Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another thing I came to think of as well is that they often employ write-blockers, don’t they? Pieces of hardware that go between the computer and the storage media. So by the time decryption is demanded, it will be done with the system in a read-only state right?


They don't run forensics on the actual device if at all possible, only a read-only cloned image.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: