pub fn echo_transcript(
challenge: &[u8],
device_fpr: &[u8; 32],
handshake: &[u8; 32],
) -> [u8; 32]Expand description
K31, step 2: proof-of-possession echo bound to the conversation.
HMAC-SHA256(key = challenge secret, "CC/v1/echo-transcript" ‖ device_fpr ‖ handshake), where handshake is the output of handshake_transcript.
§What this fixes
K23 included only the fingerprint in the message. An echo recorded from the wire worked in
ANY conversation with the same device whenever the secret repeated, and the server
secret repeats after snapshot rollback (I-1, argument C-13; K30 addressed repetition,
but not the construction itself). The safety margin depended on the server currently issuing
nothing on Proven without a session MAC, making it just one edit thick.
The echo is now a function of the conversation: the server seals anew
in each conversation, with its own ephemeral Seal pair, so challenge bytes differ.
§What this does NOT provide
It does not fix full snapshot rollback TOGETHER with the clock: then both the secret (time is in K30’s preimage) and the ephemeral sealing pair repeat, repeating the entire transcript. It does not address an attacker possessing the device private key: that attacker legitimately proves possession.