Skip to main content

echo_transcript

Function echo_transcript 

Source
pub fn echo_transcript(
    challenge: &[u8],
    device_fpr: &[u8; 32],
    handshake: &[u8; 32],
) -> [u8; 32]
Expand description

K31, step 2: proof-of-possession echo bound to the conversation.

HMAC-SHA256(key = challenge secret, "CC/v1/echo-transcript" ‖ device_fpr ‖ handshake), where handshake is the output of handshake_transcript.

§What this fixes

K23 included only the fingerprint in the message. An echo recorded from the wire worked in ANY conversation with the same device whenever the secret repeated, and the server secret repeats after snapshot rollback (I-1, argument C-13; K30 addressed repetition, but not the construction itself). The safety margin depended on the server currently issuing nothing on Proven without a session MAC, making it just one edit thick. The echo is now a function of the conversation: the server seals anew in each conversation, with its own ephemeral Seal pair, so challenge bytes differ.

§What this does NOT provide

It does not fix full snapshot rollback TOGETHER with the clock: then both the secret (time is in K30’s preimage) and the ephemeral sealing pair repeat, repeating the entire transcript. It does not address an attacker possessing the device private key: that attacker legitimately proves possession.