<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cell phones Archives - Burgess Forensics</title>
	<atom:link href="https://burgessforensics.com/category/cell-phones/feed/" rel="self" type="application/rss+xml" />
	<link>https://burgessforensics.com/category/cell-phones/</link>
	<description>Computer Forensics, Electronic Discovery &#38; Expert Witness</description>
	<lastBuildDate>Mon, 31 Aug 2026 22:28:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://burgessforensics.com/wp-content/uploads/2016/08/burgess-42x42.png</url>
	<title>Cell phones Archives - Burgess Forensics</title>
	<link>https://burgessforensics.com/category/cell-phones/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed</title>
		<link>https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/</link>
					<comments>https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 22:28:12 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16213</guid>

					<description><![CDATA[<p>Your phone has been keeping a travel diary. For years, Google kept a copy too. That made possible one of the more controversial investigative tools of the smartphone era: the geofence warrant, sometimes called a reverse-location warrant. Instead of starting with a suspect and asking where that person’s phone had been, police could start with [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/">Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed' data-link='https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/' data-app-id-name='category_above_content'></div><p>Your phone has been keeping a travel diary. For years, Google kept a copy too.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/phone-diary.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16219 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/phone-diary-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>That made possible one of the more controversial investigative tools of the smartphone era: the geofence warrant, sometimes called a reverse-location warrant. Instead of starting with a suspect and asking where that person’s phone had been, police could start with a place and a time and ask Google which devices had been there.</p>
<p>It was the sort of technology made for a crime show and sure enough, it’s likely been in countless episodes of this and that cop show, with thousands of mentions in the news headlines. Draw a circle around the crime scene, pick a time window, find the phones inside it and start looking for your suspect.</p>
<p>There was just one problem. By the time the Supreme Court finally ruled on the practice this summer, Google had already pulled the plug on the system that made the classic Google geofence warrant work.<img loading="lazy" decoding="async" class="size-medium wp-image-16216 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/Geofencing-300x225.jpg" alt="" width="300" height="225" /></p>
<p><strong>First, what exactly is geofencing?</strong></p>
<p>The terminology gets muddled, especially outside the technical world.</p>
<p>Geofencing is a technology; a geofence warrant is a legal process that uses location records in a very particular way.</p>
<p><strong>Geofencing itself is not dead, illegal or particularly exotic.</strong> A geofence is simply a virtual geographic boundary. Apps can use one to do something when a device enters or leaves an area. Retailers can use it to serve ads, which is just what we need – more ads, no? Your shopping app can notice that you’re near a store. A fleet-management system can report when a truck reaches a destination. Your smart-home system might turn on the lights for you when you get home.</p>
<p>A <strong>geofence warrant</strong> turns the idea around.</p>
<p>Instead of asking whether one known device crossed a boundary, investigators historically could give Google a geographic area and a time period and compel it to search its Location History database for devices whose records put them inside the “fence.” Initially, Google returned anonymized device information. Investigators could then narrow the candidates and, through additional steps, obtain identifying information. For some time, the technique was anything but obscure: Google received 982 geofence warrants in 2018 and more than 11,000 in 2020.</p>
<p>An ordinary warrant says, in effect, “Tell me where this person was.”</p>
<p>A geofence warrant says, “Tell me who was here.”</p>
<p>That difference became a rather large constitutional question.</p>
<p><strong>Then Google changed the map.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/location-history-dead.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16218 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/location-history-dead-300x225.jpg" alt="" width="300" height="225" /></a></strong></p>
<p>In December 2023, Google announced a major redesign of Location History, now presented to users as Google Maps Timeline. Instead of keeping Timeline centrally on Google’s servers, Google said the information would be stored on the user’s device.</p>
<p>Google’s public explanation emphasized privacy and customer control. The company said putting Timeline on the device would give users “even more control” over this personal information. Location History was already opt-in and off by default.</p>
<p>There was another consequence, and it was a big one.</p>
<p>Once Google no longer possessed a giant centralized repository of users’ Location History, police could no longer hand Google a circle and a time period and have it search that repository for everybody inside.</p>
<p>Reporting at the time suggested that was not an accidental side effect. <em>Forbes</em> reported that a Google employee said that, along with the privacy benefits, the change was intended specifically to bring an end to these broad location searches. Google’s public announcement itself did not say that, so I wouldn’t put words in Google’s mouth. But the practical result is beyond dispute.</p>
<p>The migration took time. By July 2025, according to Google and the Supreme Court, Location History was being stored on individual devices rather than Google’s servers. Google told the Court that it was therefore no longer capable of responding to geofence warrants seeking that Location History data<strong>.</strong></p>
<p>In other words, Google leapfrogged SCOTUS and redesigned where location evidence was stored.</p>
<p><strong>Then SCOTUS arrived. </strong>On June 29, 2026, the Supreme Court decided <strong><em>Chatrie v. United States</em></strong>.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/scotus-geofence.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16221 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/scotus-geofence-300x300.jpg" alt="" width="300" height="300" /></a>The case arose from a 2019 Virginia credit union robbery. Investigators did not initially know who the robber was. They obtained a geofence warrant directing Google to search Location History information for devices in the area with a 150-meter radius around the building during the relevant period. That process eventually helped identify Okello Chatrie.</p>
<p>The Supreme Court held that police conducted a Fourth Amendment search when they acquired Chatrie’s location information from Google, because a person has a reasonable expectation of privacy in his cellphone location information.</p>
<p>That’s significant., but it is narrower than saying, “The Supreme Court outlawed geofence warrants.” It didn’t.</p>
<p>&nbsp;</p>
<p>The Court did not decide that every conceivable geofence warrant is unconstitutional, nor did it finally resolve whether the particular warrant in <em>Chatrie</em> satisfied all the requirements of the Fourth Amendment. Those questions remain more complicated.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/robber-scotus.jpg"><img loading="lazy" decoding="async" class="wp-image-16220 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/robber-scotus-300x200.jpg" alt="" width="537" height="358" /></a></p>
