Since I watched this monkey and organ grinder show I have become more and more irritated by the whole "expert" and "analysis" piece they spewed.
From someone who has actually had to stand up in court and support the digital forensics my teams have run on suspect electronic documents, forged emails, scanned images etc here are a small selection of the typical questions that I have had to defend and need to be answered........
What methodologies did the CCP and their “experts” use to seize forensically sound originals of the images they “analyzed”
Did they have access to the data storage device the file resides on or did they simply copy a file over the internet
If they did not have access to the originating storage media, what steps could they have undertaken to ensure the file they worked on is the file stored on the originating media.
Where are the work books detailing the steps undertaken, tests performed, individuals performing them, test software and hardware used
What methods were used to ensure inviolate copies of the seized originals
What steps were taken to take forensically sound working images of the “frozen” images
What steps were taken to ensure that the files being analyzed had a sound, inviolate chain of custody from start to finish
Which hashing method, version and application did they use
Where and how were the hash values stored and can they be demonstrated not to have been altered, amended or changed at any stage
Since, by the very nature of electronic transfer of data via the Internet, data can and (unless sound methods are in place) will be changed during the transfer and recording process, what steps, policies, processes, procedures, applications and methodologies were used to ensure an inviolate and sound copy was transferred.
What steps were undertaken to ensure that the file that was identified and copied was in point of fact originating from their supposed target. For example was any network traffic analysis undertaken to provide some surety that the believed target was the actual target.
In addition what steps if any were taken to ensure that the data was not maliciously or inadvertently altered, amended, changed or corrupted in transit through multiple routers and routes.
When the file was being worked on what assumptions were taken and worked on and where is the record in the report.
When the file was initially analyzed was it noted and recorded that the file meta data indicated it was created using a Mac computer using an operating system specific and embedded process to create a PDF file via scanning.
If so noted, where is it recorded in the working documents and where is the decision matrix explaining exactly which criteria were used to NOT replicate this and instead use Windows PC’s, a Windows operating system and a third party application to create a PDF.
Where is it documented and recorded that the CCP and their analysts identified which model, make and manufacturer of scanner was used to create the file and where is it also noted that the CCP and their analysts used the same to create and work on their images.
Now, that's 17 questions, I could probably flesh out a hell of a lot more.