Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Don't want your laptop tampered with? Just add glitter nail polish (wired.com)
221 points by rdl on Dec 30, 2013 | hide | past | favorite | 83 comments


This reminds me of 1984, where Winston placed a speck of dust on the corner of his diary. He knew he couldn't prevent the authorities from reading it, he just wanted to know if they had or not. However (spoiler alert) he learns at the end of the book that they were careful to put the speck of dust back just where he left it.

This is like that, except it (hopefully) would actually work.


By far the most unbelievable thing about 1984 was how competent the government was.


I thought this was gonna be an article about making your laptop look like it belonged to a 14yr old girl and therefore uninteresting to the NSA.


i wish i were still at the point where i could believe that government agencies weren't interested in the doings of 14 year old girls (or kids in general).


Exactly what I was thinking, and may even hold some truth


Misleading title - this doesn't prevent tampering, it just makes it obvious to you, as the laptop owner, that your machine has been tampered with. Still useful, but then what are you supposed to do about it?


It may actually prevent tampering if the tampering is supposed to remain undetected.


Just look for the dude with glitter on his face.


In all seriousness: glitter gets everywhere. Something I learned in a non-security context....

You can (by means) embarrass / frustrate / reveal undesired examination / tampering of possessions by placing one or more "glitter bombs" in them. A sealed bag, container, envelope, etc. Use different colors to reveal to you just what was accessed.


glitter <nailpolish> !


It has to dry eventually, glitter falls off.


That's a stretch, and there's no mention of that in the article.


Agreed, should be titled something like "Use glitter nail polish to detect if your laptop has been tampered with"


You are informed that the machine is not to be trusted. From then on proceed depending on how secure your data is.


Still, misleading title.


Don't want your laptop tampered with? Use a [detrerrent]

Seems fine...actually. All security tools are only deterrents to varying degrees.


As mentioned in the article: before logging into a VPN, make sure your laptop hasn't been tampered with. You just downgraded the consequences of tampering from a security breach to an inconvenience (wiping / replacing your machine).


EDIT: Holy smokes. I wasn't trying to be inflammatory. Sorry. I was only saying not to trust that this is an absolute guarantee that your laptop hasn't been tampered with.

Even the top comment is misleading -- "this doesn't prevent tampering, it just makes it obvious to you, as the laptop owner, that your machine has been tampered with. Still useful, but then what are you supposed to do about it?"

This method provides no guarantee of detecting tampering. It provides a guarantee that if an adversary is dumb and unaware of this method, then they may break the seal and get themselves caught. But it's a bad idea to be confident that the seal itself is evidence you haven't been tampered with.

Would anyone please explain which ideas are mistaken and why?


First off, there's a whole school and practice of security measures which is aimed more at revealing breaches than in preventing them, per se. Audits, tamper-evident seals, tell-tales placed in maps, watermarks in documents or images, and very large swaths of system monitoring, reporting, and alerting. Much of military electronic security "Orange Book" procedures have much more to do with auditing than they do securing data.

Sometimes the goal is to determine what was taken or breached, sometimes who violated confidentiality (especially via watermarks or telltales), or how.

In some cases, the goal may be to ensure/assess planted information was actually accessed. One counterintelligence mission, Operation Mincemeat from WWII involved landing a dead body (a deceased criminal if memory serves) with bogus military plans, and a pretty elaborate back-story, to mislead German intelligence into thinking an Allied attack would occur in Greece rather than Sicily. Part of the assessment of the plan involved determining whether or not the Germans had in fact examined the documents, and forensics showed that the corners of the papers indicated that they had been secured in a manner consistent with being photographed.

https://en.wikipedia.org/wiki/Operation_Mincemeat

Another case might be, say, a journalist who wanted to be able to positively demonstrate that electronics were accessed without authorization by officials (whether in a border crossing or some other means). The glitter polish trick would make for a useful and highly embarrassing bit of evidence which could be shown to the public in the form of before-after photographs.

No, it doesn't prevent access (and the title is misleading), but it does identify access.


I just wanted to thank you for this fantastic comment. Security history is fascinating, and this provides a ton of new material for me to osmose. Do you have any more reading recommendations? I've been wanting to research the WW2 period up through the end of the cold war in particular.


I'm mostly just a vast store of useless information. Your comment brought up the association with the earlier story. I couldn't tell you the first place I encountered it, probably in some juvenile archive of war / spy stories, it's stuck with me through the years.

