Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
The Courts Government Operating Systems Software Windows Encryption Security Privacy IT News

Vista Makes Forensic PC Exam Easier for Lawyers 343

Katharine writes "Jason Krause, a legal affairs writer for the American Bar Association's 'ABA Journal' reports in the July issue that Windows Vista will be a boon for those looking for forensic evidence of wrongdoing on defendants' PC's and a nightmare for defendants who hoped their past computer activities would not be revealed. Krause quotes attorney R. Lee Barrett, 'From a [legal] defense perspective, [Vista] scares me to death. One of the things I have a hard time educating my clients on is the volume of data that's now discoverable.' This is primarily attributable to Shadow Copy, TxF and Instant Search."
This discussion has been archived. No new comments can be posted.

Vista Makes Forensic PC Exam Easier for Lawyers

Comments Filter:
  • by ls671 ( 1122017 ) on Saturday July 14, 2007 @07:24AM (#19858363) Homepage
    How are you going to wipe out the virtual computer once the computer is into ennemy hands ? ;-)
  • by bigstrat2003 ( 1058574 ) on Saturday July 14, 2007 @07:45AM (#19858469)
    I don't know if that really matters. If you have something that crucial to hide, what's an obstruction of justice conviction compared to whatever else you might get slapped with? I'd imagine for any serious criminal, the potential reward is very high (won't get in jail, yeah!), while the risk is relatively low (obstruction of justice, damn... but it beats life in prison!).
  • by fish ( 6585 ) on Saturday July 14, 2007 @07:51AM (#19858499)
    It is closed source encryption - who would trust that?
  • by smittyoneeach ( 243267 ) * on Saturday July 14, 2007 @07:57AM (#19858525) Homepage Journal
    Because freedom requires commitment and effort.
  • by Ravnen ( 823845 ) on Saturday July 14, 2007 @08:17AM (#19858587)
    The article just says it's easier to gather evidence from a PC with Vista than from a PC with an older version of Windows, like XP. It's also easier to gather evidence from a PC than from a box of papers, and easier to gather evidence when there is a box of papers than when there isn't. If you wish to be secure in your illegal activities, you'd probably be wise to avoid keeping any records at all.

    As for privacy, to the extent that this sort of thing requires a legal order to hand over the information, I can't really see that it's an issue of privacy. If it is accepted that preserving the rule of law sometimes requires surrendering information that would otherwise be considered private, then that is the end of the matter: the information in such instances has ceased to be private.

    If a PC is stolen, that is another matter, but in such cases, encryption can be used to prevent private data falling into the hands of thieves. This arguably makes a PC with appropriate encryption enabled safer than paper records.

  • by Anonymous Coward on Saturday July 14, 2007 @08:29AM (#19858659)
    They do mention the good stuff, don't they? Shadow Copies, TxF, Instant Search...
    People who need to keep their computing history private will know to encrypt their block devices and disable unnecessary indexing and data safekeeping. People who are too dumb or lazy to do that are going to get bitten by random "marked as deleted" filesystem remnants on any OS. People who accidentally delete their master thesis on the day before it's due will thank Bill Gates for Shadow Copies. People who buy cheap power supplies will thank Bill Gates for TxF when their computer crashes due to a short voltage spike and their data remains consistent (or they will curse him because they think Vista crashed and they don't know what kept them safe).
  • Comment removed (Score:2, Insightful)

    by account_deleted ( 4530225 ) on Saturday July 14, 2007 @08:53AM (#19858781)
    Comment removed based on user account deletion
  • by adamwright ( 536224 ) on Saturday July 14, 2007 @09:04AM (#19858855) Homepage
    Disclaimer: I use Mac laptops, Linux servers, and Windows desktops (in the main). I am *not* a Microsoft shill.

