<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Digital Evidence</title>
	<atom:link href="http://tharrnacker.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://tharrnacker.wordpress.com</link>
	<description>The world of computers and the law.</description>
	<lastBuildDate>Wed, 19 May 2010 18:25:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='tharrnacker.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Digital Evidence</title>
		<link>http://tharrnacker.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://tharrnacker.wordpress.com/osd.xml" title="Digital Evidence" />
	<atom:link rel='hub' href='http://tharrnacker.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Preservation of Evidence</title>
		<link>http://tharrnacker.wordpress.com/2010/05/19/preservation-of-evidence/</link>
		<comments>http://tharrnacker.wordpress.com/2010/05/19/preservation-of-evidence/#comments</comments>
		<pubDate>Wed, 19 May 2010 18:25:42 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=60</guid>
		<description><![CDATA[When encountering a system for investigation, every effort to preserve the evidence and not alter it in any way should be taken. Sometimes, though, this is not easy. In one case that I&#8217;ve heard about, an IPod had been linked to a MacBook, and it was important for them to know when the two were [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=60&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>When encountering a system for investigation, every effort to preserve the evidence and not alter it in any way should be taken. Sometimes, though, this is not easy.</p>
<p>In one case that I&#8217;ve heard about, an IPod had been linked to a MacBook, and it was important for them to know when the two were last &#8216;synced&#8217;. Now there are usually two ways to get evidence such as that out of a program. The first is to actually run the program, in this case ITunes, and use it to extract the data. THe other way is to bypass the program and get at the raw data files and use other tools to extract the needed information. In this case, there were a few files that ITunes uses to keep track of the synced IPods and when they were last synced.</p>
<p>Both approaches have their benefits. Working through the program is sometimes much easier that bypassing it, but it risks damaging the evidence, changing it in some way. Bypassing is more acceptable, but it can be very difficult if the evidence is encrypted or in a proprietary format. In rare cases, it makes it impossible to proceed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=60&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2010/05/19/preservation-of-evidence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>Integrity</title>
		<link>http://tharrnacker.wordpress.com/2010/01/12/integrity/</link>
		<comments>http://tharrnacker.wordpress.com/2010/01/12/integrity/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 19:53:52 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=57</guid>
		<description><![CDATA[The last principle of Information Security is Integrity. The data that you have and use should be correct. This is the most insidious part. If your data has been altered and you do not know it, you will act on the information, usually with negative consequences. The classic case of this is the computer savvy [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=57&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The last principle of Information Security is Integrity. The data that you have and use should be correct. This is the most insidious part. If your data has been altered and you do not know it, you will act on the information, usually with negative consequences.</p>
<p>The classic case of this is the computer savvy student breaking in to the school computer to change his grades,  but as serious as that is, it can get even more serious. If you need to make electronic payments, the account numbers you have on file for your suppliers don&#8217;t take much to change. One break in, and all of a sudden you are paying someone who isn&#8217;t your supplier.</p>
<p>The best way to deal with this is to have clearly defined roles with minimum access given to your data. Your employees should have just enough information to do their jobs.</p>
<p>The three principles together define Information security policy.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/57/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=57&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2010/01/12/integrity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>Exclusivity</title>
		<link>http://tharrnacker.wordpress.com/2010/01/12/exclusivity/</link>
		<comments>http://tharrnacker.wordpress.com/2010/01/12/exclusivity/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 19:40:25 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=55</guid>
		<description><![CDATA[The second principle of Information Security is Exclusivity. Simply put, this is the principle that those that shouldn&#8217;t have information, don&#8217;t. This is what most people think about when they think of Info Security. In some places of work, the need for this is obvious. A doctor or lawyer needs to keep his client&#8217;s information [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=55&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The second principle of Information Security is Exclusivity. Simply put, this is the principle that those that shouldn&#8217;t have information, don&#8217;t. This is what most people think about when they think of Info Security.</p>