As for things to read: I'm generally interested in, well, a lot of things, but crypto, security, organizational and national aspects of both, and the like. Schneier's Cryptography and his more recent works (most of which focus increasingly on human factors), comp.risks, The Art of War, Neal Stephenson's Cryptonomicon, random linkage through Wikipedia (highly underrated). Actually, for that last, I should probably write intentional linkage. Find some topic you're interested in, search for a few base articles, and follow the links out to other related aspects. Particularly case studies / people, and the like.

If you're going to study WWII, I have to recommend Daniel Yergin's The Prize (either the book or the video series, I've viewed the latter and confess only skimmed through bits of the former, it's voluminous). The relationship of oil to the events of the 20th century simply cannot be overstated.


If you are interested in that sort of thing, I highly recommend the novel Cryptonomicon by Neal Stephenson - it is partly about the activities of a joint British/American counterintelligence unit whose mission is to make sure the Axis does not figure out that the Allies have broken their codes. It's also a great read in general.


Cryptonomicon is a pretty shallow treatment of intelligence during ww2, and Stephenson makes stuff up (as fiction, he doesn't claim it is fact) when the truth is even more outlandish.

I would recommend the following books:

http://www.amazon.com/dp/0743217349

http://www.amazon.com/dp/006097771X/

http://www.amazon.com/dp/0679762892

http://www.amazon.com/dp/068486780X/

http://www.amazon.com/dp/0452287472

http://www.amazon.com/dp/1452206120/


I trust Singh's "the Code Book" is hiding behind one of those amazon links?


Don't be so lazy. If you're just interested, click and find out. If you feel it should be, suggest why it's an interesting read.


Naked links offer varying level of affordance on different platforms. I've frequently been on systems (or networks) in which following through on individual links is a pain. What's particularly annoying in this case is that Amazon's full links do include item descriptions (for books: the title) in them, though you'd have to click through to the links here, search the fucking title and then click on that link before you get what you're looking for:

http://www.amazon.com/dp/0743217349 fully expanded is:

http://www.amazon.com/Battle-Wits-Complete-Story-Codebreakin...

e12e's comment was helpful: it supported the original post and included additional information of use to others. And as it happens, Singh's The Code Book was not included in the original list. You can find it here:

http://www.amazon.com/Code-Book-Science-Secrecy-Cryptography...

munin would have performed a superior service (remember: writing is for the benefit of the reader) if he'd at least included descriptive URLs, if not the titles of the works in question.

And your attitude could use considerable improvement.


If one bothers to post on hacker news, it should be for the benefit of the community. It was a lazy action and you can spare me the snide remark.


I thought it was clear that I think it belongs on a list of books that give a better treatment of codes, codebreaking and intelligence history than "Cryptonomicon" (as parent's list claim to be).

As for being lazy, I'm not about to click through ten [edit six] links on my cell phone just to see what title hides behind the links; I appreciate that parent made a list of (presumably) relevant books -- I would have appreciated it more if he or she listed the actual book titles/authors as well.

As it was; I felt it made sense to recommend Singh's book as it is very good and relevant -- and that it wouldn't contribute much to the discussion to overtly critize parent for being inconveniently (for me) lazy.

But since you bring it up; personally I think it is good netiquette to prefix links with a meaningful title when not contained in the url, when posting in a mostly-plain-text medium. The title and author (optionally year) is relevant information -- an amazon link is trivially discoverable from that (as is a hit in your local library db) -- but the amazon link by itself isn't useful without leaving the context of the discussion. And opening ten tabs on a desktop browser on a reasonable fast connection is certainly not an insourmountable effort -- but is rather inconvenient on a cell phone (For all I know that might be why parent choose to list just the links -- mobile cut'n'paste between tabs is a pretty miserable).


Hah! I just composed my reply above and included this as well.

Stephenson's acknowledgements also serve as something of an indirect bibliography to some of his sources -- his books in general are fantastically well researched, and often better as learning tools than nominally nonfiction texts (though you do have to keep in mind that they are works of fiction). They're generally much more engaging, for starters (after the first 100-300 pages or so...).


He may have done too much research on Captain Crunch breakfast cereal for that one...


But you've got to admit that he has his technical execution down to a T there.


You've went ahead and since heavily edited your comment after all the downvoting, but your initial comment was asinine and demonstrated that you had little understanding of the contents of the article (eg. probably didn't read the article).

That's why you're seeing all of the downvotes.


