Google probably has the largest team of internal forensics software developers.
>>> To gain access to Waymo’s design server, Mr. Levandowski searched for and installed specialized software onto his company-issued laptop. Once inside, he downloaded 9.7 GB of Waymo’s highly confidential files and trade secrets, including blueprints, design files and testing documentation. Then he connected an external drive to the laptop. Mr. Levandowski then wiped and reformatted the laptop in an attempt to erase forensic fingerprints.
The bit about connecting the external drive is interesting but I guess there's probably a ghost of that action somewhere on a drive (assuming you could more or less restore the drive before being wiped).
Or he didn't do a secure wipe when he reformatted the drive and google inspected the computer when he returned it.
OR google modifies their laptops and has separate chips logging this stuff, which would be fairly impressive!
Or he didn't actually do any of this alledged stuff and it's all innocent.
We will find out in the court case either way!
Accessing large amounts of files you haven't previously accessed and shortly thereafter attaching an external drive should trip a competent IDS.
JAMF I believe gathers application usage data but nothing as in depth as what's being discussed. It's also comically handicapped. It somehow manages to do a poor job of everything it tries to do so "the world's largest online Mac administrator community" is forum post after forum post of half understood franken-scripts. I used to think it was milquetoast but after sitting through their sales reps crapping all over open source software (despite extensive use of OSS libs in their products) and seeing it fail to do the most basic stuff out of the box my opinion is that it's over priced crap.
I can see the temptation—I've always missed having access to IP after leaving a company.
What Google could be doing is remote logging on the laptops - logs uploaded to ze cloud every time you connect to the mothership. Plugging in USB drive leaves trace with USB ID, volume information etc. Windows also logs this and more http://www.forensicswiki.org/wiki/USB_History_Viewing
Protip: to exfiltrate data with minimal trace your best bet is taking out the drive and reading it in another computer (using write blocker for best effect), this can still be traced if someone is logging SMART written/read data (I am, but Im paranoid), not all HDD/SSD vendors provide this info. Second best is booting from USB drive so the original OS never sees the plug/unplug event in the first place, I have no idea about current state of UEFI/AMT logging going on tho.
Disclaimer: I used to do forensics.
I was asked to figure out what had happened on a system where some data had changed and 2 parties were blaming each other. After about a hour digging around I managed to piece together a picture of how Person X had got up on a Monday morning, discovered (on their mobile, home wifi) that they had made a mistake on Friday, then logged in on their desktop to fix it from home (first time they logged in at home), then went to work and blamed someone else.
What was remarkable was how many different sources there were to pick up bits and pieces from. In isolation there wasn't much to go on, but once you start the connecting the parts, it's really incriminating.
They had to know that he:
1. modified the software on his laptop
2. logged into an area he should not have had access to (this is probably standard)
3. attached an external drive (possible, but standard?)
4. and they got all this info after he deleted the drive, which means they either went in and found remaining data on the drive or else they captured the info in real time.
I suppose if the drive is clean now, and they know he downloaded data, they can infer that he wiped it.
I suppose that if they know he accessed it, and there was software on his computer preventing him from doing so, they can infer that he downloaded something to overcome it.
But knowing that he connected to an external drive implies active monitoring. That's the part I am most curious about.
I'd think that standard antivirus software detects and alerts external drives being attached.
> they can infer that he wiped it
For 4), Levandowski reformatted the hard drive before returning it, so there's no inference there.
Perhaps the size of the downloaded repository is larger than the physical size of the drive on the laptop?
Google also has an internal PKI CA - I think they meet and exceed that security baseline for rigor.
The threat models targeting anti-Google malicious actions obviously worked since they have traces of the Otto guy's activities. What I am asserting is that these forensics logs they use as evidence can be attacked in court as not being sufficiently protected from tampering by an internal Google party interested in fabricating evidence.