I was thinking about this after I posted this. One thing that worries me is that Windows is closed source. It also has way too many parts that are completely undocumented. How can we ever be certain that some registry value we didn't consider won't allow an evidence drive to be formatted or that scandisk won't automatically kick in. With Nix, we can at least look at the source code and reasonable say that no, we can't write to the drive if this flag is set.
Encase isn't open source and it is the big dog in the forensics industry. To be admissable you don't have to look at the source code to prove it, you just have to recreate it in court. If you do the same process over and over again your results are provably the same.
What ever happened to Coffee (sp?) that Microsoft released to certain segments of the forensic arena? I can't find much on it.