I read the article. It makes no mention of the fact that this isn't any guarantee your laptop hasn't been tampered with. Was it asinine to call this "another false sense of security" and "humans have invented ways around every lock in existence"?

It felt very much like people were going out of their way to misread me, so I replaced my comment with one that was absolutely clear that I was saying "this provides no guaranteed way of detecting tampering." Which is true, no?

I recently promised the mods that I'd try hard to be less inflammatory, and I was legitimately shocked to see my comment downvoted to oblivion when it seemed to contain no mistaken ideas. I'm doing my best to learn from this experience, but no one is providing anything for me to learn from. All I've learned is not to warn people about invalid security assumptions...


When somebody gives you tips on getting free food from restaurants, or saving money on your taxes, detecting whether someone has tampered with your computer, or X - arguing that you can't "trust that this is an absolute guarantee" of X is always going to be a strawman argument.

You should save those arguments for people who actually claim that you can trust that their method Y is an absolute guarantee of X. Hint: the words "absolute" and "guarantee" will be in the post.

edit: the only occurrence of "absolute" in the article:

>Short of keeping a machine with you 24/7, there is little you can do to be absolutely sure these things don’t happen[....]


Ah. Makes sense, thank you. I'm sorry if I set up a strawman, and it's worrisome to think I'm doing this without realizing it.

In order to not do that anymore, I'll need to figure out how my argument was a strawman. It seems like the only reason people are interested in this is because they're believing it provides some sort of security; else it wouldn't be interesting by definition. So it seemed reasonable in turn to point out that this method isn't reliable.

I suppose that's literally the definition of a strawman (they never claimed it was absolutely reliable) but I'm trying to understand why it was bad to infer people would see this as a protection mechanism rather than a detection mechanism. I'll be careful about this sort of thing in the future though.


off topic: as hn lacks comment history, it's advisable to not use "edit" as a "rewrite" button. I don't know if the only editing you did to you original comment above was add the single paragraph prefixed by "edit" -- or if you first changed the comment substantially, possibly without any indication -- as the first reply seem to indicate.

Generally I'd just go with "delete" if something came out really wrong and/or doesn't contribute anything worthwhile as written -- possibly following up with a fresh reply/comment. Prevents others from having to spend time reading something that doesn't really contribute to the conversation.

On-topic: This does sound like a great way to get a false sense of security. Who's to say some firmware hasn't been replaced? You could ofcourse transform your entire mainboard to an epoxy blob - but still - how good are you at telling epoxy blobs apart?

Using some rare colours and strange patterns might raise the bar - but an average system could probably be broken into various pins ons sockets and whatnot (pci bus/firewire/...)


> "..., but then what are you supposed to do about it?"

Maybe run the laptop off a bootable USB 3.0 stick, which you keep in your pocket? The file system actually on the laptop could serve as a honeypot.


Did you read the article?

It provides an idea for a tamper-evident seal. Nothing more.


People are going to apply this tamper-evident seal and believe they are secure when it hasn't been tampered with. That's dangerous, because it assumes an adversary has no way of bypassing the seal. That's quite an assumption. And if you're not getting security guarantees, then what kind of security are you getting?


1.) This is just a particular method to detect tampering. It's pretty clever in a lot of ways. As mentioned elsewhere, try reading the article.

2.) The presenters specifically mention that this isn't the "be all/end all" of detecting tampering and the sort of people who would believe that probably have no interest in watching this presentation. Relax.


No one is actually going to do this, just talk about it. Further, those interested would be well aware of the limitations.


"He put the diary away in the drawer. It was quite useless to think of hiding it, but he could at least make sure whether or not its existence had been discovered. A hair laid across the page-ends was too obvious. With the tip of his finger he picked up an identifiable grain of whitish dust and deposited it on the corner of the cover, where it was bound to be shaken off if the book was moved."


Hi -- this was a fun talk to give.

The big point which wasn't so clear is that seals are not locks. Seals exist to identify tampering; locks exist to prevent it. We use a software tool (and remote network service) to turn seals into (electronic) locks, which is kind of cool -- the integrity is measured locally using a trusted device (iPhone for now, eventually something better), verified remotely, and then a 2FA token is returned.

Glitter nail polish is maybe 70% good for this, but has the huge advantage of being widely available. Part of the goal here is to travel completely "naked" to a country, then buy a random local laptop, other local stuff, and tools, and then be able to re-create your capabilities. There are some custom conformal coatings which are brittle, much harder to pry off, single-layer, etc. which we've played around with which work much better. Plus actual paper/tape/plastic seals, and indicators already in devices (manufacturing defects like the grain of a casting).

