# Attested TLS Was Supposed to Be the Last Trust Boundary. It Isn't. Formal Methods Show How. Page: https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isn-t-formal-methods-show-how Text version: https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isn-t-formal-methods-show-how.md Podcast: [Cybersecurity Tech Brief By HackerNoon](https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646) Published: 2026-07-13T16:01:29+00:00 Episode link: https://share.transistor.fm/s/420e4cee Audio file: https://media.transistor.fm/420e4cee/42992e1f.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-tech-brief-by-hackernoon-6365646/episodes/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isn-t-formal-methods-show-how Duration seconds: 1512 ## Resource This story was originally published on HackerNoon at: https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how . Formal methods researchers at TU Dresden found a relay attack in attested TLS. It hits Meta, Cocos AI, Edgeless Systems, and three IETF drafts. Check more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity . You can also check exclusive content about #cybersecurity , #cyber-threats , #confidential-computing , #cve , #open-source , #ietf , #ai-cyber-security , #hackernoon-top-story , and more. This story was written by: @salkimmich . Learn more about this writer by checking @salkimmich's about page, and for more stories, please visit hackernoon.com . A relay attack breaks attested TLS, the mechanism confidential computing uses to prove a secure cloud enclave is genuine. Formal verification found it in Meta's WhatsApp privacy system, Edgeless Systems' Contrast, Cocos AI, and three IETF draft standards, none of which a prior manual security audit caught. It's tracked as CVE-2026-33697 (CVSS 7.5), with three more related CVEs near 9.1 still in disclosure. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-tech-brief-by-hackernoon-6365646/episodes/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isn-t-formal-methods-show-how/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isn-t-formal-methods-show-how.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.