4 ms·
Really nice project. I have a few questions if the authors or anyone knowledgeable is around. From the listed features: Cryptographic signing of all test r
by progbits 2y ago
Really nice project.
I have a few questions if the authors or anyone knowledgeable is around.
From the listed features:
Cryptographic signing of all test results
Tamper-evident resin seals on all connections and access points
Any attempts to open or modify the machine result in visible damage to security seals
This sounds like tampering won't break the signing, but only leaves evidence. How would this be enforced? Is the idea that a third party would regularly inspect the machine, and if evidence of tampering is found any results signed since last inspection are not to be trusted?
> The system is designed for use in supervised laboratory environments where sample chain of custody is maintained. While the machine can't prevent sample swapping before testing, it ensures that once a sample is tested, the results cannot be manipulated.
Two questions here:
- Would an approach where you have to commit to a sample label before testing help? Before running the machine you say "ok this is sample of experiment X on patient Y", this gets written to a third party transparency log, and only then the machine will produce a result and sign it together with a reference to the log. Later you can't hide such results, or run the samples again.
- Maybe the "supervised laboratory" answers my first question of inspecting the machines for tampering, if we assume the laboratory itself is to be trusted, and that only researchers might falsify results. Is this reasonable assumption? Wouldn't the laboratory or the institution be also incentivized to at least overlook cheating?