<p>In some places of work, the need for this is obvious. A doctor or lawyer needs to keep his client&#8217;s information confidential. The CIA has lots of secrets that the general public shouldn&#8217;t have. However, every office has information that needs to be held closely. Payroll, for example. Beyond just keeping salaries confidential, a payroll database has bank account information. A client list can be judged to be important enough to keep secret.</p>
<p>The real problem comes when you pair this with Availability. In short, those who are allowed to use data get access, and those who shouldn&#8217;t, don&#8217;t. You could simply shut off a computer that is being compromised to prevent access, but that would also deny access to those who need it. Sometimes, though, that is what you have to do to prevent an immediate threat.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/55/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=55&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2010/01/12/exclusivity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>Availability</title>
		<link>http://tharrnacker.wordpress.com/2010/01/12/availability/</link>
		<comments>http://tharrnacker.wordpress.com/2010/01/12/availability/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 19:16:21 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=53</guid>
		<description><![CDATA[For the next few posts, I&#8217;ll be talking about Information Security as opposed to Digital Forensics. One of the principles of Information Security is the concept of Availability. Simply put, your data, or your company&#8217;s data, should be available for your use. How is this an Info Security concept? Simply put, if your data is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=53&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For the next few posts, I&#8217;ll be talking about Information Security as opposed to Digital Forensics.</p>
<p>One of the principles of Information Security is the concept of Availability. Simply put, your data, or your company&#8217;s data, should be available for your use. How is this an Info Security concept? Simply put, if your data is not available for you to use, do you really have it?</p>
<p>The classic attack on Availability is the Denial of Service attack. In it, a computer is bombarded with network traffic, overloading the computer or network card making it so no one else can access the resource. The computer needs to spend time dealing with all of these packets coming in over the network, and so it cannot give legitimate users the time they need.</p>
<p>It&#8217;s not just in the computer world that this exists. Say you have a library of books, but the building has been cut off by a flood. The rising water is a threat to the Availability of the books.</p>
<p>I&#8217;ve had to deal with a DOS attack once. I was working as an engineer for an IT Services company when a client called. His internet connection was extremely slow, and he wanted me to find the problem. I logged in to his firewall and found out he was right. The web interface for the firewall was extremely slow. I looked at the processor for the firewall and it was maxed out. The net connection was normal. It was the firewall that was being used. I checked the logs, and found that tons of traffic was coming from one IP address. For each packet that came from that address, the firewall had to process each command through every rule before denying it. To deal with it, I added a new rule denying the IP address and put it as the first rule. Instantly, everything was better. The firewall could dismiss the traffic instantly. Before I did that, the client could not use the internet.</p>
<p>For a resource to be valuable, it needs to be used. That is why Availability is so important.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/53/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=53&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2010/01/12/availability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>Forensics and Security</title>
		<link>http://tharrnacker.wordpress.com/2010/01/12/forensics-and-security/</link>
		<comments>http://tharrnacker.wordpress.com/2010/01/12/forensics-and-security/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 08:25:14 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=51</guid>
		<description><![CDATA[At first blush, the roles of an information security expert and a digital forensic expert would seem to be very similar. After all, both come in contact with the shadier elements of the computer world. Viruses, hackers, naughty employees, thieves&#8230; they all come in to contact with both professionals. What happens when they meet though [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=51&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>At first blush, the roles of an information security expert and a digital forensic expert would seem to be very similar. After all, both come in contact with the shadier elements of the computer world. Viruses, hackers, naughty employees, thieves&#8230; they all come in to contact with both professionals. What happens when they meet though is an entirely different matter.</p>
<p>The information security expert is involved before an incident happens. They go through and assess a location or system, find vulnerabilities and figure out how to deal with them in order to either prevent an attack or mitigate the damage from one.</p>
<p>The digital forensic expert usually arrives after an incident has happened, and figures out what went wrong. He doesn&#8217;t assess vulnerabilities, but actual damage. He doesn&#8217;t figure out what to do to prevent attacks. He finds out the exact nature of the attack that happened,  if it is an attack at all.</p>
