Monday, March 30, 2009

Questions Surround Former Sheriff's Laptop

Three months before 11,000 files were deleted from former Sheriff Bill Balkwill's laptop, the sheriff and two top administrators signed a document saying the computer had been sent off for recycling, according to court documents made public Friday.

In November, Balkwill, Maj. Tim Carney and Information Technology director Jeffrey Feathers each signed paperwork that indicated the laptop -- a key piece of evidence in a lawsuit over a lucrative jail contract -- was "obsolete," worth only $10 and had to be scrapped.

But the laptop was never sent to the recycling yard and Carney went to Balkwill's home to retrieve it on Feb. 4 -- the same day that someone used a common Internet program to erase 11,000 files.

The revelation that Balkwill's work laptop was supposed to be recycled came amid a criminal investigation at the Sheriff's Office, where detectives are trying to find out who deleted the files.

Read more here.


AddThis Social Bookmark Button

Wednesday, March 4, 2009

The Security Implications of a Computer Clock

Is the clock on every computer system in your organization set to the correct time? If your answer is no, you're not alone. According to a 2007 study by Florian Buchholz and Brett Tjaden, both professors at James Madison University in Virginia, more than a quarter of the Web servers on the Internet have their clocks off by more than 10 seconds. Making sure that computers are set with the correct time is one of those seemingly petty technical things that can unfortunately have big, negative consequences if not done properly. That's because assumptions about time and its flow permeate modern computer systems—including software, hardware and networking. This is true of desktop systems, servers, mobile devices and even embedded systems like HVAC, alarm systems and electronic doorknobs.

Buchholz and Tjaden studied Web servers because they are particularly amenable to analysis: Every time you request a page from a modern Web server, the server sends back an HTTP header called "date" which indicates the time-of-day for the server's clock. But unless your organization has made an effort to keep time in a precise and accurate way, the chances are very good that you're doing a bad job.

Read more here.


AddThis Social Bookmark Button

Thursday, January 29, 2009

Recession Affecting E-Discovery Providers

Economic belt-cinching has hit some electronic discovery firms, prompting layoffs and rumors of realignments.

Rumors of recent layoffs at i365, a Seagate Technology company, were confirmed by a spokesman who declined to provide details.

"We're not able to disclose any specific numbers about our recent realignment," said John Sun, spokesman for i365, a data retention and recovery company.

Read more at Law.com.


AddThis Social Bookmark Button

Thursday, January 22, 2009

Kazeon Cuts Costs of Entry-Level E-Discovery

As e-discovery becomes a must-have application and more vendors enter the market, e-discovery specialist Kazeon Systems Inc. today introduced several new licensing models and drastically cut the entry price for companies looking to get started using the software to protect themselves during litigation. With a variety of new e-discovery services and applications competing for a piece of the growing market, Kazeon's move may be the first salvo in a new e-discovery price war.

Kazeon has been charging $80,000 for a server license. Under the new pricing models, customers can get started using the company's software for $10,000, says Karthik Kannan, vice president of market and business development for Kazeon. "We don't want e-discovery to be a multimillion-dollar, six-month process," he says.

Read more at Byte and Switch.


AddThis Social Bookmark Button

Monday, January 19, 2009

Court Affirms Order Requiring a Non-Party to Spend $6 Mil. to Comply with e-Discovery Subpoena

Appellate courts do not often weigh in on e-discovery issues, but when they do, it is a big deal. The United States Court of Appeals for the District of Columbia did so on January 6, 2009, when it issued an opinion on e-discovery and sanctions. In re Fannie Mae Securities Litigation, _ F.3d _, 2009 WL 215282009, U.S. App. LEXIS 9 (D.C. App. Jan. 6, 2009). Typically, I would be glad to have a Circuit Court opinion on e-discovery. Not so here.

Unfortunately, In re: Fannie Mae Securities Litigation sets a troubling precedent in favor of enforcing exorbitant e-discovery costs. In this case, the Office of Federal Housing Enterprise Oversight (”OFHEO”), was required to spend six million dollars, representing nine percent of its total annual budget, just to comply with a subpoena for electronic documents. Although OFHEO clearly had relevant information to the multidistrict litigation against the Federal National Mortgage Assn. (”Fannie Mae”) and the Federal Home Loan Mortgage Corp. (”Freddie Mac”), they were not a party to the litigation. This fact, coupled with the high expense involved in an over-broad e-discovery request, did not seem to concern the court, which is why this decision is troubling.

Read more at e-Discovery Team.


