Featured Post

Welcome to the Forensic Multimedia Analysis blog (formerly the Forensic Photoshop blog). With the latest developments in the analysis of m...

Friday, February 27, 2015

New training course available

New training course available:

BASIC FORENSIC MULTIMEDIA ANALYSIS WITH AMPED FIVE

This is a practical course on Amped Five.

Description:
Basic Forensic Multimedia Analysis with Amped FIVE Professional

Expectations and Goals:
Graduates will acquire basic level training in the techniques and skills necessary to perform examinations, clarifications, and analyses on digital multimedia evidence in a “forensic science” setting as well as to package, deliver, and present those findings in their local courtroom context. The focus on this course is practical usage of FIVE for forensic video and image analysis.

Dates:
April 21-23, 2015

Location:
Memphis, Tennessee (Memphis PD is host agency)

Instructor:
Jim Hoerricks

For details or to sign up, click here. Seats are limited.
For any questions, email training@ampedsoftware.us or call (866) 547-0099 Ext. 101.

Thursday, February 26, 2015

SWGDE News

This just in from SWGDE:

The Scientific Working Group on Digital Evidence (SWGDE) is pleased to announce the posting of the following four new draft documents for public review and comment at https://www.swgde.org/ documents/Released%20For% 20Public%20Comment

SWGDE Best Practices for the Recovery of Data from CCTV Digital Video Recorders (version 1.0)
SWGDE Mac OS X Tech Notes (version 1.2)
SWGDE Best Practices for Forensic Audio (revision 2.20)
SWGDE-SWGIT Glossary (version 2.8)
The draft "SWGDE Best Practices for Handling Damaged Mobile Devices" document released for public review and comment last September is still in draft status and remains open for comments: https://www.swgde.org/documents/Released%20For%20Public%20Comment/2014-09-08%20SWGDE%20Best%20Practices%20for%20Handling%20Damaged%20Mobile%20Devices

In accordance with SWGDE policy, draft documents will be posted for a minimum of 60 days for public comment. The first page of each draft document gives instructions on how to submit feedback to our Secretary via an email to secretary@swgde.org All feedback received prior to our next meeting in June 2015 will be reviewed by the appropriate subcommittee at that meeting.

At the conclusion of our last meeting, SWGDE voted to re-release the "SWGDE Establishing Confidence in Digital Forensic Results by Error Mitigation Analysis" document as an Approved version 1.5 making some minor grammatical/stylistic changes to it. However, as noted on the cover page of all our documents, "SWGDE encourages stakeholder participation in the preparation of documents. Suggestions for modifications are welcome and must be forwarded to the Secretary in writing at secretary@swgde.org"

All approved documents are available for download on the Current Documents page of the SWGDE website: https://www.swgde.org/ documents/Current%20Documents

We appreciate your participation as SWGDE continues its mission to bring together organizations actively engaged in the field of digital and multimedia evidence to foster communication and cooperation as well as ensuring quality and consistency within the forensic community. Anyone interested in receiving regular updates via email is encouraged to sign up for the SWGDE NewsBytes newsletter here: https://www.swgde.org/ newsletter/newsletterSignUp

Thank you,

David Hallimore
SWGDE Outreach Committee Chair
https://www.swgde.org/

Monday, February 16, 2015

A big update to Amped FIVE

Amped Software announced a big update today. Along with some bug fixes, this update includes batch conversion, fish eye correction, and a few other niceties. If your support contract is current, use the feature in the Help menu to check for the latest update.

Enjoy.

Friday, February 6, 2015

Image kernels explained visually


Here's a cool page that interactively demonstrates and explains how image kernels work.

Thursday, February 5, 2015

Facial recognition technology: How well does it work?

This just in from the BBC: "The revelation that police are holding a database of around 18 million mugshots has provoked an examination of the balance between civil liberties and catching criminals. But how effective is the technology?

Not as good as many people think, according to the Metropolitan Police officer in charge of the force's central forensic image team.

