<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; evidence extractor</title>
	<atom:link href="http://www.ghacks.net/tag/evidence-extractor/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Sun, 08 Nov 2009 22:45:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Computer Online Forensic Evidence Extractor</title>
		<link>http://www.ghacks.net/2008/04/29/computer-online-forensic-evidence-extractor/</link>
		<comments>http://www.ghacks.net/2008/04/29/computer-online-forensic-evidence-extractor/#comments</comments>
		<pubDate>Tue, 29 Apr 2008 20:10:36 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[Computer Online Forensic Evidence Extractor]]></category>
		<category><![CDATA[evidence extractor]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=3968</guid>
		<description><![CDATA[The Computer Online Forensic Evidence Extractor (Cofee) is a USB thumb-drive developed by Microsoft that was distributed to more than 2000 law-enforcement officers in 15 countries including the United States, Germany, New Zealand and Poland. Software on the device supports more than 150 commands that eliminates the need to seize the computer from the scene [...]]]></description>
			<content:encoded><![CDATA[<p>The Computer Online Forensic Evidence Extractor (Cofee) is a USB thumb-drive developed by Microsoft that was distributed to more than 2000 law-enforcement officers in 15 countries including the United States, Germany, New Zealand and Poland. Software on the device supports more than 150 commands that eliminates the need to seize the computer from the scene because it can gather the evidence right there.</p>
<p>The commands can be used to decrypt passwords, analyze the Internet activity and data that is stored on the computer. The advantage of this method is that data can be analyzed while the computer is still connected to a network or the Internet which would not be possible of the computer would be seized. </p>
<p>Some blogs have gone so far as to <a href="http://techdirt.com/articles/20080429/095514977.shtml">assume</a> that Microsoft would give Vista backdoor keys to the police but the original <a href="http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html">article</a> at the Seattle Times did not mention that at all.  The tools on the USB device provide a set of commands that speed up the evidence gathering process and allow that process to be started while the computer is still running in its local environment.</p>
<p><span id="more-3968"></span>The original Seattle Times article seems to support that by quoting the head of the Special Assault Unit in the King County Prosecuting Attorney&#8217;s Office.</p>
<blockquote><p>The 35 individual law-enforcement agencies in King County, for example, don&#8217;t have the resources to investigate the explosion of digital evidence they seize, said Johnson, who attended the conference.</p>
<p>&#8220;They might even choose not to seize it because they don&#8217;t know what to do with it,&#8221; she said. &#8220;&#8230; We&#8217;ve kind of equated it to asking specific law-enforcement agencies to do their own DNA analysis. You can&#8217;t possibly do that.&#8221;</p></blockquote>
<p>I think it is fair to assume that Microsoft is providing the tools and probably even the training, or at least training manuals, so that law-enforcement agents won&#8217;t face the decision of what to do with the computers.</p>

	Tags: <a href="http://www.ghacks.net/tag/cofee/" title="cofee" rel="tag">cofee</a>, <a href="http://www.ghacks.net/tag/computer-online-forensic-evidence-extractor/" title="Computer Online Forensic Evidence Extractor" rel="tag">Computer Online Forensic Evidence Extractor</a>, <a href="http://www.ghacks.net/tag/evidence-extractor/" title="evidence extractor" rel="tag">evidence extractor</a>, <a href="http://www.ghacks.net/tag/forensic/" title="forensic" rel="tag">forensic</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2007/01/20/zune-does-not-allow-to-share-all-songs/" title="Zune does not allow to share all songs (January 20, 2007)">Zune does not allow to share all songs</a> (3)</li>
	<li><a href="http://www.ghacks.net/2006/10/21/zoom-it/" title="Zoom It (October 21, 2006)">Zoom It</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/04/23/yuck-new-windows-vista-ultimate-extras/" title="Yuck new Windows Vista Ultimate Extras (April 23, 2008)">Yuck new Windows Vista Ultimate Extras</a> (20)</li>
	<li><a href="http://www.ghacks.net/2008/08/06/yahoo-sick-of-them-yet/" title="Yahoo, sick of them yet? (August 6, 2008)">Yahoo, sick of them yet?</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/04/29/computer-online-forensic-evidence-extractor/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
	</channel>
</rss>
