But the police have a well designed chain of custody system to at least reduce the possibility of tampering. Not everybody in the office can tamper with evidence behind lock and key with seals -- of course it still happens, but the goal is to reduce the possibility.
This falls apart when the evidence in question is data that can be copied, altered, etc.
And of course we can likely come up with clever cryptographic answers to this problem, but in the end, it's far easier and a more understood procedure for the police just to grab hardware and seal it up.
Keep in mind that ultimately the chain of custody must be explained to a jury, to convince them that what they're being shown actually comes from the defendant's computer, while a defense attorney does his best to sow doubt in the jury's minds.
Do you want to explain to 12 randomly selected people how virtual disks work, and the cryptographic algorithms you used to ensure that the data you're showing them is identical to the data the defendant had on their system? Could you explain it so well that a reasonably skilled defense attorney couldn't confuse them enough to produce reasonable doubt?
I don't think it does answer the question, though. The data is the evidence rather than the medium it exists on. What guarantee is made that the disk wasn't tampered with that cannot be made by a cryptographic signature...
...or is the answer that the law has no adequate treatment of abstract evidence?
Honest question: why are physical hard disks more valid as evidence than virtual ones? Aren't they equally easy to tamper with?