←back to thread

81 points DoctorFreeman | 3 comments | | HN request time: 0.607s | source

If you have heard of [Haven](https://github.com/guardianproject/haven), then Tripwire fills in the void for a robust anti evil maid solution after Haven went dormant.

The GitHub repo describes both the concept and the setup process in great details. For a quick overview, read up to the demo video.

There is also a presentation of Tripwire available on the Counter Surveil podcast: https://www.youtube.com/watch?v=s-wPrOTm5qo

1. whalesalad ◴[] No.46246287[source]
We used to put nail polish on all the screws/panels so that if they were ever removed it was clear as day.
replies(1): >>46247924 #
2. lukan ◴[] No.46247924[source]
If you just have nail polish, can't an attacker just put on new nail polish after removing all the previous one?

The first comment here https://news.ycombinator.com/item?id=46244062 links to something more elaborate with nail polish.

replies(1): >>46248085 #
3. swores ◴[] No.46248085[source]
The person you replied to didn't explain the full concept - it's not just nail polish, it's nail polish with glitter in to create a unique pattern that the attacker wouldn't be able to replicate.

Unfortunately... I've seen a video of somebody defeating this concept before, not by trying to recreate the pattern with new nail polish and glitter, but by using a chemical (I can't remember what) that lets them, gently and very carefully, remove the whole layer of nail polish in one piece rather than having to break it apart, and then afterwards they stuck it back in place such that it looked identical. So it's not as secure an idea as it's often considered to be.

Edit: actually my memory was slightly wrong. The video I was remembering wasn't about defeating glitter in nail polish on a screw, but about "tamper proof" stickers which are made for the same purpose. I don't know for sure if nail polish could equally be defeated, but I suspect so. Here's that video (LockPickingLawyer defeating a tamper proof sticker): https://youtube.com/watch?v=xUJtqvYDnkg&