<p>How are these two related? Well both do a little bit of each other&#8217;s job. This is especially true during an ongoing attack. In that case, both roles need to be performed at the same time. A forensic examination gives important data as to the nature and severity of an attack. An assessment of security can identify ways of stopping and limiting damage.</p>
<p>In each case, both perform police like functions. Which one is more important? Whichever one you need.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/51/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=51&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2010/01/12/forensics-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>It comes in all shapes and sizes.</title>
		<link>http://tharrnacker.wordpress.com/2010/01/05/it-comes-in-all-shapes-and-sizes/</link>
		<comments>http://tharrnacker.wordpress.com/2010/01/05/it-comes-in-all-shapes-and-sizes/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 21:55:47 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=44</guid>
		<description><![CDATA[Just to illustrate the point that digital evidence comes in all shapes and sizes comes this story of a man who had his PlayStation 3 stolen but not his Playstation Portable&#8230;.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=44&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Just to illustrate the point that digital evidence comes in all shapes and sizes comes <a href="http://consumerist.com/2010/01/if-your-ps3-thief-is-a-moron-you-can-macgyver-its-recovery-via-psp.html">this story</a> of a man who had his PlayStation 3 stolen but not his Playstation Portable&#8230;.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=44&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2010/01/05/it-comes-in-all-shapes-and-sizes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>So true&#8230;</title>
		<link>http://tharrnacker.wordpress.com/2010/01/01/so-true/</link>
		<comments>http://tharrnacker.wordpress.com/2010/01/01/so-true/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 08:22:49 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=42</guid>
		<description><![CDATA[If anyone wants an illustration as to the difference between real and tv science: look here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=42&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If anyone wants an illustration as to the difference between real and tv science: look <a href="http://xkcd.com/683/">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/42/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=42&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2010/01/01/so-true/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>What is real?</title>
		<link>http://tharrnacker.wordpress.com/2009/12/21/what-is-real/</link>
		<comments>http://tharrnacker.wordpress.com/2009/12/21/what-is-real/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 08:02:57 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=40</guid>
		<description><![CDATA[One of the things that often comes up when dealing with digital evidence, or just computers in general is how much of it is real? If you&#8217;re playing a video game, you aren&#8217;t really firing bolts of magic at elves. If you&#8217;re transferring money, cold hard cash isn&#8217;t really being shipped between vaults. So is anything that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=40&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the things that often comes up when dealing with digital evidence, or just computers in general is how much of it is real? If you&#8217;re playing a video game, you aren&#8217;t really firing bolts of magic at elves. If you&#8217;re transferring money, cold hard cash isn&#8217;t really being shipped between vaults. So is anything that you do online, or even just on a computer, real?</p>
<p>Well, yes, it is. You may not be firing a magic bolt, but several computers, all over the world, are rendering an effect, moving your avatar, and recording the damage that that caused. At a very basic level, it makes a change on the hard disk recording the battle, and those little bits either have a charge or they don&#8217;t. And that is real and measurable.</p>
<p>The problem is, even that doesn&#8217;t seem real. Little magnetic bits on a platter? Can&#8217;t be touched. Can&#8217;t be seen. Doesn&#8217;t seem real. And how they are arranged makes them valuable? Certain arrangements of bits are more valuable than others?</p>
<p>Well yes. Consider a book. Any book. On the surface, its just leather with paper and ink inside. Open the book, though, and the value becomes clear. It can be read conveying information. A good novel can command a price. Take those same ink markings though and make them random, and its completely worthless. Or consider if the story inside is terrible. Or if the information it contains has been proven wrong.  All of that makes the value of the book go up or down as the case may be. The arrangement of those markings makes the book what it is. It is all important. If that statement seems a little out of proportion, consider the recent development of the e-book. No leather cover. No paper. No ink. But the black markings that appear on the screen mean you are reading, and have in your posession, <em>The Adventures of Huckleberry Finn.</em></p>
<p>Now consider that in that e-book, its all made up of those same bits. The arrangement of those bits defines the book. If it isnt real, then you can&#8217;t read it. If you can&#8217;t read it, then you can&#8217;t write a book report on it. And you fail your English class. That&#8217;s real.</p>
<p>It comes down to this. If it can change something that is real, then it itself is real.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/40/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=40&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2009/12/21/what-is-real/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>Sometimes they get it right</title>