The system used by the force works by taking measurements between various points on people's faces in order to build up a picture of what they look like.

That is then matched against two databases - one holding mugshots taken of people who have been arrested and the other containing images from outside sources, such as CCTV.

'Super recognisers'

The main problem, Det Ch Insp Mick Neville told the BBC, is that most images are not of a good enough quality to produce any sort of match.

"With the vast majority of CCTV images, it will not work - in 18 months, we have had fewer than 10 hits."

That did not compare well against human performance. Mr Neville said he recently brought 90 "super recognisers" - people who are particularly adept at facial recognition - to Scotland Yard. "We had the best part of 300 IDs over three evenings," he said.

He added that, of the 4,000 images loaded on to the database following the 2011 London riots, only one has actually been matched to a person.

He was speaking after BBC Newsnight reported that many of the people whose images were being held by the police were innocent."

Continue reading the article by clicking here.

Wednesday, February 4, 2015

Coming soon

I've been working on some videos to help folks working in image analysis - some special cases - working with Amped FIVE and a few other tools. Stay tuned. I'll post them here and over on my YouTube channel.

If you have any special requests for techniques, or to highlight a particular tool/filter, let me know.

Wednesday, January 28, 2015

Thank you

I simply want to say thanks and I love you....
But please don't say you love me back, or that you love my page, or that I am great, or the best, or any of that, because then I will think that you think I am posting this just to get feedback and feel good about myself. Which isn't true. I just want to say I love you all very much and thank you for being a part of my life. And if you think: 'Well, how can she love me; she doesn't even know me?" Then you are likely Aspie, logical thinker, or don't read my blog. hehehe Anyhow, Thank you for being here.... 
I simply want to say thanks and I love you... 
(If you must post something, post a heart or smile)

Tuesday, January 20, 2015

Libavcodec bug threatens Windows XP VLC users

This just in from PCWorld.com:

"Watch out Windows XP diehards: if you run the open source media player VLC you may be vulnerable to malicious attacks. A bug discovered in November affecting VLC was recently made public on Full Disclosure, a security-focused mailing list.

The reported bug (dubbed CVE-2014-9597) allows a specially crafted video file with the FLV file extension opened in VLC 2.1.5 to corrupt memory. This could then allow the attacker to execute any code they want on the target machine. The vulnerability was tested on Windows XP SP3.

Why this matters: A bug that affects Windows XP may not be much of a worry for most users as XP’s user base has been slowly declining. But there are still some diehards holding on to the OS—around 18 percent of PC users worldwide run XP, according to Net Market Share.

While the bug apparently affects VLC users, it doesn’t appear to be an issue with VLC itself. Instead, the bug is caused by libavcodec, Jean-Baptiste Kempf, president of VideoLAN, the non-profit behind VLC, confirmed to PCWorld. Libavcodec is a third-party code library for encoding and decoding video and audio, maintained by FFmpeg. Kempf also said that he was unable to replicate the bug on Windows.

Whether or not the bug is a serious concern for users, the threat may not be long lived anyway. Kempf says the second release candidate for VLC version 2.2.0 fixes the issue. Concerned XP users can download and try out the release candidate from VideoLan."

Monday, January 19, 2015

Stop Believing TV’s Lies: The Real Truth About "Enhancing" Images

This just in from How-To-Geek: "You’ve seen it over and over. The FBI uses their advanced technology to “enhance” a blurry image, and find a villain’s face in the worst possible footage. Well, How-To Geek is calling their bluff. Read on to see why.

It’s one of the most common tropes in television and movies, but is there any possibility a government agency could really have the technology to find faces where there are only blurry pixels? We’ll make the argument that not only is it impossible with current technology, but it is very unlikely to ever be a technology we’ll ever see. Stick around to see us put this trope under the lenses of science and technology, and prove it wrong once and for all."

Click here to read the whole article.

Wednesday, January 14, 2015

The end of the CCTV era?

