<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Expert Witness Insights Archives - Burgess Forensics</title>
	<atom:link href="https://burgessforensics.com/category/expert-witness-insights/feed/" rel="self" type="application/rss+xml" />
	<link>https://burgessforensics.com/category/expert-witness-insights/</link>
	<description>Computer Forensics, Electronic Discovery &#38; Expert Witness</description>
	<lastBuildDate>Mon, 24 Aug 2026 21:30:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://burgessforensics.com/wp-content/uploads/2016/08/burgess-42x42.png</url>
	<title>Expert Witness Insights Archives - Burgess Forensics</title>
	<link>https://burgessforensics.com/category/expert-witness-insights/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>When “Auto-Delete” Becomes “Adverse Inference”</title>
		<link>https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/</link>
					<comments>https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 21:30:20 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16199</guid>

					<description><![CDATA[<p>The messages were set to delete within an hour, and some of those settings were changed after a litigation hold had already landed. That was really the whole idea. If you practice long enough, you learn that the tools change but human nature doesn&#8217;t. Caveguy Ugg didn&#8217;t want anyone to know where he buried the [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/">When “Auto-Delete” Becomes “Adverse Inference”</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='When “Auto-Delete” Becomes “Adverse Inference”' data-link='https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/' data-app-id-name='category_above_content'></div><p>The messages were set to delete within an hour, and some of those settings were changed after a litigation hold had already landed. That was really the whole idea.</p>
<p style="text-align: left;">If you practice long enough, you learn that the tools change but human nature doesn&#8217;t. Caveguy Ugg didn&#8217;t want anyone to know where he buried the mammoth haunch. Today the digging stick is a setting inside Signal, and the dirt is a &#8220;disappearing messages&#8221; timer. Same instinct, better encryption.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/08/burying-a-bone.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16200 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/burying-a-bone-300x225.jpg" alt="" width="300" height="225" /></a>A million years post-Ugg, the same instinct turns up in the Delaware Court of Chancery. It&#8217;s a decision worth reading once, and worth repeating to a client twice.</p>
<p><strong>Wait, isn&#8217;t the whole point of an encrypted app that the messages are gone?</strong></p>
<p>Gone from the phone, maybe. Not gone from your obligations.</p>
<p>In <em>In re World Wrestling Entertainment, Inc. Merger Litigation</em> (Del. Ch., May 2026), Vice Chancellor Laster addressed exactly this. Senior people ran Signal with auto-delete turned on, after receiving litigation holds, several manually changed individual chats so messages would disappear in a little less than an hour. The court didn&#8217;t shrug. The court <a href="https://burgessforensics.com/wp-content/uploads/2026/08/wrestler-slammin-evidence.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16206 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/wrestler-slammin-evidence-300x225.jpg" alt="" width="300" height="225" /></a>held that the first hold already reached Signal communications that overlapped with the potential deal. And even apart from the hold, it found that the duty to preserve sale-related evidence had arisen by August 31, 2022. That was months before the later sale-process hold. Sophisticated parties in that situation should reasonably have anticipated litigation.</p>
<p>The line worth taping to your monitor: litigation holds are not self-executing. Sending the memo, and even making sure they got it, is not the same as preserving the data. Somebody has to identify the relevant apps and devices, verify the settings, and actually disable the auto-deleted function.</p>
<p><strong>So, what did it cost them?</strong></p>
<p>The court didn&#8217;t reach for the biggest hammer. Rather than make a default judgment or give a blanket &#8220;assume the worst&#8221; instruction to a jury, it did something more surgical. It was arguably more dangerous for the sanctioned side: it presumed certain specific facts to be true and then shifted the burden, requiring the defense to overcome those presumptions by clear and convincing evidence rather than the usual preponderance. A bit of a switcheroo on the usual burden of proof ground floor.</p>
<p>Read that again if you litigate. The evidentiary floor moved. That&#8217;s not a slap on the wrist.</p>
<p>Now, I&#8217;m a forensic examiner, not a lawyer, and the doctrine here (when the duty attaches, what sanction fits) is your department, and it varies by jurisdiction. What I can tell you is the part that lives on my side of the table: how this actually plays out in the data.</p>
<p><strong>Can&#8217;t your people just recover the deleted Signal messages?</strong></p>