Hooking this stuff into conventional security measures (MDM, VPN, FDE, various access control, etc.) is the ultimate goal; it's useless to detect tampering if your data is all they're after and unencrypted, after all.

My coauthor Eric Michaud is a former safeguard seals guy from Department of Energy's VAT, probably one of USG's top 3 seals programs (and probably one of the top 10 seals groups in the world), and has a physical security company (and is a lock expert), so I've been learning a lot from him about that technology.


This Slasdot article: http://m.slashdot.org/story/28566

describes a similar technique - glass spheres in transparent epoxy resin creating an uncopyable optical fingerprint. One of the comments states that tinfoil pieces in clear epoxy photographed from several angles were used as tamper proof seals during the cold war era.


There is an interesting comment in the original article, that I wasn't sure about, and figured I'd bring up here:

"There was always a question that bogged me. Imagine you are called aside to do a routine border check in airport security area. Imagine they want to inspect your laptop. Can you refuse to surrender your password which encrypts the whole disk? Is there such right to say "Nay, what is mine stays mine"?"

As somebody who is not from the USA, are you allowed to ask that they perform any security checks in front of you? Are you allowed to ask for the TSA agent's supervisor and have them walk you through each of the steps?

I guess one obvious solution is to carry the laptop/device with you on the flight, and leave the battery/adapter in check luggage, but this becomes more difficult when you consider tablets, phones, and the like. Thoughts? As somebody who may travel to the USA one day, I'd like to hear what kinds of situations you might end up in playing games like this.


The short and general answer is that the border entry area, where you are typically interacting with US Customs, is a "no-man's land" and you basically have zero rights in that zone. That goes for US citizens as well.

The simplest result is that they can turn you away from the USA and send you back on the next flight if they think you're a problem or unqualified to enter. You may also be detained and things get worse from there.

Carrying a laptop without a charger is not a solution at all. The hard drive can be extracted and read apart from the machine. Same for your phone/SD cards/external disks, etc.

The safest way to enter the US it seems is to carry completely blank devices, if you need to carry them at all.


If you are a US citizen who continuously gets refused reentry at the border, what would happen if you snuck across?

Presumably once you were across the border you would have rights again and could not be removed from the US. I imagine you would be arrested, but at least you would be officially back in the system, right?


Its very difficult to be refused entry as a citizen. Not impossible, but very difficult.

They can F with you WRT interrogation pretty much as they please until you give up or contact a lawyer, or state a belief in your being intoxicated until you get a lawyer and/or blood test, or mess with your belongings (YOU can enter but not that bottle of tequilla and not (you+the bottle)). Another way to mess with you is dual citizenship type stuff like you've legally become a citizen of Canada but haven't officially renounced US citizenship yet. They can also threaten to arrest you if you persist in trying to gain entry while illegally importing something, like, say, a bottle of tequilla or the clothes on your back. The most effective way to be refused entry as a citizen is to be drunk (aka the whole so-cal/tijuana thing).

I've heard stories from coworkers who used to visit tijuana back when it was safe (or at least, safer). I'd be mildly interested in any story of a citizen actually being denied (as opposed to them screwing around with obnoxious drunks). Or great Tijuana stories, for that matter.


I suppose the best way to handle this sort of situation would be to refuse the search, turn back away from the border, figure out somebody to hold onto your computer (mail it to a friend in the US? It would cross customs, but maybe you could hope it wouldn't be randomly searched. Alternatively just copy the drive to the internet, then trash or sell the hardware), then approach the border again without the computer. They cannot turn you away for refusing to let them search a computer if you do not have a computer.


Keep the data remote via VPN/SSH/rdesktop/VNC, and the appliance is a lump of hardware that can be reinstalled. This is easy with a laptop running vanilla Debian, not so easy to wipe/reinstall some appliances.


> and could not be removed from the US

Nope. You'd be deported. Probably held in a jail (or jail like) facility until you were placed on a plane/bus.

You would however have full benefit of the constitution, so anything found during an illegal search probably could not be used against you (assuming you can prove that a search took place and that the search was illegal).


That doesn't make sense to me, where would they deport you to? You'd be a citizen of the US, not the country you were coming from. What if your visa in that country was expired? Would the two countries just deport you back and forth until one got bored?