This just in from the BBC: "Twenty years ago the government backed a major expansion of the CCTV network - now funds are being cut and cameras shut off. Is the UK's CCTV boom over, asks Rachel Argyle.

In 1994, the Conservative government launched the Partners Against Crime initiative, with Home Secretary Michael Howard saying he was "absolutely convinced that CCTV has a major part to play in helping detect, and reduce crimes and to convict criminals".

The next year the CCTV Challenge Competition fund was started to encourage local authorities to set up surveillance schemes - the Home Office and local authorities invested £120m in CCTV systems within three years.

The UK has one of the largest CCTV networks in the world. But as cash-strapped councils look for cost-saving measures, the effectiveness of public CCTV is under scrutiny.

Dyfed-Powys police are set to cut funding to monitor CCTV following an independent report set up by Police and Crime Commissioner Christopher Salmon. The force covers over half of Wales and just under half a million people.

The report found that the removal of Powys Country Council CCTV did not result in a significant rise in crime or anti-social behaviour and there is little evidence that CCTV deters violent or alcohol-related crime. Salmon says the police will direct funds where the public want them, with "more bobbies on the beat".

These cuts are not an isolated case.

Cornwall was one of the first local authorities to cut their CCTV budget back in April 2011 - by £350,000. Denbighshire council will stop their funding and make a saving of £200,000 from 2016-17. Anglesey Council scrapped its CCTV altogether last year but following a successful charitable trust bid it will now be run by the island's five town councils. In Derby, 48 cameras in the city centre may be switched off.

Other areas are scaling back. Birmingham's 250 CCTV cameras will no longer be monitored around the clock and CCTV managers across the country face redundancy.

Police are under similar financial strain. Thames Valley Police could reduce its CCTV funding for the city from £225,000 annually, to as little as £50,000 by 2018.

A Freedom of Information request by Labour MP Gloria de Piero in March 2013, found that one in five councils had cut the number of CCTV cameras on the streets since the last election.

Supporters of CCTV point to the success of cameras in identifying suspects in high-profile cases, such as Robert Thompson and Jon Venables in the murder of toddler James Bulger, the Boston Marathon bombing, the London 7 July 2005 attacks and the 2011 UK riots. CCTV was crucial in the hunt for the Charlie Hebdo attackers.

But campaigners against CCTV believe it violates personal privacy and question its effectiveness.

"Britain's crime rate is not significantly lower than comparable countries that do not have such vast surveillance," says Emma Carr, director of Big Brother Watch.

The pressure group welcomes that budgetary restraints may make authorities look more closely at whether CCTV is really working. Carr adds: "Councils that reduce the number of ineffective CCTV cameras, diverting resources to where they will keep the public safer, are to be praised."

Charles Farrier, spokesperson for No CCTV, is a little more apprehensive. "The alleged cost-cutting is leading to a restructuring rather than a real reduction of camera surveillance." He points out that budget cuts will see others jump to the rescue. "Often the solutions offered are merging control rooms or taking the cameras out of the hands of democratic local bodies and into management by private companies driven by a profit motive," he added. He calls for an urgent public debate.

For some people, there's a more human alternative to fighting crime with increased CCTV. Farrier believes the solution lies in the findings of a 2013 report entitled Fortress Britain, published by the New Economics Foundation, which found that residents on an estate in London felt that "knowing people" was the key to creating trust.

"We no longer have park keepers, bus conductors, toilet attendants - people there to help act as a glue to hold the community together. Now we abdicate that responsibility to a machine. Surely instead of spending money on surveillance cameras it should be spent on proven strategies or encourage more people to walk, talk, and problem solve in their own communities?"

There has been much research into the effectiveness of CCTV as a crimefighting tool during the boom years.

A study entitled the Effects of Closed Circuit Television Surveillance on Crime (2008) found that CCTV schemes had little effect on crime deterrence, other than car crime ..."

Click here to keep reading the article.

