Commodore 64 Confuses Austrian Police
toomanyairmiles writes, "It seems that Wolfgang Priklopil, the communications technician who kidnapped Austrian pre-teen Natascha Kampusch, relied on a Commodore 64 as his primary machine. Interestingly this is presenting some problems to the Austrian computer forensics people. Major General Gerhard Lang of the Federal Criminal Investigations Bureau told reporters it would 'complicate investigators' efforts' and would be difficult to transfer the files to modern computers 'without loss.' Could this be the latest in the criminal world's security strategy? Can we expect to see Spectrums, Archimedes, and Atari STs turning up in police investigations soon?"
Could this be the latest in the criminal world's security strategy? Can we expect to see Spectrums, Archimedes, and Atari STs turning up in police investigations soon?
Um, no. This was an aberration; nothing more, even if its use for those reasons was deliberate on his part.
But here's an actual question:
I can absolutely understand and appreciate that people value some of the features and functionality of things like the Commodore 64 and Newton, and many other machines that were considered to be state-of-the-art in their time.
But why would someone go out of their way to continue to use it? I can understand practical and pragmatic answers like "It's still functional for me" or "I just like it better and I haven't had any problems". But are there other reasons?
I mean, you can literally get systems for free (or next to nothing) that are capable of running various modern operating systems, including various versions of Windows, Mac OS and Mac OS X, myriad Linux distributions to your heart's content, BSD distributions, and so on, that would be much more functional and capable, particularly in the context of the internet and associated applications.
So what's the draw? Why keep running on something like a Commodore 64? Even considering legitimate reasons for continuing to use it, I don't see how sticking with something exceedingly obsolete can be functional when viewed alongside semi-modern systems. I understand people collect all manner of antiques for a variety of reasons, including other things that may be nearly impossible to service or repair easily; is the reason for using obsolete computing equipment the same?
Status? Hobby? Entertainment? Eccentricity? Just to "do it"?
And to reiterate, I can understand collecting pristine Commodore 64s or similar in working order, and even making TCP/IP stacks and such work, just for the sake of doing it. But using it as a primary system exclusively? Some people may own and spend a great deal of time on something like, say, a Model T, but they don't use it as their daily driver...
On another note, I do agree that his system being a Commodore 64 will "complicate investigators' efforts"; but to say that it would be difficult to transfer files "without loss" is disingenuous at best. Do they mean "transfer files" to include possibly-deleted files (in which case I agree there may be "loss")? Do they mean contextual loss, because modern applications may or may not be able to open files and represent context-sensitive features like position, text styles, and so on? Or are they talking about "loss" in that they won't be able to run their standard forensic tools that package everything up with a nice little bow? If they're talking about files representing images and text, I don't care what it is: if it's functional and intact, there's no reason for there to be "loss". I don't care if it takes resorting to eBay, digging up old company engineers, or weirdos on web forums...they should be able to recover anything they need to.
Any box that doesn't run Windows confuses most investigators. Yep, all their tools are Windows-specific.
I've abandoned my search for truth; now I'm just looking for some useful delusions.
From the article:
There are emulators available which can make a modern PC capable of running Commodore 64 programmes but Maj Gen Lang said it would be difficult to transmit the data from Priklopil's machine to a modern computer "without loss".
What, have they forgotten how to create a DIN-5 to Sub-D9 cable? I'm sure google has several websites with the schematic of the machine (also available in the original user's manual), it shouldn't be THAT hard to construct an asynchronous serial cable.
SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
My Basic skills will rule them all
back in the day we didnt have no old school
I'll have that bugger fixed in no time!!! ...as long as it involves writing elementary BASIC loops, LOAD "$",8,1 or beating Space Taxi or Questron.
Did you ever notice that *nix doesn't even cover Linux?