It doesn't make sense to me that a US citizen, in the US not at any sort of border, could be deported under any circumstances.


Doh... reading comprehension fail... did not notice the important "US citizen" bit (yeah... the key operative bit).


> The hard drive can be extracted and read apart from the machine. Same for your phone/SD cards/external disks, etc.

Perhaps, but in this case we can assume encryption works. They can't expect you to unencrypt the drive if you don't have a power source. And really, they have less leverage to bully you into needing to operate the computer for security reasons, especially if you can show there's no way the computer can operate during flight.


If you think the US government will just throw up their hands and let you pass because they can't instantly turn on the computer, I don't know what to tell you.

If they want the data, they'll get it.

http://www.wired.com/threatlevel/2012/02/laptop-decryption-a...


This has always bothered me: if it's a "no-man's land", then the situation is symmetrical: they have no rights either.

Has this ever been tested in court?


It's not symmetrical at all. The border patrol and homeland security are charged with defending the borders of the USA. You, as a traveller approaching the border, are physically on USA soil interacting with government agents/citizens but in the eyes of the government you have not entered the USA yet.

http://en.wikipedia.org/wiki/Border_search_exception


What you'd want is an encryption system that had two passwords: one that was accepted and caused the de-encryption of a volume of data that looked real, plausible, and had recent atime/mtime timestamps but wasn't actually your secret data. You would also have a second password, the existence of which you wouldn't reveal, that would also be accepted but result in the de-encryption of your true volume with your secret data.

I think truecrypt has something like this but I wouldn't trust truecrypt to my data. Not in this day and age.


Customs is not the TSA.


"As somebody who may travel to the USA one day"

Well, if you remove this requirement, I have a solution for you.


Just buy a HP/Compaq CQ series notebook and make sure that you aren't going to be parted with it for more than the ten hours needed to get to the hard drive. Simple.

Jesting apart, who has not had screws fall out or work loose from a Dell or HP laptop? The likelihood that the screws are in differently due to some secret spy type of person opening the machine is quite unlikely compared to the high likelihood that they have just worked loose of their own accord.


> who has not had screws fall out or work loose from a Dell or HP laptop?

Me. If your laptop is falling apart, it might be time for a new one.


Relevant section of the talk (about all sorts of seals, not just nail polish):

https://www.youtube.com/watch?v=d6tdq603z20&t=1h45m31s


Wax stamps, for the internet dark age.


By taking the picture with a cellphone that is kept with you at all times

... wait a minute, I remember seeing this earlier...

Border areas can be especially dangerous, as authorities can confiscate a laptop or cell phone


hash photo, remember hash.


It's more about "knowing" that your laptop was tampered with.

Nothing about "preventing" it from happening. Or knowing "who" was tampered with it.

Big difference.


I can already imagine US border officer asking "Why do you keep a bottle of nail polish? Are you a terrorist?"


Giving a whole new meaning to "robust tradecraft is such a drag" ...


Assuming you were carrying secret information on a business or government trip, wouldn't you carry the data on your person in an encrypted USB drive, with a blank/vanilla OS install on your laptop? That seems more efficient (and effective) than all this glitter spraying and photography.


How are you supposed to glitter over a laptop's ports?


Put a sticker over them, put glitter on the sticker edges.


[deleted]


This won't stop firmware attacks.


Is there a substantial risk of mailing your hard drive to your destination and simply travelling with a hollow computer?


"Border areas can be especially dangerous, as authorities can confiscate a laptop or cell phone to “examine” it, then return it with the drives imaged or malware installed."

Has anyone actually had this happen to them? What was the fallout from it?


If this got popular, I'm not sure how easy it would be to detect if someone broke your seal, replaced the screws/stickers as they were and resealed it with a clear topcoat of a similar gloss level.


Based on the comments here, I can see that this tamper evidence method is not foolproof. Is there anything that is better (harder to detect, harder to replace even if known about)?


Perhaps encrypt HDD and store boot loader, kernel and keys on USB?


I don't see how this prevents anyone from adding hardware keyloggers, mics to do side channel attacks on private keys, speakers to jump airgaps, etc.


Uhm, well that's another level of paranoia all together. The more solutions the better, even to problems that we (me at least) most probably will never have (or at least, I hope so!).


Clever!


This article is useless without pics


Good idea; we're doing another talk at RSA where we drop some tools, so I'll set up a macro rig and take some pics/videos for a supporting website. I need to buy a ring flash which actually doesn't suck, I think.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: