Title    Evil Maid Attacks - Remediation on the Cheap
Date    Saturday November 19, @10:18PM
Author    janrinok
We all know that when somebody gets unauthorised access to your computer hardware that security is out of the window! But what if you have to leave your hardware unattended but ostensibly in a 'secure' location - your hotel room or somebody else's home? fab23 has submitted this article on what you can do if that is the case:

fab23 writes:

The SANS Internet Storm Center published the guest diary Evil Maid Attacks - Remediation for the Cheap:

The so-called evil maid attack is an attack against hardware devices utilizing hard- and/or software. It is carried out when the hardware is left unattended, e.g., in a hotel room when you're out for breakfast. The attacker manipulates the device in a malicious way, e.g.:

There are several ways to minimize the risk of an unnoticed, successful evil maid attack. Which road you go depends on your personal threat model (and your budget, of course).

[...] If you want to have a cheap solution to be reasonably sure nobody messes unnoticed with your device when you have to leave it alone, you may carry out some countermeasures, e.g.:

Seal all screws with nail polish or glue with glitter pieces in it, and take pictures that are stored offline so that you will be able to spot manipulations

Seal not needed peripheral interfaces (e.g. USB ports)

Lock needed peripheral ports with tamper-proof solutions (e.g. one-time locks which have to be destroyed to access the port)

Leave the device in the bootup password prompt of the FDE (Full Disk Encryption) password:

So, if you absolutely have no other option, what do you do to ensure that your data remains as secure as possible?