I would say this does raise another valid point, though: as systems and media age, it's actually quite an interesting question how all of this data that isn't transferred to modern day systems will be dealt with, both from a technological and machine- and media-aging point-of-view. And in the context of criminal investigations, what happens if evidence is "lost" (or simply unrecovered) from a 25-year-old computer in a murder investigation which has no statute of limitations? It's an equally difficult question for governments, corporations, and academic institutions that actually *want* to keep the data but are having trouble instituting standards, policies, and mechanisms for data retention.
I also hear they are having trouble getting information from his IBM typewriter. Apparently he used White Out to clear the data.
//TODO: Insert catchy phrase
In my mind I see the secretaries at the Austrian police station behind their typewriters, listening hard and trying to make sense of what exactly is being said on those strange tapes...
Seriously, I have a Commodore 64 sitting right next to me hooked up to a dos box as a hard drive. Data is data. You just need a x1541 cable. There are lots of free software tools to facilitate this, and the d64 and t64 formats are well supported. You can even use audio tapes and a soundcard to transfer files. Once you have the data on the PC, there are multitudes of C64 emulators to run the software directly. I've been doing this since the late '90s. Google is your friend.
Waiting for ad.doubleclick.net...
We must ban all Commodores, to save the children of course. Think of the children!
It's now security by obsolescence!
Really, if the raid happened 20 years ago, everyone would be able to get the info off those floppy disks. Now they've got to find a C64 user group or specialty store (how many of them are there, even on the net?) to transfer the data and convert it to a usable format.
Help! I'm a slashdot refugee.
If the C64 confused them wait tell they find people storing porn on an abacus or two.
does the story about a girl kept in a dungeon for eight years revolve around the kidnapper's computer. Tor
The article, and most of these comments, are missing the point. The point isn't that you can't get the data off the hard drive - the investigators aren't that stupid - it's that they can't get previoiusly deleted or overwritten files off the hard drive using their standard techniques, because there is no way to image both a drive and the magnetic clues that these folks use.
The back of the Commodore 64 has an RS-232 interface. Any schmuck with a bachelor's degree in electrical engineering can hook the Commodore 64's serial interface into the serial interface of any modern desktop.
Here's the best way to do it:
i l.prg) to make your .d64 files. Additionally, if they're feeling up to the challenge, mnib (http://markus.brenner.de/mnib/index.html).
1. Use Star Commander or the equivalent program (ftp://ftp.zimmers.net/pub/cbm/archiving/c64/emut
2. Use PDS Hash Toolkit or some other approved toolkit to hash the disk images you've created.
They can also use 64hdd (www.64hdd.com), set it as drive #10, make directories on the partition they copy the files to, and then individually hash each file using PDS Hash Toolkit. You'll have to hash the 64hdd binaries as well.
If he's a really hardcore user of the C= series, I think the price of that SuperCPU on eBay just went up by a few hundred euro.
My other account has a 3-digit UID.
Can't Transfer the Files:
...and the number one reason why Austrian Police Can't Transfer the Files:
10.There's no USB port
9. Austrian govenment mandate that all computers must be able to play music from "The Sound of Music".
8. Investigators were at Oktoberfest the day they taught pre Windows XP forensics.
7. Unable to install popular folk dancing software on Commodore 64.
6. Jokes about the situation being hopeless but not serious in Austria have become true.
5. Police still worried about riots after UPC Arena name change.
4. There's no USB port
3. The floppy drive is WAY to big
2. The modem baud rate is slower than pooh
1. Can't copy and paste without a mouse
Zaxxon
Beware the fury of a patient man
- John Dryden
Of course they'd lose information. Haven't you seen how bad Arial screws up ASCII porn... Uh Nevermind
There are a myriad of other issues with this too. For one, the Commodore 64 uses PETSCII and not standard ASCII. To complicate matters more, he may have even used GEOS to store his data on floppy disks, and without the right conversaion tools, coverting that to plain text, muchless PC readable media, is going to be tricky without the right C64 hardware. If he had all that CMD hardware, or stored all his information on a hard disk or CMD formatted floppy disk, it will be harder again.
READY.
