UK crime fighters grapple with iPhone wipe threat

PC-mobile shift causing headaches for forensics chief

NEWS

He said: "It is a concern that society is moving more towards using mobile phones. The PC architecture is usually stable but with mobile devices they change daily. If a mobile device comes out tomorrow we will not be able to look at it until a tool becomes available.

"We can still analyse it by photographing every screen on it but we won't be able to get hidden data on it, so photographing every screen is not a very practical way of doing it.

"That is an area where we are almost playing catch-up."

Another growing obstacle to forensics' teams ability to recover evidence is the encryption features found in modern operating systems.

Security from A to Z

Click on the links below to find out more...

A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day

"With Windows Vista you have BitLocker that will cause us some problems," Foggon noted.

"It ties in the encryption to a chip, there are ways around it but it is something we can't crack, we need a pass to get around that."

The team cracks low-grade encryption using 100 quad-core PCs but for high-grade encryption it relies on the threat of a prison sentence for individuals refusing to hand over passwords or decrypted files.

Foggon believes that the unit's years of experience in unearthing evidence from everything from 186s to MacBooks will mean it will have a key role to play in any central UK e-crime policing unit.

The government has committed itself to funding such a unit and indicated it could be part of the proposed National Fraud Reporting Centre, under the Attorney General's Office, while the Metropolitan Police Service and the Association of Police Officers has put forward proposals to the government to establish a policing central e-crime unit.

Foggon said the unit's structure could soon be transformed and it may even tackle a wider range of criminal investigations, following the publication of its reaction, due imminently, to a review of the Serious Fraud Office (SFO) carried out by former senior New York City prosecutor Jessica de Grazia.

The review called for clarity about the roles, responsibilities, and qualifications of case controllers and assistant directors within the SFO.

  • 1
  • 2

Comments

There are 4 comments. Join the discussion

  1. 1. euty

    Government funding to crack security systems set up by companies for there consumers????? Government should pass legislation for companies to provide the law enforcers with ways to access data from devices (with a warrant of course) as a condition for a device to be on the consumer market.

    • 4 September 2008 01:55
    • Add comment
  2. 2. Robert Charleston

    It really is a shame that in UK the police/prosecution can lock you up if you refuse to hand over your encryption keys. In the US it was recently ruled to fall under 5th amendment - the self incrimination clause if I recall correctly. It really is scary when the US has better human rights and privacy than UK - not something you'd expect.

    • 4 September 2008 09:21
    • Add comment
  3. 3. Ehud Gavron

    ALL they have is the threat of a prison sentence if they aren't handed the key.

    They are a tissue-paper tiger.

    Ehud

    • 4 September 2008 11:24
    • Add comment
  4. 4. Garry

    Whilst the concept that real criminals can obscure or even delete evidence of their activities is of concern I frankly, am more concerned about the activities of our Governments in their efforts to have an iron control over us and spy on every aspect of our lives.


    • 4 September 2008 13:20
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters