http://www.huffingtonpost.com/2011/09/01/michael-west-fabric...
An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
11–20 of 37 posts
Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#12Ironically, the amount of pressure from the top involved in this (and related) cases caused several prosecutions of sexual misconduct in the military to be dismissed . You read that right. There's a doctrine called "unlawful command influence" where, if the posture of the Commander on Chief on down suggests that there is a "right verdict" independent of the facts, then the military courts should dismiss cases rather…
Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#13Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#14An Example of Pathetically Self-Aggrandizing Twaddle, Nearly at Its Worst.
I'm surprised that the article got so many up-votes considering it has so little technical detail.
Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#15Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#16So, I read through the article and could not find what was concretely wrong, technically, with the data. Does he state that any where? Thanks.
Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#17Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#18So, I read through the article and could not find what was concretely wrong, technically, with the data. Does he state that any where? Thanks.
"There are reasons I’m not going to dig into the details of the case. Certain people that were involved could easily be pinpointed by revealing technical details that could be pieced together with news reports, and help build a story in your mind that would probably be inaccurate. The details aren’t so important as the errors that were made. All you need to know from a technical perspective is right here: some of the types of information that these commercial tools were (and likey still are) misreporting is significant. Evidence and timestamps of a device erasure event. Evidence of a backup restore event. Application usage dates. Application deletion events and timestamps. File access times. This, and many other types of artifacts are often either completely overlooked by numerous commercially sold, expensive-as-hell tools, or in the case of at least one tool – seemingly made up data. All of these came into play in this case and would later play a role in its outcome."
Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#19I wonder if anyone has ever been wrongfully convicted because of poor forensic software. Those programmers are incredibly unethical people. I'm familiar with the food-on-the-table argument, but wow, possibly getting innocent people locked up just because you don't know what you're doing is something. It can't feel good to receive the double whammy of knowing you're incompetent and that you're incompetent enough to ru…
Re: An Example of Forensic Science at Its Worst: US v. Brig. Gen. Jeffrey Sinclair
#20I wonder if anyone has ever been wrongfully convicted because of poor forensic software. Those programmers are incredibly unethical people. I'm familiar with the food-on-the-table argument, but wow, possibly getting innocent people locked up just because you don't know what you're doing is something. It can't feel good to receive the double whammy of knowing you're incompetent and that you're incompetent enough to ru…
This struck a nerve because that's how I feel in my position. I really had no idea what went into the products that I'm not working on. I feel ignorant, but someone's giving my code the okay and occasionally throwing some back, so I must be doing something right. Someone said, "He looks like he can handle this job" and here I am with no prior experience in this particular field (I did have some programming experience). I wonder how many juniors these forensic software companies employ?
On one hand, mission-critical companies should only hire people who are both experts in programming, experts in safe and reliable programming, and experts in the domain that they programming in. (note: actual experts, not "i've-done-it-once-or-twice-so-i'm-the-department-expert-because-no-one-else-is-really-working-on-it" expert)
On the other hand, it's incredibly hard to find all three of those things in sufficient numbers to staff a team capable of handling large and complicated software. With employees in general changing positions more often (sometimes on whim alone, nevermind what the world needs), it's even harder to cultivate 5+ year employees who really know their way around the software and the business.
There is just a huge volume of information and practice required to become that individual, and you really run into daily practical concerns if we were to only hire these experts. You have to be fed challenges that teach you so you can eventually become a real expert, but you need competent oversight -- a mentor, really. And sometimes you just don't have the luxury of tackling problems that are 'small enough'. Sometimes your mentor really doesn't have time to teach to the level of detail needed because let's face it, there's still a business behind all of this. And then they should be competent in security, performance, and a host of other skills because software is just so connected and reliant on the other parts of the system.
So now you need someone with all of those previous skills and the ability to teach people well. These newly minted experts will have to pass down the knowledge as well.
How do you cultivate experts without also creating a little danger to your customers and their customers and maybe even the general population? At some point, that trainee is going to have to make change and implement things without a safety net behind him. He's got to do this enough until he becomes that actual expert, but that takes a really fucking long time, and I don't think the market is really motivating people to take that route ("Why not just make some websites for 80k a year and save myself all of that stress and an early death?").
If someone else makes a big mistake, most of that time you spent to become better becomes worthless when your firm hits the front page. Now you're associated with someone else's problem and that's going to affect your chances of a job. So not only do you have to watch out for your own mistakes, but also your peers' mistakes as well. While you may not have to resort to flipping burgers, you probably won't be able to get a job in a critical environment for a while.