Tripwire: A new anti evil maid defense
Details
- External ID
- 46229437
- Source
- HN
- Company
- —
- Product
- Tripwire: A new anti evil maid defense
- Website domain
- github.com
- Launched
- Dec. 11, 2025
- Cohort
- —
- Upvotes
- 82
- Upvotes percentile
- 0.8702290076335878
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
If you have heard of [Haven](https://github.com/guardianproject/haven), then Tripwire fills in the void for a robust anti evil maid solution after Haven went dormant.The GitHub repo describes both the concept and the setup process in great details. For a quick overview, read up to the demo video.There is also a presentation of Tripwire available on the Counter Surveil podcast: https://www.youtube.com/watch?v=s-wPrOTm5qo
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- B2B
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- anti evil maid defense system
- Manually corrected
- False
Could you build this?
Partial While an app that monitors sensor events can be coded easily, designing an untamperable 'evil maid' defense requires secure hardware attestation, cryptographic verification, and deep OS security engineering.
What it would actually take: A proper anti-evil-maid system requires an Android/embedded device interacting with TPM 2.0 or hardware keystores, using cryptographic challenge-response protocols (e.g., TOTP or public-key signing via encrypted communication channels like Signal/Tor) to verify device integrity. The primary challenge is hardening the sensor-monitoring device against physical compromise, bypassing, or network spoofing while managing false alarms.
Discussion
20 comments analyzed.
Concerns raised: Incremental key rotation allows attackers to compute past keys, unlike hashing, False positives from insects/bugs could trigger excessive secret rotations and confuse users, Symmetric key compromise enables attackers to forge security footage, unlike asymmetric design, Nail polish tamper detection can be defeated by carefully removing and reapplying the polish layer, Low practical likelihood of successful real-world deployment
Feature requests: Rotate secret on every frame regardless of trip status, with boolean flag indicating active trip, Include timestamp and signed MAC data with each frame to prevent backdating after compromise, Add more diagrams to explain key pair signing and persistent network outage scenarios, Derive new secrets via hashing instead of deleting, to maintain record of all trips including false alarms
Competitors
Other products that read as similar to this one — 4 launches clear the similarity bar.
Attention rank: #3 of 5 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 6 days after the earliest competitor.
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.