Looks like computer crimes investigators have some legal tricks (and some below-the-radar techs) at their disposal to help them tip the scales in their favor...

I did raise the question of how do they deal with encrypted file systems. There are 2 ways:- One is a bit of legislation which requires the accused to give up the password or be liable to a sentence of up to 2 years. The other is they take the disk to some shady government people with an office on the banks of the Thames in London and they just get the data back, no questions asked.

I did wonder if the technology such as the forth coming ZFS encryption would make their life harder, but they often take an disk image of the system before it is powered off and removed. The other point they made is that all but the most organised criminals are not computer literate enough and make enough mistakes to make acquiring forensics evidence possible. They deal quite happily today with Bitlocker, in most cases as the password used to encrypt data is the same as the password used to log in.