<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Forensically sound(ing off)</title>
	<atom:link href="http://marshalla99.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://marshalla99.wordpress.com</link>
	<description>This is the weblog of Angus M. Marshall, forensic scientist, author of Digital Forensics : digital evidence in criminal investigations and MD at n-gate ltd.</description>
	<lastBuildDate>Sun, 08 Jan 2012 14:24:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='marshalla99.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/1696d304d8fb2c971c5b7a806340dfff?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Forensically sound(ing off)</title>
		<link>http://marshalla99.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://marshalla99.wordpress.com/osd.xml" title="Forensically sound(ing off)" />
	<atom:link rel='hub' href='http://marshalla99.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Hi there,

I am a forensi&#8230;</title>
		<link>http://marshalla99.wordpress.com/2012/01/08/hi-therei-am-a-forensi/</link>
		<comments>http://marshalla99.wordpress.com/2012/01/08/hi-therei-am-a-forensi/#comments</comments>
		<pubDate>Sun, 08 Jan 2012 14:13:56 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
		
		<guid isPermaLink="false">http://marshalla99.wordpress.com/2012/01/08/hi-therei-am-a-forensi/</guid>
		<description><![CDATA[<blockquote>Hi there,

I am a forensic computing student at bournemouth university, just want to ask you that if you can help me with this question which been asked in one of our assignement. The question is

a) The knowledge and skills required by Computing or Information Technology staff working in that industry area, based on your analysis of relevant, recent job advertisements;
b) How your assessment in part a) compares with recent surveys of the Computing/IT industry in the USA, as reported by Fernández-Sanz (2009), Gallagher et al. (2010) and Litecky et al. (2010);
c) The teams’ predictions of any changes to the knowledge and skills required by Computing Forensics staff working in that industry area during the next 20 years, explaining the reasons for those predicted changes.

I have kind of done the first two questions by mentioning the knowledge and skills which we need to have for the forensic computing area etc, but I am a bit strugged to think the last part fo my question which as you can see " the predictions of any changes to the knowledge and skills required by Computing Forensics area during the next 20 years plus explaining the reasons for those predicted changes.

Is there any points or idea you can think of and would be appreciable if you could share with me.

Many Thanks</blockquote>
This arrived in my inbox today. It makes a change from the usual questions about placements. How would you respond ?<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=177&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>Hi there,</p>
<p>I am a forensic computing student at bournemouth university, just want to ask you that if you can help me with this question which been asked in one of our assignement. The question is</p>
<p>a) The knowledge and skills required by Computing or Information Technology staff working in that industry area, based on your analysis of relevant, recent job advertisements;<br />
b) How your assessment in part a) compares with recent surveys of the Computing/IT industry in the USA, as reported by Fernández-Sanz (2009), Gallagher et al. (2010) and Litecky et al. (2010);<br />
c) The teams’ predictions of any changes to the knowledge and skills required by Computing Forensics staff working in that industry area during the next 20 years, explaining the reasons for those predicted changes.</p>
<p>I have kind of done the first two questions by mentioning the knowledge and skills which we need to have for the forensic computing area etc, but I am a bit strugged to think the last part fo my question which as you can see &#8221; the predictions of any changes to the knowledge and skills required by Computing Forensics area during the next 20 years plus explaining the reasons for those predicted changes.</p>
<p>Is there any points or idea you can think of and would be appreciable if you could share with me.</p>
<p>Many Thanks</p></blockquote>
<p>This arrived in my inbox today. It makes a change from the usual questions about placements. How would you respond ?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/177/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=177&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2012/01/08/hi-therei-am-a-forensi/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>Excellent news</title>
		<link>http://marshalla99.wordpress.com/2011/11/29/excellent-news/</link>
		<comments>http://marshalla99.wordpress.com/2011/11/29/excellent-news/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 14:45:27 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[competence]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[forensic computing]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[proficiency]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[regulator]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[validation]]></category>
