Bruce Schneier | |||||||||||||||
Schneier on SecurityA blog covering security and security technology. « Burmese Government Seizing UN Hard Drives | Main | Cheap Cell Phone Jammer » October 9, 2007Mesa Airlines Destroys EvidenceHow not to delete evidence. First, do something bad. Then, try to delete the data files that prove it. Finally, blame it on adult content. Hawaiian alleged Murnane -- who was placed on a 90-leave by Mesa's board last week -- deleted hundreds of pages of computer records that would have shown that Mesa misappropriated the Hawaiian information. EDITED TO ADD (11/6): In the aftermath, the CFO got fired and Mesa got hit with an $80 million judgment. Ouch. Posted on October 9, 2007 at 2:02 PM • 14 Comments • View Blog Reactions To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. > How not to delete evidence. Posted by: Max Belch at October 9, 2007 2:51 PM So we're never allowed to delete our browsing history, cookies, etc.? Posted by: Spot Main at October 9, 2007 3:21 PM Interesting to compare this story with the previous entry about the UN spending the weekend deleting files. Here's hoping that the UN's backup strategy is not as good as Mesa. Posted by: John Davies at October 9, 2007 3:38 PM I believe the Mesa file deletion happened after the court order requiring them to turn the data over. It's a crime. I'm all for deleting browing history, cookies, etc, at regular intervals, and have my computer set up to do it automatically. Posted by: Bruce Schneier at October 9, 2007 4:03 PM "Here's hoping that the UN's backup strategy is not as good as Mesa." Deleting data is actually very hard. Posted by: Bruce Schneier at October 9, 2007 4:04 PM "I believe the Mesa file deletion happened after the court order requiring them to turn the data over." That's the key point. Deleting files at will is fine. Doing it after you have been ordered by a court to provide those files is not. Posted by: Joseph at October 9, 2007 4:12 PM Here's an article on e-discovery (legal issues) worth reading: http://www.ciostrategycenter.com/cmp-insurancetech/Reg/law/facing_ediscovery/index.html Posted by: Jojo at October 9, 2007 4:22 PM Ain't that the way it always is - haole stealing from the hawaiian!!! Posted by: Sum Dum Guy at October 9, 2007 11:52 PM "But Mesa says any deletion was not intentional and they have copies of the deleted files." Given that they admit they have backups of the deleted files, they can't be claiming that they have accidentally lost any data. Posted by: Steve Parker at October 10, 2007 2:54 AM This month's ;login: has an article by Alexander Muentz on IT aspects of preparing for litigation. Posted by: 4kb and uphill both ways at October 10, 2007 10:00 AM I love the pornography defense.. a kind of plausible deniability?? Some years ago someone suggested that private steganographic messages be hidden in porn files, as it would make a good cover for secretively downloading and keeping lots of images. Posted by: jayh at October 10, 2007 10:23 AM And when all of that fails, check into rehab. To hide, presumably. Posted by: Kashmarek at October 10, 2007 5:28 PM Actually, there are laws that require the maintenance of specific types of records for business and legal purposes. So you can't delete some records at all. For example, the Federal Government must backup and keep ALL emails, written documents, and electronic documents forever. If you work for the Feds, you have no secrets on your computer. There is also the issue of recovery. Good techs with the right tools and software can recover data at least as many as 10 to 20 generations back or more. That is why file scrubber software often writes patterns over and over thousands of times to "clean" a hard disk. Usually bits of 1's and 0's in various patterns Exactly how many layers that can really be recovered is dependant on the current state of the art technology. The top of the line stuff is likely classified and in the hands of the government. The NSA, CIA, or the Military. Posted by: Guitar Man at October 21, 2007 11:08 PM It's funny that they spoke out of both sides of their mouth... 1st John O says we keep copies then we don't have copies. Posted by: Eduardo at July 24, 2008 1:29 PM Post a comment
Powered by Movable Type. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments