All the latest UK technology news, reviews and analysis

Microsoft confirms Cofee spill

by Dave Neal

11 Nov 2009

Comment: 1

  • Tweet this
police car
Cofee was intended for use by law enforcement teams

Microsoft has confirmed that its crime scene computer forensic software Cofee has been leaked onto the net.

Richard Boscovich, senior attorney of Microsoft's Internet Safety Enforcement Team, said in a statement that the software had been leaked onto filesharing and torrent sites "improperly", and urged anyone who has seen it not to download it.

"We have confirmed that unauthorised and modified versions of Microsoft’s Cofee tool have been improperly posted to bit torrent networks for public download," he said.

"We strongly recommend against downloading any technology purporting to be Cofee outside of authorised channels – both because any unauthorised technology may not be what it claims to be and because Microsoft has only granted legal usage rights for our Cofee technology for law-enforcement purposes for which the tool was designed."

However, he poured cold water on suggestions that the software could be manipulated so that it could be used by criminals to steal information. Earlier this week Graham Cluley, senior technology consultant at Sophos, said that criminals could set up systems that would react when Cofee is being used on their machine.

"That might make life difficult for the computer cops when they try to dash-and-grab data from a suspicious PC," he said.

Boscovich countered, "We do not anticipate the possible availability of Cofee for cybercriminals to download and find ways to ‘build around’ to be a significant concern.

"Cofee was designed and provided for use by law enforcement with proper legal authority, but is essentially a collection of digital forensic tools already commonly used around the world. Its value for law enforcement is not in secret functionality unknown to cybercriminals, its value is in the way Cofee brings those tools together in a simple and customisable format for law-enforcement us e in the field."

He added that Microsoft was committed to stopping the leaks and encouraged all parties not to download Cofee illegally.

"In co-operation with our partners, we will continue to work to mitigate unauthorised distribution of our technology beyond the means for which it’s been legally provided and, again, would strongly discourage people from downloading unauthorised versions of the tool," he said.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

0%

11%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Application Security SME, Penetration Tester / Ethical Hacker

Application Security SME, Penetration Tester / Ethical...

Java Developer

Java Developer Thomas Cook Online is the business unit...

Contract Systems Administrator, Windows £320 per day

Contract Systems Administrator, Southampton My...

PHP Web Developer, PHP, to £30k + 30% bonus

PHP Web Developer required to join my market-leading...

To send to more than one email address, simply separate each address with a comma.