		<category><![CDATA[verification]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=160</guid>
		<description><![CDATA[Yet again, other activities have kept me away from this blog for far too long. Personally, I think that&#8217;s probably a good thing. A mix of casework and research commissions means I can afford to eat properly again (and those who know me will know how important it is that I maintain my physique &#8211; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=160&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Yet again, other activities have kept me away from this blog for far too long. Personally, I think that&#8217;s probably a good thing. A mix of casework and research commissions means I can afford to eat properly again (and those who know me will know how important it is that I maintain my physique &#8211; particularly in the current high winds).</p>
<p>The major projects that are keeping me busy are on a new website : <a title="Forensic Excellence" href="http://www.forensicexcellence.co.uk/" target="_blank">Forensic Excellence</a> where work on two of the three major elements of &#8220;forensic&#8221; quality systems is underway. The other bit of news is that I have an interview for funding of some work on the third element, and hope to be able to kick that work off towards the middle of next year.</p>
<p>Onwards and sideways!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/160/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=160&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/11/29/excellent-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>That&#8217;s interesting&#8230;</title>
		<link>http://marshalla99.wordpress.com/2011/10/29/thats-interesting/</link>
		<comments>http://marshalla99.wordpress.com/2011/10/29/thats-interesting/#comments</comments>
		<pubDate>Sat, 29 Oct 2011 07:21:39 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=158</guid>
		<description><![CDATA[Someone has just tried to reset the password on this WordPress.com account &#8211; and failed (so far). If you see more than the usual levels of rambling &#38; complaining in the near future, it may mean they&#8217;ve succeeded. &#160;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=158&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Someone has just tried to reset the password on this WordPress.com account &#8211; and failed (so far).</p>
<p>If you see more than the usual levels of rambling &amp; complaining in the near future, it may mean they&#8217;ve succeeded.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/158/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=158&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/10/29/thats-interesting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>Nothing else of significance&#8230;</title>
		<link>http://marshalla99.wordpress.com/2011/07/31/nothing-else-of-significance/</link>
		<comments>http://marshalla99.wordpress.com/2011/07/31/nothing-else-of-significance/#comments</comments>
		<pubDate>Sun, 31 Jul 2011 14:18:05 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[forensic]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[forensic computing]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[writing]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=149</guid>
		<description><![CDATA[This week I was approached to quote for a defence case. Helpfully, the solicitor sent me a copy of the prosecution statement so I could prepare a realistic quote. Unfortunately, for the &#8220;other side&#8221;, I&#8217;ve spent most of the week working on a couple of proposals for new ISO standards &#8211; including something on content [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=149&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This week I was approached to quote for a defence case. Helpfully, the solicitor sent me a copy of the prosecution statement so I could prepare a realistic quote. Unfortunately, for the &#8220;other side&#8221;, I&#8217;ve spent most of the week working on a couple of proposals for new ISO standards &#8211; including something on content of reports for various purposes &#8211; so was particularly sensitive to languages issues.</p>
<p>As soon as I saw the source of the statement, I knew I was going to find a phrase that troubles me &#8211; and there it was, near the end &#8220;Nothing else of significance was found&#8221;.</p>
<p>The report details the material upon which the case is based, but gives little in the way of context or other material found. It builds the case for the prosecution solicitor nicely, but doesn&#8217;t allow anyone else to form an opinion about the significance of the material because it doesn&#8217;t actually give any detail of anything except the &#8220;significant&#8221; material as determined by the report&#8217;s writer.</p>
