Live data from Hacker News

Police Return Seized Hardware to Victorious BitTorrent Admin, Trashed

torrentfreak.com

41–44 of 44 posts

Re: Police Return Seized Hardware to Victorious BitTorrent Admin, Trashed

#41
post #27

Earlier quoted context omitted.

> Failure to comply means you sit in a jail cell until you cough up the password. So, keyfiles on easily-destroyable thumbdrives, then? If they say the only copy of the key (that they're aware of) was destroyed, that's basically equivalent to saying they wiped the disk; you can't really hold them expecting them to magically recreate it, right?

"Tampering with evidence is the knowing and intentional physical manipulation, altering or destruction or falsification of evidence relevant to a criminal case or investigation. It is important to note that tampering is not the accidental destruction or modification of evidence, it is only if the individual had reason to believe the material or item was part of an investigation." Evidence tampering often carries much…

That's only in the case where you can prove that someone knew there would be an investigation and destroyed the key as a result. The nice thing about thumbdrives: they're incredibly easy to lose. If it's only needed for startup, you can just say that you lost it a long time ago, but it wasn't a problem because you just left the machine running. To disprove that, they'd need to check the system logs, which are, of course, also on the encrypted disk. :)

Re: Police Return Seized Hardware to Victorious BitTorrent Admin, Trashed

#42
post #30

Earlier quoted context omitted.

Again: that 80% stat? I'm certain it's true, but it's meaningless. The stat you want is, how often are challenges to seizures denied. Because --- and I'm not saying this is what happened with your nephew --- it is very likely the reason that 80% of those seizures don't match up with a conviction is that the people whose assets are seized are in fact criminals. Recognizing that doesn't mean I think civil asset forfeit…

I don't think it matters much whether many challenges are successful. When it takes years and costs more in unrecoverable legal fees (it's a civil court case, not merely a request) than most seized property is actually worth, very few victims are going to bother. http://www.csmonitor.com/USA/Justice/2009/1209/p02s06-usju.h...

I don't know how bad it is at the state level, but according to the US Code, at the federal level it shouldn't take years; there's a rigid statutory timeline on hearings, measured in increments of 30 days.

Re: Police Return Seized Hardware to Victorious BitTorrent Admin, Trashed

#43
post #37
post #12

Earlier quoted context omitted.

> * If the systems are turned on, record the datetime and shut them down. Did this ever lock you out of any machines configured to use Whole Disk Encryption or out of encrypted, mounted volumes? You could have dumped the keys out of ram, etc. > we used EnCase Did you ever come across any exotic filesystems that EnCase can't read, like XFS?

I work on criminal cases, so have a slightly different perspective to bradleyland. > Did you ever come across any exotic filesystems that EnCase can't read, like XFS? I've come across something "obscure" only once or twice (in several hundred cases). The bottom line is that most computer crime isn't conducted by technically adept people, but by normal people. i.e. Windows is by far the most common system, with Mac a…

Thanks for the response!

> mostly due to "user error"

Can you elaborate on this? I'm aware of taking advantage of idiotic Firewire/USB drivers to inject code into a running system and the "evil maid" attack, but that's where my knowledge of WDE attacks stops.

Re: Police Return Seized Hardware to Victorious BitTorrent Admin, Trashed

#44
post #43
post #37

Earlier quoted context omitted.

I work on criminal cases, so have a slightly different perspective to bradleyland. > Did you ever come across any exotic filesystems that EnCase can't read, like XFS? I've come across something "obscure" only once or twice (in several hundred cases). The bottom line is that most computer crime isn't conducted by technically adept people, but by normal people. i.e. Windows is by far the most common system, with Mac a…

Thanks for the response! > mostly due to "user error" Can you elaborate on this? I'm aware of taking advantage of idiotic Firewire/USB drivers to inject code into a running system and the "evil maid" attack, but that's where my knowledge of WDE attacks stops.

Nothing fancy. Often we get a few computers in such cases, and they reuse passwords. Or write it down somewhere (that's a common one).

Or you can "guess" it from likely combinations (names, dates etc.)

Post reply on HN