<p>Sometimes, but not always, and not the way Professor Google’s many advisors say. Here&#8217;s what’s real.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/ugg-mammoth-disappearing.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16204 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/ugg-mammoth-disappearing-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>Disappearing-message apps are built to leave little behind, but &#8220;little&#8221; is not &#8220;nothing.&#8221; Copies and traces have a way of surviving in places people forget. A forensic acquisition or Signal backup made while the data still existed. The conversation on another participant’s or linked device where some data has survived. A screenshot somebody took. Notification artifacts preserved elsewhere. A message quoted in an email. Encryption is a strong lock on the message itself. It does nothing about the copies that already walked out the door and went for a jog.</p>
<p>But if the content is truly gone, the forensics may not bring back the words. This matters much for setting expectations with a client. What may be able to show is the activity on the device or app artifacts: that an app was installed, that auto-delete was switched on, that a timer was shortened at a telling moment. Note that we’re talking about what the device did, not who was holding it. Putting a specific person at the keyboard is a separate and much harder question. But in a spoliation fight, showing that a message was set to vanish, and when the setting changed, can matter as much as the words that vanished.</p>
<p><strong>So, what to do?</strong></p>
<p>If you represent the party with the duty, the practical steps are unglamorous and they work.</p>
<p><strong>Identify the apps early.</strong> Ask, in plain language, what everyone messages on — not just email and texts. Signal, WhatsApp, Snapchat, Teams, the group chat nobody mentions.</p>
<p style="text-align: left;"><strong>Turn off disappearing settings the moment litigation is reasonably foreseeable</strong>, and confirm that preservation is actually occurring rather than trusting that the memo did the job.<img loading="lazy" decoding="async" class=" wp-image-16205 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/ugg-swtich-off-setting-300x225.jpg" alt="" width="262" height="197" /></p>
<p style="text-align: left;"><strong>Preserve any available backups</strong>, forensic images, and secondary devices before data rolls off or is overwritten. But don&#8217;t assume an ordinary phone backup contains Signal history—or that a Signal backup captured short-lived disappearing messages. It’s a good idea to collect that before today’s backup writes over yesterday’s.</p>
<p>&nbsp;</p>
<p><strong>Document your preservation, not just your hold.</strong> When someone later asks what you did, &#8220;we sent a notice&#8221; is a weaker answer than &#8220;we sent a notice and confirmed the settings on every device by this date.&#8221;</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/preserving-a-backup.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16203 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/preserving-a-backup-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>None of this requires a particular level of paranoia. It requires remembering that a message built to vanish can still leave a record of having been built to vanish.</p>
<p>Ever had a &#8220;disappearing&#8221; conversation turn out not to be the dead end everyone assumed? I&#8217;d like to hear how it surfaced.</p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</em></p>
<p><em>Burgess Forensics: (866) 345-3345 | steve@burgessforensics.com</em></p>
<p><strong><em>Don’t miss a single issue of our informative newsletter … </em></strong><a class="uRHgOlUNgMoEOwgGoLxklVwtWfKTKfVqDQxSCg " tabindex="0" href="https://burgessforensics.com/subscribe/" target="_self" data-test-app-aware-link=""><strong><em>Subscribe now</em></strong></a><strong><em>!</em></strong></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='When “Auto-Delete” Becomes “Adverse Inference”' data-link='https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='When “Auto-Delete” Becomes “Adverse Inference”' data-link='https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/">When “Auto-Delete” Becomes “Adverse Inference”</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/when-auto-delete-becomes-adverse-inference/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Happens to Your Digital Life When You Die (And Who Can Access It)</title>
		<link>https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/</link>
					<comments>https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 22:14:32 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Elder Abuse]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Digital Assets]]></category>
		<category><![CDATA[Digital Assets After Death]]></category>
		<category><![CDATA[Digital Estate Planning]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Digital Legacy]]></category>
		<category><![CDATA[Phone Forensics]]></category>
		<category><![CDATA[Probate]]></category>
		<category><![CDATA[RUFADAA]]></category>
		<category><![CDATA[Stored Communications Act]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16188</guid>

					<description><![CDATA[<p>By Steve Burgess, Burgess Forensics, 2026 “He passed last month, and his whole life is locked inside his phone. Can’t you just get in?” I hear some version of that rather often —more than you might think, in fact. The request comes from grieving families, from fighting families, and from the attorneys handling their estates. [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/">What Happens to Your Digital Life When You Die (And Who Can Access It)</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='What Happens to Your Digital Life When You Die (And Who Can Access It)' data-link='https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/' data-app-id-name='category_above_content'></div><p><em>By Steve Burgess, Burgess Forensics, 2026</em></p>