<p>It&#8217;s a format and form of words that I&#8217;ve seen several times over the years, and every time I see it, it sounds an alarm.</p>
<p>I&#8217;ve always been told that my responsibility as an &#8220;expert witness&#8221; is to the court (or whoever is going to make a final judgment based on all the reports submitted), and is to state the facts and my interpretation as best I can based on the information available to me. If I find evidence of guilt, I should state it, if I find evidence of innocence, I should state that. I also believe that I should try to make as much information as possible available so that a proper judgment can be made.</p>
<p>To this end, I don&#8217;t just list things of &#8220;significance&#8221; but I try to give an indication of the context in terms which a non-practitioner can understand.</p>
<p>For example, if an email relates directly to the case, I don&#8217;t just list that email. I give the total number of emails found and the number found which involve the same people in the &#8220;significant&#8221; one. If illegal images are found, I try to determine how they have been downloaded, whether they&#8217;ve been deliberately saved or just cached, and whether there&#8217;s a pattern of searching or browsing that relates to them.</p>
<p>I try never to build a case directly myself but I will, quite happily, poke holes in someone else&#8217;s case &#8211; especially if they are concealing, deliberately or accidentally, useful information behind statements like &#8220;nothing else of significance was found&#8221;.</p>
<p>In my book, saying something like that is almost tantamount to dissembling. A digital evidence examiner rarely has the full facts and circumstances of the case available. A prosecution examiner or first responder will have no idea of possible defences or excuses. Limiting the report to the most damning evidence doesn&#8217;t help anyone.</p>
<p>Well &#8211; it doesn&#8217;t help anyone except the &#8220;other side&#8221;. A good independent examiner will read that sort of report and realise that there&#8217;s a lot more work they could do, and SHOULD do, to determine if a proper rebuttal can be produced &#8211; and that means more time and bigger fees. I&#8217;m not a fan of the use of Bayesian ratios in reports because I know how few people really understand them, but I know why some forensic disciplines use them &#8211; they force the reporting scientist to think about the evidence and alternative explanations, resulting in a closer examination of &#8220;insignificant&#8221; material at times.</p>
<p>At a time when pressure is on to reduce spending on legal aid, perhaps it&#8217;s time someone looked more closely at standard reports coming from both sides to see if they are really fit for purpose ? The better those reports are, the less work needs to be done performing re-examination, re-analysis and re-interpretation.</p>
<p><a title="n-gate ltd." href="http://www.n-gate.net/">n-gate ltd.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/149/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=149&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/07/31/nothing-else-of-significance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>Power &amp; Pageantry</title>
		<link>http://marshalla99.wordpress.com/2011/07/18/power-pageantry/</link>
		<comments>http://marshalla99.wordpress.com/2011/07/18/power-pageantry/#comments</comments>
		<pubDate>Mon, 18 Jul 2011 14:22:48 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[motoring]]></category>
		<category><![CDATA[cholmondeley]]></category>
		<category><![CDATA[fun]]></category>
		<category><![CDATA[heritage]]></category>
		<category><![CDATA[lotus]]></category>
		<category><![CDATA[motorsport]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=146</guid>
		<description><![CDATA[Those who know me, know that I have interests apart from thing &#8220;forensic&#8221; in nature &#8211; the main one being classic Lotus cars. I&#8217;m not going to kick off yet another debate about the direction that Group Lotus, under Proton, are trying to move in, nor am I going to talk about the problems between [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=146&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Those who know me, know that I have interests apart from thing &#8220;forensic&#8221; in nature &#8211; the main one being classic Lotus cars. I&#8217;m not going to kick off yet another debate about the direction that Group Lotus, under Proton, are trying to move in, nor am I going to talk about the problems between the new Team Lotus, Group Lotus and Classic Team Lotus.</p>
<p>Instead, something more positive.</p>
<p>I&#8217;m fortunate enough to run a 1990 Lotus Excel as my every day car (yes, it can be done, no it doesn&#8217;t stand for &#8220;Lots of Trouble, Usually Serious&#8221;, and yes it is damn good fun). Allied to that, I&#8217;m very involved with <a title="LotusExcel.net" href="http://www.lotusexcel.net/">LotusExcel.ne</a>t which has become the meeting place for the unofficial and disorganised owners&#8217; club (we also cater to the earlier wedge Elites &amp; Eclats).</p>
