You know how in cop shows they seize deviants' computers and bring them back to the lab for some good ol' latex gloved analysis to prove how obviously guilty or sick the suspect is? That's old hat. Microsoft's latest treat for law enforcement is COFEE (Computer Online Forensic Evidence Extractor), a USB drive that'll cut through whatever flimsy security miscreants have slapped on their computer in a flash, and then automatically analyze the dirty bits the cops need to bust their ass, from internet activity to stored data, no pwnage skillz or trips to the lab needed. Microsoft's giving the wonder tube to lawmen for free, and 2,000 officers in 15 countries are already using it. But will it work on Macs? [Seattle Times, Thanks M]
Microsoft COFEE Won't Perk You Up, But It Will Instamagically Hack Your Computer
8:30 PM on Tue Apr 29 2008
By matt buchanan
14,197 views
98 comments







Comments
*Goes and buys a mac* . .
obviously this is a mac fanboy conspiracy.
Am I going to be the only one that is left feeling less secure by this "instamagic" wonder? That said........I want one. (or 2)
When will this hit torrents?
WTH? Did MS leave themselves backdoors? Isn't that how security holes are created... Let alone, all it takes is one bad cop to spread this to the masses of the black market...
The mac version is called maclockpick. It is also used by law enforcement
Oh Microsoft, why do you constantly work so hard to make me hate you so?
I wonder whether it works by exploiting windows, or by actually going through the security. Exploiting windows has a long and storied history, but if it works that way, it wouldn't be able to crack particularily tough software. Either way, that is probably the coolest program so far put on a flash drive.
@matto:
Definitely. I can see it now. People will think that Macs are impregnable, and thus buy more Macs, increasing the market share.
@mecoolai: *Goes and installs ubuntu again*. . .
Comment on Microsoft COFEE Won't Perk You Up, But It Will Instamagically Hack Your Computer yeah, glad I have Linux, but I'm going to encrypt my /home partition because of this
*Goes and doesn't give a shit, but is still slightly amused at yet another attempt to make Macs look fantastic...ly gay*
@shenanigans61: *Goes and says: Hey I never owned a mac and was just joking on the myth that macs are un-hackable*
Kinda scary, but if the computer is in the hands of a capable nerd its just a matter of time before they get through all the security stuff. This just expedited the process I guess.
Does it work on encrypted stuff though. What if you have "filevault" enabled or whatever the PC equivalent is. I thought that stuff was impenetrable.
If you have, say, an 8 disk raid-5 array that contains your data and you overwrite two of the drives with random data, is it possible to reconstruct anything from the array?
I'm gonna go out on a limb and say this is not actually about OS's or manufacturers.
Nothing in this post is inherently about Macs/PCs, Windows/Leopard being better or worse. It's just about about a particular tech company deciding to help the police access information.
So, when you get stopped at the airport and have to have your laptop out and inspected. Bam! They'll stick this doohickey in.
@mecoolai: Well, now I'm intrigued...
MacLockPickâ„¢ is a valuable tool for law enforcement professionals to perform live forensics on Mac OS X systems. The solution is based on a USB Flash drive that can be inserted into a suspect's Mac OS X computer that is running (or sleeping). Once the software is run it will extract data from the Apple Keychain and system settings in order to provide the examiner fast access to the suspect's critical information with as little interaction or trace as possible.
So: Does this circumvent FileVault?
shit!!!! my hd porn!!! no!!!!!!!!!
Does it break Bitlocker?
@92BuickLeSabre: You obviously haven't been here long. Why would these posts differ in anyway from all others in "similar" news?
"News at 11. Cops now have a flash drive capable of gaining access to any PC.."
OMG Macs are better! I don't get malware or viruses and all my stuff just works together flawlessly and sunlight shines out of my arse.
"News at 12. Microsoft buys Yahoo..."
OMG Windows is such a better gaming machine than Mac and so much cheaper too, you guys are sheep.
"News at 6. Schools to switch to Linux."
OMG Linux is teh 7337, I can compile stuff by myself and code drivers for my dot matrix printer.
