Showing posts with label phone forensics. Show all posts
Showing posts with label phone forensics. Show all posts

Wednesday, December 31, 2008

Business: Cell phone forensic company sells products for "free"

This is a departure from the main, science and technology thrust of this blog - I want to talk about the business side of forensics. The motivation is to highlight the government-industry partnership that exists in some countries, such as the grant program discussed in this Philadelphia Business Journal article, to push forensic tools and procedures out into the law enforcement community. The company profiled in the article (BKForensics) got into cell phone forensics through a small US Federal Government grant and then grew from there. This is also a great "lesson" for all of you budding entrepreneurs out there!

(Hat tip to Forensic Focus)

Tuesday, June 05, 2007

Evidence: Courts feeling their ways through electronic discovery issues

The Economist (UK news and economics magazine; liberal in the classic sense) reports on how the judicial system is learning to deal with discovering evidence on mobile phones, computers, and other digital devices.

Friday, May 11, 2007

Phone Forensics: Cell/Mobile Phone Forensics Recognized for What It Is

Wired has an article on Cell Phone ("Mobile Phone" for those unfamiliar with US English) Forensics that comes across as critical in tone, but, in my humble opinion, simply conveys the message that there is nothing magic about cell phone forensics - it is evidence and should be treated as such. That means establishing the chain of custody to preserve it and protect it from intentional and unintentional tampering.

The article makes a point about some software tools not having tamper protection built in. I know that this is a current issue regarding evidence, particularly digital evidence. However, the drive to ideally preserve evidence can be taken too far - real world practicalities must also be acknowledged and accommodated or else the evidential system, and therefore justice, will suffer in the end.
Aside: Please do not mistake my point - I am not against establishing standard operating procedures and best practices for preserving evidence, performing examinations, and the like. What I am against is establishing overly idealistic expectations that are not achievable in the real world across the myriad law enforcement and justice agencies. Put another way, I am for a reasonable balance that is biased toward continually improving the system over time.

The Wired article, at least to my reading, gives the impression that if a tool does not have built-in digital signature protection that it is somehow completely suspect. I don't think that is the case. There are ways to adjust operating procedures to accommodate this, such as MD5 hash generation software routines and proper (in the British sense of the word) evidence handling procedures. I think it is a good idea to have protection built-in, but that it is likewise a bad idea to automatically assume that if a tool that is used in an investigation doesn't have digital signature features built in that the evidence was likely tampered with. That sounds blindingly obvious when approached in this manner, but may not be so obvious to a jury or the general public.
To return to the main thrust of this post, cell phone data is not just any run of the mill evidence, it is "scientific evidence", so someone acting as an examiner needs to recover and analyze the data and then present the results. The article helpfully provides a link to a draft NIST (The National Institute of Standards and Technology, a US government agency) recommendation titled Guidelines on Cell Phone Forensics.

Phone forensics is a helpful tool and can provide valuable clues that would not be otherwise available. But like all scientific evidence, it must be handled, analyzed, and presented properly, and then taken into account along with other evidence, to be of use to investigators and the court.