Or that they formatted them before returning them?
(And by "unknown" I mean of course "anything that is not FAT* or NTFS"...)
The moral of the story is for individuals, whom should implictly fear government overreach no matter whom is in office, one has to back their shit up and make it SWAT-proof, even if that means running several TahoeLAFS boxes in countries like Switzerland, because running a server (physical or Linode) or just replicating data to a friend's server just doesn't cut it and never did.
Thanks for reminding me to set up Amazon glacier for my FreeNas today. Jesus Christ, the world is a messed up place.
Disclaimer: I work on GCP
I wonder how would they handle full disk encryption.
Maybe that's what they wanted him to think. I refuse to believe the alternative...
you would think that national level stuff would have people take more care, but if you're dealing with state or local police, they will have someone who has taken an 8 hours Encase or FTK class driving a GUI to gather evidence and if the tool doesn't support it, there's effectively no evidence to gather.
I guess it depends on whether the hard drives were the target of the raid or just a collateral of "grab anything that may be useful" mindset. They could already have gathered enough evidence without needing to waste time/money on digital forensics. Hard to say without specifics.
The fact that they went out of their way to assure him that his own hard drives were empty reeks of manipulation.
Color me highly skeptical.
I had imagined that computer forensics "experts" would make this mistake somewhere at some point, but I did not think I would actually hear that it had happened. Thanks for the affirmation, even if it is just hearsay.
It makes me curious about what goofs were made with the IRS hard drives that had "crashed" according to forensics "experts".