<p>As a club, we were invited to join other clubs at the <a title="Cholmondeley Pageant of Power" href="http://www.cpop.co.uk/">Cholmondeley Pageant of Power</a> over the weekend of 15th to 17th July. It rained. It rained a LOT. We got wet. We got muddy. We had a bloody good time standing in a field watching very expensive machines trying to avoid contact with hay bales on a slipper tarmac surface.</p>
<p>CPOP is described as &#8220;The Goodwood of the North&#8221;, but it&#8217;s far more than that. The Goodwood Festival of Speed has become an event for money &amp; celebrities. Huge sections of it are closed to the public and even the press.</p>
<p>CPOP still doesn&#8217;t take itself that seriously and is all the better for it. It&#8217;s possible to get close to everything, including unrestricted access to the paddock where you can see the cars up close, talk to the drivers and mechanics and generally do things that are no longer possible anywhere else in motorsport.</p>
<p>Yes, there are some wrinkles still to be ironed out, but on the whole this event needs to carry on so that everyone can get closer to the action and relive the glory days of motorsport while learning a bit more heritage, history and technology.</p>
<p>Of course, the main thing they need to change for next year is to let the clubs onto the track at some point. Even a couple of parade laps would be nice &#8211; we promise not to do anything too silly. Honest!</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/146/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=146&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/07/18/power-pageantry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>Valid conclusions?</title>
		<link>http://marshalla99.wordpress.com/2011/07/12/valid-conclusions/</link>
		<comments>http://marshalla99.wordpress.com/2011/07/12/valid-conclusions/#comments</comments>
		<pubDate>Tue, 12 Jul 2011 10:07:28 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[forensic]]></category>
		<category><![CDATA[casey anthony]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[forensic computing]]></category>
		<category><![CDATA[quality]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[validation]]></category>
		<category><![CDATA[verification]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=144</guid>
		<description><![CDATA[WARNING : Initial thoughts on a recent situation ahead &#8211; incomplete  &#8211; more to follow, eventually ! Recently, the Casey Anthony trial in the USA has been a source of discussion in many fora, but most recently a bit of a &#8220;spat&#8221; seems to be in danger of breaking out between the developers of two [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=144&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>WARNING : Initial thoughts on a recent situation ahead &#8211; incomplete  &#8211; more to follow, eventually !</p>
<p>Recently, the Casey Anthony trial in the USA has been a source of discussion in many fora, but most recently a bit of a &#8220;spat&#8221; seems to be in danger of breaking out between the developers of two of the tools used to analyse the web history.</p>
<p>Leaving aside the case itself, let&#8217;s start by looking at what the two developers have to say about the issue that came up during cross-examination :</p>
<p><a title="NetAnalysis" href="http://blog.digital-detective.co.uk/2011/07/digital-evidence-discrepancies-casey.html" target="_blank">http://blog.digital-detective.co.uk/2011/07/digital-evidence-discrepancies-casey.html</a></p>
<p><a title="Cacheback" href="http://www.cacheback.ca/news/news_release-20110711-1.asp" target="_blank">http://www.cacheback.ca/news/news_release-20110711-1.asp </a></p>
<p>No preference is implied by the ordering of those links, by the way, it&#8217;s just the order in which I became aware of them. I don&#8217;t use either tool &#8211; I have my own methods for doing these things when necessary.</p>
<p>Two issues arise from these two posts, for me :</p>
<p>i) Both developers admit that there were possible problems with their tools which may have resulted in incorrect results and no-one was aware of this until the two tools were run side by side</p>
<p>ii) Neither tool seems to have been validated for the case in question. I&#8217;m sure they were verified (i.e checked for conformance to design/specification) but not convinced that they were tested against the requirements for the case.</p>
<p>Here comes the repetitive bit : as far as I&#8217;m concerned under the requirements of current and proposed ISO standards, neither tool could be considered reliable. There is no clear documentation about errors nor is there evidence that either has been subjected to a proper structured validation process. Dual-tooling is not validation. It merely compares two implementations of methods designed to solve the same problem as the developers understand things. At no point does anyone check that the results are correct, just how similar they are. Two implementations of the same wrong algorithm are more likely than not to come up with the same wrong results.</p>
