Go back

Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible.

74m 38s

Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible.

Heather and Alex explore the contentious debate around chat encryption on platforms like Meta, discussing its impact on child safety versus user privacy. They present both perspectives, drawing on ethical dilemmas like the "ticking time bomb" scenario to illustrate the complexity of balancing privacy and public safety. The discussion emphasizes that even with encryption, forensic examiners must rely on proactive techniques—such as infiltrating groups or analyzing unencrypted data—to identify perpetrators. A major highlight is the growing potential of memory forensics on Android devices, where tools like XRY’s RAM Decoder can extract 12GB+ of data, including keystrokes, app activity, and location logs—some dating back years. This data can reveal critical evidence, like a user’s movements or password reuse. The episode also stresses the importance of foundational technical knowledge, such as encoding and timestamps, and advocates for peer-reviewed validation of forensic tools. Ultimately, the conversation calls for stronger technical safeguards beyond user vigilance, especially in combating online exploitation, and underscores the need for examiners to stay ahead of evolving technologies through continuous learning, collaboration, and rigorous validation.

Transcription

12596 Words, 65868 Characters

English
(upbeat music) - Good day, today is Thursday, December 14th, 2023. Welcome to the Digital Forensics Now Podcast. My name is Alexis Briggs Brignoni, and I'm a company, but I'm like, her host, Nicole for Nadi folks deliverer, the faster than the gingerbread man examiner, the Rudolph of our Digital Forensics LAY, leading the way, the Mary Heather Charpentier. The music is hired up by Shane Ivers, and it can be found at sillermansound.com. Hello, hello, hello, Heather, what's going on? I know you love this introduction. - Hello, thank you for the wonderful introduction. - Very good, I think it might be your best one yet. - Very seasonal, as people can, the folks that are watching can see. - Oh my gosh, it's definitely the best one yet. (laughing) - Well, I appreciate that you think so. (laughing) Thank you everybody for being here with us, the folks that are coming in live, we always appreciate you coming in here, see some comments coming in, and as the folks that are watching can see, I have a really Christmasy shirt, I have a Hello Kitty Christmasy dress in the topic for the day, and we have a nice little Christmas theme intro and message behind us, it's great. - Yes, thank you for the Christmas introduction. We've got a little comment here, you're too funny. I don't know, Geraldine, I don't know. - I was crafting that intro as you know, and I was laughing to myself about it, so I really, I really enjoyed it. Delivering was even better. (laughing) - Thank you. - Yeah, I wanna say hello to Andrea, good friend, and to Johan, my man, I'm happy that you're all here, so. - Yes, thank you for joining. - All right, so what's going on Heather? What happened between last time we met and now? - Uh, nothing been busy doing work and watching podcasts. I see it's your second one of the day. - Oh yeah, that's right, that's right. - I was lucky enough to be with Amy Moles from Art Point Forensics talking about, you know, Defermas, the 12 days of Defermas, it was great. - I will be joining her next week for one of the Defermas podcasts, so looking forward to that. - Yeah, no, me too, I wanted to drag you on mine, but you're like, no, no, no, you can have yours, and I'll have mine though. - Unless you have your own. - Plus we'll have one together. - We're together enough here, right? (laughing) - I'm tired of being Briggs, please give me some space. - Who knows what kind of introduction I would have gotten? (laughing) - That's right. So, well, as you know, I've been busy. I was in Panama last week, so I wanna share with folks a little bit of what I was doing over there. And it's always a good time to go out and interact with folks from the community, from around the world. So, I was lucky enough to be at an event, if I could open the picture here, and an event for a regional Deuter Forensics event in Panama, so let me show you here. And now I cannot show you, great Alex, you're a genius. Yeah, well, I guess I'll show you later, but (laughing) yeah, so we were there folks from Costa Rica, many kind of republic from Panama, there we were, I found it at last, so that's the banner of the event, it's a, well, before, let me finish my sentence. So, Panama, Costa Rica, Dominican Republic, and Peru, and obviously the United States. And we're doing a regional workshop on Deuter Forensics, and medium to advanced level Forensics, so that was a ton of fun. And I was teaching there, so it was pretty good. - Very nice. - Yeah, there's a lot. - What else did you get to do while you were there, anything exciting? - I ate a lot. - I ate a lot. - I always do that. - I think I'm pretty sure I may have seen some pictures of that. - Oh my goodness, oh, here we go. - Maybe. (laughing) - I think you did, right? - Yes, I think it's, the folks are, the folks aren't, I can't see, I'll tell you what it is. It's that dessert that they had there in Panama. I said it was traditional, people probably just dessert. I know I'm gonna bungled the name. I wanna say it's panache, but I'm not really sure I'm pronouncing it right. But it's delicious. It's just delicious. It's like all sorts of like two different types of milk and like a cake on the bottom. And some, it's just delicious. It's a mixture of different type of cultural things. For those people, I don't know, Panama is a place that a lot of different cultures mix. I would say the whole world mixes there because you know, Panama Canal, but a great monument to human ingenuity and panamanian skill, right? So it was a great time being there with the brothers and sisters from Panama. So it was really, really good. - Since I don't do the lovely introductions for you, I'll call you out on your eating habits while you're away then. (laughing) - Oh my goodness, yeah, they could be better but we're working on it. - It looked delicious. It was, it was, I ate it all in one sitting which is kind of like, oh my goodness. I need to walk that, walk it out. Well, that's, it was good. So there's a lot, I mean, this episode's gonna be packed with a whole bunch of interesting things. So I'm glad that everybody's here. Geraldine agrees with me that series, her electronics, K9, the text electronics, beautiful dog, that she agrees that eating is exciting. So yes, yes, it is exciting. (laughing) I've seen her in action. She does love to eat. (laughing) - If you keep it on your back, she will find it. (laughing) Right, so, well, like I was saying, there was a lot of good topics for today. Oh, we're gonna revisit a topic. It's a little bit contentious topic but I think it's worthwhile discussing again. It's the whole thing about chat encryption, right? And let me show you here what the deal is, what the news have been saying lately about this. So why is it back in the news? So it's back in the news because recently, in meta, which is the parent company for Facebook and some others, came out with encrypting chat. So the chats were not encrypted and now they're gonna be encrypted, right? And I'm showing here an image of the Guardian and newspaper, I think it's in the UK. And it says, well, meta's encryption plans be a devastating blow to child safety online, right? And for folks who are not familiar with this discussion, Heather, what's the deal with this whole child safety? How would that be impacted by this lack of encryption? Or actually, they're putting out of encryption. - So meta or Facebook, as most people know it, has been detecting and removing images and videos of children who've been sexually exploited for more than a decade. Last year in 2022, there were over 20 million reported incidents of children being sexually exploited and those images and videos being shared on the platform. And with encryption, it's likely that the number of reported incidents is going to greatly decrease. I guess my question related to this topic is why make this move knowing that there's so many images being shared yearly and why not continue to combat such horrendous problem? - Well, and that's a great point you make. That's why as we were discussing the topic, we named it chat encryption, instead of a moral responsibility or moral abdication, right? You're just an aspect of what is the right thing to do here? Right? And what I'm gonna do here is both of us, right? We're gonna opine on both sides of the argument. And I want people to understand that we're not representative of our workplaces and this discussion. We're not representatives, even of ourselves in this discussion. We just try to show different counterpoints so people can be aware of, and what is the threat of significance for us, right? Since we're tasked with getting some of that data, right? So I'm gonna take the devil's advocate role here in regards to assuming that the proposition is that, yeah, it's a moral responsibility to protect kids in general and online, right? So I'm gonna take it as the position of the devil's advocate for, no, it's a moral abdication, which sounds kind of intuitive, but bear with me. So like Heather will say, and this has been done for a long time, so why change it now, right? And let me show folks here where the market seems to be, right, based