Tuesday, March 22, 2016

Looks like GuidanceSoftware / Guid support forum is not working

I've run into issue with new EnCase v7.12 during Encase Advanced trainign, processor start to die with error messages. Almost same problem happened before and solution was listed  on of the support forum topics, Looks like GuidanceSoftware (now Guid) decides to move from old support forum to new one, it was announced about month ago and looks like it is not working yet.
It was announced that old accounts are not migrated and now  there are some issues with creating new accounts, so effectively it is not working . Some of our customers already asked us what is going on and what are that doing wrong. Extremely unpleasant situation.
It was so embarrassing trying to log in, creating account and getting strange messages about email being already used. Maybe to most comic moment was during password reset effort when I've tried to guess answer to secret question
It was almost same situation with partner portal some time ago and it takes quite a lot of time to resolve. Partner web is not critical but a support forum is, especially for such troublesome version as v7 is critical, Looks like bad luck or bad decisions continues plague EnCase, even after cosmetic re-branding and huge product name changes. 

Friday, March 18, 2016

Nice warning on hacking of cars

Just article on BBC "FBI warns on risks of car hacking" It will be much better if we have a legal framework regulating manufacturer responsibility for dangerous and unnecessary tehnology embedded into systems. Just project this on ITO idea and paranoia steps in :)
Fridge works perfectly without Ip connection, haidryer too..
It is not problem in tehnology but in designers and unintelligent application of tehnology. Usual free market mantra "a market forces will remove unsuccessful products and companies" simply does not apply, wee need legal framework and clear responsibilities.
Also it should be good to have a technical description of such critical systems approved trough formal testing and tools to do such tasks.  Again I'll strongly recommend  Nancy Leveson writings.

Wednesday, March 16, 2016

Interpol and digital forensic training

Interpol is working on  cybercrime training proposal, as I understand it is still in early stage, but shows huge possibility of setting standards in this wild zone, Probably we will get something like ISO/OSI networking model for law enforcement cybercrime training, if we a lucky a gold standard.

Looks like there will be set of  tracks, based on current practice compilation, Digital Forensics is separated from other roles, especially  from investigation and intelligence / analytic so it means full understanding of digital forensics role what is a bit obscured in many law enforcement environments. Same is for judiciary and management, also clearly separated from other roles, but having same requests to knowledge as other roles. .

We will compare our training curriculum with the ideas from Interpol, tu see what we are missing and how to improve. 

Friday, March 11, 2016

It is hard to write something to blog

It is hard to to write something for blog, plenty of things happen but I can't see any usefulness writing about it. I've finished one training of Advanced Forensic and found EnCase servlets for latest mac OS faulty, fortunately new release of Encase gets updated servlets, Nice to see EnCase is still trying to survive but it all looks supernatural. Almost all people I know left company in last few months, re-branding product, name changes, communication channels and support links almost all is changed or gone.
Even worse there was some arguments among shareholders and management mentioned recently on LinkeInd, all this are not good signs,  Looks like trouble with version v7, well known, but an publicly unspoken thing is taking its toll. Even  after so many years v7 is still dobious among many users.
Other big vendors had its own troubles too,  Access data had some reorganisation and splinting into different companies lately, same signs of kind of trouble, but at least FTK is still working in acceptable manner.
I suppose this is final signs of problems which this market has, even better to say whole IT security and law enforcement oriented digital forensics vendors.
All this leaves bad taste and big frustration.
I hope EnCase as product can survive, since it has some great things in it, but also a lot of misconceptions, Enterprise version with its fine tunned acces control system is good, perfect thing which is strangely seldom seen in usage. Ability to develop code for your own extensions is extremly useful but again seldom used in community. Looking from distant Europe even further from broke and technically undeveloped Croatia whole market looks in turmoil with plenty of snake oil around.
It all looks like a giant flop waiting to happen.
Verizon put some nice case studies online worth of reading, "Data breach digest" nice reading,  I'll prepare some of cases as material for my students.