4 ms·
This reminds me of a recently discussed [0,1] new method for tamper evident packing. The item is completely surrounded with multi-colored small objects (like ri
by matthberg 4y ago
This reminds me of a recently discussed [0,1] new method for tamper evident packing. The item is completely surrounded with multi-colored small objects (like rice, though plastic pellets would probably be better for customs to avoid plant pest inspections) in a clear vacuum sealed bag. The random patterns are too complex to recreate after tampering since accessing the device requires breaking the vacuum seal and disturbing the pattern, then resealing it and somehow manipulating the grains back into place from the other side of the plastic. Sending photos from each side for comparison on an off-channel medium is all that's required to verify tamper safety. The pellets or rice stay in place surprisingly well under a vacuum seal, and nesting of vacuum seal bags can be used to increase security or daisy-chain in multiple packages.
This might be worth looking into for Purism since it takes a lot less effort than painting each screwhead, which I believe has also been defeated without detection (it's mentioned in the linked article). Maybe a combined approach would work best for narrowing down the tampered with areas.
0: https://news.ycombinator.com/item?id=31897530 https://news.ycombinator.com/item?id=31897530
1: https://dys2p.com/en/2021-12-tamper-evident-protection.html https://dys2p.com/en/2021-12-tamper-evident-protection.html
- charles_kaw 4y agoA practical, long-existing solution is glittery nail polish. For non-painted metal seams, it's quick, simple, cheap, and easy to clean off. It's also almost impossible to duplicate.
- akavel 4y agoGlitter nail polish is literally the first item discussed in the article linked by the parent poster, with the claim notably being: "With the first two methods [of applying glitter nail polish], it is sometimes very difficult or even impossible to detect manipulations. However, a thorough approach can increase the chances." Additionally, glitter nail polish is specifically what's written in the OP post (by the Librem team).
- selfhoster11 4y agoIf you want to protect a device between the factory and receipt by the customer, pellets are a far less invasive way to solve the issue. I don't expect the device to be compromised after it gets to me, mainly because it's within my sight at all times (unless I'm sleeping) because I use it all the time.
- nonrandomstring 4y agoTwo factors are important for a viable anti-tamper technology. First, the recipient must have an available technology to verify integrity. The random beads/rice method is cool because you just need a digital camera. Software that works like face recognition (a set of distance vectors between identifiable features) can run in seconds. There are 3D scanners that can snapshot an object to such accuracy that fingerprints will show up like mountain ranges. The point cloud for a laptop PCB is many gigabytes. We can send a hash to save space. Of course it's totally useless to an average person who doesn't have the same advanced scanner which costs millions. X-rays, which are super useful for supply chain integrity present a similar problem. But that creates a second problem, worse in a way. The technology cannot be too good. The scanner will pick up the thermal drift of solder during transit. That, or speck of dust, will then throw up a false positive. Unless you visually verify what the disturbance is (can't do that with the hash, need the full scan and it's time consuming) now you have a suspect device. Because digital devices might be maliciously soft-modified in undetectable ways, we can't take a chance. a $1000 device has to go in the trash. Too many false positives and it's not viable. My feeling is that several low-tech methods in cascade (to create defence in depth) are better than any single hi-tech method.
- gcr 4y agoLossily compress the point cloud then, come on. For thin two-sided objects like laptops, rasterize the depth map of each side. You might be interested in how biometric hashes for things like fingerprints or irises work, since these have the same problems: the biometric is decomposed into a “stable” part and an “unstable” part. The stable part is hashed and the unstable part is encoded as a residual. W.J.Scheirer and T.E.Boult’s work on bipartite biotokens is one potential implementation
- nonrandomstring 4y ago> W.J.Scheirer and T.E.Boult's work on bipartite biotokens is one potential implementation Cheers. Something maybe like that already going on with a bespoke principal component analysis. But finding the needle in the haystack is knowing what _might_ change and be significant. Perhaps someone re-flashes a EEPROM, leaving only tiny dimple in a gold PCB pad. A system sensitive enough to pick that up doesn't necessarily know that a micro-fracture caused by vibration isn't a threat. What you're suggesting might be good for image processing of the plastic bead vacuum shield though.
- pengaru 4y agoNice thing about using rice is it absorbs moisture, I like this idea far more than defacing a brand new object with glittery nail polish.
- Brian_K_White 4y agoDeface? I'd ask for yellow or bright green and never clean it off.
- pengaru 4y agoIf I wanted a dirty phone with clogged up screw heads I'd go buy something used off ebay/cl.
- anotherhue 4y agoNot new at all, previously used to validate nuclear disarmament http://news.bbc.co.uk/2/hi/europe/8154029.stm http://news.bbc.co.uk/2/hi/europe/8154029.stm > Additionally, the seal has a blob of glue with multi-coloured glitter inside. This is photographed close-up by the inspectors once it is in place and then again when inspectors return.
- O__________O 4y agoIt is different, the glue with glitter is hardened and adhered to the seal, making hard to replace that specific seal with another like seal. The vacuum sealed package compress and lock the beads (but could be glitter) into place, if the seal is broken, the random pattern visible through the vacuum sealed package is broken.