I've pulled together what we can learn from the October 22, 2020 CYA memo on the Hunter Biden laptop. Hoping some tech folks, esp @malwarejake and @matthew_d_green can review it to see if they can figure out why FBI had to install laptop hard drive in new laptop to get an image of it.

https://www.emptywheel.net/2023/07/06/the-technical-oddities-of-the-fbis-exploitation-of-hunter-bidens-laptop/

The Technical Oddities of the FBI's Exploitation of Hunter Biden's Laptop - emptywheel

For some reason, the FBI deemed it necessary to buy a new laptop and install the hard drive from the laptop once owned by Hunter Biden before it could image the laptop.

emptywheel
@emptywheel forensic practice would be to pull the drive and connect it via a write blocking cable/device over usb to a forensic tech’s computer possibly with another usb drive to then image the drive with out altering its contents.

@wpoland @emptywheel

This.

You don't even need a write-blocking cable (although it's the safe way). You can just set a Mac to not mount disks at plug in, and then mount it by hand read-only. After that, the SSD sits sealed in a bag, and everybody works from locked read-only disk image copies (dmg or iso files) that are easy to share and faster than an SSD.

(You do also need an Apple proprietary enclosure for the non-standard Apple SSDs. Widely available.)

@thomasafine @wpoland @emptywheel the big thing a write blocking cable preserves is admissibility. It's basically as important as chain of custody which in this case is already a bad joke.

"[Some guy who might or might not have been Hunter Biden dropped off this laptop for repair then never came back to pick it up and pay for the work. Once it was legally deemed abandoned and became my property I started it up and started snooping through it, then called some people who hate Hunter Biden's father and let them have unfettered and unrecorded access to it as well. There's some very incriminating stuff on there!]"