AddThis Social Bookmark Button

Thursday, January 15, 2009

Houston Computer Forensics Expert Reinvents Career as "New Age" PI

A Houston computer forensics expert has changed his career in a surprising way. Gary Huestis is now a licensed private investigator for the state of the Texas.

Huestis, who is well-known in local computer IT circles, represents the new face of an old profession. “My new career path was literally born of the computer and Internet age,” said Huestis. “I am the last person in the world most people think would ever become a private investigator.”

The Private Security Board of the Texas Department of Public Safety recently licensed Huestis as a private investigator. He owns Houston-based EDiscovery Forensics, Inc. Since 1995, Huestis has also owned Houston Computing Services, a computer repair company.

Read the rest of the story here.


AddThis Social Bookmark Button

Monday, January 12, 2009

Hackers Spread Virus Through Fake CNN E-mails

Leave it to computer hackers to find a way to profit from a war. But hackers are apparently using the Gaza conflict and a fake CNN news site to infiltrate computers and steal passwords.

"Malicious software or malware takes passwords for online banking sites, online shopping carts, e-mail and chat programs and FTP sites and sends them to a computer in the Ukraine," explained Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham.

Read more at examiner.com.

AddThis Social Bookmark Button

Thursday, January 8, 2009

Top 10 Trends for eDiscovery in 2009

The folks at Clearwell Systems, whose platform works to streamline the eDiscovery process, have looked into their crystal ball and have offered a few predictions for the new year. Among them, trends that respond to financial and legal stresses as well as a need for more collaboration. The most compelling of their predictions lay within the realm of compliance and technology.

For the most part, there predictions aren't surprising our outrageous. They take aim at the very crux of what eDiscovery proselytizes -- show your work, collaborate, adapt and take control!

Drum roll please -- Top 10 Trends for eDiscovery in 2009:

1. Government Investigations Increase: If you thought 2008 had a lot of law suits, you ain't seen nothing yet. An increase in economic tensions and the increase in high-profile scandals will most probably lead to a rise in government data requests, compliance audits and investigations from both a state and federal level.

Click here to see the other 9 top trends.



AddThis Social Bookmark Button

Monday, December 29, 2008

BKForensics Reveals the Secrets of the Cell Phone

True story: The Orlando (Fla.) Police Department is taking a homicide suspect to trial. The bad guy’s cell phone is being held as evidence. Apply sophisticated software to reconstruct deleted files and — what have we here? We see the defendant dressed in the clothes that witnesses described. Plus, there are pictures of the murder weapon. Score one for the white hats.


AddThis Social Bookmark Button

Thursday, December 11, 2008

Ineffective Law Enforcement, Bad Economy Fueling Cybercrime

Cybercriminals operating worldwide are benefitting from ineffective law enforcement and a growing economic recession that could make jittery people more susceptible to cybercrime scams.

So concludes security firm McAfee in its new report, "Virtual Criminology Report—Cybercrime vs. Cyberlaw." published Tuesday. The report pulls together the opinions of about two dozen legal experts, academic researchers and security-response professionals working as far afield as Britain, continental Europe, the Baltic countries, Brazil, India, Japan, Australia, New Zealand and North America.


AddThis Social Bookmark Button

Monday, November 24, 2008

Psystar Case Reveals Apple's Weak E-Discovery Practices

Apple has sold enterprise-class storage hardware and software for years, but the company has yet to embrace systematic e-mail and document retention policies that are common among publicly traded companies.

According to a recent legal filing (page 7) in the Psystar vs Apple antitrust case, Apple employees are responsible for maintaining their own documents such as e-mails, memos, and voicemails. In other words, there is no company-wide policy for archiving, saving, or deleting these documents.


AddThis Social Bookmark Button

Wednesday, November 19, 2008

E-Discovery Requests Loom for Financial Services Firms

As regulators delve into firms' archives to try to pin down responsibility for the current financial meltdown, experts anticipate that litigation will rise sharply. The FBI already announced that it is investigating Freddie Mac, AIG and Lehman, and it is expected that countless other firms will be asked to produce data to support other investigations.

Vivian Tero, program manager for compliance infrastructure at research firm IDC, says e-discovery already has risen on Wall Street's priority list. "The selling cycle [for e-discovery products and services] has become shorter. The need is immediate -- firms have regulators breathing down their backs," she explains. "Many companies are very worried and concerned, and want systems to respond [to potential e-discovery requests]."


AddThis Social Bookmark Button

Friday, November 7, 2008

UAB Students Uncover "Obama Speech" Virus

Computer science and criminal justice students at the University of Alabama at Birmingham have uncovered a series of fraudulent e-mails that claim to link to video of Sen. Barack Obama's acceptance speech, but could put a visitor's personal information in the hands of criminals.