<p>And there is a touch of technological irony here. Justice Alito’s dissent actually called the Google procedure before the Court “now-obsolete.”</p>
<p>Rarely does technology have the courtesy to become obsolete while the Supreme Court is still writing the opinion.</p>
<p><strong>So, are geofence warrants dead?</strong></p>
<p>Google’s classic Location History geofence warrant largely is, but geofencing itself isn’t. Reverse-location searching isn’t necessarily, either.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/08/cell-tower-locaiotn.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16214 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/cell-tower-locaiotn-300x225.jpg" alt="" width="300" height="225" /></a>Incidentally, Apple isn’t an alternative source for the same information. Apple says it has no data to provide in response to geofence requests. At least as far back as 2015, Apple was telling law enforcement that it did not track the geolocation of individual devices or retain GPS information for a specific device or user. An iPhone may know a great deal about where it has been. That doesn’t necessarily mean Apple does.</p>
<p>Other companies, however, may hold different kinds of location data that law enforcement can seek. Telecommunications carriers, app providers, ride-sharing companies and other services can possess records tied to where a device or account was at a particular time. Those systems are technically different from Google’s old Location History database, and they should not all be lumped together simply because somebody draws a circle on a map.</p>
<p>More important for lawyers, location evidence itself certainly hasn’t gone away.</p>
<p>Phones still contain or generate GPS information, Wi-Fi and Bluetooth data, application location records, photographs with location metadata, navigation history and other traces that may help answer the familiar question: Where was this phone?</p>
<p>But the source matters. So does the acquisition method.</p>
<p>A targeted search warrant for a known person’s records is not a Google geofence warrant. Location evidence extracted from a seized phone isn’t one either. Cell-site records aren’t Google Location History. A map with a dot on it may look wonderfully definitive on television, but the underlying technology determines what that dot actually means.</p>
<p>That is where the forensic work begins.</p>
<p><strong>The map still isn’t the territory</strong></p>
<p>Whatever <em>Chatrie</em> ultimately does to Fourth Amendment law, the forensic caution remains the same.</p>
<p>Location data can be remarkably powerful, and it can also be remarkably easy to oversell. A coordinate may carry an accuracy estimate. Different technologies derive location differently. A phone in a building is not necessarily a person in a particular room, and a dot on a map did not acquire certainty merely because PowerPoint made it red.</p>
<p>Ask where the location came from. Ask how it was collected. Get the underlying records and available accuracy information rather than relying solely on the tidy map someone prepared from them.</p>
<p>The old Google geofence may have gone away before the Supreme Court could finish arguing about it. The larger question has not:</p>
<p>When a phone tells us where it was, exactly what does it know, who else can get that information, and how certain should we be? Or, as The Bard might have imagined: To be there or not to be there: that is the geofence question. The forensic question is how well the data can answer it.</p>
<p>When has location data in one of your cases turned out to say less, or more, than everyone first assumed?</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed' data-link='https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed' data-link='https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/">Geofence Warrants After Chatrie: SCOTUS Ruled on a Search Google Already Killed</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/geofence-warrants-after-chatrie-scotus-ruled-on-a-search-google-already-killed/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Happens to Your Digital Life When You Die (And Who Can Access It)</title>
		<link>https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/</link>
					<comments>https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 22:14:32 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Elder Abuse]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Digital Assets]]></category>
		<category><![CDATA[Digital Assets After Death]]></category>
		<category><![CDATA[Digital Estate Planning]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Digital Legacy]]></category>
		<category><![CDATA[Phone Forensics]]></category>
		<category><![CDATA[Probate]]></category>
		<category><![CDATA[RUFADAA]]></category>
		<category><![CDATA[Stored Communications Act]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16188</guid>

					<description><![CDATA[<p>By Steve Burgess, Burgess Forensics, 2026 “He passed last month, and his whole life is locked inside his phone. Can’t you just get in?” I hear some version of that rather often —more than you might think, in fact. The request comes from grieving families, from fighting families, and from the attorneys handling their estates. [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/">What Happens to Your Digital Life When You Die (And Who Can Access It)</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='What Happens to Your Digital Life When You Die (And Who Can Access It)' data-link='https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/' data-app-id-name='category_above_content'></div><p><em>By Steve Burgess, Burgess Forensics, 2026</em></p>
<p><em>“He passed last month, and his whole life is locked inside his phone. Can’t you just get in?”</em></p>
<p>I hear some version of that rather often —more than you might think, in fact. The request comes from grieving families, from fighting families, and from the attorneys handling their estates.</p>
<p style="text-align: left;">From the grieving, it’s asked with a kind of hope. It’s as though the phone were a filing cabinet, and I kept the master key in a drawer. From the fighting, it’s asked with a harder edge, and even a kind of unfounded certainty, because by then everyone suspects the phone is holding something someone would rather it didn’t.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/FAmily-wanitng-data.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16193 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/FAmily-wanitng-data-300x169.jpg" alt="" width="300" height="169" /></a></p>
<p>Sometimes I can help. Often the honest answer is: it depends on who planned, what’s stored where, and a couple of laws most people have never heard of.</p>
<p>A person’s digital life doesn’t end when they do. It just sits there —email, photos, messages, cloud backups, a crypto wallet, the online business, the loyalty points, the birthday wishes from casual friends who didn’t realize the intended recipient is gone —waiting for someone with the right authority (and sometimes the right password) to come along. The question your client is really asking is who that someone is, and whether the door will open when they get there.</p>
<h5><strong>“Isn’t the executor just entitled to all of it?”</strong></h5>
<p>Not automatically. This surprises people. Two things do most of the governing here, and they don’t always pull in the same direction.</p>