<p>This is typical of the issues we will see more and more of in the digital forensics world &#8211; we depend too much on third-party tools which use algorithms developed through reverse engineering and have not been completely tested.</p>
<p>I&#8217;m not suggesting that every tool needs to be tested in every possible configuration on every possible evidence source -that&#8217;s plainly impossible &#8211; but we do need to get to a position where properly structured validation is carried out, and records which document that validation &#8211; including areas which have NOT been tested &#8211; are maintained and made available.</p>
<p>An examiner should always be free to use new methods, tools &amp; processes, but should be personally responsible for choosing them and justifying their use. Information about usage limits &amp; limitations on testing are vital and any competent examiner should be able to carry out additional validation where it is needed.</p>
<p>Let the flamng (of this post) begin&#8230;</p>
<p>&nbsp;</p>
<p>P.S. &#8211; I&#8217;ve been doing a lot of work on models &amp; systems for validation recently &#8211; they&#8217;re currently commercially confidential but if you&#8217;ld like to discuss the issues more please do contact me via <a title="n-gate.net" href="http://www.n-gate.net/" target="_blank">n-gate.net</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/144/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=144&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/07/12/valid-conclusions/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>Mobile phone hacking &#8211; a warning to all</title>
		<link>http://marshalla99.wordpress.com/2011/07/07/mobile-phone-hacking-a-warning-to-all/</link>
		<comments>http://marshalla99.wordpress.com/2011/07/07/mobile-phone-hacking-a-warning-to-all/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 10:10:00 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[answering machines]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[mobile phone]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[voicemail]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=138</guid>
		<description><![CDATA[In the UK we are currently undergoing a media frenzy about &#8220;mobile phone hacking&#8221; &#8211; unauthorised access to voicemail. Firstly, the rant &#8211; IT&#8217;S NOT HACKING! (well technically it is &#8211; but it&#8217;s not some fancy complicated technical attack requiring specialist knowledge and equipment). A lot of people are under the impression that mobile phone [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=138&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In the UK we are currently undergoing a media frenzy about &#8220;mobile phone hacking&#8221; &#8211; unauthorised access to voicemail. Firstly, the rant &#8211; IT&#8217;S NOT HACKING! (well technically it is &#8211; but it&#8217;s not some fancy complicated technical attack requiring specialist knowledge and equipment).</p>
<p>A lot of people are under the impression that mobile phone voicemail is only accessible from the mobile phone itself and some may even believe that messages are stored on the phone. In fact, messages are recorded at the mobile network providers&#8217; data centres and played back over the network when the user dials in to pick them up. It isn&#8217;t even necessary to have access to the mobile phone itself to get access to someone&#8217;s voicemail account &#8211; dialling their number while the phone is off or busy on another call results in call diversion so a message can be left, and this is where the &#8220;hack&#8221; can start. By pressing the right key sequence during the &#8220;please leave a message&#8221; welcome message, anyone can get to the menu which allows voicemail to be played back. It&#8217;s a feature designed to let users listen to their messages from anywhere in the world, whether their phone is working or not, and is genuinely useful &#8211; but it creates a backdoor through which messages can be accessed.</p>
<p>Of course, a PIN is required to gain access to the mailbox but many people leave the default PIN on their account, and these are very well known &#8211; most are published on the network providers&#8217; websites or are available in the manuals available with any phone or SIM from the provider. In other cases, PINs can be guessed in the same way as passwords by doing a little bit of background research to find out things like birthdays of relatives, friends or pets, other significant dates or registration numbers of cars. Other methods, like social engineering &#8211; where carefully crafted questions and behaviour are used to get the target to reveal their PIN or even just &#8220;shoulder surfing&#8221; (watching someone enter their PIN while they listen to their messages) can be very successful too.</p>
