Don't want your laptop tampered with? Just add glitter nail polish
wired.com
wired.com
This is like that, except it (hopefully) would actually work.
You can (by means) embarrass / frustrate / reveal undesired examination / tampering of possessions by placing one or more "glitter bombs" in them. A sealed bag, container, envelope, etc. Use different colors to reveal to you just what was accessed.
Seems fine...actually. All security tools are only deterrents to varying degrees.
Even the top comment is misleading -- "this doesn't prevent tampering, it just makes it obvious to you, as the laptop owner, that your machine has been tampered with. Still useful, but then what are you supposed to do about it?"
This method provides no guarantee of detecting tampering. It provides a guarantee that if an adversary is dumb and unaware of this method, then they may break the seal and get themselves caught. But it's a bad idea to be confident that the seal itself is evidence you haven't been tampered with.
Would anyone please explain which ideas are mistaken and why?
Sometimes the goal is to determine what was taken or breached, sometimes who violated confidentiality (especially via watermarks or telltales), or how.
In some cases, the goal may be to ensure/assess planted information was actually accessed. One counterintelligence mission, Operation Mincemeat from WWII involved landing a dead body (a deceased criminal if memory serves) with bogus military plans, and a pretty elaborate back-story, to mislead German intelligence into thinking an Allied attack would occur in Greece rather than Sicily. Part of the assessment of the plan involved determining whether or not the Germans had in fact examined the documents, and forensics showed that the corners of the papers indicated that they had been secured in a manner consistent with being photographed.
https://en.wikipedia.org/wiki/Operation_Mincemeat
Another case might be, say, a journalist who wanted to be able to positively demonstrate that electronics were accessed without authorization by officials (whether in a border crossing or some other means). The glitter polish trick would make for a useful and highly embarrassing bit of evidence which could be shown to the public in the form of before-after photographs.
No, it doesn't prevent access (and the title is misleading), but it does identify access.
As for things to read: I'm generally interested in, well, a lot of things, but crypto, security, organizational and national aspects of both, and the like. Schneier's Cryptography and his more recent works (most of which focus increasingly on human factors), comp.risks, The Art of War, Neal Stephenson's Cryptonomicon, random linkage through Wikipedia (highly underrated). Actually, for that last, I should probably write intentional linkage. Find some topic you're interested in, search for a few base articles, and follow the links out to other related aspects. Particularly case studies / people, and the like.
If you're going to study WWII, I have to recommend Daniel Yergin's The Prize (either the book or the video series, I've viewed the latter and confess only skimmed through bits of the former, it's voluminous). The relationship of oil to the events of the 20th century simply cannot be overstated.
I would recommend the following books:
http://www.amazon.com/dp/0743217349
http://www.amazon.com/dp/006097771X/
http://www.amazon.com/dp/0679762892
http://www.amazon.com/dp/068486780X/
http://www.amazon.com/dp/0743217349 fully expanded is:
http://www.amazon.com/Battle-Wits-Complete-Story-Codebreakin...
e12e's comment was helpful: it supported the original post and included additional information of use to others. And as it happens, Singh's The Code Book was not included in the original list. You can find it here:
http://www.amazon.com/Code-Book-Science-Secrecy-Cryptography...
munin would have performed a superior service (remember: writing is for the benefit of the reader) if he'd at least included descriptive URLs, if not the titles of the works in question.
And your attitude could use considerable improvement.
As for being lazy, I'm not about to click through ten [edit six] links on my cell phone just to see what title hides behind the links; I appreciate that parent made a list of (presumably) relevant books -- I would have appreciated it more if he or she listed the actual book titles/authors as well.
As it was; I felt it made sense to recommend Singh's book as it is very good and relevant -- and that it wouldn't contribute much to the discussion to overtly critize parent for being inconveniently (for me) lazy.
