COFEE is just an epic failure as a computer forensics tool simply because when it comes to Forensics the accepted Medium is to switch off the machine, remove the Hard-Disk and then Mirror the contents of the hard-disk in a secure read only medium such as LibEWF or Expert Witness Format.
Unfortunately when a tool like COFEE that is inserted into the machine on USB, whilst it's running, cracking the password as it's inserted, it would access the RAM on the machine when it got inserted. Which can be construed as Data Tampering as it would have to Read & Write Data from the Hard-Disk!
By reading and writing to the Suspects computer via a USB device it paves the possibility of a rouge application spreading via the USB. How can anyone determine the effects of COFEE if it is closed source and distributes in the marvelous Self *.exe'cuting Binary .Win32 format?
In Forensics, you read and reconstruct the Data from a Disk-Image of the HDD or in the Case of a USB device you would Extract the Data from Thumbs.db which is a hidden file on any Fat16 formatted USB Pen. Only the accepted norm is you do not tamper with the Data in anyway by allowing your machine to Write to it!
As a younger (20's) half reader who also happens to be a pro photographer, I think the hyperbole of "all apps on the web!" is silly. Tell me, when will my upload speed equal the speed of my 10,000 RPM Raptor HD's? My Core 2 Duo? Man, I can't sit around and wait while 75MB RAW files are uploaded to someone else's computer (that's all a server is, after all). This is the day and age of the personal super computer. Outsourcing apps to the web and cheering their stripped down interfaces isn't progress to me. It's like watching your neighbor's HD TV through the window with binoculars.
Unfortunately when a tool like COFEE that is inserted into the machine on USB, whilst it's running, cracking the password as it's inserted, it would access the RAM on the machine when it got inserted. Which can be construed as Data Tampering as it would have to Read & Write Data from the Hard-Disk!
By reading and writing to the Suspects computer via a USB device it paves the possibility of a rouge application spreading via the USB. How can anyone determine the effects of COFEE if it is closed source and distributes in the marvelous Self *.exe'cuting Binary .Win32 format?
In Forensics, you read and reconstruct the Data from a Disk-Image of the HDD or in the Case of a USB device you would Extract the Data from Thumbs.db which is a hidden file on any Fat16 formatted USB Pen. Only the accepted norm is you do not tamper with the Data in anyway by allowing your machine to Write to it!