    Right, karma to burn. How the hell is this "Informative"? "+5 Groupthink", or "+5 Telling me what I want to hear", sure. But there is no information here at all - Vista does have some "good features", regardless of what some people think. Answering your points specifically

    1) Eye Candy: If you don't like it, turn it off.
    2) Missing or shitting drivers: I have not noticed, nor do I know anyone who has noticed, Vista not supporting hardware that XP supported. Shitty drivers, well, this is a more reasonable concern, but it applies in my experience only to graphics, and then only to people for whom a 5-10% drop in performance (until nVidia get their ass in gear) is a "shitty problem". It's *vastly* better than Linux in this regard.
    3) UAC: You're doing it wrong. I have not seen a UAC prompt that wasn't because I launched an app that required admin priviledges for weeks. Sure, when you're setting up the system, you get them a lot - much like in Linux, where you prefix half the first weeks commands with "sudo". After that, if you're seeing it more than once or twice a week, you need to seriously look at what kinds of software you're running that constantly need "root" access.

    As to a sample of "good points"

    1) New graphics and sound stack is vastly superior - I can set sound volume on a per application basis, automatically, using an simple interface built right in. No more stupid Flash in Firefox blaring away at 80db when I'm listening to music via iTunes.
    2) Integrated search - Works as well as Spotlight for me, and I thought Spotlight was the best thing since sliced bread.
    3) UAC - Yes, in my eyes, this is a good thing (and the biggest step forward in Vista). Windows no longer uses an "Admin for everything" model, something most people have been crying out for it do have for years.

    Does it add anything *huge* over OS X, or even XP? No. Since when has a new OS release added anything world changing? They have been, since OS X 10.0, Linux 2 and Windows 2000, incremental. Is the DRM stuff a bad route? Yes. Does Vista use too many resources? Well, the idle footprint over my OS X machine isn't significantly greater - I would say it *does* use a too much, but frankly, as my machine is fairly modern, I don't notice. In many operations, it's faster than XP.

    Should we all move to desktop Ubuntu? I don't know - I use Linux on servers, but it's still not ready for desktops, in my eyes. A technically semi-literate friend installed it on his Laptop, as someone had preached too him, and it *mostly* worked - except sound, which was a huge pain in the ass, and even I (with years of Linux experience) couldn't make work. Mostly is not good enough (he bought an OS X laptop to replace it, and is very happy). When Linux sorts out these issues, and gets a decent suite of end user software (no, Openoffice is not good enough to be an Office replacement), I might consider putting friends and familiy onto it.

    Is Vista the devil? No. It's no worse than XP, and has several significant features that make it better, much like XP over 2000.
  • Re:Not to worry (Score:4, Insightful)

    by arashi no garou ( 699761 ) on Saturday July 14, 2007 @09:06AM (#19858871)
    Spoken like a true totalitarian. What happens when the laws change and the perfectly legal and moral things I do on my computer become immoral and illegal according to the government? Sorry bud, but I'll hang on to my privacy.
  • by value_added ( 719364 ) on Saturday July 14, 2007 @09:25AM (#19858965)
    If you wish to be secure in your illegal activities, you'd probably be wise to avoid keeping any records at all.

    Allow me to edit the above:

    If you wish to secure your data from unwanted intrusion, you'd probably be wise to avoid using Vista which records your activities using methods not found in previous Microsoft systems, or other systems in general.
  • by Anonymous Coward on Saturday July 14, 2007 @10:06AM (#19859195)
    Whenever there is an article on Privacy, or the article a few days ago on the humans need for privacy, slashdotters come out in droves to state why privacy isn't important or why privacy is already gone deal with it, or all information should be free,etc.,etc.

    Those same people come into these articles and comment about how security choices allows information to be free. Geez, make up your minds :)
  • by Ravnen ( 823845 ) on Saturday July 14, 2007 @10:20AM (#19859251)
    I'm afraid you're mistaken in suggesting that other systems do not use similar methods. Mac OS X, for example, includes Spotlight, which has similar implications to Windows Search, and the upcoming 10.5 version will include a feature called Time Machine, with similar implications to Shadow Copy in Windows. The use of ZFS might too introduce issues similar to those inherent in Transactional NTFS.