But since you bring it up; personally I think it is good netiquette to prefix links with a meaningful title when not contained in the url, when posting in a mostly-plain-text medium. The title and author (optionally year) is relevant information -- an amazon link is trivially discoverable from that (as is a hit in your local library db) -- but the amazon link by itself isn't useful without leaving the context of the discussion. And opening ten tabs on a desktop browser on a reasonable fast connection is certainly not an insourmountable effort -- but is rather inconvenient on a cell phone (For all I know that might be why parent choose to list just the links -- mobile cut'n'paste between tabs is a pretty miserable).
Stephenson's acknowledgements also serve as something of an indirect bibliography to some of his sources -- his books in general are fantastically well researched, and often better as learning tools than nominally nonfiction texts (though you do have to keep in mind that they are works of fiction). They're generally much more engaging, for starters (after the first 100-300 pages or so...).
That's why you're seeing all of the downvotes.
It felt very much like people were going out of their way to misread me, so I replaced my comment with one that was absolutely clear that I was saying "this provides no guaranteed way of detecting tampering." Which is true, no?
I recently promised the mods that I'd try hard to be less inflammatory, and I was legitimately shocked to see my comment downvoted to oblivion when it seemed to contain no mistaken ideas. I'm doing my best to learn from this experience, but no one is providing anything for me to learn from. All I've learned is not to warn people about invalid security assumptions...
You should save those arguments for people who actually claim that you can trust that their method Y is an absolute guarantee of X. Hint: the words "absolute" and "guarantee" will be in the post.
edit: the only occurrence of "absolute" in the article:
>Short of keeping a machine with you 24/7, there is little you can do to be absolutely sure these things don’t happen[....]
In order to not do that anymore, I'll need to figure out how my argument was a strawman. It seems like the only reason people are interested in this is because they're believing it provides some sort of security; else it wouldn't be interesting by definition. So it seemed reasonable in turn to point out that this method isn't reliable.
I suppose that's literally the definition of a strawman (they never claimed it was absolutely reliable) but I'm trying to understand why it was bad to infer people would see this as a protection mechanism rather than a detection mechanism. I'll be careful about this sort of thing in the future though.
Generally I'd just go with "delete" if something came out really wrong and/or doesn't contribute anything worthwhile as written -- possibly following up with a fresh reply/comment. Prevents others from having to spend time reading something that doesn't really contribute to the conversation.
On-topic: This does sound like a great way to get a false sense of security. Who's to say some firmware hasn't been replaced? You could ofcourse transform your entire mainboard to an epoxy blob - but still - how good are you at telling epoxy blobs apart?
Using some rare colours and strange patterns might raise the bar - but an average system could probably be broken into various pins ons sockets and whatnot (pci bus/firewire/...)
Maybe run the laptop off a bootable USB 3.0 stick, which you keep in your pocket? The file system actually on the laptop could serve as a honeypot.
It provides an idea for a tamper-evident seal. Nothing more.
2.) The presenters specifically mention that this isn't the "be all/end all" of detecting tampering and the sort of people who would believe that probably have no interest in watching this presentation. Relax.
The big point which wasn't so clear is that seals are not locks. Seals exist to identify tampering; locks exist to prevent it. We use a software tool (and remote network service) to turn seals into (electronic) locks, which is kind of cool -- the integrity is measured locally using a trusted device (iPhone for now, eventually something better), verified remotely, and then a 2FA token is returned.
Glitter nail polish is maybe 70% good for this, but has the huge advantage of being widely available. Part of the goal here is to travel completely "naked" to a country, then buy a random local laptop, other local stuff, and tools, and then be able to re-create your capabilities. There are some custom conformal coatings which are brittle, much harder to pry off, single-layer, etc. which we've played around with which work much better. Plus actual paper/tape/plastic seals, and indicators already in devices (manufacturing defects like the grain of a casting).
Hooking this stuff into conventional security measures (MDM, VPN, FDE, various access control, etc.) is the ultimate goal; it's useless to detect tampering if your data is all they're after and unencrypted, after all.