<p>The first is a federal privacy law, the <strong>Stored Communications Act</strong>, written in 1986, before almost any of your clients had an email address. In plain terms and except in narrow circumstances, it bars the companies that hold the actual words of emails, messages, and the rest of the electronic communications from handing over the <em>contents</em>. It really doesn’t care that Grandma died and the family is grieving. A provider can face liability for oversharing, so its reflex is “no.”</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/SCA-protect.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16195 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/SCA-protect-300x169.jpg" alt="" width="300" height="169" /></a>The second is a state law that most states have now adopted: <strong>RUFADAA</strong> —the Revised Uniform Fiduciary Access to Digital Assets Act (yes, it’s a mouthful; blame the committee that named it). Drafted by the Uniform Law Commission, it has been adopted in most U.S. states, though details and terminology may vary by jurisdiction. It gives executors, trustees, and agents under a power of attorney a legal path to a decedent’s digital assets while carving out those private communications for extra protection, to stay on the right side of that 1986 federal law.</p>
<p>Now the necessary disclaimer, and I mean it: I’m a forensic examiner, not a lawyer. RUFADAA’s details vary from state to state, so treat what follows as the lay of the land, not legal advice for your jurisdiction —that’s your department (or your attorney’s), not mine. But the structure is worth knowing cold, because it may decide who wins before a referee enters the picture.</p>
<h5 style="text-align: center;"><strong>The three-rung ladder (and it’s upside down from what people expect)</strong></h5>
<h5 style="text-align: center;"><strong><a href="https://burgessforensics.com/wp-content/uploads/2026/08/3-rung-ladder.jpg"><img loading="lazy" decoding="async" class=" wp-image-16190 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/3-rung-ladder-300x169.jpg" alt="" width="394" height="222" /></a></strong></h5>
<p>RUFADAA sets a priority order for who controls an account. Picture a ladder that the platform reads from the top down.</p>
<ol>
<li><strong>The online tool. </strong>If the person used a tool the platform itself provides, such as Facebook’s Legacy Contact, Google’s Inactive Account Manager, Apple’s Digital Legacy, then that choice sits on the top rung. It can even override a contradictory will. Let that land: a two-minute setting on a phone can outrank a document a lawyer carefully drafted.</li>
<li><strong>The estate documents. </strong>No online tool? Then the directions in the will, trust, or power of attorney control who gets what, which is exactly why explicit “digital assets” language belongs in those documents now, not someday.</li>
<li><strong>The fine print. </strong>Nothing from above? Then the platform’s terms of service decide. But note that those were written to protect the platform, not your client’s heirs.</li>
</ol>
<p>Most people are sitting on rung three without knowing it.</p>
<h5><strong>So, what do the big platforms actually do?</strong></h5>
<ul>
<li><strong>Apple’s Digital Legacy</strong> can provide a designated Legacy Contact access to eligible Apple Account data, such as certain iCloud-stored photos, files, notes, messages, and device backups, after Apple approves a request supported by the access key and proof of death. It does not provide the decedent’s device passcode or decrypt a passcode-locked device, although Apple can remove Activation Lock. It’s one of the more generous setups, though. One caveat: if a paid iCloud+ account stops being paid, Apple does not guarantee indefinite preservation of data exceeding the free storage allowance and reserves the right to restrict access to or delete stored content.</li>
<li><strong>Google’s Inactive Account Manager </strong>is triggered by inactivity, not death. Set a window, say, three or eighteen months, and Google will either share the data you chose with the people you named, or delete the account. If nobody set it up, the family is left negotiating with support. Inactive Account Manager is an access plan, not a preservation plan: Google’s separate inactivity and storage-quota deletion policies still apply.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/Big-3-protect-data.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16191 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/Big-3-protect-data-300x169.jpg" alt="" width="300" height="169" /></a></li>
<li><strong>Facebook </strong>memorializes an account once it learns of a death, and a Legacy Contact can tend that memorial page, but Facebook does not hand over private messages. Full stop.</li>
</ul>
<p>The pattern: the cloud is a locked building, and every landlord has its own rules for who gets a key, and which rooms that key opens.</p>
<p>Note that companies change policies and the above are accurate as of the writing of this article.</p>
<h5><strong>“What if I need it for a case, not the estate?”</strong></h5>
<p>This is where the fighting families come in. Same walls, different reason for wanting in. When a decedent’s texts or emails matter to a wrongful-death claim, a probate contest, or a business dispute, a subpoena to the provider still runs headfirst into the Stored Communications Act on content. Still, a properly authorized fiduciary may have a stronger route to a catalogue of communications or other non-content records than to message content, though providers may require formal documentation and may impose statutory or policy-based conditions.</p>
<p>Which is why, in my line of work, the device usually beats the cloud. A phone, laptop, or backup that’s lawfully in the estate’s possession, when examined with proper authority, frequently holds the messages, photos, and app data the platform won’t volunteer, plus deleted material that never made it into any legacy tool.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/device-_-cloud.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16192 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/device-_-cloud-300x169.jpg" alt="" width="300" height="169" /></a>The catch is always the same pair: authority and access. The right to look, and a way in. And that “way in” is the quiet crisis. Desktop and laptop computers, and their physical backup drives, often give the enterprising computer geek a number of ways in. We’re frequently called on to excavate these potentially rich sources: existing files, deleted ones, and former drafts of the very documents and evidence a case turns on.</p>
<p>Phones are another matter. Modern ones are encrypted by default, so without the passcode, a legacy contact, or a good backup, even the family’s own forensic examiner can end up staring at a very expensive brick. (“Encrypted” isn’t always the dead-end people assume —but it isn’t a guarantee either.)</p>
<h2><strong>So, what to do?</strong></h2>
<p>This is the easy part, and it’s worth handing to clients now rather than litigating later.</p>
<ul>
<li><strong>Set the online tools. </strong>Apple Digital Legacy, Google Inactive Account Manager, Facebook Legacy Contact. It only takes about five minutes each, and they sit on the top rung of the ladder.</li>
<li><strong>Put digital assets in the estate plan. </strong>Explicit language in the will, trust, and power of attorney authorizing the fiduciary to access digital assets, including the content of communications, is exactly the consent RUFADAA and the SCA are looking for.</li>
<li><strong>Keep an inventory, not a password list in the will. </strong>A will can become a public record; a sealed, separately stored list of accounts and where the keys live does not. Crypto especially. Custodial exchanges may have separate estate-access procedures, subject to identity, probate, and compliance requirements. But self-custodied crypto is unforgiving: no seed phrase or proper login and no crypto coins for you. No exceptions.</li>
<li><strong>Don’t “clean up” the device. </strong>For anything that might become contested, powering through a phone or running a factory reset can destroy evidence. It’s also very likely to raise spoliation questions in a contested case. When in doubt, preserve first and examine later.</li>
</ul>
