Wednesday, November 10, 2010

Interview with Stephen Mason - Barrister, author and publisher

Forensic Focus: Stephen, can you tell us something about your background?

Stephen Mason
Stephen Mason

Stephen Mason: After leaving school in 1972 and spending six months at a bank in London, I joined the army (1973-1982). I served in what used to be known as the Royal Army Ordnance Corps as an Ammunition Technician. This work involved the inspection, repair and disposal of military ammunition, and included what is colloquially known as bomb disposal (this includes military bombs found from previous wars (known as explosive ordnance disposal ‘EOD’) and improvised explosive devices ‘IED’, commonly known as terrorist bombs).

I left the army to take a degree in 1982. My first degree is in history and educational philosophy, and I then took further qualifications to become a Barrister. I was called to the Bar in 1988.


Forensic Focus: How did you become involved in writing on electronic signatures?

Stephen Mason: In the autumn of 2002 I realised that few people knew anything about electronic signatures, so I sent in a book proposal to LexisNexis. It was duly accepted, and I wrote the text in the spring and summer of 2003. I had already written about the topic, and wanted to write a book that was useful to lawyers, ordinary users and technical people to illustrate the different types of electronic signatures that the law recognizes. This book covers over 100 jurisdictions with case law, and it is now in the second edition (Electronic Signatures in Law (2nd edn, Tottle Bloomsbury Professional Publishing, 2007)), and I am presently up-dating the text for a third edition in 2011.

The point is, electronic signatures cover a wide range of law, including: Employment law; family proceedings; divorce proceedings; formation of contracts; insurance; ewills; public administration; judicial use; property transactions; local government; planning applications; criminal proceedings and corporations. The list is endless.


Forensic Focus: You have been responsible for two books on electronic evidence, both of which are a first, and both are substantial texts. What made you do it?

Stephen Mason: Once the book on electronic signatures was published, my publisher wrote to ask me if there was sufficient material for a book on electronic evidence and electronic disclosure. I was convinced there was, although there was a gap between the initial e-mail (2004) and the first book being published (2007). Now in its second edition (Electronic Evidence (2nd edn, LexisNexis Butterworths, 2010)), I intend it to be a useful guide to lawyers and digital evidence specialists covering, as it does, 11 jurisdictions: Australia, Canada, England & Wales, Hong Kong, India, Ireland, New Zealand, Scotland, Singapore, South Africa and the United States of America.

The second book came about as a result of my work on the first book. I realised that the issue is global in nature, which is why I put together an additional 35 jurisdictions and edited the second book: International Electronic Evidence (British Institute of International and Comparative Law, 2008), covering: Argentina, Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Egypt, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Japan, Latvia, Lithuania, Luxembourg, Malta, Mexico, Netherlands, Norway, Poland, Romania, Russia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Thailand and Turkey.


Forensic Focus: You then went on to found and publish a new journal, the Digital Evidence and Electronic Signature Law Review. Why?

Stephen Mason: Once I finished my book on electronic signatures, I realised that most legal journals would not really focus on the practical legal issues and case law that I expected to occur in these fields as the century progressed. This is why I began the journal. It has gone through three name changes, partly because of my attempt to get the title right, partly to ensure people understand what the journal covers. I include articles, legal developments and case reports from judges, lawyers, academics and digital evidence specialists. I aim to cover the industry in relation to digital evidence and electronic signatures from across the world. I also include reports on technical advances and book reviews. Additionally, I publish case reports and translations into English of cases relating to electronic evidence and electronic signatures from across the world...

Read more at http://www.forensicfocus.com/stephen-mason-interview-051110

Monday, November 01, 2010

UK legal professionals - interested in writing for Forensic Focus?

Forensic Focus is looking for someone within the UK legal profession who might be interested in joining the current group of Forensic Focus columnists by writing a monthly column on computer forensics/computer crime issues.

This is not a paid position but would be useful for anyone wishing to raise their profile within the computer forensics community and present the perspective of UK legal professionals involved in this field. If you're interested, or would like to recommend someone who might be, please contact admin@forensicfocus.com

Thursday, October 28, 2010

A big thank you from David Benford!


