?id=CVE-2026-33697) and EUVD-2026-16488 (https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488), which is substantial technical evidence of how *intra*-handshake attestation fails in practice, even _without physical access_. Moreover, since continuous attestation is generally required, *intra*-handshake attestation adds *unnecessary complexity*. The results are backed by the research [Intra-handshake.fail] and the artifacts [Intra-handshake.fail-repo] in state-of-the-art tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-intra-handshake-fail/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-intra-handshake-fail-04.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-intra-handshake-fail-04 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]