Detecting unauthorized physical access with beans, lentils and colored rice (2021)
dys2p.com
dys2p.com
I'm fairly certain that this cannot defend against a determined adversary buying up a bunch of pills, reading out the ids, and then reproducing the patterns (which would already be in the database) or similar enough patterns via a non-random process. Only useful for substitution attacks where someone trusts a pill because it is in a database without realizing that its contents could have been substituted for e.g. poison.
This may be obvious, but it also seems critical for any database that might use these to have expiration dates, otherwise expired pills could be bought in bulk and resold or have their codes reused.
Not something you hear often. =D
I know explosives are often laced with statistical chemical properties that identify them. I was wondering if that could be done to limit ammunition purchases as a way to get around gun control.
In addition to authentication, I imagine they could also be used to double-check expiration dates or as a last-ditch effort to notify consumers in the event of a recall. Being able to precisely identify exactly which factory and batch any given pill or other edible item came from could be very useful in some cases.
Something like Take RED ones in afternoon, Take the capsule in evening. Would be a pain for her if each one has a different color.
Set it up once a week and then just take the pills in the appropriate cell when the time is right. This also solves the problem of "did I already take my pills for today?".
Otherwise, a block of (say) white icing sugar, encapsulated in a block of (opaque) resin, would pass a machine inspection and icing sugar-sniffing dogs at the border... and a lot of icing sugar would enter the country in a resin mold.
Rice, for example, is not allowed or might require specific permission to import into Australia. Coffee, noodles, pasta, pepper, and wheat might be restricted.
https://www.abf.gov.au/entering-and-leaving-australia/can-yo...
Colorations brand from discount school supply or amazon works well for her and she makes a lot of colorful rice!
It's great to see someone packaging what look like Reggio style provocations. I hope she is as successful (or more) as Love Every has been with aesthetic Montessori objects.
Thanks!
I've noticed that ECE can be Montessori or Waldorf but never Reggio -- instead it's 'Reggio inspired'. I thought this was a local quirk of how programs describe of themselves but perhaps it's more widespread.
Has your wife had any discussion with kiwico? Is kiwico a threat to success? Are there noticeable advantages/disadvantages to subscription vs á la carte sales?
Definitely very similar to kiwico, no direct conversations, not that worried as there is a fair amount of overlap as well as differences.
She’s done lots of approaches over the years (eg selling at festivals pre-Covid) and life is a lot easier now that the focus is mainly subscriptions.
Phone number is on the site and she says she’d be happy to chat if you want to give a call.
The problem with doing something as elaborate as wrapping stuff in vacuum packed beans is that it draws attention and provides an adversary plausible deniability due to customs inspections etc, "Oh sorry the DEA had to inspect your package but it's fine, here's your beans too".
If my use case for this device is so sensitive that I’m taking these steps to avoid it being intercepted, any evidence of tampering, even slight, means the device is compromised, /full stop/.
In your scenario when the government hands me three bags of lentils & my device I thank them, walk to the nearest dumpster, and pitch the whole lot in because I have to assume it’s been bugged.
As you suggest, if your use case is so sensitive or critical that you can afford to send 10 laptops and only use the ones that arrive in tact then fair enough - however for the more common scenario of just being a privacy conscious individual who would like some degree of ability to determine tampering in transit - this is a non-starter.
It's not unthinkable that a method exists with as much resilience without attracting unwanted attention.
I do this to detect obvious attempts at opening the suitcase (to have a look what is inside, or to plant nuclear weapons for me to transport them).
When the suitcase is on the reception belt, I inspect the zips and if they are broken (or missing) i immediately go to the police/customs agents for them to inspect my suitcase because I see it was tempered with.
It happened twice that the zips were missing. There was no problem for the agents to inspect my luggage. Nothing was found or missing, the zips were probably broken during transport (or someone had a look inside but did not find anything interesting.
Just in case you didn't know, unless you buy ones that are specifically hard to open (like if you instead use ones from a random hardware store), they are trivial to open without breaking it by lifting the flap inside the lock-mechanism with something thin and sharp, roll it back out and inserting it again once you've done your deed.
It will not protect le against everything, and this is the reason i do not go for anything fancy. I just hope that the ones who would like to put something in would be deterred by the zips.
Anything that breaks visibly (a seal for instance) would do, but this leaves traces on the suitcase.
The question "did you pack your bag?" that customs officers ask is used to infer guilt. Once you answer yes to this question you are criminally liable for whatever is in the suitcase. In Australia a number of baggage handlers have been convicted of trafficking drugs. Unsuspecting tourists have also been convicted of drug trafficking and sentenced to 10+ years in prison
A company makes security seals for this very purpose and markets them under the name "TamperTell". They have a serial number on them and a matching receipt tab that you remove before flight then check against on arrival.