My coauthor Eric Michaud is a former safeguard seals guy from Department of Energy's VAT, probably one of USG's top 3 seals programs (and probably one of the top 10 seals groups in the world), and has a physical security company (and is a lock expert), so I've been learning a lot from him about that technology.
describes a similar technique - glass spheres in transparent epoxy resin creating an uncopyable optical fingerprint. One of the comments states that tinfoil pieces in clear epoxy photographed from several angles were used as tamper proof seals during the cold war era.
"There was always a question that bogged me. Imagine you are called aside to do a routine border check in airport security area. Imagine they want to inspect your laptop. Can you refuse to surrender your password which encrypts the whole disk? Is there such right to say "Nay, what is mine stays mine"?"
As somebody who is not from the USA, are you allowed to ask that they perform any security checks in front of you? Are you allowed to ask for the TSA agent's supervisor and have them walk you through each of the steps?
I guess one obvious solution is to carry the laptop/device with you on the flight, and leave the battery/adapter in check luggage, but this becomes more difficult when you consider tablets, phones, and the like. Thoughts? As somebody who may travel to the USA one day, I'd like to hear what kinds of situations you might end up in playing games like this.
The simplest result is that they can turn you away from the USA and send you back on the next flight if they think you're a problem or unqualified to enter. You may also be detained and things get worse from there.
Carrying a laptop without a charger is not a solution at all. The hard drive can be extracted and read apart from the machine. Same for your phone/SD cards/external disks, etc.
The safest way to enter the US it seems is to carry completely blank devices, if you need to carry them at all.
Presumably once you were across the border you would have rights again and could not be removed from the US. I imagine you would be arrested, but at least you would be officially back in the system, right?
They can F with you WRT interrogation pretty much as they please until you give up or contact a lawyer, or state a belief in your being intoxicated until you get a lawyer and/or blood test, or mess with your belongings (YOU can enter but not that bottle of tequilla and not (you+the bottle)). Another way to mess with you is dual citizenship type stuff like you've legally become a citizen of Canada but haven't officially renounced US citizenship yet. They can also threaten to arrest you if you persist in trying to gain entry while illegally importing something, like, say, a bottle of tequilla or the clothes on your back. The most effective way to be refused entry as a citizen is to be drunk (aka the whole so-cal/tijuana thing).
I've heard stories from coworkers who used to visit tijuana back when it was safe (or at least, safer). I'd be mildly interested in any story of a citizen actually being denied (as opposed to them screwing around with obnoxious drunks). Or great Tijuana stories, for that matter.
Nope. You'd be deported. Probably held in a jail (or jail like) facility until you were placed on a plane/bus.
You would however have full benefit of the constitution, so anything found during an illegal search probably could not be used against you (assuming you can prove that a search took place and that the search was illegal).
It doesn't make sense to me that a US citizen, in the US not at any sort of border, could be deported under any circumstances.
Perhaps, but in this case we can assume encryption works. They can't expect you to unencrypt the drive if you don't have a power source. And really, they have less leverage to bully you into needing to operate the computer for security reasons, especially if you can show there's no way the computer can operate during flight.
If they want the data, they'll get it.
http://www.wired.com/threatlevel/2012/02/laptop-decryption-a...
Has this ever been tested in court?
I think truecrypt has something like this but I wouldn't trust truecrypt to my data. Not in this day and age.
Well, if you remove this requirement, I have a solution for you.
Jesting apart, who has not had screws fall out or work loose from a Dell or HP laptop? The likelihood that the screws are in differently due to some secret spy type of person opening the machine is quite unlikely compared to the high likelihood that they have just worked loose of their own accord.
Me. If your laptop is falling apart, it might be time for a new one.
... wait a minute, I remember seeing this earlier...
Border areas can be especially dangerous, as authorities can confiscate a laptop or cell phone
Nothing about "preventing" it from happening. Or knowing "who" was tampered with it.
Big difference.
Deleted comment
Has anyone actually had this happen to them? What was the fallout from it?