Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why? It's people following a forensics script/program which looks for Windows partitions. There aren't a huge number of people who understand this kind of thing and most of them are able to work at places where they're paid much better than the FBI.


the forensics programs (EnCase, FTK) have a lot of problems but they don't assume that the drive is "windows partitions" though it's possible that they don't deal with ZFS.

you would think that national level stuff would have people take more care, but if you're dealing with state or local police, they will have someone who has taken an 8 hours Encase or FTK class driving a GUI to gather evidence and if the tool doesn't support it, there's effectively no evidence to gather.


Yeah, I once had to explain to an officer what a known_hosts file is so they could send MLAT requests and release me from jail without risking that I would wipe (the already automatically wiped) servers myself when I got out.


You're going to go through the trouble to get a warrant for a raid and then apply such gross incompetence to the seized evidence? When was the last time you pulled a hard drive out of a functioning machine, found it to be empty and didn't immediately think, "huh, that's odd" before throwing it in the trash.

I guess it depends on whether the hard drives were the target of the raid or just a collateral of "grab anything that may be useful" mindset. They could already have gathered enough evidence without needing to waste time/money on digital forensics. Hard to say without specifics.

The fact that they went out of their way to assure him that his own hard drives were empty reeks of manipulation.

Color me highly skeptical.


I'll color you trusting: you are choosing to be fixedly _un_-skeptical of the FBI's competence.


Slightly off topic, but it really isn't hard to find partitions. Just run the various software to scan and that's it. I've done it at least twice when accidentally erasing a windows partition (once with fdisk when I misread the output, and at that time I didn't even know what a partition is).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: