The Inquirer-Home

Microsoft's not bothered about COFEE leak

It's illegal to download it illegally
Wed Nov 11 2009, 16:32

MICROSOFT HAS confirmed that its digital forensics software, called COFEE, has been leaked onto the web but says it's not concerned that cyber criminals can ‘build around' the program.

The Vole has also said that it is illegal for people to download the software, spotted on a bit-torrent site.

Computer Online Forensic Evidence Extractor (COFEE) is a forensics tool that fits on a USB flash drive for the police to use in PC forensics.

The programme was spotted on a file-sharing site, available for all to download on Monday. At the time it was reported that security experts were concerned that cyber criminals could analyse COFEE and write code that would identify and intercept it, securely wiping incriminating data from their hard drives. But Microsoft now says it's not worried.

In a statement from Vole's Internet Safety Enforcement Team, senior attorney Richard Boscovich said, "We do not anticipate the possible availability of COFEE for cybercriminals to download and find ways to ‘build around' to be a significant concern."

He Boscovich also pointed out that Microsoft has only granted legal usage rights for COFEE technology for law enforcement purposes for which it was designed. So illegal downloaders would be using it, err, illegally. Words guaranteed to strike fear into the hearts of any cyber criminals using the software.

He continued, "[COFEE is a] collection of digital forensic tools already commonly used around the world. Its value for law enforcement is not in secret functionality unknown to cyber criminals, its value is in the way COFEE brings those tools together in a simple and customisable format for law enforcement use in the field."

COFEE is free to police forces around the world and helps the plod ferret out details about crimes such as identity theft, online fraud, child pornography and illegal filesharing.

It can be an effective investigative tool, apparently, if the coppers can get access to wrong-doers' systems before the criminals can wipe the information. µ

Share this:

Comments
Porky Pies or just a Cloudy Dust Up Storm in a See Cup

Err, ... Microsoft's not bothered about COFEE leak/break?

http://cryptome.org/0001/ms-cofee.htm

posted by : amanfromMars, 14 November 2009 Complain about this comment
Mocha do about nothing

There's a stain on my notebook
Where your COFEE cup was
A stain on my notebook
Says nothing of me
Not as a citizen of
The Republic of Tea

posted by : Bill Shakesbad, 12 November 2009 Complain about this comment
Why use Microcrap

Funny just a couple a days ago theres a release of a Linux based Forensic Software , http://distrowatch.com/table.php?distribution=deft .
SO why even use Winders if you don't have to ?

posted by : 1linuxfreak, 12 November 2009 Complain about this comment
Treason and Sponsorship of Terrorism

Intentional and advertent sponsorship of terrorism. Explicit providing of resources and exploits in support of organized crime and terrorism. Sponsorship of international crimes and espionage including sponsorship of terrorism. Direct and intentional provisioning of resources and support for organized crime and terrorist use.

THIS IS YOUR INTERPOL, YOUR DMCA. [sing] It's fun to sponsor terrorism with the D. M. C. A., Organized crime, terrorists can rhyme! D. M. C. A. Eh, terrorists?

posted by : lee, 12 November 2009 Complain about this comment
Incompatible

Are there any compatibility issues between COFFEE and properly configured bit locker? Vole needs to be really up front about it...

posted by : Core Dude, 11 November 2009 Complain about this comment
heh

There's already an AutoHotkey script out there that automatically deletes files and shuts down the computer if an unknown thumb drive is inserted.

posted by : Fart Vader, 11 November 2009 Complain about this comment
no worries

It was never used. The truth is the law enforcement didn't have a clue on how to use it and no one in the nsa even knew what a usb slot was let alone how to make a machine boot from one. They are all still trying to feed cards into the floppy drive.

posted by : mogwai, 11 November 2009 Complain about this comment
What?!

Did I just read all of that right? Did MS just say that they aren't worried about criminals downloading a copy of the Forensics program and using it illegally because its illegal to do so?! I think my wife put something in my coffee or something, I must not be awake yet, carry on.

posted by : DarkElfa, 11 November 2009 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Authorities in several countries raided Megaupload recently, shut down all of its services, seized hundreds of servers and arrested several of its executives on criminal charges.

Do you think the move was justified?