<p>However the PIN is obtained, once the attacker has it, they have full control of the voicemail system and can listen to and delete messages at will.</p>
<p>For some users this could lead to personal data being disclosed, while for businesses it could be used to discover sensitive material.</p>
<p>If you don&#8217;t need voicemail, turn it off. If you do need it &#8211; don&#8217;t use the default PIN, use a number which isn&#8217;t associated with anything that is obviously connected to you &#8211; and change it regularly. Avoid obvious PINs like 1111, 1234, 9999 and so on &#8211; treat it like the PIN for your bank card, it could have similar value to someone who wants to spy on you. The same rules also apply to the answering machine on your land line &#8211; most of them have remote access capabilities so anyone who dials your number could listen to your messages if they can guess the access code.</p>
<p>Get into the habit of checking your voicemail. If you regularly seem to be receiving messages without the network telling you that they&#8217;re waiting, it could be an indication that someone else is listening to them. Don&#8217;t store sensitive messages on the server for too long either. Delete them as soon as you can.</p>
<p>If you&#8217;re going to leave a message for someone &#8211; don&#8217;t disclose any sensitive material, or better yet send a text message. SMS is far more difficult to intercept without legal authority.</p>
<p>Of course, there is another way to access voicemail &#8211; but that does require some technical skill and access to right equipment. It would be unprofessional of me to describe it here though. Suffice to say that OFCOM take an interest in anyone trying to offer the service commercially.</p>
<p><a title="n-gate ltd." href="http://www.n-gate.net/" target="_blank">n-gate ltd.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/138/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=138&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/07/07/mobile-phone-hacking-a-warning-to-all/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>Juries vs. the Internet &#8211; time for a change ?</title>
		<link>http://marshalla99.wordpress.com/2011/06/13/juries-vs-the-internet-time-for-a-change/</link>
		<comments>http://marshalla99.wordpress.com/2011/06/13/juries-vs-the-internet-time-for-a-change/#comments</comments>
		<pubDate>Mon, 13 Jun 2011 09:42:19 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[forensic]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[validation]]></category>
		<category><![CDATA[courts]]></category>
		<category><![CDATA[juries]]></category>
		<category><![CDATA[advisors]]></category>
		<category><![CDATA[justice]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=136</guid>
		<description><![CDATA[This story caught my eye this morning : http://www.telegraph.co.uk/technology/facebook/8571855/Juror-in-Facebook-contempt-prosecution-after-contacting-defendant-during-trial.html It highlights one of the problems we have with jury trials in the age of pervasive technology. It is only natural for someone involved in deciding the fate of another to want to obtain as much information as possible so that they can be sure they&#8217;ve made [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=136&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This story caught my eye this morning : <a href="http://www.telegraph.co.uk/technology/facebook/8571855/Juror-in-Facebook-contempt-prosecution-after-contacting-defendant-during-trial.html">http://www.telegraph.co.uk/technology/facebook/8571855/Juror-in-Facebook-contempt-prosecution-after-contacting-defendant-during-trial.html</a></p>
<p>It highlights one of the problems we have with jury trials in the age of pervasive technology. It is only natural for someone involved in deciding the fate of another to want to obtain as much information as possible so that they can be sure they&#8217;ve made the right decision. No matter how often a judge reminds a jury not to discuss the case and not to attempt to carry out their own research or to make contact with anyone else involved in the case, the temptation to &#8220;break the rules&#8221; must be almost overwhelming.</p>
<p>This is particularly true when complicated scientific or business evidence is involved. Much of it can be so obscure to the uninitiated that they feel they cannot hope to understand it without help, but that help is not provided to them, so they go off and do their own research &#8211; using untested, unapproved and unvalidated sources. Either that, or they believe what they&#8217;ve seen in the mass-media and we get the results of the dreaded &#8220;CSI effect&#8221; creeping in.</p>
