Feeds

Will your mobile squeal to the police?

Digital forensics turns smartphones into supergrasses

Top 5 reasons to deploy VMware with Tegile

Analysis It's been 20 years since a UK drug dealer discovered too late the folly of keeping all his records on a Psion Organiser, helpfully providing police with names and addresses of customers and suppliers, as well as sales records*. Today's criminals aren't generally that stupid, but regardless, today's phones are perfectly capable of accumulating evidence without their help.

Mobile phone forensics is a decent-sized industry these days, with companies queuing up to help police extract every iota of information from handsets of every shape and size. There's no industry body as yet, so anyone can call themselves a mobile phone forensics specialist. But police forces tend to have preferred suppliers, and look to each other for recommendations.

Not that the police can just grab every phone they see for analysis - if you're stopped and searched they're only allowed to check for weapons (some supermodels notwithstanding, a mobile phone is not classed as a weapon). Even if you're suspected of a crime the police need to believe there might be pertinent evidence on the handset, or pick it up as a legal seizure during a raid.

Your new cellmate

In the UK it's also standard practice to scoop up mobiles belonging to the recently deceased, to see what they were doing prior to being dead.

Once legally seized the police can do what they like with a phone, though they'll take care not to compromise the evidence. The industry has produced a set of guidelines for police forces working with digital evidence (pdf), with the section on mobile phones having been recently updated (page 45).

The overriding concern is not to alter the data in any way, as that might compromise its integrity – providing a get-out clause for defence lawyers. For personal computers that means taking an image of the disk, leaving the original untouched; on mobile phones it's not quite that easy. Just getting the data off the phone might require the installation of an application, which could destroy important evidence.

Flash memory, of the type used in most smartphones, is not normally erased as such. Deleted data is marked as deleted, then overwritten when the space is needed - but there is a limit to how often Flash can be written, so the OS will avoid overwriting things for as long as possible (a process called wear-levelling) to ensure the whole memory is used.

For example: an iPhone may have 16GB of memory, but most users will only fill half that, and once full the data generally remains pretty static. So old information can hang around for years, and be extracted using the right forensic tools.

Jonathan Zdziarski, author of O'Reilly's iPhone Open Application Development, recently demonstrated how to do that using open source tools, by jail-breaking the handset. In fact Jonathan has demonstrated that clearing data off the iPhone is just about impossible, and he's been busy lifting personal data from refurbished iPhones using his hack.

Forensic software specialists Hex-Dump has a package called Pandora's Box which can lift data from a wide range of handsets without installing anything (and thus risking overwriting evidence), with support for the iPhone coming any day now.

Even the most basic handset has an address book and a list of recently dialled numbers, which can give investigators an insight into the life of the user. SMS messages, and address-book entries, stored on the SIM are not generally deleted – just marked as available space, so may be retrieved even when the user thinks they've gone.

*He also bought himself a £100,000 house, paid for in cash, while still signing on, so he wasn't just technically illiterate.

Intelligent flash storage arrays

More from The Register

next story
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
Broadband sellers in the UK are UP TO no good, says Which?
Speedy network claims only apply to 10% of customers
Virgin Media struck dumb by NATIONWIDE packet loss balls-up
Turning it off and on again fixes glitch 12 HOURS LATER
Fujitsu CTO: We'll be 3D-printing tech execs in 15 years
Fleshy techie disses network neutrality, helmet-less motorcyclists
Facebook, working on Facebook at Work, works on Facebook. At Work
You don't want your cat or drunk pics at the office
Soz, web devs: Google snatches its Wallet off the table
Killing off web service in 3 months... but app-happy bonkers are fine
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.