The increasing use of full disk encryption can significantly hamper digital investigations, potentially preventing access to all digital evidence in a case. The paper does go on to suggest some ways to ameliorate these issues, though better awareness at the evidence-gathering stage would help, though it also suggests “on-scene forensic acquisition” of data, which involves ripping unencrypted data from volatile, live memory with the cryogenic RAM freezing technique. Ultimately, the researchers aren’t hopeful: “Research is needed to develop new techniques and technology for breaking or bypassing”
Source: https://thehackernews.com/2011/11/is-it-hard-to-crack-full-disk.html