I-D Action: draft-intra-handshake-fail-05.txt
[email protected] Mon, 10 Aug 2026 12:25:03 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178638990333.444786.7423834414703129018@dt-datatracker-559c48c7fb-9llwz> |
Internet-Draft draft-intra-handshake-fail-05.txt is now available. Title: Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming) Author: Muhammad Usama Sardar Name: draft-intra-handshake-fail-05.txt Pages: 25 Dates: 2026-08-10 Abstract: The draft aims to provide technical details of CVE-2026-33697 (https://www.cve.org/CVERecord?id=CVE-2026-33697) and EUVD-2026-16488 (https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488), which is substantial technical evidence of how *intra*-handshake attestation fails in practice, even _without physical access_. Moreover, since continuous attestation is generally required, *intra*-handshake attestation adds *unnecessary complexity*. The results are backed by the research [Intra-handshake.fail] and the artifacts [Intra-handshake.fail-repo] in state-of-the-art tool, ProVerif, under Apache-2.0 license for reproducibility, and have been acknowledged by the relevant stakeholders. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-intra-handshake-fail/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-intra-handshake-fail-05.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-intra-handshake-fail-05 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]