<p>Perhaps its time we revised the jury system &#8211; not to abolish them, and not to have expert jurors only, but to give them access to court-approved sources of information in the jury room. Independent advisors, completely isolated from the trial materials, who can speak on the underlying principles of the technical evidence, seeking permission from the court before commenting and keeping rigorous notes of everything they discuss so that all parties can be fully aware of the issues being raised by the jury. Of course, jurors might need to be kept in isolation to prevent them seeking the extra information anyway, but perhaps having a source &#8220;on tap&#8221; in the jury room could help speed up their deliberations by giving them confidence that they know the whole story.</p>
<p>Of course, it might lead to longer trials, but that could be a price worth paying if we  can eliminate uncertainty and reticence to make a decision introduced by jurors who feel they need more information or worse, hurried decisions made by those who already think they know it all.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/136/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=136&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/06/13/juries-vs-the-internet-time-for-a-change/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>It&#8217;s the little things</title>
		<link>http://marshalla99.wordpress.com/2011/06/08/the-little-things/</link>
		<comments>http://marshalla99.wordpress.com/2011/06/08/the-little-things/#comments</comments>
		<pubDate>Wed, 08 Jun 2011 15:25:55 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[forensic]]></category>
		<category><![CDATA[forensic computing]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[fraud]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=132</guid>
		<description><![CDATA[A while back I was asked to help out with a fraud case. The investigators had done a pretty decent job of extracting relevant information but a critical aspect of the hinged on the dates when a couple of letters were written. We had some issues around the way a disc image had been captured [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=132&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A while back I was asked to help out with a fraud case. The investigators had done a pretty decent job of extracting relevant information but a critical aspect of the hinged on the dates when a couple of letters were written. We had some issues around the way a disc image had been captured which meant that everything except the &#8220;last modified&#8221; date was considered unreliable.</p>
<p>These letters had been written in word and the timestamps in the filesystem were about 2 years AFTER the dates in the text in the documents. The meta-data in the documents agreed with the filesystems.</p>
<p>The defence experts, quite rightly, put forward a suggestion that the computer used to create the documents could have had an inaccurate clock, possible even set to a future date. Unlikely, in my opinion, but possible and probably enough to create &#8220;reasonable doubt&#8221; if the evidence came to court.</p>
<p>However, as we explored the issue further and got further and further into the niceties of Windows XP clock synchronisation using NTP when connected to the Internet something in my subconscious prodded me.</p>
<p>Just out of curiosity, I ran the GNU &#8220;strings&#8221; program against one of the documents and out popped a couple of JPEG JFIF headers. so &#8211; I carved out the two JPEGs and checked the EXIF data. Both contained dates which matched the filesystem &#8211; hardly surprising and not much help countering the &#8220;clock was wrong&#8221; argument &#8211; but they also contained a signature from the program used to produce them. It was a version of photoshop which wasn&#8217;t produced until at least 18 months after the dates in the letter text.</p>
<p>Either the suspect had been indulging in time travel, or the letters as printed must have been created some time after the date he claimed.</p>
<p>Sometimes, we forget that there&#8217;s more to timeline analysis than just the clock data. Knowing when a piece of software or a file first appeared can be very helpful too.</p>
<p><a title="n-gate ltd. Forensic Science" href="http://www.n-gate.net/" target="_blank">http://www.n-gate.net/</a></p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/132/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=132&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/06/08/the-little-things/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
		<item>
		<title>ISO ISO baby &#8211; part 2</title>
		<link>http://marshalla99.wordpress.com/2011/04/20/iso-iso-baby-part-2/</link>
		<comments>http://marshalla99.wordpress.com/2011/04/20/iso-iso-baby-part-2/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 09:03:25 +0000</pubDate>
		<dc:creator>marshalla99</dc:creator>
				<category><![CDATA[forensic]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[forensic computing]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[regulator]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[validation]]></category>
		<category><![CDATA[verification]]></category>

		<guid isPermaLink="false">http://marshalla99.wordpress.com/?p=127</guid>
