Restored from the project wiki (we.riseup.net), which is no longer online.
During a seizure it is worth paying attention to a few details:
At the end of the seizure all the digital material will be analysed by a forensic technician. At this stage it is possible to:
If the acquisition is carried out under article 359 of the Italian code of criminal procedure (c.p.p.), it is repeatable. The CTP (party-appointed technical consultant) will therefore be able to carry out the examination again on a forensic copy.
In some cases (smartphones or other devices) it is not possible to make a forensic copy of the data, so the analysis is carried out – under article 360 c.p.p. – directly on the original medium and cannot be repeated by the CTP (party-appointed expert). The presence of a CTP becomes particularly important in these situations because, since the analysis cannot be repeated, the only way to make sure the operations were carried out correctly is to be present at them.
Requesting the forensic copy acquired by the police is a very expensive procedure that can end up costing thousands of euros.
Unfortunately, though, if a counter-examination has to be carried out, the CTP (party-appointed technical consultant) must be able to have a copy to work on.
Once the material has been released (if you avoid using the computer), you have the original material used by the CTU (court-appointed technical consultant) to create the forensic copy that will be analysed. This means that the CTP (party-appointed technical consultant) can go ahead with a new acquisition using our computer, thereby saving us from having to spend a lot of money needlessly.
It is therefore important NOT to use the computer that has just been released.
It is then possible to verify, using particular tools, that the copy made by the CTP is identical to the one used by the CTU and therefore usable for carrying out the counter-examination.
In addition, carrying out a further forensic acquisition – especially if you were not present at the acquisition procedures carried out by the CTU – is also useful for working out whether the computer has been tampered with, or whether the acquisition procedure was carried out in an anomalous way.