PRINT ""+-0
10 REM hide your stuff from the fuzz 20 POKE 53280,0 : POKE 53281,0
This is simple. Get a Catweasel floppy controller, and use the bundled tools to make images of the disks. You don't even need any of the original Commodore hardware for this, any PC 5.25" drive will do.
If they're too cheap to do that, an X1541 cable and a copy of Star Commander will work fine, plugged between the Commodore drive and a PC. This shouldn't be forensically valid, because the 1541 is a smart peripheral and could concievably be running a modified ROM.
Seriously: Do a block image copy of every floppy disk.
How would you suggest they go about doing that 'block image copy'? Should they use the 1541 drive? Do they understand enough about the drive to make it do the copy?
I don't believe a standard PC drive will read Commodore disks. The Commodore used "GCR" encoding, where PC drives have always used "FM/MFM". These encodings are incompatible with each other.
Also, I know that some Commodore drives would adjust the spindle speed to get more bits packed into outer tracks - I don't know if the 1541 drive did this, though.
I assume there must be a machine that'll do a true bit-by-bit copy of a disk (and, presumably one that would copy to a medium compatible with a PC).
Disclaimer: I haven't looked at PC disk controllers in years - maybe recent controllers have changed in a way that they can understand "GCR" (but I don't see why the design would have changed to support this, as it's not needed on a PC).
- Paulb
Computer software or hardware that is not compatible with common forensic tools will automatically be deemed to be evidence of child pornography or terrorist activity.
Dumb Asses. They just need to go to the goodwill and get a complete.. tricked out vintage system of their own. Data loss my eye.
Of course, here's the funny story. I got the computer, and figured `ok, what do I do with it?' ... so I tried to remember BASIC, and put in this program as soon as I got it working at the office --
10 I = I + 1 ;
20 PRINT "HELLO THERE # ", I
30 GOTO 10
(sorry if I got this wrong. This is the last time I did any BASIC, and it was years before that that I'd last done any.)
In any event, it's still running today. It's up to (let me check) 509176235. It's doing roughly 4.2 iterations/second, with most of the cpu obviously going to scrolling the display. Of course, if I do the math, that only works out to about four years, so I'm not sure what the discrepancy is.
In any event, it's lasted several office moves, and now it's in my garage, with a wal-wart transformer connected and some AA's in the battery slot. The batteries will run it for a remarkably long time, and I just replace them every year or so.
I've been tempted to pull it out and play with it a bit, but I'm reluctant to lose all my uptime ...
Ah but guess what they get for that fuel inefficiency; marvelous bodies. I've sometimes marveled in amazement at the bodies of those bike-riding Dutch girls; solid from the waist down.
Except that those same media companies may in the future with high probability consider providing say Britney Spears' "tracks" (sorry, if I spelled her name wrong) for re-purchase as a "not interesting from operating profit point of view" thus consumers will be unable to repurchase thus they lose their beloved tracks. Or become criminals.
Feel free to replace "Britney Spears" with any other name from current "popular music" (or even past "popular music").
hany
You wouldn't call them smart just because they're hot, would you?
If it was going to get you laid.... :-p
in dutch cities, riding a bike is often faster than going by car. it's also cheaper and if you get drunk you can walk home with your bike.
No one can understand the truth until he drinks of coffee's frothy goodness.
--Sheikh Abd-Al-Kadir, 1587
...the police suspect that he may have had an accomplice. Apparently the normal M.O. for this type of criminal relies on having another person in the mix (lookout during original kidnap, looking after victim if other needs to go anywhere for an extended period etc.).
Marc Dutroux (the Belgian Paedophile) had several accomplices - one of whom was directly responsible for Julie and Melissa's death by not feeding them whilst Dutroux was in prison on another charge.
