Ethical Hacking Training at InfoSec Institute

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Computer Forensics Computer-Forensics
[Top] [All Lists]

Re: Tools accepted by the courts

Subject: Re: Tools accepted by the courts
Date: Tue, 28 Jun 2005 14:51:46 -1000
Evidence Technology wrote:
I also agree wholeheartedly with Tobin, in that "our job is to provide
objective, accurate, scientifically sound testimony of often complex
material in a manner that can be reasonably understood by a jury, using
tools techniques and processes that we understand and can defend if
necessary." But in my experience some lawyers and even corporate clients do
put stock in certs. And I also believe we'll see judges attaching more and
more credibility to valid certs, as well.

Jerry,

Certifications do nothing to put a stop to the common practice of spreading misinformation and misunderstanding about technology, the Internet, information security, digital communications and software.

What we really need is public disclosure of the mistakes made by specific computer forensic examiners.

How many times have you seen terrible analysis and completely wrong, misleading technical testimony or expert report writing? In my experience it happens in nearly every case.

I attempted to post a message in this discussion about specific failures of well-known persons and the moderator rejected it.

Go forth and obtain whatever certifications you wish, but do not forget that your mistakes tell more about what you do not understand than any certification you ever acquire, and there are people such as myself who will not stop calling attention to the mistakes that are being made and the harm that those mistakes cause.

Everyone understands that nobody is perfect, that people make honest mistakes. What nobody understands is that people who claim to have technical knowledge and who have credentials to back up that claim often times do not understand enough about the hidden details of the operation of technology, despite their competency as skilled technical persons.

Too many certified forensic examiners and too many technical expert witnesses or law enforcement professionals learn how to operate a computer as an end user of forensic tools but fail to understand the basics of information security.

Complete mastery of the field of information security must form the foundation of computer forensics, or those who practice it are deaf, dumb, and blind.

Worst of all, these certified examiners think they are doing valuable work, when what in fact they are doing is spreading lies and unsupportable beliefs about their own economic worth -- being paid very well for wearing a 'forensic' seal of approval appears to cause people to believe that their 'expertise' is worth money.

What about the pursuit of truth? What about correct technical testimony and proper explanations to judges, juries, prosecutors, and law enforcement as to what is really going on in the digital world? Everyone seems to care more about getting certified and getting paid than about putting a stop to widespread abuse of other people's ignorance and profiteering through presumptions of competency that ignore solid evidence to the contrary.

I don't want a judge seeing a certification and giving it weight. I want a judge seeing through the technical flaws of supposed-experts who come before them offering electronic 'proof' and 'digital evidence' from computer hard drives where neither can truthfully be found.

Woefully,

Jason Coombs
jasonc@science.org

<Prev in Thread] Current Thread [Next in Thread>