on this argument. So users are asking for encryption, for platforms to encrypt their stuff. It's a business requirement nowadays. And why is that? It's because people are all of a sudden smart about forensics or encryption, no, it's because I have a news article here saying that Rinsecurity cameras gave every employee full access for customer videos for years, right? So that seems problematic to say the least. - Yeah. - Not only that, so I have another one here. I have another news article here. I'm from the FTC where Twitter has to pay a $150 million penalty for breaking some promises. And their promises were that Twitter told users that they could control access to their tweets and their private messages, right? And that they could only be viewed by the recipients, which was not true, right? Folks and like users are requiring that because they don't trust platforms to keep their information private, right? Which leads to the point of what do we value, right? We value child protection for sure. And the question is, do we also value privacy? It's become this issue, and it's not a new issue, right? And this part of having discussed with you, Heather, but I don't know, it's a hard one. It's a really hard one. For example, it's the classical ticking time bomb, right? If you have a terrorist, right? And there's a bomb going to go off. And we need that information. Do we go on tour to the terrorist to get that information, right? Are we justified in torturing the person to get to the greater good of saving people's lives, right? And that's a tough one. And technology kind of puts us in that position constantly, like having to choose between two values, right? And I don't know what, I mean, what do you think? What would the argument be? - So I've always been on for this entire conversation. I've always been on the side the children first, right? So I understand the privacy concerns, but there needs to be something in place to monitor and find these images that are to being shared, or these people that are searching out children, or grooming children online, or sending messages that are in groups that are looking for children. And I stand by that. I think that finding these people is important, and I don't know, if it saves one child, if one child is saved from being abused by someone, I find it to be more important. I may not, that may not be the popular opinion. I know a lot of people value their privacy, and I value my privacy as well. I really do, but I just feel like if one child is saved by a little bit of, I don't want to say invasion of privacy, but a little bit of maybe oversight on these platforms, then I feel better about it. - Yeah, I mean, I guess the question is, what do we value, right? And not that we don't value kids, or not that we don't value privacy, but we can, and the argument goes from the other side as well, we can extend that to other crime problems, right? Why don't we have some sort of monitoring at home, at home? You'll be like, well, it's my property, and that's Facebook's property, so they have responsibility. Well, what if you live in an apartment? It's not your apartment, you're just renting it. Well, maybe we should have some surveillance to make sure that you're not abusing kids, right? And sure, it becomes a slippery slope. A slippery slope could be an argument or a fallacy, I guess, depending on which side of the argument you're on, and it's tough, right? How does the end justify the means, right? And that's, I think that's the underlying point. What do we value, and I remember, and some of the folks that are old-timers like me, I remember the time where you could go and, let's say, you did an arrest, right? And incident to the arrest, you had to see some items, and you had to inventory them. That's a common procedure. Well, part of the inventory was getting to the phone, no search warrant, no order, no court order, and just inventory those contents, which mean I'm getting to your phone. And no court order was required. That was a common practice. And the Supreme Court said, no, there is a privacy interest in the individual that needs to be weighted against a privacy industry of government, you know, need, right? Same thing with GPS trackers. I remember the days where you could slap a GPS tracker on a car and just keep it there. And again, no court order, again, law, the law, say law, but courts decided that that was not the way to go in regards to privacy, right? So the question is, well, why would companies, since they're not being mandated by Congress to, you know, either take the encryption off or make it illegal, why would they carry that liability? They're rather just give what the customer wants, value privacy over another particular value, and go from there. And it's tough, because for some folks that you're saying, well, if it says a kid, I don't care about anything else, right? And some folks might say, well, that type of reasoning, where would it lead, right? What type of monitoring, bug monitoring, are we allowed to, will we allow government to have, and we say government, it's Facebook doing it, but come on. We know who consumes that output is law enforcement, right? And again, I'm saying this as the devil's advocate, again, I don't, I don't, I don't go about giving policy descriptions to anybody, right? But that's the research that I've done on what the argument on that side is. And some find it persuasive, some don't. I think from the forensic perspective, not the policy perspective, because the policy perspective, I believe, should fall in Congress. I say Congress, because Congress is the reflection of the will of our society through our elected officials. So Congress needs to get involved from my opinion. That's my personal opinion. But beyond that, from a forensic perspective, will that make it hard in a sense? Well, I mean, yeah, some leads might go away, but I believe that as investigators, we need to go back to those roots, right? Go back to the roots, finding these perpetrators, infiltrating those groups, taking over accounts, getting sources, making sure we understand how this platform works, where we can get from that data to follow up on it, whatever is not encrypted, might help us lead us to other information, like really do that, the hard work. I mean, not that we're not doing it, but really focusing on not forgetting about those fundamentals. Because just pressing a button or waiting for Facebook to send me a lead, so I can just go unnapped it the person that's technologically speaking, even if they don't do it, even if Facebook doesn't implement that encryption themselves, at some point criminals will get smart enough to do it themselves. So I definitely think the hard work needs to be put in. Encryption or not, right? I mean, sitting and waiting for the forensics to be done, you should be doing all of that back work as the forensics is being done anyway. But yeah, I mean, you're right about that part. There's additional work that can be done if the encryption does go through and is put in place. Yeah, yeah, and look, did really bad perpetrators, not only in this type of crime, but any type of crime that uses communications, they will have some sort of encryption that even third party or from some other sources. They don't have to, if there are some more criminal and I got to do my crimes in Facebook and meta or some platform like that, well, of course not. They will use some other methods. But even if they do, they will have encryption. So we have to be really smart about how we do it. And as the forensics examiners, how can we recover it? How can we go about different techniques to be able to do our constitutionally mandated work? And which again, at the end of the end, but a little bit in the conversation in the show, we have some of that that I think people will be really interested in. So don't, don't, don't, don't leave. It's gonna get better and better. Yeah, so anything else to add, Heather, do you think we're good on that? Yeah, I think we're good on that. All right, so don't be spying on me now, okay? All right, so, all right. So yeah, so Alex Cadness, a good friend of ours and of the show, as a show, he made an awesome video about how time, time, time, time, time, let me repeat that again. Time, time, fork, there we go. How they tick, you know, it's a clock, get it? So it's pretty neat. I love his voice, obviously, from being from the UK. So, he has the perfect podcast blog, whatever voice, perfect. Whatever he says sounds way better than me. It sounds way better than everybody. I think it's worth a while to go watch it. So, and you'll be surprised in the sense that as examiners, we have this, the habit of just pressing the button getting the answer and we criticize that to no end. But at some level, we really need to understand how these things look natively, right? I was talking to a group not too long ago and I said, well, you see this series of characters and what is this? And these are forensic folks and they're blank stairs. And I said, well, okay. So, tell me what an encoding that uses the letters A to C, the numbers, your two nine, the plus, the minus, the kind of slash symbol like that and the equal sign in their encoding. Equal sign being like the tell off or the clue, big clue about it. And nobody knew how to tell me B64. Like nobody had an idea. And we should have an idea, right? Because we're gonna see it, I come across it and we need to visually identify so we know what to do next. I did the same thing to the same group, looking at a Unix epoch