<p><em>“He passed last month, and his whole life is locked inside his phone. Can’t you just get in?”</em></p>
<p>I hear some version of that rather often —more than you might think, in fact. The request comes from grieving families, from fighting families, and from the attorneys handling their estates.</p>
<p style="text-align: left;">From the grieving, it’s asked with a kind of hope. It’s as though the phone were a filing cabinet, and I kept the master key in a drawer. From the fighting, it’s asked with a harder edge, and even a kind of unfounded certainty, because by then everyone suspects the phone is holding something someone would rather it didn’t.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/FAmily-wanitng-data.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16193 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/FAmily-wanitng-data-300x169.jpg" alt="" width="300" height="169" /></a></p>
<p>Sometimes I can help. Often the honest answer is: it depends on who planned, what’s stored where, and a couple of laws most people have never heard of.</p>
<p>A person’s digital life doesn’t end when they do. It just sits there —email, photos, messages, cloud backups, a crypto wallet, the online business, the loyalty points, the birthday wishes from casual friends who didn’t realize the intended recipient is gone —waiting for someone with the right authority (and sometimes the right password) to come along. The question your client is really asking is who that someone is, and whether the door will open when they get there.</p>
<h5><strong>“Isn’t the executor just entitled to all of it?”</strong></h5>
<p>Not automatically. This surprises people. Two things do most of the governing here, and they don’t always pull in the same direction.</p>
<p>The first is a federal privacy law, the <strong>Stored Communications Act</strong>, written in 1986, before almost any of your clients had an email address. In plain terms and except in narrow circumstances, it bars the companies that hold the actual words of emails, messages, and the rest of the electronic communications from handing over the <em>contents</em>. It really doesn’t care that Grandma died and the family is grieving. A provider can face liability for oversharing, so its reflex is “no.”</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/SCA-protect.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16195 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/SCA-protect-300x169.jpg" alt="" width="300" height="169" /></a>The second is a state law that most states have now adopted: <strong>RUFADAA</strong> —the Revised Uniform Fiduciary Access to Digital Assets Act (yes, it’s a mouthful; blame the committee that named it). Drafted by the Uniform Law Commission, it has been adopted in most U.S. states, though details and terminology may vary by jurisdiction. It gives executors, trustees, and agents under a power of attorney a legal path to a decedent’s digital assets while carving out those private communications for extra protection, to stay on the right side of that 1986 federal law.</p>
<p>Now the necessary disclaimer, and I mean it: I’m a forensic examiner, not a lawyer. RUFADAA’s details vary from state to state, so treat what follows as the lay of the land, not legal advice for your jurisdiction —that’s your department (or your attorney’s), not mine. But the structure is worth knowing cold, because it may decide who wins before a referee enters the picture.</p>
<h5 style="text-align: center;"><strong>The three-rung ladder (and it’s upside down from what people expect)</strong></h5>
<h5 style="text-align: center;"><strong><a href="https://burgessforensics.com/wp-content/uploads/2026/08/3-rung-ladder.jpg"><img loading="lazy" decoding="async" class=" wp-image-16190 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/3-rung-ladder-300x169.jpg" alt="" width="394" height="222" /></a></strong></h5>
<p>RUFADAA sets a priority order for who controls an account. Picture a ladder that the platform reads from the top down.</p>
<ol>
<li><strong>The online tool. </strong>If the person used a tool the platform itself provides, such as Facebook’s Legacy Contact, Google’s Inactive Account Manager, Apple’s Digital Legacy, then that choice sits on the top rung. It can even override a contradictory will. Let that land: a two-minute setting on a phone can outrank a document a lawyer carefully drafted.</li>
<li><strong>The estate documents. </strong>No online tool? Then the directions in the will, trust, or power of attorney control who gets what, which is exactly why explicit “digital assets” language belongs in those documents now, not someday.</li>
<li><strong>The fine print. </strong>Nothing from above? Then the platform’s terms of service decide. But note that those were written to protect the platform, not your client’s heirs.</li>
</ol>
<p>Most people are sitting on rung three without knowing it.</p>
<h5><strong>So, what do the big platforms actually do?</strong></h5>
<ul>
