Slashdot Mirror


Vista For Forensic Investigators

Ant writes "SecurityFocus has a two-part article offering a high-level look at changes in Windows Vista that a computer forensic investigator needs to know about. Part 1 covers the different versions of Vista available and Vista's built-in encryption, backup, and system protection features. Part 2 continues with a look at typical user activities such as Web browser and email usage."

3 of 125 comments (clear)

  1. Oh n0es by mboverload · · Score: 4, Interesting

    The smart people already use drive encryption via TrueCrypt and other methods.

    This may make it easier for the not so completely stupid criminals to protect themselves, but I doubt it will have any real effect.

    People are stupid. Thats why they get caught.

    1. Re:Oh n0es by Detritus · · Score: 4, Interesting

      There is a legal distinction between testimony and material objects like diaries and journals. From what I've read, a court can compel someone to hand over material objects, like a safe, but it can't compel someone to say the combination. This issue came up quite often during Prohibition. Many rum runners kept their business records in code. The government would often seize these records during a raid. The government used their own cryptanalysts to break the codes and testify in court as expert witnesses.

      --
      Mea navis aericumbens anguillis abundat
  2. encypted backups? by RedElf · · Score: 5, Interesting

    After reading the article (I know we're not supposed to do that) I'm a little confused on if you backup an encrypted volume if the backup is also encrypted. If not, doesn't that defeat the whole purpose of encrypting that data in the first place?

    --
    You know, I have one simple request. And that is to have sharks with frickin' laser beams attached to their heads!