Submitting a review for consideration is easy; please first read Slashdot's book review guidelines. Updated: 2008114 by samzenpus
All trademarks and copyrights on this page are owned by their respective owners. Comments are owned by the Poster. The Rest © 1997-2009 Geeknet, Inc.
While I don't have any use for the program (Score:5, Insightful)
It's a bit short-sighted to say that nobody does. I'm sure there are lots of people out there with material on their machines that they wouldn't want a law enforcement officer to find. This tool would be perfect for their needs.
Re: (Score:2)
It sounds so basic that you really don't need to see the application to prevent it from hurting you.
Re:While I don't have any use for the program (Score:5, Insightful)
As a fan of maximizing my privacy, I would find such a tool useful just for auditing the effectiveness of my standard cleanup procedures.
You don't need to break the law to have an interest in others not seeing what you do with your computer. Whether making sure you haven't left personal financial information unencrypted on your machine, or have accidentally clicked "yes" to have your browser remember your passwords, or simply your taste in porn stars... All legal, yet things you probably would rather not leave lying around for anyone other than yourself.
Now, aside from that, don't forget that police exist to help prosecute cases, not to protect us or find the guilty party or any fluffy BS like that. Once they have you in their sights, the less they can dig up, the better. "Good news - Your alibi checked out, you didn't kill that girl. Bad news - Your computer proves that you played poker online once last year, enjoy your 2+ year federal sentence".
And hey, who better to know where Windows leaks information than Microsoft itself? Not that I would trust them as my sole source of privacy maintenance, but as I said, for auditing "best practices", such a tool would appear fairly useful.
Parent
Re: (Score:3, Insightful)
Most warrants are specific... not that I'd want to defend myself on that basis, but I'm sure a good lawyer could help you if you were investigated for child porn and the only thing they find is some evidence of Internet gambling.
On the other hand, I'd stop the Internet gambling right away, because you know they'd be looking for a way to justify getting you for that having 'lost' the child porn case.
Re:While I don't have any use for the program (Score:5, Informative)
Most warrants are specific... not that I'd want to defend myself on that basis, but I'm sure a good lawyer could help you if you were investigated for child porn and the only thing they find is some evidence of Internet gambling.
On the other hand, I'd stop the Internet gambling right away, because you know they'd be looking for a way to justify getting you for that having 'lost' the child porn case.
The *warrant* is specific, but if, in the service of the warrant, the officer finds something else, that evidence *can* be seized, and I believe it would be admissible in a court of law (IANAL!).
The police cannot search for something that is not on the warrant, however. So if the warrant specifies a "bicycle", the police would have no business looking in your sock drawer (unless said sock drawer was large enough to hold the bicycle, of course). But if the warrant specifies drugs (which could reasonably be hidden in a sock drawer), and when searching the sock drawer find a pistol, they can seize the pistol, even though it's not on the warrant.
Given the nature of a computer search, I'd expect anything on the hard drive to be fair game...
Parent
Re:While I don't have any use for the program (Score:4, Informative)
But if the warrant specifies drugs (which could reasonably be hidden in a sock drawer), and when searching the sock drawer find a pistol, they can seize the pistol, even though it's not on the warrant.
No they can't. They can only seize it if it is illegal, by itself, for the owner to possess. Now, if they find drugs as well they can probably do so under the right circumstances.
Owning a firearm, in and of itself, is not illegal for most people. This, of course, excludes certain persons such as felons, the mentally unstable and most legal, yes legal, aliens.
Parent
Re: (Score:3)
This may be true for many parts of the U. S. A. In much of civilized world,
Don't pull that "civilized world" shit. Your government telling you that you can't own them is quite uncivilized. I suppose you think the police are there to protect "you" as an individual, too.
Which, in my opion, is a good thing, but that's a different matter altogether.
Well, you're wrong. See above.
Re:While I don't have any use for the program (Score:5, Interesting)
They'll get you, one way of the other.