    The reality is that most users like the ability to index and search their data, and to recover previous versions of a file, as well as the better reliability offered by transactional file operations. In the general case of a non-criminal user, these features provide far greater benefits than the potential harm of having their activities more effectively analysed by law enforcement officials, in the highly improbable case of a legal order to hand over their data.

  • by ScrewMaster ( 602015 ) on Saturday July 14, 2007 @10:58AM (#19859433)
    The problem with that idea is that you are talking about a technological solution to a cultural problem. That's been discussed here on Slashdot before: so many things have been criminalized that even your "relative safe" stuff could still land you in jail. The bar has been lowered on what the law considers "bad shit".

    Personally, if I had any really bad shit on my system I'd probably just have a buried NAS box somewhere on (or even off) the premises. Probably would be best if there were a hardwired connection to it: wouldn't want the Feds to use a sniffer and figure out you have the thing. Oh sure, if they really wanted to they could find it, but why make it easy? Hide the cabling and hide the point at which it attaches to the rest of your LAN. Probably want the box to run a watchdog task that will disable it completely if it detects that specific machines on the LAN have disappeared (as in "having been confiscated".) That way, even if someone performing forensics notices that there was another network drive mapped, by the time they get back to search for another machine it won't be detectable unless they start tearing down your walls.

    Of course, you'd be a lot safer not having that bad shit in the first place.
  • by Dunbal ( 464142 ) on Saturday July 14, 2007 @11:15AM (#19859505)
    I think the issue here is choice.

    YOU should be the one to decide if your OS phones home, if it stores every keystroke you ever made, if it keeps copies of all the files you ever had, etc.

    Just like a bad doctor who decides for his patient, Microsoft has decided to take choice away from the user. The only choice you are limited to now if you don't want the OS to do this is to choose another OS.
  • Re:Computer OS (Score:5, Insightful)

    by SEMW ( 967629 ) on Saturday July 14, 2007 @12:21PM (#19859943)
    "This is primarily attributable to Shadow Copy, TxF and Instant Search."

    Now, when that OS has deliberate code to track and monitor a users 'usage', it really is no more a tool to run a computer, but rather a tool to watch a user. The main job of that code is absolute control of the computer taken away from the user. ... MS have been trying to do this for years, and now it looks like they have succeeded ~ and the sheep follow and buy the crap.
    Did you read a different story to me? Exactly which one out of shadow copy, a transactional file system, and faster search (or, indeed, any other part of the OS) is designed to "track and monitor as user" or "[take] control of the computer away from the user"?
  • by ScrewMaster ( 602015 ) on Saturday July 14, 2007 @02:52PM (#19860859)
    It's very difficult for an individual to change a cultural problem, but much simpler to defend against it with technology.

    Very true, however if enough individuals begin to mount such defenses (and they are readily available to all) a change in the culture has been made. The act of convincing a significant number of people to defend themselves against potential governmental intrusion is what is important here. Doesn't matter whether they have anything specific to hide, in fact the more people who have nothing to hide that do protect themselves in this way, the safer all of us will be. I'm one of those people: my life is an open book, I have performed no criminal activity of any kind. However, as a matter of principle I can assure you that law enforcement would have to spend significant resources to get their fingers on my data without my willing cooperation. Now I might consent to give them that, but they would have to guarantee certain safeguards before I'd permit anyone to go through my stuff, and I would insist on having my attorney involved to protect what rights I still have. The reason I feel this way is because I no longer have any faith in law enforcement, because it's all to easy to criminalize someone for an activity they had no idea was illegal. They have plenty of law on their side, and I want to make sure that, if push comes to shove, I can use the law to protect myself as well. Allowing the cops to peruse your network at their convenience is not the way to do that. My father used to tell me that all governments want more and more authority over their citizens, and the only way slow that process down is to make them fight for it at every opportunity.

    Besides, things are qualitatively different nowadays. In past, cops could just walk in and take your file cabinets and that was that. Now they may have to ask for encryption keys: that puts a fair amount of control back in the hands of the individual ... and the cops don't like that.

    Tough.

An Ada exception is when a routine gets in trouble and says 'Beam me up, Scotty'.

Working...