timestamp, which is what the video that Alex just made. And everybody had blank stairs. I said, no, look, that is a timestamp. You're looking for a timestamp that is how it looks. It's one six, which now started with one six. Now they're gonna be started with one seven. We make that switch. And explain to folks and not only to them, but you need to know this to explain it to the jury and say, look, why is this timestamp like that? Well, because we decided that in 1970 the same. or whatever, 31st or whatever, at this time we're going to count how many seconds happened from here to there. In the same way we count how many years happened from year zero to 2023. So we decided to make this calculation in time and that's how we get at a date, right. And we need to know those things. So even if you say I know what it is, watch those videos, understand the basic concepts behind it so you could be, you know, better understood and also be better at identifying things in your in your forensic work. So yeah, in in his blog, he also, he talks about rabbit hole to decode the timestamps, which is his tool at CCL solutions. But he also talks about decode and other options that are free utilities. And he also provides Python scripts to decode timestamps. So if you are don't do Python or you have no idea, he provides them right there in the video. And there is also a cheat sheet. I'm going to put the link to the cheat sheet. And I'll actually put it up on the screen too, so you guys can take a look at the cheat sheet. Because it's awesome. Yeah, and we're going to have obvious always we're going to put all those links in the notes for the folks that are not, and they're listening and not watching. So don't worry about it, you have the links there in the show descriptions, you can get it. Yeah, so he's got a whole cheat sheet that goes with the epoch timestamps that you can go download right from the website. And I'll just do a quick scroll, but everybody can go can go download it. And those Python scripts there that I was talking about are right in the cheat sheet. So super helpful. For anybody who wants to use it to decode timestamps. Oh, this is this I love cheat sheets, so highly recommend it. It's awesome. Go check it out. And I will have some more to say about some of the stuff that Alex and CCL have been, have been bringing out. As always, just to make people understand, we make reference to tooling, to people, to companies, we were not, we're not, what do I say? We're not chills, but we're also not haters. We get zero payment for anything we mentioned here. So it's just we just mentioned it as part of, we believe, might benefit you. So just making that clear. Yeah, and he's going to be doing some additional blog posts to with additional cheat sheets in the future I've heard. So keep an eye out for that because the cheat sheets are great to have right at your desk. Oh my goodness, no kidding. And you know, this type of tooling cheat sheets, a lot of good stuff coming out last couple of months. So we have one that's coming up. What do we have Heather? Oh, no, we don't have that yet. So yeah, yeah. So there we go. There we have it. Yeah. So recently, the last couple of weeks, I have been playing around with and so has Alex. We've been playing around with memory dumps from phones with X R Y and using the Ram Decoder. I don't know if anybody has ever heard of the Ram Decoder and we have yes memory for Christmas banner back there. But Ram Decoder is a tool that X R Y has that I had no idea about until Adam from X R Y told me about it, tried it out. Of course, I tried it out on my own without being told how to use it and I did the whole user error thing. But I spoke with Adam, learned how to use it and it's awesome. So I'm going to show you guys and talk about a little bit of the Ram. Let me get my I was I was blown away of stuff. So we're doing this testing. I wasn't aware that you could even get memory like that. I mean, conceptually, yeah, but I didn't know of a process to get it, right? And I believe that most folks don't know this. So this is really important for you to all be aware that for these devices and is Android devices, you can get some memory from them. There's a lot of good stuff there that you you will not even believe. So this is going to be a little small to see on the screen at first while I type in the commands because I'm going to run a couple of them. But X R Y MSAB provided a RAM dump from a device to run their RAM decoder program on. And I'm going to just run one of the processes live. Hopefully it goes well. Sometimes live demos are not a good idea. But I'm going to try it before you hit enter. So to get the you obviously use X R Y and there's a process using X R Y to get that memory correct? Yes. So I I'm going to talk about that in one second here. Let me just scroll in on this so you can see it. So this is running a process to let me go back up so you can see I just put in a command to run a process to show the tasks in the memory dump that the MSAB provided. So the tasks that are in the memory are provided here on the screen. But let me back up for a minute. So X R Y will do consent, um, RAM dumps on Samsung devices and X R Y pro supports a variety more and a variety in a variety of different states, including lock states. So if you're an X R Y user already, you can do, um, RAM dumps on Samsung devices that are unlocked. You already have that capability. If you are an X R Y pro user, you have a lot more capabilities. If you're not an X R Y pro user, you may want to look into it. Um, I'm going, I want to look into it and possibly get a demo of it. But I don't have X R Y pro, but I want to look into it and see what the capabilities are. What what RAM decoder is is a command line tool where one or more binary files can be analyzed. And I so I have a binary file from a Samsung device here. And the code that I just put in shows the tasks that are running in the memory. So I'm going to just scroll out real quick. And we're going to focus on one particular task, which is the ID 8991, which is Samsung Honeyboard. So the Samsung Honeyboard is the keyboard for the Samsung device. And I'm back down here. Yeah, those, and this is, this is reminds me a lot of forensics on computers, right, where you can, you know, look at the processes that are using that memory space. You can look at different, um, you know, connections and data. So there's this tool really gives me this kind of volatility vibe, but in Android, I guess, which is, which is pretty neat. I can't believe they can add. Now I'm just going to run the show task for that specific ID. So you took, so you identified the ID and you took what the process ID, right, to put it there. Took the process ID. And now I'm just showing the tasks for that process ID. So again, it's like this that kind of volatility vibe in a sense, I, that's what would be my, my take. So we have the tasks for that particular process ID. And you can see all the different pages that have the tasks for that process ID. Actually, I think I'll leave it zoomed in because you guys can see it right there. Yeah, looks pretty good. I'm just going to pop over to the other page here. At live demo, I have to come out or I can't get off that screen. Sorry. Now we know. And let me pop back. So now I'm just going to grab the very first page. I'm not going to scroll back up and show you what I'm going to grab the very first page. And just, um, let me put it out to a text file so we can take a look at the strings that are related to the keyboard application itself. Yeah. So there's a command there for show strings, right? And then the process ID on the page number, process ID 8991 and then the page number. And I'm just putting it out to a honey board. You're piping it out to a text file. Perfect. Yes. And this is kind of, you know, command line, kind of basic command line navigation. And that's something that we all should work on, of course. And then I already have one ready. So before I show you what's in here, with the memory, the Samsung RAM, I was surprised to know that the amount of data that's in a memory dump, right? So I'm thinking you power the phone down and that's gone, right? Like a traditional computer. It's not. It's not gone. It's there. After I show you the keyboard data here, I'm going to show you a memory dump actually from one of my old phones. And there is data in there from years ago. And I'm just shocked at the amount of data that's actually in RAM for mobile devices. When you shut the device down, that memory, that RAM, it's not gone. Look, if you have a forensic examiner, a digital forensic examiner listening to this, a you're not surprised or mind blown, please rewind a few seconds, six seconds back and listen to Heather again. she just said. Okay. This to me, this is just too much thing to handle, right? So you made it. If I'm wrong, you're saying messages, text messages from years ago, sitting, sitting in memory. And I would like to hear like an engineer explain to me because I'm not an engineer, I'm a software guy, but how does memory work in these Android devices that even if you turn it off, quote, unquote, off, it retains, like there's some sort of, like, you know, some energy still going through it or what happens if I lose battery powerfully, like, I'm really interested on how this memory that is volatile doesn't seem to behave volatilely in these devices. That's stuff that's to me immensely interesting. Yeah. So the device of mine, it's a Samsung Galaxy S21 Ultra. And I had recently gotten the