I'm too lazy to find links, but there was a case a while back of some minor who was accused of accessing child porn from one of Yahoo's services. By all accounts I've read, the defense correctly used the high probability of malware infection to introduce doubt that he actually downloaded the CP himself. Facing a harsh, drawn-out legal battle (as most defendants in these cases do), the family took a plea. The boy plead to a count of (something like) corruption of a minor. His "crime"? He apparently gave (or displayed -- can't recall) some adult magazine to one of his fellow under-aged buddies.
That's right, folks, some kid ended up with a criminal record and a listing on his local sex offender list for looking at nude pin-ups with a friend, something countless curious teen boys have done since nude centerfolds have been around.
Won't somebody think of the children?!?
Parent
Re:While I don't have any use for the program (Score:5, Informative)
Well, that sort of thing comes from the idea that if we don't tell kids about sex then they won't have it. You know, unlike their parents, grandparents, great-grandparents, and great-great-grandparents.
Parent
Re:While I don't have any use for the program (Score:4, Informative)
Most warrants are specific
Yes but IIRC, in the US, they can use any evidence, even of a crime other than what the warrant was initially for, if they found it while carrying out a legitimate search, while acting within the scope of the warrant.
This happens with Terry stops all the time: The officer has a right to perform a limited search of a suspect (a pat down) to ensure he isn't armed, but in so doing finds a nickle bag, which he can keep as evidence, even though that wasn't what he was allowed to look for.
I believe this goes back to the plain view doctrine [wikipedia.org].
Car analogy: If they have a warrant to search your car for coke, and while searching, notice a bloody body in the trunk and a machete with your fingerprints and the victim's blood on it in the glove box, they can certainly charge you with murder, even though that's what the warrant was for.
IANAL
Parent
Re: (Score:2)
FTFM
Re: (Score:2)
COFEE is a live-response tool. It's by no means sufficient to audit the effectiveness of your cleanup procedures.
Re:While I don't have any use for the program (Score:5, Insightful)
I agree. Using the software may not prove useful, but studying the software to see how it works might be. It is said the software can decrypt passwords and access otherwise inaccessible files. If true, that would be a major security hole that black hats could exploit, so the public has the right to know what exactly COFEE does, how it works, and how to defend their systems from it and similar software.
Parent
on a live computer system? (Score:5, Insightful)
So, don't run windows, encrypt your drive with hidden partitions and turn the thing off when the cops arrive.
Re: (Score:3, Interesting)
One of the things that happened during the "Hacker Crackdown" in 1990 was that Law Enforcement were trained to quickly separate people and their computers. Then take pictures of the set-up before touching anything. IDK if that is still the case or if they do it for say any old warrent they are serving.
Not having seen the app, but (Score:5, Insightful)
Re:Not having seen the app, but (Score:5, Insightful)
I would think even mere insertion of a USB device into a computer could lead to all sorts of problems - what if that USB key had a virus that transferred itself to the PC and then deleted itself from the USB device? The fact that this is a bog-standard set of files means that someone has to put these programs onto a writable USB drive (it's possible it's write-once but I would be dubious of that actually being the case) and then plug it into a computer - exactly the action that companies block by default because of the potential for rogue programs to be introduced and destroy/modify data.
Want to put someone in jail? Put something illegal on that USB drive, plug it into their computer with an autorun script that copies itself over and then deletes itself (and the script) from the USB drive. Then claim that it was a *different* drive you put in and submit a "clean" drive as evidence if they demand to see it.
Not to mention that actually doing *anything* on the original PC is damn stupid anyway but relying on a USB stick to run it? That's got to be asking for trouble. Oh, and disable USB and you've just stopped that attack.
I was always told that *anything* capable of writing to the drive or modifying the data you're trying to access was a no-no... that's why they image the drives through special "read-only" adaptors (apparently harder with SATA nowadays) and then analyse the image. Saving transient information onto a writable USB stick by execution of a program from that stick? Sounds like a recipe for disaster. That's gotta touch your swap or do something to memory in order to execute and proving that happened cleanly and provided a complete accurate copy of the contents of RAM/disk/swap before you plugged it in is probably impossible.
Parent
WRONG (Score:3, Interesting)
You are 100% incorrect.