According to Gary Warner, UAB's director of research in computer forensics, the spam links to Web sites registered Tuesday in China.

Visiting the Web site requires the user to install an "Adobe Flash Player" to watch the speech. Installing it will cause all user IDs and passwords, whether for online banking, online stores, e-mail, or even chat programs, to be sent to the criminal's computer.


AddThis Social Bookmark Button

Wednesday, November 5, 2008

RNC Lined Up Computer Forensics Companies for Potential Electronic Voter Fraud Suits

Forensicon, Inc., a Chicago-based computer forensics company, was contacted last Thursday by a security firm lining up vendors to assist the Republican National Committee with consulting related to potential allegations of computerized voter fraud. It has been widely reported that electronic voting machines in many states are vulnerable to hacking by anyone with the right equipment and a few minutes' access to the voting machine.

Yesterday, noted Chicago resident Oprah Winfrey attempted to cast her vote for her candidate, but the vote failed to register correctly.


AddThis Social Bookmark Button

Monday, November 3, 2008

Computer Investigators Trace Digital Fingerprints

A wall of Erin Nealy Cox's office is covered with framed milestones: her law degree from Southern Methodist University, a seal from the U.S. attorney's office in the Northern District of Texas autographed by former colleagues. There are plaques from the Internal Revenue Service, the U.S. Postal Service and the FBI thanking her for helping convict bad guys in big cases.

"I jokingly call it the 'I love me wall,' " says Ms. Nealy Cox, who spent 10 years as a federal prosecutor.

The former assistant U.S. attorney was so adept at computer hacking and intellectual property that the feds chose her for a nationwide SWAT team that hunts down and prosecutes cyber-criminals.

Now, as managing director of Stroz Friedberg LLC's new Dallas office, the 38-year-old hopes to do for the for-profit world what she did for the public good: recover information thought to be lost to delete keys or hidden in cyberspace.

Think of it as CSI: Corporate America, and Ms. Nealy Cox as chief investigator Horatio Caine.


AddThis Social Bookmark Button

Monday, October 27, 2008

BrightTALK Hosts Digital Investigation Summit

At this online summit, experts will share information on trends in digital investigation, answer questions, and offer strategies and tips to professionals in e-discovery and computer forensics. BrightTALK hosts livewebcast summits each week around themes that matter to businessprofessionals.

WHEN: Tuesday, October 28, 2008, 9:00 a.m. - 3:00 p.m. Pacific Time

WHO: Presenters at the Digital Investigation Summit include:

Carrie Whitcomb, director of the National Center for Forensic Science

Dave Kleiman, board member of the National Center for Forensic Science

Jeffrey Ritter, CEO of Waters Edge

Patrick Eitenbichler, director of product marketing for HP InformationManagement

Paul Luehr, managing director and deputy general counsel, Stroz Friedberg,LLC

Sean Regan, product marketing manager for Symantec Enterprise Vault

Steven Burgess, founder of Burgess Forensics



AddThis Social Bookmark Button

Thursday, October 23, 2008

iPods Helping Criminal Investigations

Some months ago we reported on the use of iPods as an educational tool, and provided information on schools and universities that have incorporated this technology for the benefit of their students. Our report today involves a more complex use of iPods; iPods used by investigators to collect evidence and by defense attorneys. iPods' storage capability and functionality makes them a perfect device for defense attorneys and criminal investigators. They are inexpensive technology to record or format lengthy information. Maybe its creators did not envisage iPods for purposes other than entertainment but, as my grandmother said, a chair can help reach higher places.

In 2006, a U.S. District Court judge in Toledo, Ohio, approved the purchase of six iPods and power adaptor to be used by defendants in a multi-count drug conspiracy case. The goal was to provide the iPods to six defendants so they could listen to the FBI's wiretaps of their conversations before the case went to trial. Defendants were to listen to these wiretaps either at the U.S. Marshal's office -those detained- or at their defense attorney's office. Formatting the wiretaps into CDs cost the tax payers between $80,000 and $100,000 while the iPods and power adaptors cost less than $2,000 (about $330 per iPod). Content from 13 CDs were inexpensively downloaded in each iPod. One of the defense attorneys in that case said "the iPods are easy to use, save a lot of money, and control access to the information pursuant to the orders of the court. This is a promising solution to a real practical problem." Most of the defendants in this case were convicted; and, as for the iPods, it is not reported but our guess is that the court kept them; not the defendants.

