Why does forensic analysis run on a verified duplicate instead of the original disk?
answer
- three objects: device, master, working copy
- analysis writes, even when it claims not to
- verified is an act, not a label
- discard a copy that fails, do not reason from it
- same digest lets others reproduce you
basics
~20 sAnalysis writes: tools mount, index, carve and cache. The original is sealed so it can be re-read later, and work runs on a copy whose digest you matched to the acquisition digest. Verified is an act, not a label.
solid answer
~50 sThe original device is the only irreplaceable thing in the case, and analysis is not read-only in practice — tools mount volumes, build indexes, carve files and write caches. So the original goes into storage after acquisition and everything happens against copies. A duplicate becomes a *working copy* only once you have computed its digest yourself and matched it to the one recorded at acquisition; if it does not match, you discard it and make another rather than reasoning from it. Keeping the master image pristine also means a damaged working copy costs nothing and, more importantly, that a second examiner or the other side's expert can take their own duplicate, compute the same digest, and argue about interpretation rather than about the bits. Re-verifying the master when you finish shows the authoritative copy is exactly as it was before you started looking at the miner's artefacts.
go deeper
Be able to say that examination runs on a copy and that the copy is checked against the digest recorded at acquisition before any analysis starts. Never open the original.
Explain the three objects — device, master image, working copy — and why analysis tooling writes even when it appears to read: mounting, indexing, carving and caches.
Show the judgment: when you re-verify, what you do when a copy fails, and how a shared acquisition digest lets an independent examiner reproduce you and moves the dispute onto interpretation.
Own where the master lives, who may take duplicates, what verification events the team performs by default, and how long the original device is retained against how long its media can be trusted.
## The chain from device to workbench There are three distinct objects and confusing them is the usual mistake. 1. **The original device** — the physical disk from the file server. Irreplaceable, possibly failing, sealed and stored after acquisition. 2. **The master image** — the acquired copy, with the digest recorded at capture. Treated as read-only for the life of the case. 3. **The working copy** — a duplicate of the master that the examiner actually opens. Analysis happens only on (3). If the working copy is damaged, cluttered by an experiment, or accidentally written to, it is deleted and remade from (2) at no cost to the case. ## Why not just work on the original Because examination is not passive. Forensic tooling mounts volumes, indexes content, extracts and carves files, builds databases of parsed artefacts, and writes caches. Some of that lands on the examination host, but plenty of it wants to land on the examined volume, and a general-purpose operating system will help it along by replaying journals and updating metadata. On a decade-old server disk there is a second reason: every read stresses hardware that is already failing, and the readable surface you have today may be smaller tomorrow. The original is read exactly twice — once to acquire, once to verify — and then left alone. ## What "verified" actually means It is not an attribute stamped on a file; it is an act. You compute the digest of the duplicate in front of you and compare it, yourself, to the digest recorded when the source was acquired. Equality means this copy is bit-identical to what came off the device. Anything else — a note in a ticket saying it was verified last month, a filename ending in *verified*, the fact that it came from the evidence store — is hearsay about a number, not the number. Practically, that means verifying at the points where the copy changes hands or changes location: when the image arrives from the acquisition, before a working copy is made from it, and before it is produced to another party. Each check is a fact you can state. ## Reproducibility, which is the real prize The single digest recorded at acquisition is what lets several people work independently and still be talking about the same evidence. A second examiner in your team, a colleague reviewing your work, and the other side's expert can each take a duplicate, compute the digest, and satisfy themselves that they are looking at the same bits you looked at. That collapses an entire category of argument. Nobody gets to suggest that the copy you examined and the copy they examined might have differed; the disagreement is forced onto interpretation of the miner's artefacts, which is where a technical dispute belongs. ## When a working copy fails verification Discard it. Do not analyse it "carefully", do not note the anomaly and continue — a copy that does not match the master is of unknown provenance and every observation from it is unusable. Make a fresh duplicate and verify again. If the second one also fails, stop copying and check the master itself against its acquisition digest: if the master has drifted, the problem is the evidence store or its media, and that is a much bigger finding than a bad copy. ## Re-verifying at the end When the examination is finished, recomputing the master's digest and showing it equals the acquisition value demonstrates that the authoritative copy is byte-for-byte what it was before you started. It closes the obvious question — did the examination itself change the evidence — with a number rather than an assurance. It is cheap, and its absence is conspicuous. ## The distinction to hold on to Write-blocking protects the source *during* acquisition. Working from a verified duplicate protects the master *after* acquisition, for however long the case runs. They are the same principle applied at two different moments, and an examiner who applies one and not the other has a gap that is easy to exploit.
- Your working copy no longer matches the master image. What do you do?Discard it and make a fresh duplicate — a copy of unknown provenance cannot support any observation, however careful you were. If the second duplicate also fails, check the master against its acquisition digest; drift there points at the evidence store or its media, which is a far more serious problem than one bad copy.
- What does re-verifying the master image when the examination ends actually add?It answers the obvious challenge — that the examination itself altered the evidence — with a recomputed number rather than an assurance. It also catches silent storage problems while you can still do something about them, and its absence is conspicuous to anyone reviewing the work.
- Why does handing the opposing expert the same recorded digest help you?It removes any argument that you examined different bits from the ones they examined. They verify their duplicate against the digest recorded at acquisition and the dispute narrows to interpretation of the artefacts, which is a technical argument you can have on the merits.
The master image is the negative and the working copy is a print. You mark up prints all day; you never take a pen to the negative, and anyone can produce their own print from it.
saying these in an interview costs you the question
- Treats a file labelled verified as verified
- Analyses the original because the tool opens read-only
- Continues working from a copy that failed verification
- Cannot distinguish the master image from a working copy
- Never re-verifies the master after examination