I would think even mere insertion of a USB device into a computer could lead to all sorts of problems
The mere insertion of a USB device has its problems. First, you have to differentiate. Say, on a WinXPsp2 machine, a USB device has no working autostart mechanism. You can circumvent that, e.g. by using those "U3" devices that emulate a CD drive (Autostart is working fine with CD drives if you didn't disable autorun at all) or like the Conficker worm does, by displaying an "open folder" icon that will result in the action of calling
Re: (Score:2)
The idea of the utility-pack is to be run when the OS is still working (e.g. to capture passwords that are still in memory etc.). Bootable devices are another thing entirely. Such "off-line" analysis is much easier to do by just copying the drive in a special device that has no write logic to the source drive at all. You wouldn't risk an entire investigation just because you used a bootable CD to access the hard drive first, you'd access the copy.
"Microsoft COFFEE Spilled" (Score:5, Funny)
DECAF (Score:3, Funny)
"Won’t be long before DECAF is released, which will block attempts to use COFEE on your machine, I’m sure."
-- Mister Toast, Nov 08, 2009, 13:58 [torrentfreak.com]
Re: (Score:2)
The Solution? HURD! (Score:5, Funny)
Its a tool written by Microsoft, for Microsoft products. Do you have nefarious stuff you'd rather not have leaked? Warez or other secret stuff you'd rather keep hidden? The solution? Don't run Windows, run HURD! As added bonus, there's no viruses, no nasties that'll install on your system. No COFEE or other LEO programs to infect your privacy.
HURD...The only sensible solution. [wikipedia.org]
Re: (Score:2)
Do you have nefarious stuff you'd rather not have leaked? Warez or other secret stuff you'd rather keep hidden? The solution? Don't run Windows, run HURD! As added bonus, there's no viruses, no nasties that'll install on your system.
Are you fucking serious?! The HURD has been in development for almost 20 years, still isn't properly finished, and I've never heard of any software for it, aside (I assume) from the GNU stuff that forms the basis of any Linux distro anyway.
The HURD has likely missed the boat anyway, Linux drove it away years ago.
Re: (Score:3, Insightful)
Re:The Solution? Removable Drive Bay (Score:3, Interesting)
Anyone who is truly concerned with security knows that you take your drive with you and/or lock it up at night. Thankfully SSDs are lightweight and easy to stick in a pocket. I'm amazed at how many businesses don't have any physical protection plan in place, because that's how most data ends up getting into the wrong hands.
http://www.startech.com/item/SAT2510U2REM-InfoSafe-35-Bay-Removable-25-SATA-Drive-Enclosure.aspx [startech.com]
Under $40 for this model.
Creation of Adam... thought it was the same story (Score:3, Funny)
At first I thought these two stories were related.
http://gizmodo.com/5399583/famous-paintings-reproduced-in-coffee [gizmodo.com]
I was about to download the MS tool so I could create my own spectacular tasting, eye-opening, knock-off classic art.
Bloody DUH (Score:5, Insightful)
Well, of course it's useless to most of them...but that has nothing to do with whether or not COFEE is any good. Let's face it; how many casual downloaders are going to need a forensics toolkit? They already have access to all of their own files, and already know what they've been doing with their system. And COFEE is not meant to be a "point and shoot" system; it's really meant for professionals that know what they're looking for to some degree. So getting a copy and using it doesn't instantly give you some insight into how computer forensics work.
Ummm.... well.... (Score:5, Insightful)
> No, COFEE is 100 percent useless to you.'"
Yes, and the software that runs voting machines is "useless to us", too.
I think the submitter is missing the point. This (probably) closed-source tool by Microsoft (that bears repeating... by MICROSOFT) is going to be used by law enforcement to help throw people in jail. If for no 'practical' use, now that COFFEE is leaked, people will be able to reverse-engineer it an see exactly what it is doing, and how. That is a good thing.
free alternative (Score:3, Interesting)
Hmm... I wonder (Score:2)
I wonder... does cofee have a java component?
Can Cofee check my Kaffeine history?