<h5><strong>The uncomfortable part <a href="https://burgessforensics.com/wp-content/uploads/2026/08/2nd-digital-life.jpg"><img loading="lazy" decoding="async" class=" wp-image-16189 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/2nd-digital-life-300x169.jpg" alt="" width="398" height="224" /></a></strong></h5>
<p>Most of us have built a whole second life online without realizing and left no instructions for it. For your clients, a few minutes of planning turns what would have been a legal-and-forensic headache into a routine handoff.</p>
<p>What’s the messiest digital-estate tangle you’ve run into? A locked phone nobody had the code to, a memorialized account, a crypto wallet with no key in sight? I’d like to hear how it played out.</p>
<p><strong>Burgess Forensics: (866) 345-3345  |  steve@burgessforensics.com</strong></p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … </strong></em><a href="https://burgessforensics.com/subscribe/"><em><strong>Subscribe now</strong></em></a><em><strong>!</strong></em></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='What Happens to Your Digital Life When You Die (And Who Can Access It)' data-link='https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='What Happens to Your Digital Life When You Die (And Who Can Access It)' data-link='https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/">What Happens to Your Digital Life When You Die (And Who Can Access It)</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</title>
		<link>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/</link>
					<comments>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 21:43:33 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16150</guid>

					<description><![CDATA[<p>The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: &#8220;produce as PDF, that&#8217;s fine.&#8221; Maybe not so fine when that same attorney later pays me to explain why the file on my screen can&#8217;t [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/">Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having' data-link='https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/' data-app-id-name='category_above_content'></div><p>The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: &#8220;produce as PDF, that&#8217;s fine.&#8221; Maybe not so fine when that same attorney later pays me to explain why the file on my screen can&#8217;t answer the question the case now turns on.</p>
<p>Here&#8217;s the thing the other side already knows: whoever picks the format picks what you get to see. It&#8217;s just how the rules work. Under Federal Rule of Civil Procedure 34(b)(2)(E), the party asking for the documents gets to specify the form they arrive in. Don&#8217;t specify, and the choice falls to the producing side, with &#8220;reasonably usable&#8221; form as the only floor — and reasonably usable is a long way from native. Say nothing about format and you&#8217;ve handed them the pen.</p>
<p>Native files vs. PDFs sounds like an argument for the IT department, right? It isn&#8217;t. It&#8217;s one of the quietest, most consequential fights in the whole discovery process, and it&#8217;s worth having on purpose.</p>
<h4>A PDF is a photograph of a document, not the document</h4>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/PDF-vs-Word-doc.jpg"><img loading="lazy" decoding="async" class="wp-image-16154 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/PDF-vs-Word-doc-300x164.jpg" alt="" width="347" height="190" /></a>A native file is the thing itself &#8211; the spreadsheet with its formulas still doing math, the email with its full routing header, the Word file that still remembers every draft, the photo that quietly wrote down where and when it was taken. I have a paragraph in my engagement letter saying so, albeit a bit more succinctly. A PDF or a TIFF is a picture of that file after someone chose the pose.</p>
<p>What really gets me is when evidence is produced as a printout of a PDF of a scan of a PDF created from the actual original file. Happens all the time. But it’s several steps away from what really happened and far from the metadata that tells the real story.</p>
<p>Such “pictures” drop exactly the parts that tend to win cases. Most of the metadata, describing fields such as who made it, when, on what device, and sometimes where tends to get lost when a PDF is generated from it. This is the difference between &#8220;he says he wrote it in March&#8221; and knowing, to the minute, that he didn&#8217;t.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/4-million.jpg"><img loading="lazy" decoding="async" class=" wp-image-16151 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/4-million-300x167.jpg" alt="" width="314" height="175" /></a></p>
<p>A spreadsheet may show you a very precise value of 4,203,722.46 in the flattened PDF version but hides the formulae and structure that generated a possibly different number. A document that previously contained all the things people put in a document before they remembered other people would read the tracked changes, comments, hidden rows? Native format keeps them. The flattened copy forgets them, conveniently.</p>
<p>Hash values and container data are integrity signals that may let you and me confirm that the document produced is the same as the original are casualties of a PDF export. It snaps that verification thread and asks you to just take everybody&#8217;s word for it instead.</p>
<p>None of it comes back, either. You can&#8217;t un-flatten a PDF into the original any more than you can un-fry a flapjack. Once it&#8217;s produced that way, the missing data isn&#8217;t hiding from you. It&#8217;s gone.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/unfrying-a-flapjack.jpg"><img loading="lazy" decoding="async" class="wp-image-16156 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/unfrying-a-flapjack-300x164.jpg" alt="" width="476" height="260" /></a></p>
<p>I had a case where the “date digitized” EXIF metadata from a series of photos supported one side’s story. However, deeper in the metadata, there was satellite data that cast real doubt on the story being told. Satellites and their atomic clocks don’t lie about the time or the day.</p>
<h4>Why the other side is so agreeable about it</h4>
<p>Producing in PDF usually isn&#8217;t laziness. It&#8217;s control wearing the costume of laziness. A flattened production is easier to redact, easier to Bates-stamp, and, in a happy coincidence, easier to sanitize. The timestamp that wrecks the timeline, the author who wasn&#8217;t supposed to be within a mile of that memo, the formula that shows how a number really got built: all of it vanishes in the conversion, and it vanishes wearing the respectable coat of &#8220;routine document handling&#8221; rather than the orange jumpsuit of spoliation.</p>
<p>To be fair, imaged production isn&#8217;t always a dodge. Sometimes there are honest reasons for it — privilege review, redacting personal or protected information, or real proportionality under Rule 26(b)(1) when native would cost more than the whole dispute is worth. Those reasons are legitimate. The trick is to make the other side say so out loud, in the protocol, so that &#8220;we imaged it&#8221; has to be justified rather than simply assumed.</p>
<p>I should be clear that &#8220;save as PDF&#8221; is also a genuinely lousy way to strip metadata even when someone&#8217;s trying to be honest. It leaves things behind and takes things it shouldn&#8217;t. But that&#8217;s a different article. For today: the party that controls the format controls the evidence, and they know it even if your side doesn&#8217;t.</p>
<h4>The fight is won in the ESI protocol, not in a motion six months later. <a href="https://burgessforensics.com/wp-content/uploads/2026/08/Stripping-metadata.jpg"><img loading="lazy" decoding="async" class=" wp-image-16155 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/Stripping-metadata-300x167.jpg" alt="" width="337" height="188" /></a></h4>