I wouldn't put too much trust into the marketing of products like this. Time and time again they fail to protect against the most basic of "lockpicking", and unless I've seen multiple skilled people failing at unlocking the "TamperTell", I'd put it in the same bucket as the rest.
> DEF CON 18 (2010) held the first ever "Tamper Evident" contest, where contestants were given a box sealed with a variety of tamper evident devices, many of which purport to be "tamper proof." All of these devices were defeated, even by those with little experience and a limited toolkit. Like the computer world, many of these devices are overmarketed
The threat vector I am defending against is one baggage handler in one airport putting drugs in my bag and another baggage handler at the destination airport retrieving them.
Why would they go to the hassle of having to fiddle around with a bag with a seal on it leaving prints in the process? If they want to use my bag to smuggle drugs they will most likely just rip the tags off it. If I kick up a fuss at the destination airport they will find nothing out of the ordinary in the bag and assume that customs inspected it at departure or the seal somehow broke off in transit.
Any seal that uses an adhesive is often easily removed with acetone. Seals that use multiple materials like plastic and metal, well you can dissolve the metal component and replace it if you have multiple blanks of the seal. If the plastic part is the part that is serialized then bobs your uncle.
I moved on to using security paper to make high security envelopes. There are a ton of different features you can combine to make a unique security paper. Then mechanically sealing it with security wire and a lead seal. If an evil maid needs inside they would need to duplicate the security paper's features.
This place sells a sampler pack of high security papers for cheap: http://www.secureguardpapers.com/assortment-w.html
If you want to go off the rails and raise legal questions for the government though, do this. Go to the treasury and buy sheets of uncut US currency to make your envelopes out of - remember all bills are uniquely serialized. If you are a true high roller buy uncut $100 bills, they probably have extra security features. Assuming your theoretical evil maid is a US government employee, it raises an interesting question: are NSA/US government employees allowed to forge/duplicate US currency in the pursuit of protecting national security?
If you want to see other interesting application of anti-tampering features, go check out your passport and all your visa stamps in it. The low hanging fruit is UV, but don't forget that there are two common bands of UV, shortwave is where it's at. Lots of fluorescing going on. But don't forget IR transparent inks there (or IRT). Also don't forget that fluorescence can happen in wavelengths outside the human visible spectrum. If you shine an IR laser pointer at stuff there are inks that can fluoresce from IR back into the visible spectrum. There's a ton of other things too, but your passport has a cornucopia of interesting tamper evident features.
And don't get me started on microwires. If conspiracy folks had any idea about these their heads would explode. https://security-paper.tagit-eas.ch
We already know plenty of things they are not “allowed” to do, but happen anyway. If they’re already invested to the level of effort it takes to duplicate security seals, I think they can call off the Secret Service from investigating a little counterfeiting.
Don't forget to put some sealed US currency envelopes in your suitcases while flying kiddos, the TSA needs to have fun too.
Why would they need to counterfeit the notes? Is there something stopping the NSA from calling up the treasury and asking for uncut sheets with specific serial numbers?
Would they even be breaking the law if they decided to go it along and reverse engineer the printing process? While the Treasury is granted the right to print physical money[0] it does not exclude anyone else from physically printing money as well. Further counterfeiting/forging currency[1] needs to have the intent to defraud.
I get your point though. I guess it would operate similarly to the operations of undercover police who have to break laws as part of their work. I suspect a lot of oversight would be needed from the upper levels of the organisation so as not to fall foul of the Justice Department.
Judging by the size and description of the object it was not this though.
A while ago there was a big court case in Bali in which an Australian who was travelling there was accused of importing drugs from Australia. As part of their defence they claimed that the drugs found in the luggage was not theirs and that the most likely explanation was that it was evidence of some type of interstate drug smuggling operation. During this time a high ranking member of the Australian Federal Police came forward and said that it was well known within the AFP that criminals were using unsuspecting travelers luggage to smuggle drugs. At the same time people started coming forth claiming that they had returned home from travelling overseas and found drugs in their luggage. Scared and not knowing what to do they flushed it down the toilet.
That's not how criminal law works in most places: "Mens rea is the mental element of a person's intention to commit a crime; or knowledge that one's action or lack of action would cause a crime to be committed. It is considered a necessary element of many crimes."
It may not be how it is supposed to work but how does one defend a drug possession charge when they are in possession of drugs? Just say that the drugs in their backpack aren't theirs?
It's the task of the prosecution to establish not just that you possessed the drugs, but also that you intended to possess them.
It's the task of the defense to try to establish that one or both of these things aren't true.
It's the task of the court (probably a jury) to decide whether or not the prosecution has made a case that is beyond reasonable doubt.
So the normal stuff about believing people and possible miscarriages of justice still apply.