<li><strong>Apple’s Digital Legacy</strong> can provide a designated Legacy Contact access to eligible Apple Account data, such as certain iCloud-stored photos, files, notes, messages, and device backups, after Apple approves a request supported by the access key and proof of death. It does not provide the decedent’s device passcode or decrypt a passcode-locked device, although Apple can remove Activation Lock. It’s one of the more generous setups, though. One caveat: if a paid iCloud+ account stops being paid, Apple does not guarantee indefinite preservation of data exceeding the free storage allowance and reserves the right to restrict access to or delete stored content.</li>
<li><strong>Google’s Inactive Account Manager </strong>is triggered by inactivity, not death. Set a window, say, three or eighteen months, and Google will either share the data you chose with the people you named, or delete the account. If nobody set it up, the family is left negotiating with support. Inactive Account Manager is an access plan, not a preservation plan: Google’s separate inactivity and storage-quota deletion policies still apply.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/Big-3-protect-data.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16191 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/Big-3-protect-data-300x169.jpg" alt="" width="300" height="169" /></a></li>
<li><strong>Facebook </strong>memorializes an account once it learns of a death, and a Legacy Contact can tend that memorial page, but Facebook does not hand over private messages. Full stop.</li>
</ul>
<p>The pattern: the cloud is a locked building, and every landlord has its own rules for who gets a key, and which rooms that key opens.</p>
<p>Note that companies change policies and the above are accurate as of the writing of this article.</p>
<h5><strong>“What if I need it for a case, not the estate?”</strong></h5>
<p>This is where the fighting families come in. Same walls, different reason for wanting in. When a decedent’s texts or emails matter to a wrongful-death claim, a probate contest, or a business dispute, a subpoena to the provider still runs headfirst into the Stored Communications Act on content. Still, a properly authorized fiduciary may have a stronger route to a catalogue of communications or other non-content records than to message content, though providers may require formal documentation and may impose statutory or policy-based conditions.</p>
<p>Which is why, in my line of work, the device usually beats the cloud. A phone, laptop, or backup that’s lawfully in the estate’s possession, when examined with proper authority, frequently holds the messages, photos, and app data the platform won’t volunteer, plus deleted material that never made it into any legacy tool.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/device-_-cloud.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16192 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/device-_-cloud-300x169.jpg" alt="" width="300" height="169" /></a>The catch is always the same pair: authority and access. The right to look, and a way in. And that “way in” is the quiet crisis. Desktop and laptop computers, and their physical backup drives, often give the enterprising computer geek a number of ways in. We’re frequently called on to excavate these potentially rich sources: existing files, deleted ones, and former drafts of the very documents and evidence a case turns on.</p>
<p>Phones are another matter. Modern ones are encrypted by default, so without the passcode, a legacy contact, or a good backup, even the family’s own forensic examiner can end up staring at a very expensive brick. (“Encrypted” isn’t always the dead-end people assume —but it isn’t a guarantee either.)</p>
<h2><strong>So, what to do?</strong></h2>
<p>This is the easy part, and it’s worth handing to clients now rather than litigating later.</p>
<ul>
<li><strong>Set the online tools. </strong>Apple Digital Legacy, Google Inactive Account Manager, Facebook Legacy Contact. It only takes about five minutes each, and they sit on the top rung of the ladder.</li>
<li><strong>Put digital assets in the estate plan. </strong>Explicit language in the will, trust, and power of attorney authorizing the fiduciary to access digital assets, including the content of communications, is exactly the consent RUFADAA and the SCA are looking for.</li>
<li><strong>Keep an inventory, not a password list in the will. </strong>A will can become a public record; a sealed, separately stored list of accounts and where the keys live does not. Crypto especially. Custodial exchanges may have separate estate-access procedures, subject to identity, probate, and compliance requirements. But self-custodied crypto is unforgiving: no seed phrase or proper login and no crypto coins for you. No exceptions.</li>
<li><strong>Don’t “clean up” the device. </strong>For anything that might become contested, powering through a phone or running a factory reset can destroy evidence. It’s also very likely to raise spoliation questions in a contested case. When in doubt, preserve first and examine later.</li>
</ul>
<h5><strong>The uncomfortable part <a href="https://burgessforensics.com/wp-content/uploads/2026/08/2nd-digital-life.jpg"><img loading="lazy" decoding="async" class=" wp-image-16189 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/2nd-digital-life-300x169.jpg" alt="" width="398" height="224" /></a></strong></h5>
<p>Most of us have built a whole second life online without realizing and left no instructions for it. For your clients, a few minutes of planning turns what would have been a legal-and-forensic headache into a routine handoff.</p>