Thursday, January 8, 2015

What's wrong with Photoshop?

Long time Photoshop users know that in order to get the most out of Photoshop, you'll need a pretty nice workstation with the "right" video card. Adobe explains why:

"The advantages of using a compatible video card (GPU) with Photoshop are better performance and access to more features. In this document, you will quickly find out everything you need to know about how Photoshop uses the Video Card (GPU) in your system including troubleshooting steps and features that have been recently updated to take advantage of the GPU.

This document provides a quick reference guide to video card usage in Photoshop. Some features require a compatible video card. If the video card or its driver is defective or unsupported, those features don’t work. Other features use the video card for acceleration; if the card or driver is defective, those features run slowly."

The GPU Sniffer

"To help guard against Photoshop crashes related to bad GPU hardware or drivers, Photoshop employs a small program called the GPU Sniffer. Every time Photoshop launches, Photoshop launches the sniffer. The sniffer runs rudimentary tests of the GPU and reports the results to Photoshop. If the sniffer crashes or reports a failure status to Photoshop, Photoshop doesn't use the GPU. The Use Graphics Hardware checkbox in the Performance panel of the Preferences is deselected and disabled.

The first time the sniffer fails, Photoshop displays a dialog indicating that it has detected a problem with the GPU. On subsequent launches, the dialog doesn't appear.

If you correct the problem, either by replacing the video card or by updating the driver, then the sniffer passes on the next launch. The Use Graphics Hardware checkbox is enabled and returned to its previous state (enabled or disabled)."

Wednesday, January 7, 2015

Mrs. Lincoln, I Presume? Well, as It Turns Out ...

You might have missed this one, but it's an interesting article on authentication and hoaxes.

"For 32 years, a portrait of a serene Mary Todd Lincoln hung in the governor’s mansion in Springfield, Ill., signed by Francis Bicknell Carpenter, a celebrated painter who lived at the White House for six months in 1864.

The story behind the picture was compelling: Mrs. Lincoln had Mr. Carpenter secretly paint her portrait as a surprise for the president, but he was assassinated before she had a chance to present it to him.

Now it turns out that both the portrait and the touching tale accompanying it are false.

The canvas, which was purchased by Abraham Lincoln’s descendants before being donated to the state’s historical library in the 1970s, was discovered to be a hoax when it was sent to a conservator for cleaning, said James M. Cornelius, the curator of the Lincoln library and museum in Springfield. The museum is planning to present its findings at a lecture on April 26.

“It was a scam to defraud the Lincoln family,” Mr. Cornelius said.

The Lincolns were not the only ones fooled. Ever since The New York Times announced the portrait’s discovery in 1929, on Feb. 12, Lincoln’s birthday, historians and the public have assumed it depicted Mary Todd Lincoln. It was reproduced in The Chicago Tribune and National Geographic, and versions of it still illustrate at least two biographies, including the latest paperback edition of Carl Sandburg’s 1932 “Mary Lincoln: Wife and Widow.”

In reality, the painting depicts an unknown woman and was created by an anonymous 19th-century artist, said Barry Bauman, the independent conservator who uncovered the fraud. The con, however, dates to the late 1920s, when the portrait was recast as that of Mrs. Lincoln, he said.

Mr. Bauman identifies the culprit behind the scam as Ludwig Pflum, who rechristened himself Lew Bloom and was given to the kind of self-invention that America became famous for during the industrial era. He worked as a jockey, circus clown, boxer and vaudevillian before settling on art collecting.

When he died less than a year after the painting’s public unveiling, an obituary in a Reading, Pa., newspaper noted that he “dabbled in oil paintings.” Apparently he dabbled more than anyone at the time realized ..."

Click here to keep reading the article.

Tuesday, January 6, 2015

Validation of forensic images for assurance of digital evidence integrity

Here's an interesting paper from Murdoch University in Australia.

