“A computer is like an Old Testament god, with a lot of rules and no mercy”

Tuesday, December 15

Too Much COFEE? Time to Switch to DECAF

Via Wired.com
Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

The hacker tool, dubbed DECAF, is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.

Update: Apparently the whole thing was a stunt to raise awareness of the need for security.