I am NaN
Its one of those "without a trace" scenarios. Maybe the dead kidnapper has girls buried in basements all over Austria. You have to crack the C64 file system before they starve to death.
http://michaelsmith.id.au
Well, I can sum up the whole article like this:
:) -- It's easy for technical people to understand the realities and limitations of the technology. It's easy to understand that when you copy the contents of the files from one OS to another the contents do not usually change. But for an average person on the jury, if one computer is old and the other computer is new, and they don't speak the same language, well that means that someone had to translate it, right? And if someone translated it, could they have made a mistake? Of course they could! Of course they DID! Again, the hard evidence - the files, the pictures, the notes, etc.. - do not come under scrutiny. It's the techniques, the procedure, the competence of the investigators that get's questioned, and thanks to our "well educated" and "intelligent" jury, sometimes the guilty go free.
Forensic investigators = not stupid
Article author/editor = selling a story / lack of facts
Court system = flaky justice
Being a computer forensic investigator, what I can tell you is that the problem is not with extracting individual files (being current, deleted, overwritten), or even hashing the contents or drive images themselves. Although this does present a certain technical challenge, this can be overcome. Any forensic investigator will tell you that, what he/she finds during his/hers investigation rarely comes under question or scrutiny. You just can not deny the fact that this "stuff" was found on the suspects media. What almost always comes under scrutiny is the technique used in obtaining the evidence. Where the police do have the tools and techniques that have been court tested for the relatively modern machines and OSes, there is no such tool or a battle tested procedure for capturing and processing data from the Commodore 64. That's what the challenge is all about. It's all about how do you get your evidence, and prevent the defence from shooting it down on a technicality that your approach was not forensically sound, because you have not used the court "approved" forensic tools and techniques. -- a side note: there are no court approved forensic tools, at least not in the USA. There are forensic tools that have gone through court scrutiny and been found to be acceptable, but only in conjunction with a proper forensic sound procedure. The tool is only a tool, like a hammer, it can be used to drive a nail into a wall, or crack someone's skull. Define a proper and sound use
Could this be the latest in the criminal world's security strategy? Can we expect to see Spectrums, Archimedes, and Atari STs turning up in police investigations soon?"
No, what this means is that soon, anyone who owns or purchases an old piece of computing will either have to submit to a background check or be put on a DHS watchlist. Because there is no reason for a normal person to own an old piece of technology other than for nefarious purposes.
Terrorists can attack freedom, but only Congress can destroy it.
Or collect antiques? And why do people pay top dollar for wine that is not brand new. Why do people spend thousands of dollars trying to replicate the sound of 70's moog synthesizers. I mean they are so analog right? This is the year 2006 people, analog is out. We need digital synthesizers that use modern wave table sampling and run Linux. They make the best music right? I mean what good is an analog filter and a bunch of patch cables and no MIDI. It can't make a piano sound like a piano right?
And the same with antiques. People spending tens of thousands of dollars on old used furniture when they can go down to the LayZboy store and get something brand new.
And classic automobiles? Don't even get me started on classic automobiles. What is so classic about something that is so old it doesn't even use disc brakes, lacks airbags, and just looks old. I mean why sink money into something so old when you can get a nice Honda Civic that is going to get you around in modern style right? Who needs a Tbucket when you can get a Civic?
All mockery aside, the obvious answer to your question is that some people "like" and or "appreciate" things that are obscure, different, or old.
Not everybody wants to compose their music on an Imac. Some people choose to do it on an Atari or on a gameboy. And they make a living off it.
We have had over 30 years to improve on synthesizers but the best sounds are still made by the old patch cord Analogs like the Moogs'.
I'm not a commodore fan boy but the C64 is a capable synthesizer and music production platform. It's cheap, and it's been reverse engineered to the point that you can actually buy or make modules that will give it network access.
Having confines on something forces you to be more creative.
I mean, this guy kept some girl prisoner for 8 years, he was F'd in the head. But your arguing that classic equipment is pointless. And that's like saying that paintings are useless because of photography and photography is useless because of film, and film is useless because of television, and television is useless because of PC's with DVD players, etc etc.
Why hasn't the design of the guitar changed in the last few hundred years? Why has the electric guitar pickup not changed in 40 years or more? Because new doesn't always mean better. And some people like the sounds and feelings of old things.