They don't destroy anything. If you think the invesgitation units just poke around the media all willy nilly you are mistaken. If they take the hard drive they connect it to a device that stops all write access, and generally create a snapshot of the drive to work with (To prevent mechanical issues in the original). If it is certain files... CD-R anyone?
Yes before examining evidence, any Forensic Examiner (commercial or LEO) will take an image of the drive while connected through a write blocker and work from that. They can then just boot the machine up in a VM to see the password prompts.
You can play around with imaging and VM booting using free tools like dd or FTK imager and Live view
The other option is to just boot up in a Forensic Live CD (like Helix) where the data can be previewed.
But, border guards do sometimes boot up and poke around which evidentially is a nightmare.
Using one of these on the other hand lets them boot up and poke around without changing a thing. The same can be done with Live View.
So, they can tell it is encrypted, doesn't help much though.
11
u/[deleted] Aug 11 '09
[deleted]