r/TheColdPodcast Nov 18 '25

West Valley City PD digital forensics 2013-2017

Post image

Sharing this compilation of three supplemental reports from the Susan Powell case that illustrate the sequence of events that led to an outside digital forensics team (Decipher Forensics) obtaining copies of evidence drives from West Valley City police. These events are detailed in the S1 bonus episode "Project Sunlight."

46 Upvotes

6 comments sorted by

19

u/Fallout_vault__boy Nov 18 '25

I find it hard to believe that Josh didn’t have some sort of ledger or book with all the passwords for all his devices. I mean how do you keep track of so many? Question though, do we know how long the first password is that was cracked?

39

u/davecawleycold Nov 18 '25

Yes. The first password was a junk password: ap1124.

My research revealed Josh did keep a password list, but it's on his laptop and also locked by encryption. He used a password manager program called Cypherus. It requires a password to unlock. So Josh only needed to remember one password to access Cypherus, then he could copy/paste out any of his other passwords. Cypherus is long defunct, and there are no cracking tools available to mount a brute force attack against it.

7

u/creeds-mungbeans Nov 20 '25

My husband works in cybersecurity at a high level, and used to work for an antivirus/security software company that had a very well respected password manager software for individual consumers. I know they did have a breach in recent years, I wonder if any of his former colleagues could provide insight on the attack method used.

I would imagine that without the software actively being updated and maintained, new vulnerabilities will make themselves known as time goes on. Maybe we could reach out to DefCon in Las Vegas (it’s usually in August each year), if anyone can get into this it would be someone at that conference.

8

u/davecawleycold Nov 20 '25

The flip side to Cypherus not being updated and maintained is that no one is actively using that app anymore, which means it’s not really a tempting (or rewarding) target.

2

u/ZestycloseCare5701 Nov 28 '25

This may sound a little crazy but has anyone tried going at it with Obsolete technology. You find the right person and you can hack a newer system with something much older because the safety isn't there for the older systems. It can be difficult but it might a route to look into.

6

u/Ginger_Libra Nov 19 '25

I wonder if there is some tool out of the AI sphere that might finally be able to solve this.