<p>This is the part I most want attorneys to hear. By the time you&#8217;re standing in front of a judge complaining about a bad production, you&#8217;re asking to redo work the other side has every incentive to slow-walk into the next fiscal year — and you&#8217;re explaining to your client why the schedule, and the bill, went sideways. Nobody enjoys that conversation. Least of all the person who once said &#8220;PDF is fine.&#8221;</p>
<p style="text-align: left;">So specify the format on the front end, in writing:</p>
<ul>
<li><strong>Ask for native formats, with metadata, by default</strong> for anything data-rich — spreadsheets, databases, structured exports — with load files that actually carry the field data. Boring to negotiate. Priceless to have.</li>
<li><strong>Name the metadata fields you want.</strong> Custodian, author, created and modified dates, an MD5 or SHA-1 hash, and parent/child relationships so attachments stay tied to their emails. &#8220;With metadata&#8221; is an invitation for the other side to read the phrase as generously as their conscience allows.</li>
<li><strong>Reserve the right to request native format</strong> for anything produced as an image, and say so up front — so when you invoke it, it&#8217;s a term of the deal and not an ambush they get to act wounded about.</li>
<li><strong>Bring your examiner in before the language is set, not after the production disappoints.</strong> Format specs written without technical input have a real talent for asking, very precisely, for the wrong thing.</li>
</ul>
<h4>The bottom line</h4>
<p>This is not enhance-the-reflection-in-the-sunglasses forensics. It&#8217;s plumbing. It&#8217;s unglamorous, it&#8217;s easy to skip, and it is very often the only thing standing between evidence you can build a case on and a tidy picture of evidence you have to take on faith.</p>
<p style="text-align: left;">Courts increasingly expect native production where format carries meaning, and (hopefully) increasingly treat &#8220;well, we already gave you a PDF&#8221; as the weak answer it is. But you don&#8217;t drift there by luck. You get there by treating format as a substantive term of the case — argued with the same seriousness as scope and custodians, and about a thousand times more attention than it usually gets. <a href="https://burgessforensics.com/wp-content/uploads/2026/08/checkbook.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16152 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/checkbook-300x167.jpg" alt="" width="300" height="167" /></a></p>
<p>Have the fight early. It&#8217;s a great deal cheaper than the one you&#8217;ll have later, in front of a judge, with your client and their checkbook watching.</p>
<p><em>What&#8217;s the worst production-format surprise you&#8217;ve run into — native you wish you&#8217;d demanded, a PDF that turned out to be hiding the whole case, or something else entirely?</em></p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><strong><em>Don’t miss a single issue of our informative newsletter … </em></strong><a class="uRHgOlUNgMoEOwgGoLxklVwtWfKTKfVqDQxSCg " tabindex="0" href="https://burgessforensics.com/subscribe/" target="_self" data-test-app-aware-link=""><strong><em>Subscribe now</em></strong></a><strong><em>!</em></strong></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having' data-link='https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having' data-link='https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/">Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why &#8220;He Deleted Everything&#8221; Is Usually Good News for Your Case</title>
		<link>https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/</link>
					<comments>https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 19:49:28 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<category><![CDATA[CSI]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[Mar-A-Lago]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[testimony]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16136</guid>

					<description><![CDATA[<p>When a client or opposing party says &#8220;he deleted everything,&#8221; attorneys often hear a dead end. I hear the opposite and you probably should as well. In digital forensics, deletion is rarely the end of the story. In fact, it may be the beginning of a better one. What most people don’t understand is that [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/">Why &#8220;He Deleted Everything&#8221; Is Usually Good News for Your Case</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Why &quot;He Deleted Everything&quot; Is Usually Good News for Your Case' data-link='https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/' data-app-id-name='category_above_content'></div><p>When a client or opposing party says &#8220;he deleted everything,&#8221; attorneys often hear a dead end. I hear the opposite and you probably should as well. In digital forensics, deletion is rarely the end of the story. In fact, it may be the beginning of a better one.</p>
<p>What most people don’t understand is that hitting delete doesn’t erase data. It tells the system that the space can be reused. Think of it less like shredding a document and more like taking the label off a file folder and telling the office it’s okay to reuse the drawer — the pages are still in there until someone actually needs the room and drops the pages in a shredder. Until something overwrites it, the underlying data often sits right where it always was. On phones, computers, and servers, deleted files, messages, and app data are frequently recoverable in whole or in part. While deleted phone data is somewhat more ephemeral and tends to become unrecoverable after a couple of months, other platforms are less so. In many cases, we have recovered them months or even years later.</p>
<p>Still, recoverability is only half of it. The more valuable half is what the act of deletion reveals.</p>
<p style="text-align: left;"><strong>Deletion leaves its own trail.</strong> Modern devices tend to be relentless record-keepers. They document nearly everything, often including their own attempted cover-ups. When someone deletes files, wipes an app, clears a chat, or runs &#8220;cleaner&#8221; or “wiping” software, those actions frequently generate their own artifacts: timestamps, log entries, system events, and traces in backups and cloud sync. In practice, you may be able to<a href="https://burgessforensics.com/wp-content/uploads/2026/07/Deleted-stuff-copy.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16138 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Deleted-stuff-copy-300x167.jpg" alt="" width="300" height="167" /></a> prove not just what existed, but when it was removed, and sometimes that a wiping tool was run at 2 a.m. the night before a device was handed over. We had a case where the inspection got stalled for a couple of days to give time for the IT guy to scrub away. However, the file-destroying tool kept a record of every single file it destroyed over the previous very busy nights.</p>
<p>Nothing says &#8220;nothing to hide&#8221; quite like a freshly installed disk-scrubbing utility. That timeline can be more persuasive to a fact-finder than the deleted content ever would have been.</p>
<p><strong>Intent is the story.</strong> A single deleted photo is a fact. A coordinated wipe — messages cleared, a drive reformatted, cloud backups switched off, all clustered around a key date — is a narrative unto itself. Courts have well-developed doctrine here. Spoliation of evidence can support sanctions and, in many jurisdictions, the dreaded adverse-inference instruction: the jury may be told they can assume the destroyed evidence would have hurt the party who destroyed it. The person trying to make the problem disappear might just be manufacturing a bigger one, wrapped up with a bow on top.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/07/guilty-guy-copy.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16139 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/07/guilty-guy-copy-300x164.jpg" alt="" width="300" height="164" /></a></p>
