Anti-Interdiction on the Librem 5 USA
puri.sm
puri.sm
This might be worth looking into for Purism since it takes a lot less effort than painting each screwhead, which I believe has also been defeated without detection (it's mentioned in the linked article). Maybe a combined approach would work best for narrowing down the tampered with areas.
0: https://news.ycombinator.com/item?id=31897530
1: https://dys2p.com/en/2021-12-tamper-evident-protection.html
For non-painted metal seams, it's quick, simple, cheap, and easy to clean off.
It's also almost impossible to duplicate.
"With the first two methods [of applying glitter nail polish], it is sometimes very difficult or even impossible to detect manipulations. However, a thorough approach can increase the chances."
Additionally, glitter nail polish is specifically what's written in the OP post (by the Librem team).
First, the recipient must have an available technology to verify integrity. The random beads/rice method is cool because you just need a digital camera. Software that works like face recognition (a set of distance vectors between identifiable features) can run in seconds.
There are 3D scanners that can snapshot an object to such accuracy that fingerprints will show up like mountain ranges. The point cloud for a laptop PCB is many gigabytes. We can send a hash to save space. Of course it's totally useless to an average person who doesn't have the same advanced scanner which costs millions. X-rays, which are super useful for supply chain integrity present a similar problem.
But that creates a second problem, worse in a way. The technology cannot be too good. The scanner will pick up the thermal drift of solder during transit. That, or speck of dust, will then throw up a false positive. Unless you visually verify what the disturbance is (can't do that with the hash, need the full scan and it's time consuming) now you have a suspect device.
Because digital devices might be maliciously soft-modified in undetectable ways, we can't take a chance. a $1000 device has to go in the trash. Too many false positives and it's not viable.
My feeling is that several low-tech methods in cascade (to create defence in depth) are better than any single hi-tech method.
You might be interested in how biometric hashes for things like fingerprints or irises work, since these have the same problems: the biometric is decomposed into a “stable” part and an “unstable” part. The stable part is hashed and the unstable part is encoded as a residual. W.J.Scheirer and T.E.Boult’s work on bipartite biotokens is one potential implementation
Cheers. Something maybe like that already going on with a bespoke principal component analysis. But finding the needle in the haystack is knowing what _might_ change and be significant. Perhaps someone re-flashes a EEPROM, leaving only tiny dimple in a gold PCB pad. A system sensitive enough to pick that up doesn't necessarily know that a micro-fracture caused by vibration isn't a threat. What you're suggesting might be good for image processing of the plastic bead vacuum shield though.
> Additionally, the seal has a blob of glue with multi-coloured glitter inside. This is photographed close-up by the inspectors once it is in place and then again when inspectors return.
> The word interdiction in our context refers to a laptop being intercepted between the time it leaves our fulfillment center and the time you receive and open the box.
That's very interesting, because it has nothing to do with the usual meaning of "interdiction", which is (1) "the action of prohibiting or forbidding something" or (2) "the action of intercepting and preventing the movement of a prohibited commodity or person". So my first thought when reading "anti-interdiction" was "are they trying to stop others from forbidding something?". Ok, you could somehow derive their meaning of "interdiction" from (2), but it's a stretch. Also it's contrary to the etymology - from Latin inter "between" + dicere "to speak, to say". I mean, the bad guys are not saying something, they're doing something to your laptop. Maybe "interfaction" (doing something in between) would be a better word?
Also, glitter nail polish does not work. It can be lifted and reapplied without disturbing.
I suggest that painting and photographing multiple individual blobs on each device is inefficient and a better method would be putting the device in a bag of coloured rice and evacuating air (was discussed on HN some time ago).
From a screw? That seems implausible but I'd love to be proven wrong.
The whole glitter thing does provide really strong security against any attempt to melt/dissolve it, as well as good resilience against mechanical attacks, especially when adhered to materials it bonds strongly to, typically ones that dissolve in the solvents it contains. (iso acetone, mek, etc)
Seeing these small news restore my faith in both Free/Open hardware and software, esp. when the attacks are somewhat increased.
Seems backwards. Photos ought to precede shipping. Sending the photos once the device is in hand makes it much easier for fake photos to be injected. With GPG signing and such it would still be nontrivial, but much easier. Am I missing something?
Thanks to people chewing through this for me. Always a good exercise.
Random glitter pattern recreation simply doesn't seem that hard to duplicate given NSA-level resources.
1. Lay down a blob of nail polish that's color-matched to the original. Use a 3D or inkjet-like additive printing method that allows you to closely approximate the shape of the original blob along all 3 axes.
2. Physical glitter can be inserted into, or printed onto, the replica blob during this additive printing.
Given a budget of tens (hundreds?) of millions of dollars, it seems extremely do-able.
The results would of course only withstand a certain level of scrutiny. The recipient would possibly (likely?) need some kind of microscopic analysis to detect this fraud. However it certainly seems possible (given aforementioned state-level backing) to have a high chance of fooling the victim, especially if the victim does not have state level resources.
The best bet might be for a company like Librem to employ a variety of these cheap antiinterdiction methods. Glitter polish, colored vacuum-packed rice, etc. Layer them when applicable, and randomly alternate the ones that are mutually exclusive. Each method, while defeatable, poses a fairly significant time and resource burden on the interdictor.
Take a Dremel to the phone to scratch it random and custom. Laser etch a QR code if you want, maybe a GPG signature.
Freeze the phone in a 5-gallon bucket.
FedEx overnight early AM international delivery.
Full LTE GPS tracker on the package with minute-by-minute updates.
Ensure customer tests melted water for co2 content (it will fizz) and nitrogen content (will probably also fizz) in case somebody was clever and dropped LNOX or dry ice to re-freeze.
Retrieve phone that was tampered at the factory ahead of time, despite best efforts.
You can never hope for perfect unassailable security. The best you can do is make attacks too expensive/complex for the attackers you're concerned about. From that point of view, glitter varnish produces exceedingly good results for minimal costs.
Wired: Make the tamper detection not duplicatable.
Might be countered by supercooled water if the crystallization can be made to look natural.
Supercooled water was something I thought of later, but I didn't think about the presence / lack of bubbles from normal freezing.
With all the effort you require it's almost easier to collect your phone personally at the OEM.
My product, currently in prototype stage, is made locally here in London. I go to great lengths to ensure that (even down to raw material level where possible). It’s not economical, but that’s not why I’m doing it. I’m doing it because I believe in it. Way too many known and unknown companies just offshore manufacturing. Globalisation is bad. Support the local industry and make better things here!
So what's the difference whether it is assembled in the US and say in China? How they ensure the parts they install are not compromised? Do they only employ US and security cleared workers on the assembly line?
How hard would be for the Chinese or Russians to pay an employee to slip some compromised chips to pick and place machine?
How hard would be for the Chinese or Russians to pay an employee to slip some compromised chips to pick and place machine?
Probably some orders of magnitude harder than if it were assembled in China.