Forensic Ground Rules Applied to IoT
Digital forensic fundamentals apply to IoT devices without modification. Collection comes first, then examination, analysis, and reporting. Locard’s exchange principle holds at the edge: a perpetrator who touches an IoT device leaves traces. Findings must be reproducible by a second examiner or a court will discard them. Magnet Axiom and Cellebrite log every file an examiner opens; tools like Autopsy require manual effort to build the same audit trail. The supervising authority has final say, and the collection process must be identical every time.
Inside a $7,000 Chinese Voting Machine
Hari Hursti, founder of the DEF CON voting village, paid $7,000 plus $150 shipping for a Chinese prototype built to US politician specifications. The machine includes a touchscreen, a camera that records voters, a fingerprint reader, and a driver’s license scanner, plus Bluetooth, Wi-Fi, and 4G. Recording voters by camera violates US law. Thermal receipt paper degrades in 15-20 seconds. The device manual ships exclusively through Alibaba channels, one precinct at a time, so the open-source community cannot audit it.
Chip-Off Extraction and NSRL Filtering
The forensic team brought a $1,500 Pelican case of tools; TSA crushed the critical USB cable during transit. IoT village volunteers rebuilt the cable ends and ran a chip-off extraction overnight, producing a 1283.8 gigabyte image. File identification via GPT pinned the OS to Android 7.1. Loaded against the NSRL hash database, the team filtered out known-good files and targeted the anomalies for reverse engineering. Voting officials reviewed the findings and rejected the machine outright.
Time Card Fraud via a Hidden iPhone
A contractor hid a powered iPhone 4 under a box behind a bookshelf in a corporate building. The device connected to the guest Wi-Fi and beaconed at 9:00 a.m. and 5:00 p.m. daily, simulating login and logout for time card fraud. The phone was registered in the contractor’s real name. Splunk logs revealed multiple co-workers running the same automated schedule. Power supply meant the device could stay indefinitely and beacon continuously without battery constraints.
IoT Signals That Expose North Korean IT Workers
North Korean IT workers ship corporate laptops to US-based farms running 20-100 devices per location. An $800 Pi KVM connects up to 20 machines to one keyboard, mouse, and monitor, so one person can hold 20 simultaneous jobs and funnel income past sanctions. Detection signals: Linux emulators in 2FA logs, multiple iPhones or AirPod pairs connected to one remote account, and VPN geolocation mismatches. Duo and similar tools expose precise latitude and longitude. Wigle.net and Splunk badge logs confirm whether the worker is physically present.
Q&A
What gives away a North Korean IT worker on a video call? The camera never works. Asking them to walk to a window exposes the lie: on one call the worker claimed Northern Virginia while it was pitch black outside in Beijing time. Calling them the wrong name and watching whether they correct you reveals whether they still remember their own persona. ▶ 21:53
Notable Quotes
That violates US law. Will Baggett · ▶ 5:28
It’s like a bad MontiPython skit. Will Baggett · ▶ 15:40
Wi-Fi doesn’t reach my window. Will Baggett · ▶ 22:15
Key Takeaways
- A $7,000 Chinese voting machine collected fingerprints and driver’s licenses in clear US legal violation.
- Powered IoT implants beacon indefinitely; the power source reveals collection capability and intended persistence.
- Pi KVM devices connecting 20 machines to one user are the primary North Korean IT worker indicator.
About the Speaker(s)
Will Baggett is a Lead Investigator for Digital Forensics and Insider Threat at a Fiscal Infrastructure organization. He also serves as Director of Digital Forensics at Operation Safe Escape, a volunteer non-profit providing assistance to domestic abuse victims.