I-D Action: draft-intra-handshake-fail-07.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178696453486.420574.17596304185227490907@dt-datatracker-7c6ddbc678-86d5j> |
Internet-Draft draft-intra-handshake-fail-07.txt is now available.
Title: Intra-handshake Attestation Considered Harmful (CVE-2026-33697 of CVSS 7.5 and several other CVEs of up to expected CVSS 9.8 upcoming)
Authors: Muhammad Usama Sardar
Songbo Bu
Name: draft-intra-handshake-fail-07.txt
Pages: 27
Dates: 2026-08-17
Abstract:
The draft aims to provide technical details of CVE-2026-33697
(https://www.cve.org/CVERecord?id=CVE-2026-33697) and EUVD-2026-16488
(https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488), which is
substantial technical evidence of how *intra*-handshake attestation
fails in practice, even _without physical access_. Moreover, since
continuous attestation is generally required, *intra*-handshake
attestation adds *unnecessary complexity*. The results are backed by
the research [Intra-handshake.fail] and the artifacts
[Intra-handshake.fail-repo] in state-of-the-art tool, ProVerif, under
Apache-2.0 license for reproducibility, and have been acknowledged by
the relevant stakeholders.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-intra-handshake-fail/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-intra-handshake-fail-07.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-intra-handshake-fail-07
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]