		<description><![CDATA[Well, I&#8217;m just about back on BST after spending last week in Singapore. In the words of Robin Williams &#8211; &#8220;IT&#8217;S HOT!&#8221; out there, and sticky, but the locals are very friendly, the food is excellent (Kopi &#38; Kaya Toast highly recommended for breakfast). Of course, I wasn&#8217;t just out there for a &#8220;jolly&#8221; (but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=127&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well, I&#8217;m just about back on BST after spending last week in Singapore. In the words of Robin Williams &#8211; &#8220;IT&#8217;S HOT!&#8221; out there, and sticky, but the locals are very friendly, the food is excellent (Kopi &amp; Kaya Toast highly recommended for breakfast).</p>
<p>Of course, I wasn&#8217;t just out there for a &#8220;jolly&#8221; (but thanks for dinner Microsoft &#8211; I promise to say nice things about you for a few hours at least), but was attending the latest meeting of ISO/IEC JTC1 SC27 working groups. This is the &#8220;Information Technology &#8211; Security Techniques&#8221; sub-committee responsible for the infamous 270xx family of standards.</p>
<p>My main responsibility was to assist with the ongoing task of editing the 27037 &#8220;Guidelines for the identification, collection, acquisition and preservation of digital evidence&#8221; document. It&#8217;s coming along nicely, but we still have considerable debate about whether this is a standard for law-enforcement, Infosec. or both.</p>
<p>My own view is that, because of the nature of the committee responsible, it needs to be an Infosec. document which can be useful for everyone &#8211; including law enforcement. This approach to it seems to be paying off as some of the resistance to it is falling away.</p>
<p>The problem with treating it as a document for law-enforcement is that any international standard in this area is bound to come into conflict with local law, local procedure etc. (you&#8217;ll see the truth of that when you read the final version and see how often we have had to include a reminder about local legislation  etc. overriding the guidance). Worse still is the possibility that an ISO document might try to tell judges how to deal with evidence &amp; matters of law.</p>
<p>We can do no more than issue some helpful information and try to set a minimum standard which will allow anyone involved in investigating digital incidents to have confidence that any organisation, working to the same standard, will use methods which are compatible. In that respect, ISO/IEC 27037 looks like it&#8217;s going to work. Ideally, of course, everyone <strong>will</strong> adopt is as a minimum standard &#8211; and that can only be good news, because there will better understanding of the issues surrounding digital evidence handling and fewer situations where examiners, like me, have to turn down cases because of problems in the early stages.</p>
<p>I just hope we can achieve the same with the three new projects that we&#8217;re hoping to launch in October &#8211; &#8220;Investigation Principles &amp; Process&#8221;, &#8220;Guidelines for Analysis &amp; Interpretation of Digital Evidence&#8221;, and &#8220;Guidance on assuring suitability and adequacy of investigation methods&#8221;.  We (the UK group) are also hopeful that our proposal for some new work on &#8220;Incident Readiness&#8221; (particularly investigate readiness) will also be launched in October.</p>
<p>If you have any suggestions for what should be included in those standards, please do let me know. These things are just written by &#8220;the great and the good&#8221; (proof : they let me play!) but are the result of debate, discussion and consensus. More ideas  = better results.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/marshalla99.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/marshalla99.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/marshalla99.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/marshalla99.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/marshalla99.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/marshalla99.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/marshalla99.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/marshalla99.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/marshalla99.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/marshalla99.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/marshalla99.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/marshalla99.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/marshalla99.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/marshalla99.wordpress.com/127/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=marshalla99.wordpress.com&amp;blog=9650552&amp;post=127&amp;subd=marshalla99&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://marshalla99.wordpress.com/2011/04/20/iso-iso-baby-part-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a9fca41b1a1dff1333cc6513c4a7285?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">marshalla99</media:title>
		</media:content>
	</item>
	</channel>
</rss>
