The big point which wasn't so clear is that seals are not locks. Seals exist to identify tampering; locks exist to prevent it. We use a software tool (and remote network service) to turn seals into (electronic) locks, which is kind of cool -- the integrity is measured locally using a trusted device (iPhone for now, eventually something better), verified remotely, and then a 2FA token is returned.
Glitter nail polish is maybe 70% good for this, but has the huge advantage of being widely available. Part of the goal here is to travel completely "naked" to a country, then buy a random local laptop, other local stuff, and tools, and then be able to re-create your capabilities. There are some custom conformal coatings which are brittle, much harder to pry off, single-layer, etc. which we've played around with which work much better. Plus actual paper/tape/plastic seals, and indicators already in devices (manufacturing defects like the grain of a casting).
Hooking this stuff into conventional security measures (MDM, VPN, FDE, various access control, etc.) is the ultimate goal; it's useless to detect tampering if your data is all they're after and unencrypted, after all.
My coauthor Eric Michaud is a former safeguard seals guy from Department of Energy's VAT, probably one of USG's top 3 seals programs (and probably one of the top 10 seals groups in the world), and has a physical security company (and is a lock expert), so I've been learning a lot from him about that technology.
The big point which wasn't so clear is that seals are not locks. Seals exist to identify tampering; locks exist to prevent it. We use a software tool (and remote network service) to turn seals into (electronic) locks, which is kind of cool -- the integrity is measured locally using a trusted device (iPhone for now, eventually something better), verified remotely, and then a 2FA token is returned.
Glitter nail polish is maybe 70% good for this, but has the huge advantage of being widely available. Part of the goal here is to travel completely "naked" to a country, then buy a random local laptop, other local stuff, and tools, and then be able to re-create your capabilities. There are some custom conformal coatings which are brittle, much harder to pry off, single-layer, etc. which we've played around with which work much better. Plus actual paper/tape/plastic seals, and indicators already in devices (manufacturing defects like the grain of a casting).
Hooking this stuff into conventional security measures (MDM, VPN, FDE, various access control, etc.) is the ultimate goal; it's useless to detect tampering if your data is all they're after and unencrypted, after all.
My coauthor Eric Michaud is a former safeguard seals guy from Department of Energy's VAT, probably one of USG's top 3 seals programs (and probably one of the top 10 seals groups in the world), and has a physical security company (and is a lock expert), so I've been learning a lot from him about that technology.