<p><strong>The copies that survive.</strong> Data rarely lives in one place. A message deleted on a phone may survive in a backup, on the other party’s device, in a cloud account, or on a synced laptop nobody remembered was still logged in. Deleting the local copy does nothing to the dozen copies elsewhere. The modern device can be quite the bothersome gossip &#8211;  it tells your secrets to every other device it meets. Part of a competent forensic examination is simply knowing where those copies tend to hide.</p>
<p>Besides the potentially recoverable file being looked for, many programs, especially Microsoft Office, make invisible copies every time a file is open. Invisible to the user, that is – not to the examiner.</p>
<p><img loading="lazy" decoding="async" class="wp-image-16137 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Bucket-o-coffee-copy-e1785439723662-300x205.jpg" alt="" width="294" height="201" />So, when the other side deletes everything, they may accomplish three things that help you: they leave recoverable data behind, they create adocumented record of the destruction, and they hand you a consciousness-of-guilt argument you didn’t have before. That’s a rough return on investment for a night or two filled with buckets of coffee and frantic clicking.</p>
<p style="text-align: left;"><strong>A few practical notes for counsel.</strong> Move fast. Recoverability drops as devices keep running and space gets overwritten, so preservation letters and litigation<a href="https://burgessforensics.com/wp-content/uploads/2026/07/Rushing-attorney-copy-e1785439849217.jpg"><img loading="lazy" decoding="async" class=" wp-image-16140 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Rushing-attorney-copy-e1785439849217-300x191.jpg" alt="" width="550" height="351" /></a> holds matter enormously.</p>
<p style="text-align: left;">Preserve the device itself, not just exports; a proper forensic image captures far more than a manual copy. And loop in an examiner early, before well-meaning IT staff or clients &#8220;poke around just to check&#8221; and overwrite the very evidence you’re trying to save. Curiosity has damaged more cases than it has solved.</p>
<p style="text-align: left;">&#8220;He deleted everything&#8221; isn’t the moment your case falls apart. More often, it’s the moment it gets interesting.</p>
<p><strong>A question for the litigators:</strong> what’s a situation you’ve had where deleted data actually strengthened your side of the case? I’d be curious to hear how it played out. The best forensic stories usually start with someone who was very sure they’d covered their tracks.</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe now</a>!</strong></em></p>
<p>&nbsp;</p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Why &quot;He Deleted Everything&quot; Is Usually Good News for Your Case' data-link='https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Why &quot;He Deleted Everything&quot; Is Usually Good News for Your Case' data-link='https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/">Why &#8220;He Deleted Everything&#8221; Is Usually Good News for Your Case</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Your Smart Home Is Testifying Against You</title>
		<link>https://burgessforensics.com/your-smart-home-is-testifying-against-you/</link>
					<comments>https://burgessforensics.com/your-smart-home-is-testifying-against-you/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 20:54:30 +0000</pubDate>
				<category><![CDATA[Attorneuys]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16122</guid>

					<description><![CDATA[<p>A fitness tracker once told me the exact moment its wearer stopped moving. Not slowed down. Stopped. The device wasn&#8217;t built to establish a time of death. It was builtto count steps and nag its owner about standing up more often. But it kept a continuous record, and that record answered a question nobody had [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/your-smart-home-is-testifying-against-you/">Your Smart Home Is Testifying Against You</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Your Smart Home Is Testifying Against You' data-link='https://burgessforensics.com/your-smart-home-is-testifying-against-you/' data-app-id-name='category_above_content'></div><p style="text-align: left;">A fitness tracker once told me the exact moment its wearer stopped moving. Not slowed down. Stopped. The device wasn&#8217;t built to establish a time of death. It was builtto count steps and nag its owner about standing up more often. But it kept a continuous record, and that record answered a question nobody had thought to ask it.</p>
<p>I can&#8217;t reveal much about the case. The survivors believed the facility had let conditions get too hot for too long with too little warning. The other side believed close to the opposite: that the tracker&#8217;s own history showed the deceased knew better than to push that hard through a changing but controlled environment. Both sides were arguing about the same person&#8217;s habits, and the tracker had a record of them. Dueling cardiologists reached differing conclusions about the fitness level of the deceased.</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16127 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/heart-rate-300x164.png" alt="" width="300" height="164" />I did not expect a line chart to affect me. Heart rate climbing to a dangerous peak, dropping to zero, then flat and never moving again. Plain as any spreadsheet. Then I imagined what that jagged line meant on the floor of the event.</p>
<p>That case is the whole of digital forensics in one artifact. People imagine this work is about clever adversaries planting evidence. I hear that concern regularly, and it is rarely what actually happened. The real story is duller and much harder to argue with: an ordinary device did exactly what it was built to do, and nobody remembered that what it was built to do includes keeping a record.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/COnnected-house.png"><img loading="lazy" decoding="async" class="size-medium wp-image-16124 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/COnnected-house-300x167.png" alt="" width="300" height="167" /></a>Your house is full of these. A video doorbell logs every motion event with a timestamp, whether or not itsaved any video.A voice assistant logs when it woke up, and sometimes what it heard in the few seconds on either side, depending on a setting its owner has never opened or knew existed. A thermostat infers occupancy from temperature adjustments and motion, which turns out to be a decent proxy for whether anyone was home. A robot vacuum holds a floor plan of every room it has ever cleaned. A car knows where it went and how fast it got there. It is getting harder and harder to have a good ol&#8217; dumb home.</p>
<p>None of this was designed to be evidence,<img loading="lazy" decoding="async" class="size-medium wp-image-16126 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/dumb-house-300x164.png" alt="" width="300" height="164" /> which is one reason it can become powerful evidence when properly authenticated and interpreted. There may still be questions about reliability, chain of custody, retention settings, incomplete logs, and similar issues, but the device itself has no made-up story to keep straight. It is not shaped by human memory in the way witness recollection is, though it still has to be interpreted carefully. Someone can be careful about what they say out loud and still be wearing a watch that logged a heart rate spike at the moment in question.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/crook-in-the-themrostat.png"><img loading="lazy" decoding="async" class="size-medium wp-image-16125 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/crook-in-the-themrostat-300x164.png" alt="" width="300" height="164" /></a>The law is still catching up. Carpenter v. United States narrowed the old assumption that anything you hand to a company is fair game without a warrant, at least for cell site location records. Aside from preservation duties, discovery scope, and the need to meet and confer, there is a live question whether that reasoning will narrow access to data from a thermostat, a vacuum&#8217;s floor map, or a year of refrigerator door-open events. Those boundaries are being worked out one motion and one court at a time as we speak. I would not bet on the answers looking the same in five years as they do today.</p>
<p>For lawyers, the lesson is simple: ask early what connected devices were present, where the data is stored, how long it is retained, and who controls it.</p>
<p>In the meantime, the practical reality is simpler. Your home has more employees than you think, and all of them are taking notes. None of it is malicious. Much of it may be discoverable or obtainable, if someone thinks to ask.</p>
<p>What smart-device data point has surprised you most, in a case or in your own house? I&#8217;d love to hear about it.</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Your Smart Home Is Testifying Against You' data-link='https://burgessforensics.com/your-smart-home-is-testifying-against-you/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Your Smart Home Is Testifying Against You' data-link='https://burgessforensics.com/your-smart-home-is-testifying-against-you/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/your-smart-home-is-testifying-against-you/">Your Smart Home Is Testifying Against You</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/your-smart-home-is-testifying-against-you/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Future of Expert Testimony in a Digital World</title>
		<link>https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/</link>
					<comments>https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 14 Jul 2026 22:23:12 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15729</guid>

					<description><![CDATA[<p>Twenty years ago, a forensic report about a hard drive was mostly an argument about whether a file existed and when it was last touched. And of course, trying to recover deleted material. Today the same report might need to address whether a video is real, whether a document was generated by a language model, [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/">The Future of Expert Testimony in a Digital World</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Future of Expert Testimony in a Digital World' data-link='https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/' data-app-id-name='category_above_content'></div><p>Twenty years ago, a forensic report about a hard drive was mostly an argument about whether a file existed and when it was last touched. And of course, trying to recover deleted material. Today the same report might need to address whether a video is real, whether a document was generated by a language model, whether a &#8220;deleted&#8221; text message ever really existed on the device in the first place, and especially, whether the tool used to answer any of those questions is itself reliable enough to stand behind in front of a jury.</p>
<p style="text-align: left;">It doesn’t come up in every case, but when it does, we’d better be ready to answer. Digital forensics has always rested on the idea that a method can be explained, tested, and<img loading="lazy" decoding="async" class="size-medium wp-image-15730 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Expert-in-the-future-300x168.jpeg" alt="" width="300" height="168" /> challenged — that&#8217;s pretty much the whole premise behind Daubert and Frye. AI-assisted analysis complicates that premise, because a growing number of detection and authentication tools now involve models whose internal reasoning isn&#8217;t fully visible even to the people who built them. Courts are already grappling with what that means for the right to confront the basis of evidence against you, and there isn&#8217;t yet a settled answer For instance, I’ve seen questions about whether Cellebrite might mis‑label a recovered file as‘deleted’ or treat an active file as if ithad been deleted, even though the platform is historically solid and time‑tested in most other respects. Still, that&#8217;s not a hypothetical academic question; it&#8217;s a live one working its way through appellate opinions right now and it&#8217;s going to shape how expert reports get written well into the future.</p>
<p>What&#8217;s changing on the ground, in the meantime, is the volume and variety of source data an expert has to account for. A phone used to mean <a href="https://burgessforensics.com/wp-content/uploads/2026/07/Update-permisisons.jpeg"><img loading="lazy" decoding="async" class="size-medium wp-image-15733 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/Update-permisisons-300x168.jpeg" alt="" width="300" height="168" /></a>call logs and texts. Now it means cloud-synced photo libraries, health data, smart-home integration logs, location history from a dozen apps that nobody remembers granting permission to (or maybe that an update changed the permissions you did or did not grant, and metadata trails that span devices the owner may not even still possess. The expert&#8217;s job isn&#8217;t just extraction anymore — it&#8217;s building a coherent, defensible narrative out of data that lives in more places than any one device.</p>
<p>The next several years will bring a few concrete shifts. Although there will certainly be changing laws for changing environments, standards bodies and courts will move, slowly and , toward requiring more explicit validation testimony for AI-assisted tools. Not just &#8220;the software said so,&#8221; but documented error rates, testing methodology, and version-specific behavior, the same rigor that&#8217;s long been expected of DNA analysis and toxicology. Authentication of video and audio is going to become its own specialized sub-field, distinct from general digital forensics, the</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-15731 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/shifting-envrironment-300x168.jpeg" alt="" width="300" height="168" />way arson investigation split off from general fire science. And attorneys are going to need to get comfortable asking experts pointed questions about tool provenance — not because they distrust the expert, but because opposing counsel increasingly will.</p>
<p>None of this replaces the fundamentals. A well-documented chain of custody still matters. So does a methodology that can be explained in plain English to twelve people, a judge, and possibly an attorney who&#8217;ve never heard of a hash value, and an expert willing to say plainly what the evidence does and doesn&#8217;t show — that hasn&#8217;t changed and I don&#8217;t expect it to. What&#8217;s changing is the amount of homework required to get there, and how much of that homework now involves tools that didn&#8217;t exist five years ago.I&#8217;d like to makethis the first in a short series looking at where this field is actually headed, drawing on conversations with people building the tools and writing the standards rather than just my own two cents.</p>
<p style="text-align: left;">If there’s a specific angle—AI detection reliability, Confrontation Clause questions, how courts are handling deepfake authentication—you’d like covered first, I’m glad to hear it. Trial lawyers and judges who live with these issues every day are exactly who I’m hoping to hear from, so please let me know.</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Future of Expert Testimony in a Digital World' data-link='https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='The Future of Expert Testimony in a Digital World' data-link='https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/">The Future of Expert Testimony in a Digital World</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The 3 Phone Mistakes That Destroy Digital Evidence Before Trial</title>