pixel. So that device has been, I mean, that device has been powered off for, I don't know, a while, a few weeks now. It's been since I got the pixel and I powered it on, got the RAM capture and 12 gigabytes worth of RAM. And there is stuff in there I couldn't believe, which I'm going to show you some of it in just a minute. That's that's that's wild. That's just wild. Yeah. So with this, this data that came from MSAB though, with the Samsung keyboard, you can see here, we have some date and timestamps in the keyboard data. And then if you scroll over, there's input text and you can actually see some of the keystrokes from the keyboard. You can see where the user was text putting in text, where they were starting to type, RAM dumps at proton, mail, and then you have the dot com. And then there's some other text here and it goes on. There's a whole bunch of this in this show strings text document. Yeah. And let me paint a picture of some of those that are not going to be able to see it. It's literally as you're typing like one character at a time, right? So this is, you can see the characters being built every line of every line of that's recorded on this timestamp. At this second, you see like the N being added and the M being added and the A being added one by one line by line, which is pretty again, it's pretty wild. So just think of the types of things you could use this for, right? If you're seeing keystrokes by a user, I mean, potential password, potential, I mean, anything. Oh, yeah. I mean, if you're looking at an email address or username address type of looking data, well, what's going to come next after that? Most likely a password or some sort or some code. Yeah, that looks awesome. And this one process, the keyboard process, who knows what other data I've recited in other processes. So that's just one process. I ran a whole bunch, I ran a whole bunch on the process IDs from the data that MSAB gave me, calendar, camera, the clipboard, there's contacts, geofence, Gmail, the keychain, there's the UI, there's Wi-Fi, the Wi-Fi actually had some of the BSS IDs in it. The setup wizard had the different applications as the device was being set up, like the pre-installed applications were all there, trying to think what else here, the keychain had some of the information related that you would normally find in the keychain. But then they told me if you have an old Samsung device, capture the RAM of your device and check it out because you're not going to believe it. So my device unfortunately isn't supported by the RAM decoder yet, but it's going to be, and the RAM decoder is going to be awesome. They're going to continue to build profiles for devices, but mine's not supported yet. And if you also know what profiles is, I'm going to make an analogy like with volatility. You can have a random from your Windows computer and your own volatility and volatility, at least version 2 will tell you what's the profile. Is it a Windows 2010 version, whatever, is it 2011? You have to provide what the, and obviously has to a profile has to exist, be able to understand that RAM data capture property, right? I think volatility 3 now is does it automatically, like applies the profile by itself if I'm not mistaken. But this is kind of the same process, right? You need to build profiles to identify those particular randoms for those particular devices. Right. Actually, before I share this, I'm actually going to show you the process of the RAM extraction in XRY. So I know a lot of people have XRY. And so just get started the normal way that you would go do an extraction with XRY. Start your new case, manually find the device or app, and then up on the top part, you will type in upload. So Samsung upload mode RAM extraction is what you'll be looking for in your XRY. Now I made this additional information section bigger on this slide because it took me an extraordinarily long time to get this part right due to user error, which I do a lot. So you need to do, you need to enable upload mode on the Samsung device. And you can enable it by accessing, by entering star pound 9 9 0 0 pound in the call section. The problem is I didn't see the star. I have made an eye appointment. I am going to get my eyes checked. So I hit the star or the pound 9 9 0 0 pound. And I thought, okay, so it must have done its upload mode and I just don't see it. And I'm trying to continue doing the extraction and nothing is happening. So I reached out to Adam at MSAB and thank God, he's like, oh, you're, yeah, no. So he, he steered me in the right direction. I miss the star. In your defense, the star is really tiny. Okay. So I'll give you a fast. Very tiny. It is very tiny. So it's not a blank screen. It doesn't just go into upload mode on its own. It actually pops up options. And I'll show you the options here. So when you do that, this is part of it. Once you hit the, the last pound sign on the phone, this menu comes up on the device. Yeah. And the menu says what system, right? Yeah. So the system menu comes up and there's two options that you have to change in that system menu. You have to choose the debug level. You have to set it to mid. And then you have to enable upload mode. Once you enable upload mode, the device will, the device will shut down and then power back on. And if folks are listening, if you're interested in this process, we're showing here on screen every step with images, pictures. So you know, you can go back and watch the video after it's uploaded. So you can then actually visually see what's going on. Yeah. Then you choose the physical, physical option in XRY. Fill out your case data, put whatever your case number is. And then the option or the process is to hold the volume down and the power button for eight seconds. As soon as you hit eight seconds, let go. Once you let go, the device will come up with this screen here, which is the upload mode screen, I guess, but that's the screen that you will see. And your RAM extraction will start. Your RAM dump will start. It took less than six minutes. I think it was like five minutes and 20 seconds. There's something to extract the 12 gigabytes of RAM. That's not bad at all. That's not bad. No. And then it'll tell you extraction finished and you can open the case up in XRY's examin. I did a lot of the work in examin, but you can also save the binary file out of examin and do searches in any tool you want, any hacks that are any tool you want. So let's get out of here. I have some of the things that I found. So I found it really easy to go look for things in my data because I know what I've looked for. Not so sure it would have been as easy just to go hunting and somebody else's phone. But you know, you may have a good point. If you can find your stuff, you can definitely look at some keywords around it. If you're doing it like I hand like this and then kind of extrapolate to somebody else's. Yeah. So one of the artifacts that I picked out to show tonight is I found in my data, my Galaxy earbuds. So they're named Heather's Buds 2 Pro. But they also have, if you look down here towards the bottom, the latitude and the longitude for the earbuds. And there's a timestamp here. It's 11, 16, 2023. And there's also a horizontal uncertainty. I'd imagine it's probably in meters that's usually what the horizontal accuracy is in meters. But obviously, I've never tested it in the RAM, but so don't take my word for it. But the latitude and longitude comes up to this point on the map here, which is the, the, the, the, the, the. my house is right here. So I am certain that that is correct because that is my house. So it is very accurate latitude and longitude. And that was for my earbuds. Which is amazing because those earbuds get those through the phone obviously. So you can make those really good conclusions of where you were at or at least your phone and your earbuds where I don't know what to go to. Yeah, and I was definitely home that day. Let's see what else I have in here. This is a good one too. So this one I found on November 26, 2023 at 1206. I was at my sister's house and I was actually just getting ready to leave my sister's house and head home. And in the RAM dump there's a last updated time with a timestamp which is that 1126. And it is a connection to my sister Holly. So Holly MLS is her Wi-Fi. So the last updated time of my connection to her Wi-Fi is the very last time that I have been at her house. Shout out to Holly for helping us without knowing. Yeah, thanks Holly. Thanks again, Devers. Thank you. Yeah. So it actually has the last update of time and it is the last time I was at her house. That's wild. Yeah. There was data in the RAM dump related to the build props. Oops, sorry, I skipped it there. The build props file if you don't know what that is that. Yeah, see if I can keep it on the screen. It contains data about the device. So there's the model number or the model name. I'm sorry. And the system build date. I can't keep it on the screen. There we go. System build date and the build fingerprint. Also, there's the operating system. So I don't have a screenshot of that. But just below the build fingerprint is the fact that this device had Android 13 running, which can be super important if you're looking to do anything with a device and you need to know the operating system. Absolutely. And then this one, I might get people yelling at me for this one. More people yelling at you. So Alexis has yelled at me a little bit about it. So everybody be nice in the comments. But I wanted to see if the password to my phone