"The reliability of digital evidence is an important consideration in legal cases requiring sound validation. To ensure its reliability, digital evidence requires the adoption of reliable processes for the acquisition, preservation, and analysis of digital data. To undertake these tasks, the courts expect digital forensic practitioners to possess specialised skills, experience, and use sound forensic tools and processes. The courts require that the reliability of digital evidence can be verified with supporting documentation; notably acquisition process logs and a chain of custody register, confirming that the process of recovering and protecting the evidence was based on sound scientific principles.

In typical cases the digital evidence has been ‘preserved’ in a special file or ‘container’ that has been declared to be secure on the basis that it is not possible to tamper with the contents of the container or the information supporting the contents (metadata) without this act being discovered. However, through the use of a freely available open source library, libewf, it has been discovered that the most commonly used forensic container format, Encase Evidence File Format, also known by its file extension .E01, can be manipulated to circumvent validation by forensic tools. This digital forensic container contains an embedded forensic image of the acquired device and metadata fields containing information about the data that was acquired, the circumstances of the acquisition, and details about the device from which the forensic image was acquired. It has been found that both the forensic image and the metadata associated with that image can be freely altered using simple file editors and open source software.

Exploiting these weaknesses within the Encase Evidence File format results in a forensic container that can be altered but fails to provide any evidence that this has occurred. In practice the original device is often unavailable, damaged, or otherwise unable to provide independent validation of the data held in the container. In such situations, it would be difficult, if not impossible, to determine which of two forensic containers held the original record of the evidence.
As part of a proof of concept, existing libewf code was manipulated to allow for legitimate metadata to be attached to a compromised and altered forensic image with recalculated hashes and data integrity checksums. Without incontrovertible records of the original data’s hash value, this manipulation might only be detected by an independent third party holding a copy of the original forensic container’s metadata and hashes for comparison. While hashes and metadata held by an interested party could also potentially be altered or declared unreliable, an uninterested party would be able to provide a more reliable set of hashes that could be used to validate the unaltered container.

In order to add to the body of knowledge supporting digital forensics as a scientific discipline this research has brought into question a fundamental assumption about the reliability of a fundamental method currently used to collect and validate digital evidence. Further research is required to determine the whether processes can be designed to enhance the detection of contaminated images."

Monday, January 5, 2015

A Coursera Course on Visual Perception Starts January 7th

This just in from the Scientific American:

"For those of you who don’t know what Coursera is, it’s one of several apps/websites that provides courses online. It’s an amazing system allowing for thousands of students to participate and view the same lectures. Such courses are generically referred to as MOOCs: Massive Open Online Courses. Coursera and its competitors, such as edX could potentially change the educational landscape by bringing the highest-quality education and lecturers to the general public, anywhere in the world, cheaply or even for free. No longer will aspiring students have to compete for an entire childhood before achieving entry into the world’s best universities to see these lectures: they can simply login to view the same lectures that are offered to the intelligentsia.

There’s a new 8-week course available on visual perception taught by Dale Purves of Duke University. It’s available for free and starts on January 7th, 2015. Purves’s approach to visual perception is exciting because it’s a bit different than the usual approach. Sensation and perception courses usually try to explain perception in terms of reconstructing the physical world. That is, the world exists, it has properties that can be measured with a visual system, and those measurements are then used to reconstruct a representation of the world in the brain based on those measurements. Visual illusions—where the perception doesn’t match the reality—in this model are errors in measurement: where the visual system gets it wrong. Sounds great, right? The problem is that our perception is not an accurate representation of the world (as Purves’s course will show), even when it could be based on the quality of the sensation. That is, our visual systems sometimes perceive illusions even when its measurements are accurate.

