FULL - DISKENCRYPTION · A GUIDE FOR UK LAWYERS
Bit Locker, File Vault and Full-Disk Encryption
Recovery Keys, Escrow and What the Encrypted Drive Really Does and Does Not
Protect
COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR
PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM
ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES ENCRYPTED-DRIVE EXAM IN AT I ON
RECOVERY-KEY & ESCROW ANALYSIS CPR PART 35 EXPERT REPORT S
FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS
In this guide
01 Executive summary
02 The problem in plain English: encryption built to be recovered
03 How Bit Locker, File Vault and LUKS actually work
04 Where the recovery keys live: directory, console, cloud and escrow
05 Obtaining the key law full y and imaging the decrypted volume
06 When there is no key: the genuinely inaccessible drive
07 Deployment: the recovery position, disclosure and honest limits
08 Source architecture: where else the evidence lives
09 Worked examples
10 Common mistakes and technical limitations
11 Questions to ask · Suggested wording
12 Checklist and red flags · When to involve a digital forensic expert
13 Frequently asked questions
14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION
Executive summary
THE HEADLINE POINT: FULL - DISKENCRYPTIONISDESIGNEDTOBERECOVERABLE, AND
INAMANAGEDENVIRONMENTTHERECOVERYKEYALMOSTALWAYSEXISTSSOMEWHERE
THEORGANISATIONCONTROLS: THE EXAMINER ' SFIRSTTASKISTOFINDTHATKEY,
NOTTOATTACKTHEENCRYPTION, ANDONLYWHERENOESCROWEDKEYEXISTSISTHE
DRIVEGENUINELYBEYONDREACH
§ 02 · FIRST PRINCIPLES
The problem in plain English: encryption built to be recovered
§ 03 · HOW IT WORK S
How Bit Locker, File Vault and LUKS actually work