I am really pleased to say that I completed the Mizuno Amsterdam Half Marathon on Sunday 17th October 2010 in aid of the Cystinosis Foundation UK.

Please may I thank everyone on Forensic Focus that sponsored and supported me. My family and I are really touched by everyone's generosity and we are going to raise close to 3000 Pounds Sterling from the event. Every penny raised will go to researching improvements to drugs and ultimately a cure.

I am a trustee of the foundation and my 9 year old daughter has cystinosis, which is a chronic genetic metabolic disease. It is very rare with only around 2000 patients in the Western world. The race was particularly challenging for me as exactly 6 weeks prior to the race I competed in the Lichfield 10k event to warm up for the main run. It evolved that in the 10k run I managed to tear the meniscus in my left knee. This meant that I was unable to train or exercise further for the marathon and had to take a chance and just go for it on the day.

I flew to Amsterdam on the 16th and stayed near to the Olympic Stadium where the event was due to finish. On the day all went OK. Things were going well for me up until 15km, when my legs didn't want to work as this point was further than I had ever run before. I pushed on though and every step was very painful but I reached the stadium, where after half a lap I crossed the finishing line with massive relief and a sense of great achievement!

The Dutch crowds and bands along the route were an enormous help and very motivating. I finished in 2 hours and 31 minutes which I was quite happy with. The run has really helped raise awareness of cystinosis and people have been so generous.

For more information please go to www.justgiving.com/david-benford or www.cystinosis.org.uk

Thank you all once again.

David Benford
Managing Director
Blackstage Forensics Limited
T: 01283 762559
www.blackstage-forensics.co.uk

Thursday, October 21, 2010

Digital Forensics and ‘self-tracking’

by Forensic Focus columnist, Dr Chris Hargreaves

Chris Hargreaves
About the Author

Dr Chris Hargreaves is a lecturer at the Centre for Forensic Computing at Cranfield University in Shrivenham, UK.

This month's article is based very loosely around a recent 5-minute talk from Gary Wolf (link here) which explores the concept of ‘self-tracking’ (the trend for people to record aspects of their life) and how this can now be performed to a much greater extent than was previously possible due to changes in technology. The talk discusses the monitoring of heart rates, sleep patterns, consumption of caffeine, food and alcohol etc. While many of these could be recorded simply with a pen and paper, the talk also introduces a variety of new digital devices that automate the collection, recording and in some cases transmission of this ‘self-tracking’ data. This article ponders the implications of such devices for digital forensics.

Several technologies are mentioned in the referenced TED talk, including general purpose technologies such as Twitter and iPhones that can be used for ‘self-tracking’ of diet or exercise, but it also discusses dedicated devices. This includes technologies such as such as Nike+ (tracking distances and times), Fitbit (for fitness and sleep monitoring), Polar WearLink+ (heart rate) and Zeo Sleep Tracker (sleep monitoring). Outside of those covered in the talk, additional technologies that are already commonly in use that record information about our lives include games consoles such as the Nintendo Wii (amount of time playing a particular game or using other features such as the web browser) and GPS devices (locations visited). There are also other upcoming technologies, for example those which capture and record the total electrical power consumption of your home.

It does not require too much imagination to foresee how data from such devices could be potentially useful (particularly as evidence related to alibis, for example). Really, any additional source of potential digital evidence should be welcomed, and this is particularly true for devices that are difficult to tamper with (there is not yet an evidence eliminator for electricity usage monitors as far as I am aware). There is also an additional benefit from using digital evidence in this way – rather than relying on digital evidence from a single PC or device, multiple, independent devices can be examined for evidence that supports (or refutes) the current working hypothesis of what events occurred. More data sources can only increase the accuracy of any inferences drawn from the evidence...

Read more at http://www.forensicfocus.com/chris-hargreaves

Wednesday, October 20, 2010

It’s not always what you find...

by Forensic Focus columnist, Sam Raincock

Sam Raincock from SRC is an IT and telecommunications expert witness specialising in the evaluation of digital evidence. She also provides training and IT security consultancy.
In digital forensics we are often asked to determine the presence of evidence. However, what happens when we do not find anything? How do we prove something wasn’t there?

Proving something is present is generally a trivial problem – you find it, it’s there. Of course the complex part is explaining how it came to reside on a digital device and the circumstances surrounding it….that’s what the field of digital forensics is all about. However, proving something isn’t there and/or was never there are also questions we are asked to comment on. Take the following for example:

· Examine this laptop and establish if it has accessed the website http://www.forensicfocus.com.

· Examine this mobile telephone and determine if it sent a text message with the content “Forensic Focus”.

Let’s look at the first example. In the event there is “no evidence of access to http://www.forensicfocus.com found”, what remains is proving (or commenting on) a negative. However, just because you do not find any evidence of connections to the site, does this imply no connections ever occurred?

There are three main possibilities to consider. Firstly, the techniques used in your examination did not facilitate finding the evidence even though it is present. For example, if we simplistically relate this to an examination where only the live Internet history is examined initially, it is possible that a subsequent examination could determine some deleted Internet history and further evidence may be established.

Secondly, you did find the evidence but were unable to determine how to interpret it so you didn’t establish its meaning. For example, you found a partial registry file in deleted space but did not have the knowledge to interpret it and extract the evidence.

Thirdly, there is no evidence on the device of any connections occurring to http://www.forensicfocus.com. So no connection ever occurred?

Even given the last situation, with a computer, often the absence of any evidence is not evidence that it was never present. This is due to the fact that on a computer, data can be deleted and overwritten. Hence, it is possible that an event occurred but evidence of it is no longer available...

Read more at http://www.forensicfocus.com/sam-raincock

Friday, October 15, 2010

How to seduce your (potential) computer forensics employer

by Forensic Focus columnist, David Sullivan

David Sullivan
About the Author

David Sullivan has over 15 years recruitment experience and has spent the last 6 years running his own computer forensics recruitment consultancy, Appointments-UK

We all over-complicate things and this is certainly true when seeking a new job. Essentially, to be successful at a Computer Forensics interview you just need to demonstrate two things:

1. You have the technical skills needed to perform to a high standard;

2. You are a likeable person. This is described in numerous ways such as interpersonal skills, company fit etc, etc, but when it comes down to it I would argue strongly that essentially it comes down to whether the interviewer likes you. This is especially important in CF where you are likely to be working long hours, maybe in a hostile environment and often in stressful situations where personality clashes can cause real problems.

In this article we are going to focus on the second point - making sure we are as likeable as possible as, after all, if two people have very similar technical skills guess who gets the job? Think about it like this - when you have contacted a company or a recruiter, or when you have sat in an interview, how much have you thought about helping the potential employer to actually like you?


Who is David Herron?

This whole process starts way before you get to the interview room which I will demonstrate with the example of a CV I received a couple of months ago with the following cover note:

‘I have just finish my degree in BSc (Hons) Forensic Computing with Third Class Honours awarded and I am seeking employment. I heard of your agency when one of your reps who I think was called David Herron or David Sullivan came into our university 2 years ago to give a talk on your agency.’

Who is David Herron?!! I thought he was a line-backer at Kansas – I am David Sullivan. Agency?! We aren’t an agency, we are a Professional Search firm! Although my initial reaction was to laugh out loud that somebody had taken so little care in their cover note my next thought was that I was not going to make any effort at all to help this person. Maybe I just have issues about needing to be loved due to being ignored by my parents when I was five, but I bet that you too can remember a time when you bristled due to somebody having made no effort to know anything about you before they made contact.

On the other hand I do occasionally (very occasionally I should add) receive an email from a prospective jobseeker saying how much they have enjoyed my articles. OK, so having read my articles we both know that is unlikely to be strictly true but it doesn’t really matter – straight away I am keen to help this person purely as they have made me feel good about myself. Even if I can’t help them I am happy to spare the time to talk about the market and help them improve their CV – it is just human nature...

Read more at http://www.forensicfocus.com/david-sullivan