Purves considers that the visual system is instead working to solve an inverse problem… it’s trying to build a model of the world that will help the observer survive and reproduce (rather than to reconstruct the physical world accurately). What this means is that we can continue to work within the world (or, our model of the world) even in the absence of direct measurement. For example, to perceive the lightness of an object, the standard view of vision—as a reconstructive process—would be that the photoreceptors of the eye count photons that arrive from the object and report them so that we can reconstruct the object we’re viewing. That’s great except that—as Purves’s and his colleagues’ own lab work have perhaps shown best—lightness perception conflates the reflectance of the object (what color its surface is painted and how well it reflects photons that emanate from the light source), with the illumination of the object (how much light actually arrives from the light source), and transmittance of the object (how much light is either generated by the object directly… or travels through a through a transparent object from behind that object). All the visual system knows is the result of all of these object properties. But the object’s appearance nevertheless depends critically on knowing the contributions of all of these separate sources of photons. So what’s a brain to do? Purves’s view is that the visual system must guess at what the world looks like based on fitting its data to an internal, already-formed model of the world. Where does the model come from? From past empirical experience with the world. By experiencing and learning about objects throughout your life you adjust your model of the world to account for the frequency by which a given pattern of photoreceptor responses correlates to a given object. In this sense, genetically transmitted knowledge about the model also contribute to one’s empirical knowledge. So much of our model may be hardwired into our brains at birth, and your life tweaks your model as you go.

Many of Purves’s insights in visual science have correctly challenged the status quo and he is one of the finest phenomenologists in the world (a phenomenologist is a scientist who develops visual illusions for the purpose of drawing insight into visual processing in the brain). The image presented here is a terrific example. Notice that the orange and brown chips on the Rubik’s cube appear to be different colors that are reflecting different amounts of light (the orange chip is in the shade). Actually: the orange and brown chips are exactly the same color but are interpreted by your brain differently because they appear to have different levels of illumination. Don’t believe me? Print this image out on a printer, and cut the orange and brown chips out with scissors and compare them directly: they are exactly the same and only appear differently here due to their context."



So join me as a student in this course in January! It’s certain to be illuminating.

Friday, January 2, 2015

Why does Adobe Premiere Pro modify original footage/asset files

The following scenario was featured over on StackExchange.

Background:
  1. A colleague had given me a large 33Gb .mov for use in a project, I put this file on a backup drive.
  2. I made an identical copy of this 33Gb .mov file and placed it in a folder that I'd use to work on a Premiere Pro Project.
  3. I ran Adobe Premiere Pro CS6 and dragged in the 33Gb .mov file into the Sequence (imported it)
  4. Premiere Pro CS6 started conforming the file.
  5. After it had finished, I noticed that it's Modified Date was just now i.e different to the Modified Date on the original copy of the file on the backup drive (see step 1)
  6. I ran a BeyondCompare check between the .mov file on the backup drive (see step 1) and the one that the Premiere Pro project was using (step 2, 3) and Beyond Compare reported they were different.
I had initially thought it was unrelated file corruption of some kind, but I have checked this several times and got the same outcome, so it's definitely Premiere Pro deliberately modifying the file.

So I am puzzled: these are supposed to be the same file.

Why would there be a need for Adobe Premiere Pro to modify the footage? What does it do to the file? Would it not be better to create a separate file if necessary?

The answer to the user's question is featured here:

"It's all about this setting, "Write XMP ID To Files On Import" - which confirms that Adobe Premiere Pro is deliberately modifying the .mov file."

These posts give some background as to why having this setting enabled would be beneficial: one benefit being to be able to skip conforming files by matching the conformed file with the original using the embedded XMP tag:

http://helpx.adobe.com/premiere-pro/using/preferences.html#WSE3BD4A43-7022-4fe6-97F5-95313935347B

http://www.dvinfo.net/forum/adobe-creative-suite/498627-why-premiere-modifying-video-files.html

https://forums.creativecow.net/thread/205/876064

---

Can you imagine what would happen on the witness stand if you didn't know this was happening to your files, and the opposing attorney asked you a series of very specific questions about your Premiere Pro (of Avid) work flow? OTS software does a lot of stuff to your files without telling you. That's the peril in using it for your forensic science work. It's yet another reason I've ditched the commercial editors in favor of software purpose built for our industry.

