Skip to main content

Questions tagged [tamper-resistance]

43 votes
2 answers
8k views

A number of crypto-dongles make the claim that it is impossible to extract the stored private key once written. Yubico: The YubiKey AES Key information can never be extracted from a YubiKey ...
Praxeolitic's user avatar
37 votes
8 answers
8k views

Is it possible to know whether a textfile, e.g. in XML format, has been edited or tampered with over time? The context to my question follows: I am a scientist in industry using a technology called ...
Drew Gibson's user avatar
18 votes
6 answers
4k views

My question regards whether or not the mitigations I use are appropriate for my threat model. Please don't jump to conclusions and say "you need to use locks" or "you can't leave your computer ...
forest's user avatar
  • 67.9k
14 votes
2 answers
2k views

What would be the best practices for securing a single-purpose Windows laptop against a determined foreign intelligence agency from tampering with data on the machine? The machine would be used ...
RogerMKE's user avatar
  • 243
12 votes
3 answers
4k views

An application runs on an embedded battery-powered PC, accessible to some restricted public, that stores secrets in RAM. To prevent cold boot attacks and that the PC is stolen to extract its secrets, ...
SDL's user avatar
  • 223
9 votes
2 answers
3k views

In contrast to digital cryptographic algorithms and protocols where many qualified high-IQ individuals dig into the details and specifics, physical tamper resistance for low-tech packages is not ...
Deer Hunter's user avatar
  • 5,368
9 votes
1 answer
455 views

I recently discovered a way to bypass a commonly used security seal system, requiring no special equipment and taking only a matter of seconds. I feel obliged to disclose this, so as to avoid the ...
sampablokuper's user avatar
8 votes
4 answers
1k views

Inspired by: Why don't OSes protect against untrusted USB keyboards? Related: What can a hacker do when he has physical access to a system? (I address the points of its main answers below.) There ...
Christopher King's user avatar
5 votes
3 answers
3k views

Can you make a TPM (or any piece of hardware) Completely tamper-proof? The “regular” tamper resistant hardware has various physical attacks http://www.milinda-perera.com/pdf/EKKLP12a.pdf I have been ...
user3711518's user avatar
5 votes
1 answer
1k views

I stumbled across this image and something immediately stood out to me. This is a photograph of a discrete TPM card. That silver cylinder on the left is a crystal oscillator, used to tell time with ...
forest's user avatar
  • 67.9k
4 votes
2 answers
5k views

The scenario is as follows: An application has a web interface through which data can be configured. The data to consider for this question is Users with a many-to-many relationship with Groups. Each ...
user3337410's user avatar
4 votes
4 answers
649 views

Roughly speaking HSM is supposed to ingest or generate some secret material (key) and then never export them through the command interface. The keys can only be used according to their configured ...
user1641237's user avatar
4 votes
1 answer
123 views

I can check that an Ubuntu iso file is indeed untampered using the public keys already present and trusted in my Ubuntu system. Now I want to switch from Ubuntu to Arch and I wonder how I can start ...
humanityANDpeace's user avatar
3 votes
2 answers
7k views

If I have an HTML form, and it has hidden inputs for ID numbers and the like (so I know the id key of of table x to update), how can I secure it so the person can't just change it and screw up ...
johnny's user avatar
  • 651
3 votes
5 answers
3k views

Say I have some Apache logs that show brute force attempts on a login page. I've singled out the IP, and found out who the culprit was. How can I show to a third party that I didn't makeup the entries ...
TACO's user avatar
  • 33

15 30 50 per page