was anywhere in the RAM dump. So I did a search for the password of the phone. And I didn't find it in the way I wanted to find it. I found it in a way that makes me sound very insecure in my password habits. So my HBO Max password was set to the same password as my mobile device. And I texted my sister, I believe, the HBO Max password. And that text message was in the RAM capture. So if you had seized my phone and gone through and looked for passwords and found my HBO Max password, you would have been able to get into my device from the RAM capture because of my password stupidity. Which doesn't be real here. That's like that's a common occurrence. My new phone doesn't have the same password. I did black it out because the HBO Max password is still the same. But yeah. So I mean, you could have gotten into my device and people are creatures of habit. So you would have had, I'm sure a lot of people's password, you could get that way. They're sharing video streaming passwords and it's the same password to get into their device. I'm sure I'm not the only one that did it. It's a common thing. That password is insecure, but it's insecure because we behave that way and attackers, actors, know that, right? Yeah. And we know it too. So hey, we're going to use it for good. So. Right. So I was really surprised to see there are messages in there from years ago. It wasn't just like a couple of messages from recent. There were messages from 2020. 2021. I was just shocked to see the messages. I was looking for third party messages. And I found traces of third party apps being utilized, but I didn't find my messages in the third party apps. I'm sure I would love to look at other devices besides just this one and see if that's a capability. I'm unsure. There weren't any in mine. But just speaking with other people who have done RAM dumps, I've heard there's possible cloud tokens, chat messages with delete on read settings, and then occasionally when you can't get a file full file system, if you can get the RAM, if all of that stuff is in the RAM of my device, how valuable is that going to be if you can't get the full file system? No, yeah. So valuable. I'm going to say it right now. Heather, do you want to go home and change your HBO password? Do you want to change it? Do you know why? You know why? Because you're only just just noticed that you did not black out the hex. What? Oh, see, see, you should fire me. I should fire myself too. I didn't think about it. Thank you, Geraldine, for having an eagle eye and being just smart. Awesome. Oh, she's right. I didn't even pay attention. You know what? Anybody wants to watch a movie? Go for it. You got you got maybe one time is it? You got another 15 minutes if you're either changing the password. That's awesome. Geraldine, you're the best. It's all along now. Oh, that's good. That's hilarious. I love it. That is good. Yep. Oh, I'm going to cry. Okay. Oh, that's awesome. Well, again, it's just the HBO password. You don't use it for anything else. So all your accounts first of accounts are secure. So you're good. Yeah. Oh, definitely. Yeah. And no, I want to underline that point, right? Especially even text messages. You know, we look at an Android device as well. Where can I find some remnants? It's like an FCM or some other formats for messages. And now we got 16 gigabytes with a window of possible evidence that's retained. You can be recovered for years. I mean, again, that's what I put in my sign behind me. I want memory for Christmas, right? And I appreciate the MSAB is kind of leading the way on that. I would hope for the other vendors and open source developers will be start looking into memory forensics in Android and really developing that that area of the field because I think it's an open wide field for great development. So one thing about the RAM decoder, though, I don't think I said it. And if I didn't, I'm going to say it now. It's law enforcement only. So if you're looking to get RAM decoder, you can reach out to them. But it is currently law enforcement only. So if you are law enforcement, reach out, get it, test it out, try it. I think it's awesome. I can't wait to get more RAM captures, RAM dumps, and keep looking to see what's in there that it's amazing to me. I had no idea that there was so much data in the Android RAM. No idea. Yeah, I'm going to be keeping preaching this development because I think it could change a lot of cases going from well, I got nothing in this case to well, you know what, this case is solved just because there was some good stuff in that RAM, so. Just keeping an eagle eye. Eagle eye, yes. All right, talking about eagle eye, right? There's this kind of meme or an out, not meme, but kind of like an announcement going up in LinkedIn. I think we have it. Yeah, I put it up. Yeah, well, what's going on with this? We're making the rounds in LinkedIn. What are we looking at here? So Cyrillic alphabet. So both addresses look similar, but they are not the same. Can you tell the difference? It's kind of what the LinkedIn meme or image was asking. I don't know if anybody seen this. Well, and for the folks that are listening, it says mybanktou.com is not the same as mybanktou.com, and then you have to really look into it. To be honest, it took me a while to figure out what the difference was. Me too. I don't know that I would ever notice the difference unless it was on an image like this asking you to look for the difference. Yeah, and the difference, you know, is that, you know, the top on the top is like a normal A with a little belly on the front, right? And the other one is what? It's like an A. That's not how belly, like normal. Yeah, so, I mean, look, so the folks that posted I appreciate being security conscious, like, hey, maybe you need to be aware of this. But I mean, I don't know about, like you said, Heather, like I were in a million years whenever I ever think of seeing this, right? Yeah, yeah, and and the point I think we want to bring this always Look, this is fine. It's interesting that that a's like a Cyrillic a versus or a looking character. I don't know Cyrillic. So I'm not going to call it an a, but looks like an a and look, normal user will not catch that, right? I mean, this is not really helpful for my perspective, because really we're going to put that onus on the user. There has to be technical solutions, right? And this is more of an info sec information security type of topic. But if you're listening to this and you're part of an info information security group for your company or your business or your organization, well, think about what are the technical solutions to prevent fishing that goes beyond putting the onus on the user, because the user wants to just go to the bank, right? The user is not there to figure out if that a Cyrillic or not, right? So, you know, telling that the email says, well, be careful for every mail required you to click on a link. Well, sure, be careful. But I mean, I'm going to look for Cyrillic characters and every link in an email. I will never work. You know, no, nobody's going to think of that. Most users aren't going to think of that. We do this for our living and we don't think of that. So, I guess a lot of your point is your user base or the folks that you provide services to, how can we provide some technical solutions to take the onus out of them? Because the technical solution is predictable. It acts as hopefully as we expect it to behave and we can update it as needed. And you know, the user shouldn't be responsible for that. We should be responsible for that. Absolutely. So, we also, whoops, I don't know if anybody has seen the browser state blog from Ian Wiffen, but if you have not, you have to go check it out because it is the exact blog that you need to validate the kind of the conversation that we always have about validate your data or make sure you're testing the data to know what the data means. So, the browser state database, the last visit of time, and I actually think it is the last verified time. Let me just double check that. Hold on one second. No, it's a great article. And like Heather was saying, Ian is one of the lead folks for analysis and tooling for Celebrite. And he did a lot of testing on how last viewed time, sorry, last, last viewed time. So, the last viewed time in the browser state, it doesn't, it doesn't necessarily mean that it was the last viewed time of the URL that is in that database that's in that, that table. And it's actually been tested by Ian and it's most likely, most times, not the last viewed time. And that's crazy, right? You're like, well, it's a browser database. It's a URL. There's a last viewed time stamp. Therefore, it's the last time this page was opened by the user and viewed. And all those things are wrong. Like, you're wrong. Like, wrong, absolutely wrong in all in all senses wrong. Like, you couldn't be any, you couldn't be any wronger if you wanted to. I would see that and I would immediately think last visit a time, last viewed time. Why wouldn't you think that? Yep. And I wonder too, if any of the tools are parsing it as such. Well, I mean, look, you make a great point, right? As a tool developer, if I, if I just put, this is the name of the, of the, of that field, that record and that field there, because that's what's there. I'm going to need my users, right? So at some point, you have to balance the whole, well, this is the name of it, but what does it mean? And that's the tough one, right? Making making those decisions, because we want to be