Thursday, January 1, 2015

Content analysis and confirmation bias

I was binging on Discovery Channel shows and flipping between football games today. BTW, happy new year.

I was amazed to watch as the people featured looked at pictures and video and described what they thought was in the video - a body, a tool, a hieroglyph, a UFO, and etc. I wasn't convinced. It seemed that all the pictures contained exactly what the producer wanted to see, but critical or scientifically based content analysis was never performed.


Confirmation bias refers to a type of selective thinking whereby one tends to notice and to look for what confirms one's beliefs, and to ignore, not look for, or undervalue the relevance of what contradicts one's beliefs.

As an example of this, most people reading this will look at the picture and think "egg and french fries (chips)." But, if you thought that when you saw the image, you'd be wrong. The photo above features apple slices and a half of a peach on yogurt.

And this is the problem when the untrained eye and brain engage in content analysis. They can both be fooled quite easily.

Wednesday, December 31, 2014

Happy New Year


Wishing you and yours a healthy and happy new year (free from the Y2K hysteria of years past :) ).

Monday, December 29, 2014

A rebuttal to the case against encryption

In an article over on SC Magazine UK, a senior Met investigator argues against the use of encryption.

"In any democratic society we need to provide law enforcement with a right to obtain information authorised by a judge, based on a clear suspicion, in cases involving serious crime or terrorism. This applies to the offline world and should also apply to the online world."

“Full encryption of communication and storage online will make life very easy for the criminals and terrorists and very difficult for law enforcement and law abiding citizens. We have to find the right balance between security and freedom - and this balance has to be set by citizens in a political and ethical discussion on the trade-offs.”

Remember, of course, that in the UK there's a completely different legal system than here in the US.

In the US, you have the right to remain silent, including the right not to present evidence which may incriminate you (5th Amendment).

"The Fifth Amendment creates a number of rights relevant to both criminal and civil legal proceedings. In criminal cases, the Fifth Amendment guarantees the right to a grand jury, forbids “double jeopardy,” and protects against self-incrimination. It also requires that “due process of law” be part of any proceeding that denies a citizen “life, liberty or property” and requires the government to compensate citizens when it takes private property for public use."

We also enjoy protection against unreasonable searches and seizures (4th Amendment).

"The Fourth Amendment originally enforced the notion that “each man’s home is his castle”, secure from unreasonable searches and seizures of property by the government. It protects against arbitrary arrests, and is the basis of the law regarding search warrants, stop-and-frisk, safety inspections, wiretaps, and other forms of surveillance, as well as being central to many other criminal law topics and to privacy law."

Put these two together.

You have the right to remain silent and to protect yourself from self-incrimination. Encryption can be seen as a digital affirmation of that right.

You have the right to be protected against unreasonable searches and seizures. The problem with setting up weak protection schemes, or "trap doors" that law enforcement can open when it deems necessary is that it is simply weak protection. Hackers can and do exploit weak protection.

"Now just as then, the FBI is trying to convince the world that some fantasy version of security is possible—where "good guys" can have a back door or extra key to your home but bad guys could never use it. Anyone with even a rudimentary understanding of security can tell you that's just not true. So the "debate" Comey calls for is phony, and we suspect he knows it. Instead, Comey wants everybody to have weak security, so that when the FBI decides somebody is a "bad guy," it has no problem collecting personal data.

That's bad science, it's bad law, it's bad for companies serving a global marketplace that may not think the FBI is always a "good guy," and it's bad for every person who wants to be sure that their data is as protected as possible—whether from ordinary criminals hacking into their email provider, rogue governments tracking them for politically organizing, or competing companies looking for their trade secrets."

If you run a business, you must keep your customer data private and protected from being distributed against your customers' wishes. Think about the data breaches that happened to Target, Home Depot, and Sony for an example of how weak physical and digital security combined to negatively affect millions of people's lives.

