Microsoft device helps police pluck evidence


Recommended Posts

By Benjamin J. Romano

Seattle Times technology reporter

http://seattletimes.nwsource.com/html/micr..._msftlaw29.html

Microsoft has developed a small plug-in device that investigators can use to quickly extract forensic data from computers that may have been used in crimes.

The COFEE, which stands for Computer Online Forensic Evidence Extractor, is a USB "thumb drive" that was quietly distributed to a handful of law-enforcement agencies last June. Microsoft General Counsel Brad Smith described its use to the 350 law-enforcement experts attending a company conference Monday.

The device contains 150 commands that can dramatically cut the time it takes to gather digital evidence, which is becoming more important in real-world crime, as well as cybercrime. It can decrypt passwords and analyze a computer's Internet activity, as well as data stored in the computer.

It also eliminates the need to seize a computer itself, which typically involves disconnecting from a network, turning off the power and potentially losing data. Instead, the investigator can scan for evidence on site.

Update: Via email, a Microsoft spokeswoman said COFEE is a compilation of publicly available forensics tools, such as "password security auditing technologies" used to access information "on a live Windows system." She cited rainbow tables as an example of other such tools, and "was NOT confirming that COFEE includes Rainbow Tables."

It "does not circumvent Windows Vista BitLocker encryption or undermine any protections in Windows through secret 'backdoors' or other undocumented means."

Further, she reiterated that the tool is intended for use "by law enforcement only with proper legal authority."

Another update: This from Tim Cranton, associate general counsel at Microsoft: "The key to COFEE is not new forensic tools, but rather the creation of an easy to use, automated forensic tool at the scene. It's the ease of use, speed, and consistency of evidence extraction that is key."

From: http://blog.seattletimes.nwsource.com/tech...fee_device.html

Without a detailed list of included software, I'd say some of us already have some of the individual programs.

^^ Yes but if its labled nicely with instructions on bittorrent I can see more people who know next to nothing about stuff like that using it instead of spending the time looking. Like a scary hack pack for normal Joes.

"Further, she reiterated that the tool is intended for use "by law enforcement only with proper legal authority." "

Problem is though, most law enforcement with proper legal authority wouldn't know how to use the programs without the aid of a Micro$oft tech, let alone know how to boot from USB.

I mean hey, here in OZ the ecilops get warrants to seize hard drives, but instead take the whole PC. Every case can be thrown out of court on that alone.

Just how much does the average cop know about computers anyway?

and sooner or later someone will come out with DECAF.

"Further, she reiterated that the tool is intended for use "by law enforcement only with proper legal authority." "

Problem is though, most law enforcement with proper legal authority wouldn't know how to use the programs without the aid of a Micro$oft tech, let alone know how to boot from USB.

I mean hey, here in OZ the ecilops get warrants to seize hard drives, but instead take the whole PC. Every case can be thrown out of court on that alone.

Just how much does the average cop know about computers anyway?

and sooner or later someone will come out with DECAF.

Got an example for that one there champ? Think you might be talking out the hole in your backside to be honest.

This sort of news always scares me, probably too much lol :p . Not that I have anything bad on my computer (seriously).

It's more the possibility for abuse by criminals that make these things scary. Microsoft always say they are worried about computer security (their top priority?). But giving these tools to police is asking for trouble because you know that criminals will get these tools sooner or later. Plus the fact that this has gone on for nearly a year and is only now being made public lessens trust in Microsoft. What else about Windows don't we know about?

This is one reason I like Linux, though I am not saying anything bad about Windows or anything (seriously, Windows is cool). It's just that with open source software, you can see the source and know what it is doing. Not that I have that skill, but I feel safer using code that is open for inspection and has 'lots of eyes' constantly monitoring it.

Isn't this just a modified USB Switchblade tool???

This is what I have read: this is a USB with software on it that can be inserted into a running Windows machine. It automatically bypasses security and begins downloading data, including from RAM, off the machine. You don't need to reboot the machine for this to work at all. You don't need Admin privileges either. It just works automatically when inserted. This leads me to think that Windows itself must be coded to respond automatically to the software on this USB by dropping its security. If this is not a 'backdoor' then I don't know what is.

The question remains: does this affect MS encrypted files? Microsoft say 'no' but I am suspicious because it would be of significantly less use as a tool to police if it couldn't decrypt files, given that their targets (criminals of various types) would probably encrypt their files. I mean, if they make a 'backdoor' for all other aspects of the security of Windows systems, then why not let it decrypt as well?

This is what I have read: this is a USB with software on it that can be inserted into a running Windows machine. It automatically bypasses security and begins downloading data, including from RAM, off the machine. You don't need to reboot the machine for this to work at all. You don't need Admin privileges either. It just works automatically when inserted. This leads me to think that Windows itself must be coded to respond automatically to the software on this USB by dropping its security. If this is not a 'backdoor' then I don't know what is.

However Microsoft try to put it, Windows is executing software on a USB drive without user intervention. This is either a) intentional or b) not.

a) If it's deliberate then it's a major breach of security and trust, a 'backdoor' like you say.

b) If it's not intentional then it must be a major Windows flaw which Microsoft are not going to fix and are actually promoting.

Either way, foul play!

No with the Switchblade I've been "researching" it works with the U3 software of the U3 USB drives.

No user interaction

I put it in my test machine and downloads all passwords etc.

You can integrate a lot of software into it, such as a memory dumper etc.

This requires no backdoors

No with the Switchblade I've been "researching" it works with the U3 software of the U3 USB drives.

No user interaction

I put it in my test machine and downloads all passwords etc.

You can integrate a lot of software into it, such as a memory dumper etc.

This requires no backdoors

Then it's b) a major Windows flaw which Microsoft are not going to fix and are actually promoting.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Tor Browser 15.0.17 by Razvan Serea Protect your privacy. Defend yourself against network surveillance and traffic analysis. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. The Tor software protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody from watching your Internet connection and learning what sites you visit, it prevents the sites you visit from learning your physical location, and it lets you access sites which are blocked. The Tor Browser Bundle lets you use Tor on Windows, Mac OS X, or Linux without needing to install any software. It can run off a USB flash drive, comes with a pre-configured web browser to protect your anonymity, and is self-contained. Tor Browser 15.0.17 changelog: All Platforms Updated Tor to 0.4.9.11 Updated NoScript to 13.6.25.1984 Build System / All Platforms Bug tor-browser-build#41821: Update gpg subkeys for boklm Bug tor-browser-build#41827: Update morgan's keychain with renewed key Download: Tor Browser (64-bit) | Tor Browser (32-bit) | 109.0 MB (Open Source) View: Tor Browser Website | Other Operating Systems Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Very fitting name since AI users have air where there brains should be.
    • Yes, it was amusing at the time because even then dbrand was well known for stealing the designs of products from other companies. That’s what they do.
  • Recent Achievements

    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      530
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      99
    5. 5
      macoman
      56
  • Tell a friend

    Love Neowin? Tell a friend!