accurate. That's what the actual database is called the tape, the field. Right. But that's not actually what it means. Yeah, someone recently asked me, so how do I validate this stuff? How do I know? For sure, right? And I said, get a test phone and go test it yourself. And the response was, well, I can't, what if I can't afford that? What if my agency can't, can't afford to pay for that? And right here, the work that Ian does, that's how, that's how you do it. Go find the person that is doing it and you, and use their work. I mean, he's done the work for you on this particular issue. And it's not going to be your first option, right? Because you should test things yourself, but we also have limitations, right? We don't have an infinite budget. So, you know, it's also pays back to kind of depend on the research in the field. And if the research is, the research is validated, either by, you know, by somebody that's a known expert or organization, which is also even better. And make a segue. I know we run in a short time, but make a segue. Jessica Hyde from Exordia, she's making good points in different interviews as to be, she's been on lately. On how all this stuff that we're talking about, it's got to be acceptable at court, right? Just saying the tool gave me this output. Well, that's what it says there. It's not enough. I wasn't a research that supports this as the proper conclusion. If it's yours, it's, it's good. It's better because you can testify to what you did, right? But if you can't do that, then it's a person that's an expert in the field, it's a peer review research, right? And introduce that. If you're saying to me, I don't have time, or we don't want to invest on it, then you've got to be ready to have some of that evidence not be accepted and thrown out, right? Is that something that are not, not risk, but is that, I guess, risk is a good word. Is that that risk we're willing to take, right? And kind of eat up that risk, you know? So it's a great article. I recommend everybody to see it. I make a quick, that's it. It's a great comment. I'm going to bring it in. So Mark Spencer, he's saying Coralium can be very helpful with iOS testing. And that's a great point. Virtualization is way more accessible than maybe buying the hardware, depending on what you're trying to do, right? And how much of it you need to do. So think about that. Coralium is, it's a use, it's known for iOS virtualization. Android virtualization is a little bit more accessible, I believe, in regards to pricing and all that. You can do some Android virtualization for the price of nothing. So also, they can do that. What a great comment there. So we appreciate it. Yeah, so talking about tooling. Yep. So I want to, I want to make something mentioned to people, James Havin and Johan Polachak, that been really contributing to the projects that I spearhead, just the leap, right? It's, it's in, it's, again, I'm so grateful for people wanting to be part of the project and adding some stuff. And I want to show some of the things that Johan has been adding and some of the, how is he extending the project in different ways? So the first thing I'm going to show you is something that's, that's pretty new, that's pretty neat. Let me see is the, yeah, the load case. So when you have one of the leap programs, and you already can see there on the screen, you have an option to load case data. And now that option is not just having a JSON file that you have to make. Now the leap itself has a window where you can add that case data. You can add your case number, your agency name, the name of the examiner. And when you, you can save that case data file for later use, and it will show on your report. So that's, that's something pretty neat. And he added that option of referencing that load case data option within the command line. So that means that if you have, you know, five extractions, you need to parse with the leaves, you can code that with, to automate it with command line, you know, instructions and say, hey, here's the, the profile, and say, profile, but the load case data for it. Another thing he added, and this is even more important if you do development for, for the, for the tools for the leaps. For the longest, I only implemented the option of selecting artifacts for processing. Let's say I have supported 200 artifacts. I only need two. Well, to the graphical user interface, you can go and select those two and deselect all the others, and you have a report only of those two artifacts. But you couldn't do that on the command line. You have to, if you're at the command line, you have to get all the artifacts. No way of saying only one, two or three. So your hand came in and changed the code, added, you know, refactored it. And he added the option of feeding that profile JSON file through the command line, which is great because now when I'm doing my testing and I'm developing artifacts for the tool, I don't have to be clicking the user interface. I want to run this one, not the other ones, this one, not the other ones, or loading it manually. I can just have a command line with all my instructions and my profiles. I hit enter and boom, done. It will create my report for the particular artifacts I specified. So I highly recommend folks to check those enhancements. Another thing that he's been doing and I'm incredibly grateful for, he teaches at a really renowned university in Lausanne, if I'm saying the correct in Switzerland. And I'm like, I wish I could go teach with him. I'm all for going. Yeah, right. Take me with you, please. The students are doing great things there. Exactly. They need me there. So they just recently made some parsers as part of the schoolwork and look at all the artifacts that they're supporting. I will be merging into the the project soon. Big ol' life, booking for [BLANK_AUDIO] Android, a CFF, Garmin, Lockheed, Robolute, Ricardo, Strava, Tinder. And this is interesting because some of those apps I've never seen before. My assumption is that it's really famous or useful in that region. So this is great because now you haven't, to the platform, you have this ability to really open the parsing to the world, right? If people know the code, right? And look, Johan is on the chat. So I'm going to have you here, man. It says, you're welcome to visit us. So you know why we might need to, yeah, we might need to. I just wrote word on our way. It wrote for both of us. All right, that's awesome. I would love it. So yeah, so all these parts are coming in. And that speaks to the point of, as exammers are developing in university, I'm really happy to see them adding those coding skills and then bring it into their forensic work. It's going to be everybody better. So again, thank you, Johan, for the work you're doing for the community. And for your students, I'm going to teach them. Look, there's this conceptual stuff that I'm teaching you, but it's also practical. And you can make the world better by the things that you know and by the things that you share. So, you know, again, thank you for from us and from the community for all the work that you do, man. Appreciate it. And talking about work that's being done. I'm going to go and talk about one more thing. It's not implemented in the leaves yet, but it will. I'm going to go back to, again, our best friend for our best friend of the podcast, Alex Caitness. And we were having some discussions about a SEG-B, right? Me and him some time ago. And celebrate came up with an article explaining that SEG-B, there were some changes in it. And for those who knows what SEG-B is, let me give it a quick primer. For a long time, iOS devices and macOS devices use a database called Knowledge C in SQL, SQL database to keep track of a plethora of forensic evidence. From the app intents, we can recover messages from it and all sorts of communications and activities on the phone. It just kept the locations, it kept a whole bunch of stuff. So, in the move from iOS 15 and moving upwards from it, that database kind of emptied itself. If it's there, it's going to be pretty much empty. So, we're wondering where the data went. And it went to this files called a format called SEG-B. We call them SEG-B, because that's the header that the file has. And they're usually containing a biome folder within these devices, iOS and macOS devices, okay? So, celebrate came up with an article saying, look, that format has changed, it's a different format. So, I was talking with Alex and how could we develop a Python parser for it and he was so kind that he did. And it definitely helped me with my crappy code. And actually, I really fixed it because I couldn't really get it. And actually, that made a meme come to my head, right? There's a scene from Star Wars where the Darth Vader is telling, you know, Bobo Fett and Landau Carlisian, you know, I'm altering the deal. You know, pray that I'll turn it further. So, I changed it to Darth Vader being Apple and them two being forensic examiners. And he's saying, I'm altering the SEG-B. Pray that I don't alter it further. Because Apple's doing that on us, right? You cannot change it that format constantly. So, what part was a parser that Alex did? So, let me show you a little bit of that just to kind of close it out. So, Alex did, let me see what I have in here. Some good code on it. And I think, there he goes. I have the code now. So, let me close this out so I can show it again. The code is super accessible, even if you don't know Python, you should be, you know, you can run it. It's super easy, right? So, I'm