Rethinking Police Searches of Computers
freedom-to-tinker.com
freedom-to-tinker.com
As already pointed out timestamps can often be a problem.Limiting searches to a specific timeframe is difficult because of how the forensic tools work. It's infeasible to tell the tool "only search files and data between these dates". Indeed I wish that was possible - it would make things much faster!
But more importantly we are limited in what we can investigate. Not just for legal reasons but for cost as well. As a forensic examiner I feel (and I know most of my colleagues do as well) ethically obliged to stick to the requirements of the case - as tempting (for personal interest) as it is to poke into other corners of peoples lives it is entirely unethical and wrong.
Except that timestamps can be altered.
{edit} It would get messy if he was on a computer that had a faulty cmos battery (i.e. randomly your system clock is reset to the unix epoch). Trying to figure out the true date of files with timestamps of December 31, 1969 would be difficult. ;-) (I know that's prior to the epoch, but I had a faulty cmos battery in an old PowerBook and that's what would happen)
But there are other reasons. Firstly, when you remove drives from the machines you have to open it up, photograph them in situ, remove the drives, image and replace them. It's a reasonably time consuming job (and I doubt you'd want police in your home for hours doing it :)). Secondly there may be issues imaging the drive; wrong connectors or just fickle drives. Usually in such a case you can fire up the original machine with the drive attached and load a forensic imager from CD to pull the data (in other words it's a fail safe). And finally you have to photograph the computer CMOS time next to an atomic clock to help validate any timestamps on the hard drives.
The problem is not retaining the data. We work from images anyway. The issue is that if the drive contains evidence returning the original would probably kill the case in court. If a defence analyst questions the data - say accuses us of faking it - how do you prove that if it goes back to the suspect.
I think to clarify my above stuff: Rules of evidence should state that images of the computer files in custody should be made available to suspects in some short amount of time after they are processed, due to the easy copy aspect of digital media, and the critical nature some data on the drives.
Currently the issue is that it is a logistical nghtmare die to how large police forces work. Unfortunately we are on the outside so our suggestions mostly fall on deaf ears at management level :(
Like I said, I'm not paranoid, so I don't have time to go to such lengths, but simply having physical access to a computer these days may not yield nearly as much evidence as it may have a decade ago.
Every website he has visited (are all those boys/girls/sheep over 18?)
Every book/dvd/toy he has bought - did he declare state tax on all the stuff from Amazon.
All his tax and business records.
Everywhere he has been, everyone he has phoned,emailed, texted tweeted.
The police could get all this from other sources - but imagine going to a judge and saying "we can't prove the phone was stolen - so can we check all tax records for 10years in the hope of getting him for something else?"
But by getting a warrant for computers they have a fishing expedition for his whole life.
1 - using encrypted volumes 2 - putting stuff in the cloud (encrypted where possible) 3 - using the anonymous browsing mode (which most popular browsers support)
If I'm looking at a computer I may keep an eye out for overtly illegal stuff, but you cannot go fishing. It's probably inadmissable for a start.
However it's very hard to hide everything simply because your operating systems and programs love to store stuff.
One solution might be to use a vm stored inside an encrypted partition. So all that "meta" information is also encrypted - and the host is just clean.