I've pulled together what we can learn from the October 22, 2020 CYA memo on the Hunter Biden laptop. Hoping some tech folks, esp @malwarejake and @matthew_d_green can review it to see if they can figure out why FBI had to install laptop hard drive in new laptop to get an image of it.

https://www.emptywheel.net/2023/07/06/the-technical-oddities-of-the-fbis-exploitation-of-hunter-bidens-laptop/

The Technical Oddities of the FBI's Exploitation of Hunter Biden's Laptop - emptywheel

For some reason, the FBI deemed it necessary to buy a new laptop and install the hard drive from the laptop once owned by Hunter Biden before it could image the laptop.

emptywheel
@emptywheel @matthew_d_green
Taking a look now.

@emptywheel @matthew_d_green After a cursory review of the whistleblower transcript (item 20), there is no reason I can see why you'd do this. It's honestly a bit perplexing to me. But this drive seems to have been mishandled at every turn - at least this is consistent...

Alternate theory: it's inarticulate wording?

@malwarejake @emptywheel @matthew_d_green It seems like the last thing you'd want to do is boot it. I'd use something like a gparted boot disk or Puppy Linux to boot from usb and image the whole drive that way.

i assume there are more professional equivalent tools.

@RandomNunesParody @emptywheel @matthew_d_green Definitely, though we may be seeing the telephone game effect at play here.
@malwarejake I think I'm pretty close to convinced there are material inconsistencies between thta laptop and what has been released. @RandomNunesParody @matthew_d_green

@emptywheel @malwarejake @RandomNunesParody @matthew_d_green

Nunes' Parody beat me to it. You absolutely would not want to boot the thing directly. Every time you boot, the OS scribbles something on the drives. (Especially if there's additional stuff [e.g. malware] on it.) So you really do want to put it on a separate system that treats it as read-only data. One shouldn't need to be a computer forensics expert to know this.