gonna, again, folks, if you don't know code, don't sweat it. We can, I have, I have the YouTube channel. There's YouTube channels of video and what, how to run Python scripts, you can watch that. But it's really easy, right? So, what you do is you input, you run the script and put the name, the file name, and the location of your SEG-B file. And it's gonna, if you run it like you see here, it's gonna take, and it's gonna show you all those content. What we see here is me downloading Firefox. And let me see if I can highlight some of that. It doesn't want to let me highlight it. But, downloading Firefox, you seem safari to download it. And then you can see here, me getting the DMG, right? The container to install it. And that's just by looking at the app in focus, right? Actually, what I'm gonna do is I'm gonna, I'm gonna go up above the time. So, people, you know, bear with us. I'm gonna actually demo it. I think that's even better, let's do that. - Do it. - I'm gonna demo it. - Yeah, so let me hide all the pictures that I had here that I've been showing. (laughing) All the memes, hide all the memes. Let me share the screen. So, let me share the screen number two. Hopefully, it's the right one. Yep, this is the one. All right, so, I'm gonna bring a command line. And this is my Mac. So, I'm gonna bring a command line. And let me see if I can make this a little bit larger here. All right, I think it's more visible now, right? Yep, and I'm gonna go and go into the folder where I have my stuff. So, let's see, I should have been smarter about it. Let me be smarter about it. Let me open the tab at where I need to be and how to navigate it. So, there we are. So, I'm at my folder where my director will have my stuff. And I have here a couple of files here. I'm gonna open the media now playing one. So, let me actually move it out of the folder that is in. And I'm gonna call the secb2 script. So, I'm gonna call Python. And I'm gonna say, I wanna do the CCL on this course secb2.py. And I wanna feed it that file. I wanna feed it the 7241 file. There we go. So, for folks that are not be able to see their listening, all the interpreter in my command line, Python 3, put the name of the script that will parse it for me. And then the next argument is gonna be in founding, okay? And I'm gonna hit enter. And let me see if I can change how this looks a little bit better. There we go. So, this is the output, straight output, if you use run the tool or the script as is. And it's super nice. You can see here. And this one is the things that are being played. So, I'm in my browser. You see them will still have Firefox, right? And you can see here that I was opening StreamYard. StreamYard is a pace that we used, because I was playing, well, we used it to record this podcast, but I was playing a video from it. And it's recorded here that I'm playing that video from StreamYard in my Firefox browser, okay? If I go down, you can see me here, Instagram is open, and I'm watching videos on Instagram, right? If I go farther down, you can see, not only that I'm watching the videos on Instagram, let me kind of scroll down quickly so we can get to what I wanna show you. You can see here, for example, our point forensics, second day, or day two of the 12 days of different mess with Heather Mahalek, bar heart, of course. And I'm Firefox. So, you could see that I'm using Firefox to watch, if you Google that, it's a YouTube video, right? And this is to me, this is kind of my employing, because some of this data, if you go and delete your browsing history, well, you mean, how would you know I was watching this page in this video? But it's recorded here within the SEKB files, and it's kept there for quite a while, right? I think it's 20-something days to 30 days. And if I go scrolling down, you can see, you know, all the different things I'm watching here, even though this is, I was clicking on some of Medicare policies. Okay, sure, I click on that a bit. Oh, I know what happened is the videos ended, and another video started about Medicare for all things. Yeah, so that's what happened. Anyway, so that's an example of it. If you run the script, and if people have it here, I don't have it here, but I'm gonna show you a picture of it. If you look at the repository, and we provide those links at the show notes, let me show you two things. First of all, I'm gonna show you how the buy-and-folder looks. Let me zoom into that. You can see here, oops, sorry. You can see here the different app intents, and then the big number there is the SEKB file. Let me show you the one that MediaNow plane, that what I was doing right now, is in the MediaNow.Now playing folder, local directory, and then boom, that's your SEKB file. You can take those, and doing with the parser, okay? Now, what I was gonna show you. The repository, if you go to the link that we will provide in the show notes to get this code, Alex gives us a little bit of how to execute those commands, right? So if you use this way of doing it, it's really good because you won't get that hex data view, but you will get the data in a, what's called Python list, which allows you to manipulate it better. You can take that and make a report from it, and do certain things if you know some basic Python. If you don't know basic Python, I have a class for that, that you can watch in my YouTube channel. So, like everybody says, comment, like, and subscribe. I believe this is really good stuff. Tools are promising to support SEKB file, which is great, but I'll tell you, just because it will support the, doesn't mean that it will report on all of them. We have, again, Darth Bader couldn't alter the SEKBs at any time. Not only the content, but say, look, we're gonna add a new one and add a new folder there with some new SEKB recording of something that the vendor hasn't seen before. So we're gonna do nothing. No, you will get to that folder, get that secb out, use the script. parsed it and see what's in it and see if it's relevant to your case because that's what we're here to do. Right. So thank you Alex and CCL solutions. Even if even if the tools parse the Segbee file, they may not parse every part of it. So keep that in mind too. There may be data still in there that's important to you that they may or may not see as important. Go in and check out the ones that are parsed anyway. Absolutely. I couldn't agree more. And with that, I know we're way over the hour, but we're going to close out with something that we have to always do and we cannot get away from doing, which is what the meme of the week. The meme of the week. Yeah, I asked you this one, you're drinking water. I'm such a genius. All right. So the main week. Yeah, let's get it. So for the meme of the week, I love this one. And I'm going to describe it verbally as always. So there's a picture of, you know, two girls and they're labeled as exammers in the lab Friday at 4 p.m. Right. And if they say, hey, what you got there. And then the focus changes and is this dude. Walking with an ostrich. And the ostrich says five. The ostrich is labeled as five phones, three laps and 10 say the drives. And this label is a detective. I know his right hand or left hand, depending on what side you're on, it's a he has a drink. And when they ask him, hey, what you got there, he says as movie. Right. That's 100% how it is. This agent, so the detective show up at the last minute, with a whole bunch of stuff. And every what you got, oh, you know, just having dinner. Okay, sure, but what's that box behind you? All those, all those evidence bags with evidence tape everywhere seems to be a lot. By the way, all five phones are a few so they need to be done right now for a clock on Friday. Oh my goodness. Oh, when you're killing me, I'm getting. True story. True story. And that's how it is, right. But it is what it is. You know what? We have to do with that ostrich then we'll do with the ostrich. Look, if you're doing a search, don't do it in the afternoon of a Friday, right? Unless it's absolutely necessary because you'll be in my in my. In my naughty list, let me use the seasonal terms. There you go. Stay right with the Christmas theme. Yeah, I was going to describe the list as another way, but I'm not going to do that. Stick with naughty, naughty list. Yeah. Thank you for the work you did on the memory stuff. I think folks would be appreciative. I'm appreciative and you know, it's good. What is y'all insane, Heather? And the agent goes home and says, call me when it's done. You know what? You know what? You're going to go out. Give me dinner, right? You pay for my dinner and bring it over, right? And give me company while I eat it if I like you. Now, but yeah, no for real. I mean, thank you so much for that work. Thank you for the folks that contribute. We got a great community going and again, thank you for everything. Yes. Thank you, everybody for joining. And we know what we're doing for next episode in the sense of are we taking vacation or what? What's going on? Oh, it's up to you. Well, let's do this for everybody that's listening. Keep track of our LinkedIn. We're going to make an announcement of what's happening because it's holiday. Yeah, make sure that what's going on. So I will let you know when the next episode is in the next, you know, to weeks or what it's going to be. So we'll let you know soonish. Right, everybody, but again, thank you so much for being here and we'll talk till next time. Keep out for that announcement. Thank you so much. Yeah. Thank you. [Music] [Music] [Music] [Music]

Podcast Summary

Key Points:

  1. Heather and Alex discuss the debate over chat encryption on platforms like Meta, weighing child safety against user privacy.
  2. They present both sides
  3. The discussion draws parallels to ethical dilemmas like the "ticking time bomb" scenario, highlighting the tension between privacy and public safety.
  4. A key takeaway is that forensic examiners must focus on proactive investigation techniques—such as infiltrating groups or analyzing unencrypted data—regardless of encryption policies.
  5. Heather highlights the value of understanding fundamental concepts like B64 encoding and Unix timestamps, essential for effective digital forensics.
  6. A new tool, RAM Decoder from XRY, allows forensic examiners to extract and analyze memory dumps from Android devices, revealing data retained for years.
  7. These dumps contain sensitive information such as keystrokes, Wi-Fi connections, app usage, and even device location data, greatly expanding forensic potential.
  8. The conversation emphasizes the need for technical safeguards and peer-reviewed research to validate forensic findings, especially in court.

Summary:

Heather and Alex explore the contentious debate around chat encryption on platforms like Meta, discussing its impact on child safety versus user privacy. They present both perspectives, drawing on ethical dilemmas like the "ticking time bomb" scenario to illustrate the complexity of balancing privacy and public safety. The discussion emphasizes that even with encryption, forensic examiners must rely on proactive techniques—such as infiltrating groups or analyzing unencrypted data—to identify perpetrators.

A major highlight is the growing potential of memory forensics on Android devices, where tools like XRY’s RAM Decoder can extract 12GB+ of data, including keystrokes, app activity, and location logs—some dating back years. This data can reveal critical evidence, like a user’s movements or password reuse. The episode also stresses the importance of foundational technical knowledge, such as encoding and timestamps, and advocates for peer-reviewed validation of forensic tools.

Ultimately, the conversation calls for stronger technical safeguards beyond user vigilance, especially in combating online exploitation, and underscores the need for examiners to stay ahead of evolving technologies through continuous learning, collaboration, and rigorous validation.

FAQs

The debate centers on whether encrypting chat platforms like Meta's Facebook could hinder child safety by blocking access to exploited content, while also protecting user privacy. Forensic examiners must balance these values and continue using traditional methods to identify perpetrators.

Encryption could reduce the ability to detect and report child sexual exploitation, as platforms would no longer allow detection of such content. This creates a conflict between user privacy and the need to protect children.

Examiners should learn to identify common encodings like Base64 and Unix epoch timestamps. Tools like Alex Cadness’s RAM Decoder and Python scripts for decoding timestamps are highly useful and help in analyzing mobile device memory effectively.

Yes, RAM dumps from Android devices can contain data from years prior to the device being powered off, including text messages, app activity, and geolocation data, which can be crucial for forensic investigations.

RAM Decoder is a command-line tool developed by XRY that allows forensic examiners to analyze memory dumps from Android devices. It can extract process data such as keyboard input, app activity, and Wi-Fi connections, revealing valuable user behavior.

Forensic tools must be validated with peer-reviewed research or real-world testing to ensure accuracy. Relying solely on tool outputs without validation risks having evidence rejected in court due to lack of reliability.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.