My point is just that merely stating that you packed the bags yourself doesn't really establish anything in the prosecution's favour except that it's going to be difficult to later claim that somebody else packed it for you and that you knew this. On the other hand, if they can show that you lied about who packed your bag, then it's probably going to be easier for them to convince a jury that you were up to something (namely drug smuggling). But that mere fact itself doesn't make their case complete, and stating that you packed your own bag certainly doesn't make you criminally liable for its contents any more than you were before this statement.
As to whether you "can be charged": legally, there's no requirement that has to be met to be charged. You could find yourself charged for drug smuggling tomorrow even though you haven't done anything. Whether this will happen or not depends on whether the prosecutor thinks they can win the case. So it probably won't. Saying that you packed the bag certainly doesn't change whether or not they'd win the case for the reasons I gave above.
I think this[0] piece sums up the situation nicely.
There are some very quirky laws here in Australia like "goods in custody" in the state of NSW. Essentially you can be convicted for having items in your possession that the courts "reasonable suspect" were stolen.
There are other things too like Firearm Prohibition Orders (FPOs) which once granted give the police the right to stop and search you even if they don't believe you have committed or witnessed a crime.
[0] - https://newsroom.unsw.edu.au/news/law/drug-prohibition-makes...
Can you share examples of this happening, where the conviction dependent on that admission?
https://www.cdpp.gov.au/crimes-we-prosecute/serious-drugs/dr...
Given they didn’t see your suitcase before you sealed it… what can they inspect it for?
For post-delivery tamper deterrence, ship via package receiver and audit home door/window locks, https://news.ycombinator.com/item?id=31856444
Though if that’s a legitimate part of your threat model, you’re in a very difficult situation.
Its probably (close to) impossible to establish a trust anchor in that situation. That trust anchor being the untampered image. How do you secure that? Yes you can send it to trusted friends, but at that point that just means they're now fair game too. Its definitely not safe on your phone because 0days now definitely are part of your threat model too.
I think maybe if you make it your full time job, you might have a slim chance. But realistically you'd probably only manage that for a limited time.
This may sound overly paranoid, but if they can intercept your deliveries they'll be able to snap a picture of your house key and have covert entry.
You'd probably need to barricade yourself in your bed room so that they cant get in without waking you up. Probably move the bed against the door so it can't be opened.
At some point this just degenerates into requiring unreasonable paranoia and opsec. And unless you have a specific goal to achieve, it may just not be worth it.
Plus airgaps against 0days. It's just purely very not fun I would assume.
Enterprises hire professionals to provide physical and digital security. In time, they will extend those protections to harden the perimeter of their WFH employees, when needed to protect valuable corporate IP and privileged access. This includes tamper-detection on shipments of corporate equipment to WFH employees.
A similar technique exists for non-replicable unique tokens. The token is multiple translucent microspheres pressed together and its authenticity verified by shining a laser on it from different directions and capturing the output.
Author- portion markings like that are cool and all, but fml.
Not a problem for civilians to view actually, but those with government clearance are prohibited from viewing that material unless they are in the allowed categories.
OK it could probably be reproduced, and I don’t think I recorded what the position was, but I was only 10 at the time.
TLDR: HSM housed within an envelope composed of layered electrodes having a unique capacitive signature used to derive its secret material.
https://www.hardwear.io/netherlands-2019/presentation/Enclos...
https://media.ccc.de/v/35c3-9611-enclosure-puf
> verifying the authenticity, integrity and/or the physical state of an item by employing the propagation behaviour of electromagnetic waves. In particular, it enables to check for any tamper attempts for larger structures, such as off-the-shelf computers and their periphery. The technology extends existing tamper proof approaches from the chip/PCB to a system level and is easily retrofittable. In this presentation, we are demonstrating exemplary tamper proofing in order to protect secret information without an attack-detection or data-deletion circuit (!), which is a known difficult problem and an imperfect undertaking. Therefore, we demonstrate the simplicity and effectiveness using a very cheap self-made testbed (using alumium foil) to protect standard hardware against invasive attacks, such as needle probing through the case. Cyber-physical systems are ubiquitous and are often located in non-trustworthy environments, in which data is processed that is both sensitive and worth protecting.
That is, they are measuring something to do with capacitance (at a very small "femto/10^-15" scale) at the place where they seal it up. Then you're supposed to be able to do that same measurement at the place where it arrives after shipping, and have identical readings. Even though origin and destination likely have different ambient temps, humidity, altitudes, and so on.
Then open it inside of a room kept at dry ice temperatures, do what's needed, and then put everything back.
Let the dry ice sublimate (slowly so nothing moves) and resume the shipment.
I'm wondering if it would be possible to manufacture some sort of clear plastic sandwich-like material that contains two separate chemical "fillings", kept apart by a central barrier which, if punctured, would allow the chemicals to mix together, triggering a colour-changing chemical reaction.
I guess the problem would be wrapping the target object in a way that couldn't just be unwrapped afterwards, but maybe a glue could be used which creates a chemical bond that is tamper-evident.
I've always felt for very critical equipment you'd be better off designing a PCB to be physically cracked in two, such that you need both specific halves for it to operate at all, and then ship each half separately. E.g. the electronics version of tearing a dollar bill in half and matching the two halves to verify the identity of the holder (something I've seen in spy movies). You'd probably want to make sure the recipient got the first part before shipping the second, just to make sure.
I was able to clean up the animation a little bit: https://i.imgur.com/cgKSA7H.gif
Maybe they meant “a black lentil in the lower left area has been moved, thereby moving another lentil a little bit”? (Seems an easier demonstration to me. Removing a single lentil is trickier than moving one a tiny bit)
If your intention is to be able to detect tampering during shipping but shipping always causes some disturbance then it probably deserves some discussion?
I've bought products packaged like this before and it's a really odd sensation feeling the bag go from effectively a single solid object to a bag of mush as soon as you release the vacuum.
That said: yes, vacuum-sealing good such as beans or coffee grounds provides a surprisingly solid chunk. Releasing the vacuum instantly changes the properties of the mass.
I regularly vacuum pack clothing when I travel and things move enough to change creases even in my carry-on luggage. I'm skeptical that it won't be disturbed in regular shipping unless specific measures are taken.
Email in profile.
I could see vacuum packing machines possibly working for this.
When every single shipment shows sign of tampering I would expect them to give up on this method.
The tamperer is probably better off not tampering with packages, unless they can do so in a plausibly deniable way.
Increasing attacker costs = success.
The other thing that comes to mind would be quantum systems that can only be measured once. Unfortunately I think that practically you would need a system that is "only twice" so that it can be compared, but I have this sense that anything that can be measured twice can be measured 3 times.
Lots of great links here to people working on practical solutions, but in the limit I wonder whether for many of the "black box in enemy territory" models you just have to go with self destruction as the only safe solution because anything less than a fully trusted human being is at risk for being tampered and pwnd (and even then you might still worry).
Just spitballing, but you could do it with a "once only" system if you could generate it reliabilly/deterministically enough that you don't need to measure it post-generation
After a bit of tangentially related thinking (see below), here is one possible way, and why I don't think it works. One could deterministically create a metastable state in a quantum system, e.g. by pumping a certain specific amount of energy into it. Then to figure out how much energy there was present, any additional amount of energy from by the measurement would cause the state to collapse. Unfortunately having the measured value in hand an adversary could now reproduce that state because the original process is deterministic.
For example, a classic "easy to produce hard(er) to measure" is creating aqueous solutions, where a bunch of different solutes are mixed together (I always think of ACSF, artificial cerebrospinal fluid, because I used to have to make it all the time). The creation of these can be entirely deterministic.
Unfortunately all you need is a good analytical chemist to get an approximation. Even if you used specific ratios of different isotopically pure salts they could probably reproduce it, and you would want something that would cause an irreversible change on physical tampering, such as an oxidation, cleaving, or isomerization so that you couldn't just dump the contents and put them back. All of these are tactics that delay an adversary by presenting them with a measurement and combinatorial problem, but doesn't provide the "measure once" property we need.
For extra credit, include some mysterious oozing stuff so it looks like battery acid is leaking.
Also I wonder what effect will corrosion/shock have on the resistance ?
Maybe an impedance or inductance based system with enameled wire would be more robust. So many questions, interesting :)
Other manufacturers may be interested in increasing their slim profit margins via optional packaging services.
That said, the loose-bagged option is reusable.
Sealed foam would be an option for initial shipment. The loose-bagged option is more effective against Evil Maid attackes --- frequent periods in which devices or records are left unobserved.
A simple leaf stuck in the gate made it seem completely natural and at the same time was clear to show it someone opened it.
And it was completely natural to pluck the leaf and stick it in the gate as I was leaving each day.
That effect could be used to be less 'obvious' that the package is protected.
The problem with a QR code is the “difficult to reproduce” part —- if you can organize the rice in such a way that it’s recognized as a valid QR code, surely the attacker can recreate the same QR code (or an equivalent, since QR codes have redundancy/ECC).
This process could be repeated as many times as you wanted, adding extra layers until the desired level of protection was achieved.
Another approach would be to encase the tamper-evident packaging in wood or metal before putting it in a shipping container.
The difference pop up immediately.
Stare at it for a while, and the sigh frustrated and say whatever, it's the same? Clearly you had more luck with magic eye than I did.
The cross-eyed (or wide-eyed) option tends to reveal visual discontinuities. Our eyes / visual cortex may register this but it's somewhat inconsistent.
The blink comparison shows an apparent motion, which is a signal our eyes are primed to detect.
I use both methods myself, and find the blink option is far more reliable.