<p>What’s the messiest digital-estate tangle you’ve run into? A locked phone nobody had the code to, a memorialized account, a crypto wallet with no key in sight? I’d like to hear how it played out.</p>
<p><strong>Burgess Forensics: (866) 345-3345  |  steve@burgessforensics.com</strong></p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … </strong></em><a href="https://burgessforensics.com/subscribe/"><em><strong>Subscribe now</strong></em></a><em><strong>!</strong></em></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='What Happens to Your Digital Life When You Die (And Who Can Access It)' data-link='https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='What Happens to Your Digital Life When You Die (And Who Can Access It)' data-link='https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/">What Happens to Your Digital Life When You Die (And Who Can Access It)</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/what-happens-to-your-digital-life-when-you-die-and-who-can-access-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access</title>
		<link>https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/</link>
					<comments>https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 20:20:38 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[iCloud]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16173</guid>

					<description><![CDATA[<p>“It’s encrypted, so I guess we’re just out of luck.” I hear some version of that from attorneys and other clients more often than you’d think, usually said with a kind of resigned finality, as though the phone in evidence had sealed itself inside a block of concrete. Sometimes it’s true (well, not the part [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/">Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access' data-link='https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/' data-app-id-name='category_above_content'></div><p>“It’s encrypted, so I guess we’re just out of luck.” I hear some version of that from attorneys and other clients more often than you’d think, usually said with a kind of resigned finality, as though the phone in evidence had sealed itself inside a block of concrete. Sometimes it’s true (well, not the part about the concrete). More often, it isn’t — and treating encryption as the end of the inquiry leaves evidence on the table that the other side may be perfectly happy to collect.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/02-one-locked-door.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16175 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/02-one-locked-door-300x200.jpg" alt="" width="300" height="200" /></a>Here’s the thing worth understanding: encryption locks the front door. It rarely locks the windows, the copies, and the spare key under the mat.</p>
<p>Modern devices encrypt data at rest. When an iPhone or a current Android phone or a laptop running FileVault or BitLocker is powered off or locked, the data on it is scrambled and, without the key, is effectively unreadable. That part is real, and it’s strong – it’s real strong. But “the data on that specific device, while it is locked” is a much narrower thing than “the information you’re after,” and the gap between those two is where most access actually happens.</p>
<p><strong>The passcode is the whole ballgame — and people are careless with it.</strong> Full-disk encryption is only as strong as the credential protecting it. People reuse passwords, write them on sticky notes, store them in a notes app, share them with a spouse or an assistant, or pick something guessable. When access to a<a href="https://burgessforensics.com/wp-content/uploads/2026/08/03-copies-everywhere.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16176 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/03-copies-everywhere-300x200.jpg" alt="" width="300" height="200" /></a> device is lawfully available — through consent, a cooperating party, or a court order — the encryption stops being an obstacle the moment the passcode is in hand.</p>
<p><strong>And by the way, the data usually lives in more than one place.</strong> This is the point often missed. A message exists on the sender’s phone and the recipient’s. When the message’ sender deleted it from their phone, it doesn’t do anything to the recipient’s copy of the message. Photos sync to iCloud or Google Photos. Documents sync to cloud storage. Phones back up to a computer or to the cloud, sometimes automatically, sometimes in a form far easier to access than the locked handset itself. The encrypted device in the evidence bag may be the hardest copy of the data to reach — and the least necessary, once you map where else that same information lives.</p>
<p><strong>Cloud accounts are their own doorway.</strong> When the data has synced to a provider, the relevant credential may be an account password rather than a device passcode, and the legal path may be a subpoena or <a href="https://burgessforensics.com/wp-content/uploads/2026/08/04-different-lock-different-key.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16177 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/04-different-lock-different-key-300x200.jpg" alt="" width="300" height="200" /></a>warrant to the provider rather than an attempt on the hardware. Different lock, different key, often a more productive one.</p>
