Ride the Lightning

Cybersecurity and Future of Law Practice Blog
by Sharon D. Nelson Esq., President of Sensei Enterprises, Inc.

COFEE CAUSING JITTERS

May 5, 2008

Yes, I spelled it right! In case you haven’t heard, the computer forensics world has been buzzing about a free tool provided by Microsoft to members of the law enforcement community. COFEE (Computer Online Forensic Evidence Extractor) is basically a thumb drive which contains 150 commands and can be further customized. Distribution began last June and more than 2000 officers in 15 countries are now utilizing COFEE. Essentially, COFEE allows investigators to scan for evidence, decrypt passwords, analyze Internet activity, etc. on a “live” computer in a “read-only” mode and extract evidence for use in court.

Why the jitters? Privacy advocates worry that COFEE will find its way outside of law enforcement and be used as a snooping device. And of course, there is concern that law enforcement might misuse the device. A private equivalent of COFEE is sure to come, if indeed it doesn’t currently exist.

For all the hype, COFEE really doesn’t contain any new tools – the key to its notoriety is simply that it is a portable device that can be used onsite, often making it unnecessary to seize computers, and very quickly allowing the extraction of evidence.

Further information may be found at http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html

E-mail:       Phone: 703-359-0700