Showing posts with label Mobile Evidence. Show all posts
Showing posts with label Mobile Evidence. Show all posts

Thursday, October 21, 2010

Four Blogs

Four Blogs

I have four open webblogs that are active:

http://trewmte.blogspot.com
http://cellsiteanalysis.blogspot.com
http://sim2usim.blogspot.com
http://forensicmobex.blogspot.com

The focus of these webblogs involves dealing with all forms of forensics and evidence relevant to mobile communications in the open arena that may impact now or in the future relevant to:

- Advancing forensic evidence and analysis by challenging methodology and entrenchment in out of date concepts
- Balanced technical evidence for fair trials

I have been developing new materials for the blogs that will be gradually rolled out over the next six months.

Sunday, October 11, 2009

Extra-Statutory

Extra-Statutory
.
Where, for illustrative purposes only, a Home Office circular regulates e.g. the use of listening devices and aural and visual procedures, the standards set by that document may be the same as those under a Stature (say RIPA or, previously, IOCA) but that Home Office circular does not mean by following its guidance it makes any acts or omissions compliant with the statutory provisions; conduct arising from following the circulars regulation, and not the statute, could be "wholly extra-statutory" and would probably contravene the European Convention on Human Rights - see Malone v Metropolitan Police Commissioner [1979] Ch 344; cf Malone v United Kingdom (1984) 7 EHRR 14.
.
The above represents past history events and matters have or should have moved on since then. When RIPA was introduced it was made clear that "no" extra-statutory conduct or operations were possible arising out of that new legislation. That any acts outside of that may amount to contravention and be unlawful.
.
Having illustrated a simplistic model about "extra-statutory" activity by public authority and public bodies or their personnel to avoid giving advice, direction or guidance which would/could probably mean such acts may operate in parallel to the statutory provisions instead of being enshrined within them, the same principle of extra-statutory can apply across many other areas covered by other statutes, too.
.
Advice, direction and guidance given to facilitate the transmission of sensitive and/or unlawfuly material over public systems to aid extraction and harvesting of data from device/s might probably be "wholly extra-statutory" conduct or operations. That is even where it is a one-off case. Where advice is given to do acts which appear to go against previously stated authority in dealing with certain types of materials, the expert/examiner should record all dealings with those acts that have been instructed.
.
I picked up on this whilst reading books and papers dealing with judicial review of administrative action, Blackstones Criminal Practice, Archbold, telecommunications law and practice and the laws of the internet etc etc. I also noted that ACPO Guidelines and other provisions in public sector procurement documents appear not to cover any examiner/expert who enters into extra-statutory acts.
.
These are only my observations based upon what I read, which may assist other examiners/experts. I am not giving legal advice and I do hold out to be a lawyer. It could be from what I have read that my observations may be wrong and therefore it is always recommended to seek legal advice about instructions given or past instructions acted upon, under the belief those instructing were authorised to give such directions to do such acts in the first place.

Friday, July 10, 2009

Mobile Phone Flash Memory Chip Evidence

Mobile Phone Flash Memory Chip Evidence
.
When recovering data using flasher box devices it may be useful to support the notion of obtaining a detail (IMSI/ICCID/etc) about a previously inserted paricular SIM Card in a particular mobile telephone that the notion about storing such data in memory is:
.
- not new
- not clandestine shady black-box technology
- not a security breach by the handset manufacturer
.
In fact the entire process of maintaining a SIM List in the phone was designed to allow a user with more than one SIM Card to gain access to previously held memory data associated with each particular SIM Card.
.
In order to support that statement it would be helpful to see practitioners using authoratitive statements about the forensic 'reliability' and 'accuracy' of recovered data being obtained using flash reading devices and the evidential 'weight' and 'value' to be given to the data.
.
To assist, here is a statement from a 1996 published Electronic User Guide for the Nokia 2110:
.
SECURITY LEVEL (Menu 5 2) Page 71
"The phone keeps a list of the SIM cards which are used with the phone. This list may contain the information on up to five different SIM cards."
.
However under the same section in the User Guide it states:
.
"Regardless of the selected security level, all temporarily stored phone numbers are erased when a new SIM card is installed. On the other hand, these phone numbers are not erased when a previously used SIM card is inserted, regardless of the selected security level."
.
As a query about forensic reliability and accuracy:
.
- During the acquisition process and the harvesting of the data acquired is there/ has there been anything lost in translation of the data themselves, at first instance? If the IMSI you have recovered from flash memory is presented along with call logs etc, how do you know that those call logs relate to that IMSI and not another IMSI?
.
As a query about evidential weight and value:
.
- What weight can be given to the recovered IMSI being directly associated with those call logs? Moreover, what value is there in using such potentially uncorroborated evidence assigned to the recovered data being presented as evidence?

Thursday, May 14, 2009

Mobile Telephone Examination Procedure

Mobile Telephone Examination Procedure
.
This discussion continues on the theme to highlight, over the last five years, the diminishing quality of the knowledge in mobile telephone evidence training and very poor understanding by those giving advice about or presenting mobile telephone forensic evidence and opinion.
.
By way of further illustration about poor understanding which was given in an advice note regarding mobile telephone examination procedure, the advice given:
.
(1) by removing the battery of certain make/model of mobile telephone can lose the date and time stamp and call history, but using a Shielding Room can prevent this because you won’t need to remove the battery.
.
(1a) the party giving the advice above then went on to suggest they did not think, by and large, the above is a better methodology that should be adopted and went on to advocate that the method of producing a clone test SIM (Access Card) appeared to them to be more appropriate.
.
A shielding room is used to prevent radio signals entering a given space that the shielding is designed to protect, and also prevent the mobile telephone from registering to the mobile telephone network; [it] cannot though prevent loss of full call history and date and time stamp irrespective of whether the mobile telephone is in a shielded room or not. Removing the battery on some older models of mobile telephone can lose the full call history and date and time stamp. To produce a clone test SIM (Access Card) the examiner is required at first instance to remove the battery to get to the SIM/USIM. So how is their recommendation shown (in 1a) that it is any better than the unsuitable Shielding Room scenario (in 1)?

.
- For the record the point I am making is not to advocate shielding rooms or faraday bags, I am just pointing out the absurdity of the advice -
.
By noting in their advice that using a Shielding Room may not be the best method (thus tacitly negativing its use) the advice then goes on to positively suggest that the examiner wouldn’t need to remove the battery because it is in a shielding room and that call history and date and time stamp on the mobile telephone would be secure. They then go on to advocate the removal of the battery which implicitly requires taking the SIM out also from the handset for the purposes of producing a clone test SIM (Access Card). Their advice is confusing as they have already admitted removing the battery can lose data.
.
An examiner will naturally have to remove the SIM/USIM out of the handset anyway (thus removing the battery first is one point; another point being removing the SIM/USIM can inevitably cause loss of data in the handset - it can't be helped) because the proper order of examination requires a full examination of the SIM/USIM to get at evidence that is not readily available and obtainable by leaving the SIM/USIM in the handset during examination.
.
I concluded from reading their advice that it contained so many mixed messages and conflicting use of methodologies which each method that would usually be used for the treatment of different issues in isolation were now being squeezed together to make them work, would leave an examiner following their advice open to and vulnerable to potentially discrediting their own evidence.

.
Moreover, if the advice note was intended to succeed in getting an examiner to use Access Cards over Shielding Rooms then in my view it failed to convince me to use one or not the other.