On ZDNet: Why email is your enemy

Search:
Go!




Click Here
Security Watch : Don't get burned by viruses and hackers
Use an iPod, go to jail?
By Robert Vamosi 
Senior editor, CNET Reviews
January 20, 2006

Back 2001 and 2002, in the southeast corner of London, a gang of thieves defrauded dealers of Jaguars, Mercedes, and BMWs by hijacking someone else's identity and using that information to make loan-free car purchases. In the end, it was the presence of several high-end cars parked in a relatively poor neighborhood that led authorities to raid one of the addresses there. The incriminating evidence they found at the scene? An iPod crammed with stolen identities and contact information of criminal associates.

iPod gets bigger, more ubiquitous
The Apple iPod is a great music player and a passable video device, but at its core, it's a multiplatform (Mac, Windows, and, yes, even Linux OS) flash or hard drive with the capacity of up to 60GB that you can slip into your shirt pocket. I have a 40GB hard drive on a notebook at my desk, and I'm nowhere near filling that. In other words, with an iPod, I can take the maxed-out contents of my notebook, plus an additional 20GB of data anywhere I go.

Before you think Apple has created the perfect socially acceptable, high-data volume criminal accessory, think again.

Which gets us back to the above-mentioned crime: iPods have not only grown in capacity but in functionality as well; they include rudimentary contact management features, plus the ability to store data files of any kind. For example, members of the London gang were able to use their iPods to download and save copies of other people's bank statements, credit statements, and driver's licenses, as well as coordinate appointments at dealerships, and do so in plain sight of everyone. But before you think Apple has created the perfect socially acceptable, high-data volume criminal accessory, think again.

The iPod, soon to be seen on CSI?
Turns out Apple did some clever things within the iPod that should indirectly help criminal investigators and discourage would-be criminals. I found this PDF-formated forensic document examining the iPod's file structure. (The document predates the iPod Shuffle and the iPod Nano, both of which use flash memory instead of a hard drive, and the following discussion refers only to the hard drive versions, not the flash-based models.) The authors, Christopher Marisco and Marcus K. Rogers, from Purdue University, point out that unlike PDAs, which have to remain charged or lose their data, iPods can remain in storage for a long time; that's good if a trial takes several years to commence, because the data will last. But more importantly, the authors found that deleted data on the iPod tends to last a long time, as well.

On a typical Windows drive, deleted files aren't really deleted, they are taken out of the master boot record, but the files themselves remain on the hard drive. The deleted files aren't accessible by users, but the space used can be and often is overwritten by new files. This can cause uneven wear on the drives. iPods are similar, in that deleted files aren't strictly erased, just marked as such. But Apple made it so that the tiny iPods write to the drive until the disk's real estate is used before rewriting space that holds files that are marked as deleted. For a criminal investigator, that's a boon: old data is less likely to be overwritten. If you did commit a crime, just deleting the evidence isn't going to help.

I recommend drilling several holes through the "dead" iPod to make sure the drive tells no tales.

Better yet, iPods also remember where data came from. Say you used a computer at work to copy a large, top-secret program to your iPod to take home. Coding within the file would tell investigators not only what machine (MAC address) but also what operating system (though file format also tells them that) and username was used. So if incriminating evidence is found on your iPod, they can connect it to a crime scene.

I suspect the authors (or others) will attempt a similar paper on the flash-based iPod Shuffle and iPod Nano as iPods continue to surface as part of criminal investigations.

Doesn't apply to me
But you and me, we're law-abiding, right? So let's say you just want to discard your old iPod. At present, I'm not aware of any iPod erasing or shredding programs, but it would be a good idea to delete everything you can before letting it go. The above-mentioned ability to read deleted files is limited to special software packages, such as Guidance Software EnCase, so it's unlikely that the average person would be able to recover your deleted personal files with off-the-shelf technology. To be safe, though, I recommend drilling several holes through the "dead" iPod to make sure the drive tells no tales.

What if you lose your iPod? Then you're out of luck. Someone could learn that you have Achy, Breaky Heart on your playlist, embarrassing, yes, but someone could also access personal data--or corporate data--which could be more than embarrassing. Here the recommendation is caution: Be careful what information you put on removable media such as an iPod. Remember that deleting data doesn't necessarily completely remove that data.

What do you store on your iPod besides music? Talk back to me.



CNET's free newsletters
Rob Vamosi's
award-winning
column on Internet threats and how to counter them 
Delivered Mondays


TalkBack
89 messages

Article discussion: Security Watch: Use an iPod, go to jail?


Latest post:

"NYC subways"
by lenoxhill21 (See profile) - February 10, 2006 2:50 PM PST
So this sheds some light as to why the crime rate is very high for IPod thefts on NYC subways. No other MP3 players or similiar storage devices, just IPods in particular. There a... (Read more).
Sort by: Title |
Date
| Most helpful

Most people don't have Ipods!

This whole article is a thinly veiled attempt by one of the Apple cult members t... (Read more)
by MaxSMoke (See profile) - January 29, 2006 4:22 PM PST

Unerasability is a myth

Computer users are constantly being told that data can't be erased, and this art... (Read more)
by Inditek (See profile) - January 29, 2006 12:39 AM PST

I like this

>> It is clear that the writer does not know Macintosh and his criticism a... (Read more)
by tonezzz (See profile) - January 25, 2006 8:30 PM PST

Who's really smart?

Have you ever heard that Bill Gates and Steeve Jobs had meeting sometimes? Do y... (Read more)
by tonezzz (See profile) - January 25, 2006 6:39 PM PST

disable, wipe, encrypt - and WHY they do it.

iPods use the data that's on them. If you don't want your
contacts in an ea... (Read more)
by wjanoch (See profile) - January 25, 2006 10:57 AM PST

Same standards with any device

If a device records or has storage and i'm
worryed about what i'm trying to ... (Read more)
by zbeast (See profile) - January 25, 2006 10:45 AM PST

Easy Fix with Diskutil

In fact, Apple appears to be aware of these data privacy issues
and has take... (Read more)
by jasonsewell (See profile) - January 25, 2006 10:06 AM PST

Guidance EnCase? Use AccessData FTK!!

If you want an easy-to-use interface and a better product for forensic disk anal... (Read more)
by someguy12345 (See profile) - January 25, 2006 9:21 AM PST

Ipod fan thru and thru!!!

I received a 30G IPOD video from my fiancee for xmas this year. Along with the i... (Read more)
by rwalt76 (See profile) - January 25, 2006 8:11 AM PST


© 2008 CNET Networks, Inc., a CBS Company. All rights reserved. | Privacy Policy | Terms of Use