What about locking your computer? (Score:2)
Would this utility be useless if you lock your computer when you get up from it? If so, the criminally-minded among us should do that.
If it works even with the computer locked, it implies a Microsoft back door into Windows. I doubt this.
Re:But (Score:5, Informative)
Wikipedia is your friend [wikipedia.org].
Parent
Re: (Score:2)
Re: (Score:3, Informative)
Try Helix3. Don't jump up and down, telling me that it's another Linux LiveCD. There is a Windows executable in the root directory to capture system state stuff. When that finishes, you can reboot to the LiveCD for more tools.
They have an outdated version that is free, and if you wish to pay about 7 or 8 hundred bucks, you can get the up-to-date version.
Re:But (Score:5, Insightful)
Really... why should we have to look up something stated in the summary as "100% useless to us"? Thanks fuck head!
Because:
1) You are wondering what is the damn thing in the first place (like OP did), and
2) You want to make your own opinion.
No one is forcing you to read through the wikipedia entry. I hope, for the sake of people around you, that you don't flip out as easily in real life.
Parent
Re:But (Score:5, Insightful)
Responsible Mods needed...
Come on...this guy responds to someone, who calls him a fuck head for providing a link to information connected to the post, in a calm and measured way, and somehow he gets modded flamebait?
If that doesn't get fixed, I've lost the last little bit of trust I have in the /. mod system.
Parent
Re: (Score:3, Interesting)
As far as I know, COFEE is only used when you have a search warrant. If you have a search warrant, then by definition there is no right to privacy - by granting the search warrant, the court has said that investigators are allowed to look at your stuff.
In the past, people have tried the "I was framed by the police" gambit before with very limited success - typically courts assume that the people investigating crimes aren't out to plant evidence. I'm not sure that this is a wise decision on the part of the
Re: (Score:2)
You're right, I should have been more specific. If a LE officer has a search warrant for the contents of your computer, then he has the right to access the contents of your computer, your right to privacy doesn't apply.
Re: (Score:3, Funny)
Re: (Score:2)
That lady is most likely a model who was photographed by someone else, who in turn sold a photo license to microsoft.
Re: (Score:2)
I don't know about talking to her or putting cream in her mug, but if you look through the comments below, you can get a pic at 12k resolution for ~£700. Once you've seen her skin magnified that much, you'll likely be cured of any interest you once had ;)
Re: (Score:2)
What does someone in the "security field" know about a digital forensics tool?
Very few people are actually in the security field and most who claim to be have posted a bug on a mailing list and setup a site talking about how to "hack" with Visual Basic.
Re: (Score:2)
There's nothing wrong with that. Some guys come out of the IT trenches and some come out of the management world. Most of these security guys are presenting themselves to middle and upper level management. They only need to know how to make charts and graphs, for which VB is really very good.
They of course also need to know how to get policies signed, walk into strange meeting rooms, identify and get key people into meetings to understand those policies, implement and audit them regularly. If they hav
Re:As someone in the Security Field... (Score:4, Informative)
The lowdown:
It doesn't do anything that any number of freely available, open source tools don't do (most of which, or at least most of the lineage of which can be found in Knoppix-STD (www.knoppix-std.org), and it happens to do them poorly.
Parent
Re:As someone in the Security Field... (Score:5, Interesting)
Why has the STD distro not been updated in over 5 years?
Have you tried http://www.remote-exploit.org/backtrack.html [remote-exploit.org]? It's geared towards pen testing and ethical hacking... but it's VERY good, and modern.
Parent
Re:As someone in the Security Field... (Score:5, Insightful)
If only you'd bothered to write that in the summary, rather than the clever-clever "You don't need this" shenanigans. Half these initially posts could have been avoided.
Parent
Re: (Score:3, Funny)
So what you're saying is that it's a true Microsoft product, amirite?
-jcr
Useful (Score:2)
If you are redhat racing with ms , you can use his tool to prove that their platform can't be trusted. All you need is running it.
Re: (Score:2)
No charges were laid as a result of the raid.
WTF? Why didn't he file charges against them?
-jcr