		<link>https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/</link>
					<comments>https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 14:58:01 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15392</guid>

					<description><![CDATA[<p>Copyright 2026, Steve Burgess Smartphones are the single richest source of digital evidence in most litigation today. Text messages, call logs, photos, location history, app data, deleted files — it&#8217;s all there, sitting in a device that fits in a shirt pocket. Or in that back pocket that’s covered with bling. You&#8217;d think that because [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/">The 3 Phone Mistakes That Destroy Digital Evidence Before Trial</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The 3 Phone Mistakes That Destroy Digital Evidence Before Trial' data-link='https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/' data-app-id-name='category_above_content'></div><p><em>Copyright 2026, Steve Burgess</em></p>
<p>Smartphones are the single richest source of digital evidence in most litigation today. Text messages, call logs, photos, location history, app data, deleted files — it&#8217;s all there, sitting in a device that fits in a shirt pocket. Or in that back pocket that’s covered with bling. You&#8217;d think that because phones are so ubiquitous and so central to how people communicate, attorneys and their clients would have developed good instincts about preserving them. You would be wrong, and I say that with forty years of forensic experience and genuine affection for the legal profession.</p>
<p><img loading="lazy" decoding="async" class="wp-image-15393 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/06/Phone-police-line-300x200.png" alt="" width="311" height="207" /></p>
<p>The mistakes I see aren&#8217;t necessarily the result of bad intentions. They&#8217;re the result of people not knowing what they don&#8217;t know — which, in digi</p>
<p>tal forensics, turns out to be quite a lot. Here are the three that do the most damage.</p>
<p><strong>Mistake One: Letting the Client Keep Using the Phone.</strong></p>
<p>This one is so common that I&#8217;ve stopped being surprised by it, though I haven&#8217;t stopped being pained. The moment litigation is reasonably anticipated, a litigation hold applies to that phone. What it does not do, unfortunately, is apply itself. Unless someone explicitly tells the client to stop using the device normally, they will continue using it norma</p>
<p>lly — deleting old messages to free up space, backing up and syncing, downloading updates, letting apps purge their caches — all of which can overwrite the very data that might have been recoverable. The phone doesn&#8217;t know there&#8217;s a lawsuit. It&#8217;s just doing its job.<a href="https://burgessforensics.com/wp-content/uploads/2026/06/Cell-phone-hoarder.jpg"><img loading="lazy" decoding="async" class="wp-image-15394 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/Cell-phone-hoarder-200x300.jpg" alt="" width="117" height="176" />.</a></p>
<p>Even using the phone abnormally, that is – at all – makes potentially important changes to data that</p>
<p>could be responsive, and can also make otherwise recoverable data gone from the planet.</p>
<p>The fix is straightforward but has to happen early: tell your client, in plain language, to stop deleting anything and to bring you the phone. Not a screenshot of the phone. The phone. Best to put it into airplane mode and then turn it off immediately. We&#8217;ll get to screenshots in a moment.</p>
<p><strong>Mistake Two: The Screenshot Problem.</strong></p>
<p>Attorneys receive screenshots of text message conversations constantly. Clients send them because they&#8217;re easy, because they <em>feel</em> like evidence, and because nobody told them otherwise. The problem is that a screenshot is a photograph of information, not the information itself. It shows you what someone wants you to see, cropped to whatever boundaries they chose, dating the evidence to the very time they took the screenshot, with none of the underlying data that makes digital evidence actually useful in court.</p>
<p>Even worse, we regularly get PDFs of screenshots of the evidence, two steps of creation removed from the genesis of the underlyi<a href="https://burgessforensics.com/wp-content/uploads/2026/06/Gemini_Generated_Image_1mtnyj1mtnyj1mtn.jpg"><img loading="lazy" decoding="async" class="wp-image-15395 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/Gemini_Generated_Image_1mtnyj1mtnyj1mtn-300x164.jpg" alt="" width="220" height="120" /></a>ng evidence.</p>
<p>A proper extraction of text messages from a phone includes the full conversation thread, the phone numbers associated with each contact, timestamps that can be verified against carrier records, and in many cases deleted messages that the client may not even know still exist. A screenshot gives you none of that. It also gives opposing counsel a straightforward authenticity challenge, because a screenshot can be edited in about thirty seconds by anyone with a basic photo app and an agenda. Courts are increasingly skeptical of screenshots standing alone, and rightly so. If the text messages matter to your case, get the phone examined by someone who can extract the data forensically.</p>
<p><strong>Mistake Three: The Factory Reset.</strong></p>
<p>This is the one that occasionally crosses the line from mistake into something courts take a very dim view of, depending on the timing and the circumstances. People factory reset their phones for all kinds of innocent reasons — selling the device, switching carriers, trying to fix a software problem, general digital housekeeping, following the instructions of a tech support rep. Even just copying the data to a new phone. Hit the wrong button during the process and Poof! All the un-transferred stuff is gone. When it happens after litigation is anticipated and a litigation hold is in effect, innocent reasons tend not to matter as much as you&#8217;d hope.</p>
<p>What many people don&#8217;t realize is that a factory reset, once it happens, puts you in a very difficult position legally <a href="https://burgessforensics.com/wp-content/uploads/2026/06/Factory-reset.jpg"><img loading="lazy" decoding="async" class="wp-image-15396 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/Factory-reset-300x164.jpg" alt="" width="269" height="147" /></a>— regardless of what may or may not remain on the device. Which, with newer devices, is usually zilch. Courts don&#8217;t look kindly on resets that occur after a litigation hold is in effect, and the explanation of &#8216;I didn&#8217;t know&#8217; tends to land with a thud. The time to have this conversation with your client is before it happens, not after.&#8221;</p>
<p>The common thread in all three of these mistakes is timing. Digital evidence is not like paper evidence — it doesn&#8217;t just sit in a filing cabinet waiting patiently for someone to come find it. It&#8217;s dynamic, it&#8217;s fragile in ways that aren&#8217;t obvious, and the window for preserving it can close faster than anyone expects. The attorneys who understand this engage a forensic examiner early, preserve the device properly, and go into discovery knowing what the phone contains. The ones who don&#8217;t tend to find out what was on it the hard way.</p>
<p>If your client&#8217;s phone was examined today, would you know what&#8217;s on it — or would you find out the same time opposing counsel does?</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The 3 Phone Mistakes That Destroy Digital Evidence Before Trial' data-link='https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='The 3 Phone Mistakes That Destroy Digital Evidence Before Trial' data-link='https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/">The 3 Phone Mistakes That Destroy Digital Evidence Before Trial</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
