4 ms·
UK Police are interested in finding non-exculpatory evidence and securing convictions. Computer forensics usually means software bought from a vendor and opera
by dpwm 5y ago
UK Police are interested in finding non-exculpatory evidence and securing convictions.
Computer forensics usually means software bought from a vendor and operated by a technician sometimes with no deep technical knowledge beyond the tool they use. It probably even works well for the common case, but breaks in cases where something unusual has happened.
UK ISPs mostly use an IP pool – meaning they have to keep records about who was assigned which IP at which time. Some may run carrier-grade NAT. Those records are obviously trusted, but may not necessarily be accurate – and even if they are, human mistakes occur, especially when working with things like IP addresses, dates and timezones.
But if not for following IP addresses, how else do you investigate this sort of thing?
I would argue the fault is in a mentality that suggests presuming guilt based on an IP address, then looking for the confirmatory evidence as an "icing on the cake," and a mentality that the investigation process should be so harrowing that the guilty will always go punished even if there isn’t enough evidence for an attempt at conviction. This is long after several such scandals around the same type of crimes.