@aznplayer213:
Take heart, no one will want your "HD" porn.
Just because it's in HD. :| .
@madog: Needed said. :)
On that note, Buick was just inducted into the Poster Hall of Fame not long ago :P
hmmm... That why I have Spring Cleaning for my mac. You can over write free space 1, 7, or 35 times to destroy any forensic evidence in the free space but it cant do anything for anything on you hdd already not deleted.
@--Tito--: *Missed your point, and chuckles...late* :( :P
@shenanigans61: *Goes and gets you a mac to get you away from this drama from MS*
@shenanigans61: I saw his info, but my comment wouldn't have been the same without the chastising-ness.
Yeah, I can make up words, wanna fight about it?
@madog: obviously you failed to see the star....
Gotcha back Mr. Buick
@madog: "@92BuickLeSabre: You obviously haven't been here long."
No, YOU haven't been here long my friend, or you would have noticed that 92Buick is probably responsible for 1/10 of all posts... now that Nutbastard appears to be actually _working_ at work, anyway....
OHHH and what about TrueCrypt
OMGawds thyll fnd delishus lolicon! O teh noes.
E-mail myself all the good porn to my g-mail account and waste that space?
"is it possible to reconstruct anything from the array?"
Do you work for the NSA?
Oh the ABUSE, the ABUSE of this little object. Where the hell are those imginary privacy laws. I guess they just couldn't get anymore kicks from cavity searches anymore, so they have to cluster our electonic gadets. I wonder if they'll bann this in the DC area, cause this device is literally "the double edged sword". People won't have to steal VA or gov't laptops anymore. All they have to do is stick this in the USB slot, push ENter, twiddle thumbs, and walk away with the info when it's done.
It's not that I don't like the idea of the cops getting the sicko's or the bad guys, it just that this encompasses everybody. This is like RIAA and telecommunication taps supersized. I work with secure info all day, and this device literally makes me feel sick imagining it in the wrong hands
I know that this has been out for awhile but anybody wonder how fast and how much quanity this jump drive-ish device is going to sell on e-bay after people have read this gizmodo blog.
Probably its already counter-hacked
I pwn Macs and Windows with Linux. If they come out with a linux breaker thumbdrive, then I will shit myself.
Does it make your computer blurt out little witty quips right before the opening credits?
Did anyone else see the Weebl and Bob CSI: Pie-ami episode? Pure genius.
[www.weebls-stuff.com]
"Are you paying The Who to follow you around again? The mayor said to stop wasting tax payers money!"
@matt buchanan: "But will it run Crysis?"
FIXT.
That's why you always keep your sensitive materials on an external usb drive with self-destruct capability...
oh Ubuntu, you are my friend. Not that I have anything to hide.
Comment on Microsoft COFEE Won't Perk You Up, But It Will Instamagically Hack Your Computer I work for federal law enforcement... Sorry to say, it works on most file tables including macs
Why don't you have a seat over here.
I will destroy all the USB ports on my laptop >< haha
@Mandatory_Field:
yeah man works been intense lately, im building stuff right now, so not a lot of time spent at the desk.
Thank you, Ubuntu.
Now i understand why is that law about checking laptop on airports. This is going to do it...
If someone has one of these for their personal, couldn't they make some sort of protection?
evidence eliminator, 1 hotkey and bam!!!
nothin left
besides, at the airport your lappy would have to be running for them to exploit it
"sensitive" stuff should be on a thumb drive anyway, easy to break and toss
it isn't like people use macs for anything other than trying to look cool - so why bother?...
@Cae64: Forensics software is nothing new, and has been around for quite a while. Some will already let you load on a USB drive, and are available for the downloading. There is already much more forensics and cracker software in DC than you can imagine....
@nutbastard: Condolences: Work sucks, unless you manage to get into that groove/zone where it's not work....
Evidence Eliminator for the laptop, clean data and wipe all slack space nightly.. Any sensitive data on an external drive using multiple layers of TrueCrypt Encryption to encapsulate the files that are individually encrypted using PGP and use random filenames... Make sure you don't use the same or similiar passwords for any of the encryptions.