New US Computer Forensic Institute
Quincy writes "The DHS and Secret Service are setting up a new computer forensic institute in Alabama. Set to open in mid-2008, the new National Computer Forensic Institute will be able to train over 900 law enforcement officers per year. 'It will initially be staffed by 18 Secret Service agents and will feature classrooms, a forensic laboratory, an evidence vault, and server rooms. Courses will be offered in the investigation of electronic crimes, network intrusion investigation, and computer forensics... [T]he Secret Service says that it will help to bring judges and prosecutors up to speed as well.'" Maybe over time we'll see fewer botches of justice like those in the news recently.
Do you HAVE to be a law officer, or can anyone sign up?
The simple truth is that interstellar distances will not fit into the human imagination
- Douglas Adams
Figuring out what happened in a computer system months after the fact is not easy. Most programmers have more than enough trouble figuring out what exactly happened in their own programs thirty seconds ago.
Still -- not to say it's a bad idea. You have to start somewhere...
Microsoft must be the biggest supporter of computer forensic investigators.
Even since DOS 1.0, Microsoft operating systems never really erase a file. Now, they use cache, temp files, and the recycling bin to make lots of copies too. And that's only on the unerased portion of the hard drive. Chances are there are more copies on the erased data sectors.
Most users who really want to erase a file from the file system have to erase about two or three copies (if they know where the copies are). Wiping a file only zaps the original, not the copies.
Those investigators have it too easy.
My wiping program is made by Craftsman Tools (claw or ball-peen configuration)
"If you're a bad guy and you want to frustrate law enforcement, use a Mac."