		<link>http://tharrnacker.wordpress.com/2009/12/15/sometimes-they-get-it-right/</link>
		<comments>http://tharrnacker.wordpress.com/2009/12/15/sometimes-they-get-it-right/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:48:53 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=38</guid>
		<description><![CDATA[A few posts ago I complained about how Hollywood gets computers wrong. Sometimes though, they get things very right. In the newest first person shooter, Modern Warfare 2, there&#8217;s a mission where you hook up a portable drive to a computer, then have to defend the house it is in. To let you know how [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=38&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A few posts ago I complained about how Hollywood gets computers wrong. Sometimes though, they get things very right.</p>
<p>In the newest first person shooter, Modern Warfare 2, there&#8217;s a mission where you hook up a portable drive to a computer, then have to defend the house it is in. To let you know how long you have to defend the house, they put a status bar and time left on your heads up display.</p>
<p>Now all of that, hooking up the drive without sitting down at the keyboard and setting it all up, and not just ripping out the hard drive, that is wrong. The bit they get right is this:</p>
<p>On the heads up display the &#8216;time left&#8217; jumps around. 3 minutes. 22 minutes. 44 minutes. 5 minutes. 37 minutes. Just like a real download does sometime.</p>
<p>Its a brilliant bit of realism, and so frustrating just as you are trying to survive long enough to get the drive and get out. You can never tell just how long something like that is going to take.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/38/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=38&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2009/12/15/sometimes-they-get-it-right/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
		<item>
		<title>Who sat there?</title>
		<link>http://tharrnacker.wordpress.com/2009/12/10/who-sat-there/</link>
		<comments>http://tharrnacker.wordpress.com/2009/12/10/who-sat-there/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 08:32:39 +0000</pubDate>
		<dc:creator>Timothy Harrnacker</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tharrnacker.wordpress.com/?p=35</guid>
		<description><![CDATA[One of the most difficult things to do as a digital investigator is to prove that a particular person actually used a specific computer. For example, you can have documents and logs saying that Joe did such-and-such. But was it actually Joe at the keyboard? Maybe someone logged in using his account. Maybe he walked [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=35&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the most difficult things to do as a digital investigator is to prove that a particular person actually used a specific computer. For example, you can have documents and logs saying that Joe did such-and-such. But was it actually Joe at the keyboard? Maybe someone logged in using his account. Maybe he walked away from the computer and forgot to lock the desktop.</p>
<p>Sometimes this isn&#8217;t a problem. Sometimes the computer is in a secured area and the PC hasn&#8217;t been compromised. Sometimes its in an open office environment, and he was observed to be at the computer at the time in question.</p>
<p>Sometimes, though, the computer doesn&#8217;t even have a password, and anyone can walk in and use it. Most personal PCs are set like that. Even if you put a password on the account, it sometimes doesn&#8217;t mean anything if you are observed typing in the password. This actually happened to me once. I had set a password on my personal account on my daughter&#8217;s PC so she couldn&#8217;t be on the PC for more than an hour. She once watched me put in that password, and all of a sudden she had unlimited time. She was 5 at the time.</p>
<p>In cases like that, the best you can do is report that someone used &#8216;Joe&#8217;s&#8217; account. To do more than that may be to assume too much, and that can lead to a loss of credibility. For a digital investigator, credibility is our stock in trade. If you don&#8217;t have that you won&#8217;t have anything.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tharrnacker.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tharrnacker.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tharrnacker.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tharrnacker.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tharrnacker.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tharrnacker.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tharrnacker.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tharrnacker.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tharrnacker.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tharrnacker.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tharrnacker.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tharrnacker.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tharrnacker.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tharrnacker.wordpress.com/35/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=tharrnacker.wordpress.com&amp;blog=10616210&amp;post=35&amp;subd=tharrnacker&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://tharrnacker.wordpress.com/2009/12/10/who-sat-there/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44dd85db8853c4b03743fef4a1788e2c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tharrnacker</media:title>
		</media:content>
	</item>
	</channel>
</rss>