Criminal investigators are also using iPods to record conversations; video-tape certain scenes; and take handy photographs; all these with an innocent-looking device. iPods can store movies, encrypted files, contacts, calendar information, etc., and this data can be later downloaded in a PC. Forensic experts have revealed that iPods have some special features that allow certain content to be hidden so secret information is not noticeable. Experts from Kroll Ontrack, a computer forensic company, state that iPods can serve as external hard drive to a host computer so files can be transferred through programs such as Windows Explorer, instead of iTunes. Kroll Ontrack has conducted forensic examinations on iPods and recommends considering the following issues when an iPod forensic investigation is conducted,



AddThis Social Bookmark Button

Monday, October 13, 2008

Lawsuit Tsunami: Good for E-Discovery?

Lawsuits driven by the financial crisis may be good news for companies that sell electronic discovery software and services.

As InformationWeek reported yesterday, the tech sector hasn't been immune to the stock market slide. But one segment may find its fortunes bolstered by the turmoil. E-discovery vendors stand to benefit as a tsunami of lawsuits washes over the financial services market.

An Associated Press story reported yesterday that state governments are suing or considering lawsuits against various actors in the financial crisis, including investment banks, bond ratings agencies, and agencies such as Fannie Mae and Freddie Mac.

AddThis Social Bookmark Button

Thursday, October 2, 2008

Why Records Management?

Recent events are changing the corporate e-discovery climate, causing some business leaders to question the effectiveness of an ad-hoc, “on-the-fly” approach. As high profile cases, including Qualcomm (“Qualcomm and Attorneys Sanctioned for ‘Monumental’ E-Discovery Violations,” Findlaw, 2008 ) and Morgan Stanley (“Morgan Stanley to Pay Millions for E-Mail Mismanagement,” E-Discovery Law, September 2007), have highlighted, waiting until the subpoena arrives and assuming that IT can quickly and easily make the requested materials available--and have the ability to preserve them--is an increasingly tricky bet.

IT analysts, such as Gartner, have long advocated the cost and risk savings available by taking a proactive approach to e-discovery and using an archive with solid records management policies. However, despite numerous cost justification case studies, the adoption rate of this technology has been relatively slow. But this might change in short order, as recent e-mail and IT-related fiascos, including Bear Stearns (“Two former Bear Stearns hedge fund managers indicted,” Los Angeles Times, June 20, 2008) and the White House (“Where Are the White House E-Mails?” Time, Jan. 23, 2008), have left corporations scrambling. It seems that nothing speeds corporate action faster than legal challenges with major cost and negative publicity implications.

Will the “summer of shame” (sub-prime fallout and the continued government e-mail scandal) finally turn the procrastinators into proactive managers of electronic records? Or will we continue to see corporations wait for the inevitable subpoena to happen before taking action and pay the price? Only time will tell, but one fact is clear: In today’s corporate climate, electronic records management solutions have never been more in demand.


AddThis Social Bookmark Button

Tuesday, September 30, 2008

FORENSICS SOFTWARE A VITAL TOOL IN FIGHT AGAINST COMPUTER CRIME

South African companies that want to protect their businesses against computer-related crimes such as fraud and data theft should invest in enterprise forensic software tools that allow them to investigate security breaches and acquire evidence against wrongdoers that will stand up in court.
That's the word from Derek Street, product manager at SecureData Security. He says companies face a range of business risks around their data and IT infrastructure, including theft of intellectual property, white-collar crimes such as fraud, human resources violations, and employees using enterprise computers for illegal or immoral activities.
One of the enterprise's most effective tools against the risks of employees abusing corporate data and computers is offer them the certainty that they will be caught and punished for their actions. Companies therefore need to be able to uncover who was responsible for criminal acts or transgressions against corporate policy and provide solid evidence that can be used to prosecute them or dismiss them.
To address these challenges, companies should look for network-based forensics solutions that provide complete network visibility, and comprehensive, forensic-level analysis of servers and workstations anywhere on a network, Street adds. Such a solution should be able to securely investigate/analyse many machines simultaneously over the LAN/WAN at the disk and memory level without disrupting operations, causing downtime, or alerting the target that he or she is under investigation.
It should also as far as possible, automate time-consuming investigative processes, incident response and eDiscovery. These tools can provide detailed information across the lifecycle of a document, such as who accessed, created or edited a document, whether it was printed or emailed (and by who), and much more, often even if the user has deleted information in a bid to cover his or tracks.
One of the important things to look for in a forensics tool is a track record with courts and law enforcers around the world, proving its ability to acquire data in a forensically sound manner, says Street.


AddThis Social Bookmark Button