So where does that leave us? Here's an analogy. California passed a law recently created a "civil right to clean drinkable water." Many believed that this meant they'd never have to pay their water bills again. After all, water was now a human right. But, the law mandates that water delivered must be clean and safe. The law did not create a civil right to "water pressure." The law did not mandate that water be delivered to you, just that if it was delivered that it be safe and clean.

Courts may order that data be seized. So take it. Use it as is. If you can crack the encryption, great. If not, (for the time being) the US Constitution sill allows me to remain silent and to choose to not incriminate myself. Given that we in the US are innocent until proven guilty, once you remove the 5th Amendment's protections you might as well be done the concept of freedom as we know it. Without the 5th Amendment's protections, we will be living in a "police state." I'm not about to go down that road willingly.

Just like you can't be a little bit pregnant, you can't encrypt a file just a little bit. Thus, I say full encryption is great. Encryption protects freedom of communication. Encryption protects property. Encryption was a proper response to government and industry's mishandling of private data.

Tuesday, December 23, 2014

Hackers and Conspiracies

A few people have asked me about my opinion of the Sony hack, the Interview, and the prospect that we may be in the beginning stages of a Cyber War with North Korea. I don't really have an opinion, as such. So, I'll offer my version of a conspiracy theory as a response.

Here it is:

It is no secret that Sony has a history of being hacked. It is no secret that the bilge that Hollywood is generating isn't putting butts in seats like it used to. It's no secret that the big movie stars make a ton of money. So, if you were the CEO of Sony (the one in Japan, not the one here who made inappropriate e-mail comments about our President), what would you do if you were hemorrhaging money, had a horribly sophomoric/moronic movie that would likely not break even, and wanted to cut a few stars loose? Blame North Korea.

Maybe someone hacked Sony, maybe they didn't. Blaming North Korea means no one will know for sure. That's beside the point now. With the on-again / off-again release notices about the Interview, the media has assured us that it's our patriotic duty to go out and see this film ("up yours Kim!"). With this duty in mind, Sony will reap much better revenues on this film that it ever would have with a "normal" release. Win - Sony.

The "hard to work with" hollywood stars will also have their incomes readjusted. They'll also get to cut a bit of dead weight at the top of Sony US corporate with the release of a few e-mails to the media. Win - Sony.

There'll be a few settlements of law suits, but now Sony is the "victim" of the dreaded North Koreans.  How can you blame the victim? Win - Sony.

I'm sorry if this seems like a B-Movie screenplay, but it all seems too convenient.

Monday, December 22, 2014

PhotoDetective - first look

A few weeks ago, I alerted you to a Kickstarter campaign around a new image authentication product called PhotoDetective. Well, I've put my copy through a few tests and it's time to share the results.

The program is quite simple to use. It has a very clean/lean interface - almost too lean. It has a few of the basic authentication algorithms that you've come to expect. But, nothing fancy. No reporting. What you see is what you get.


Your basic Exif tools are there. You can export the info to a text file.


It's all menu driven.


Some of the filters are self explanatory, some aren't (if you're unfamiliar with the science of authentication). There's no title to the results - if you want to screen capture your resulting images.


There's also no comparative function. Sure, it gives you a basic look at the QT - but you'll have to do the work to make sure it's right.

Now, the results:
  • For my cut/delete/paint over tests - it found the problems rather easily as long as they were blatant. For my more subtly changed images, I found what I was looking for only because I knew where I was looking. I could probably fool the average user into a false negative (a false conclusion of no evidence of tampering).
  • For my cut/paste tests - again, it did well with the blatant examples and not so well with the subtle ones.
To be sure, there's nothing wrong (per se) with the program. It's very basic in its functionality. The problem will come when people buy this as their only tool. As I noted above, it could lead to a lot of false negatives when wielded by an untrained user.

In all, limited but not bad for $30 when used by a trained analyst. In untrained hands ... OMG.