<p><strong>The law here is genuinely unsettled, and that’s your department, not mine.</strong> Whether a person can be compelled to disclose or enter a passcode touches the Fifth Amendment, and courts around the country have landed in different places on it — some applying a “foregone conclusion” rationale, others declining to. Compelled use of a fingerprint or face has its own tangled line of cases. I’m a forensic examiner, not a lawyer, and I won’t pretend the doctrine is settled when it plainly isn’t. But knowing that these avenues exist — and that they’re contested — is the difference between assuming a device is unreachable and asking the right questions about how it might lawfully be reached.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/05-evidence-beyond-the-lock.jpg"><img loading="lazy" decoding="async" class=" wp-image-16178 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/05-evidence-beyond-the-lock-300x200.jpg" alt="" width="287" height="191" /></a>So what should you actually do? Stop treating “it’s encrypted” as the end of the road, as a verdict. Treat it as one locked door in a building with several entrances. Ask where else the data lives — the other party’s device, the cloud, a backup, a synced computer. Preserve all of it early, before someone decides to tidy up. And bring in a forensic examiner before you conclude anything is impossible, because what’s feasible depends heavily on the specific device, the operating system version, and how the data was stored — details that change constantly and that a competent examiner tracks for a living.</p>
<p>Encryption is a strong lock. It is not a force field. The attorneys who understand the difference get to the evidence; the ones who don’t talk themselves out of it.</p>
<p><em>Have you ever had a case when a locked or encrypted device in your case was or was not actually a dead end? I’d love to hear about it.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … </strong></em><a href="https://burgessforensics.com/subscribe/"><em><strong>Subscribe now</strong></em></a></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access' data-link='https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access' data-link='https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/">Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Metadata You Didn&#8217;t Know You Were Sending</title>
		<link>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/</link>
					<comments>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 21:10:04 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16161</guid>

					<description><![CDATA[<p>You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren&#8217;t looking. That paperwork is metadata — data about data. And it travels with your files whether or not you invited it along for the trip. [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/">The Metadata You Didn&#8217;t Know You Were Sending</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Metadata You Didn&#039;t Know You Were Sending' data-link='https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/' data-app-id-name='category_above_content'></div><p>You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren&#8217;t looking.</p>
<p>That paperwork is metadata — data about data. And it travels with your files whether or not you invited it along for the trip.</p>
<p style="text-align: left;">Metadata is the stuff a document quietly jots down while you&#8217;re jotting down words. There’s a lot of potential information there: Who created it, when, and on what computer.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/stowaway.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16166 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/stowaway-300x225.jpg" alt="" width="300" height="225" /></a> Who edited it, and when they last saved it. Where a photo was taken, down to the GPS coordinates. What camera, what settings, what software. None of it shows up on the page. All of it comes along, like a stowaway.</p>
<p>Most of the time this is harmless, but occasionally, it&#8217;s the whole story.</p>
<h4>A photo is a very talkative little file.</h4>
<p>Take a picture with your phone and you&#8217;ve created a small autobiography. The image, surely, but tucked inside is a section called EXIF data: the make and model of the phone, the date and time down to the second, and, if location services were on, the exact spot on Earth where you stood. Share that photo in its original form and you may be handing over your home address without meaning to.</p>
<p>The good news: most social platforms started stripping this out a few years ago when there was a public hue and cry about it. The bad news: &#8220;most&#8221; is not &#8220;all,&#8221; and emailing the original file, or dropping it in a shared folder, sends the whole talkative package along.</p>
<h4>Documents keep a diary too</h4>
<p>A Word document remembers more than the final draft. Depending on your settings, it can carry the author&#8217;s name, the company the software was registered to, how long the file was open, and sometimes, a list of former edits and tracked changes and comments you thought you&#8217;d removed. Every &#8220;on second thought, delete that paragraph&#8221; can live on in the file&#8217;s memory.</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16162 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/genrating-metadata-300x225.jpg" alt="" width="300" height="225" />The Internet is dotted with cautionary tales of press releases and legal filings that were sent out with the edits still readable underneath. The same is true with newsworthy congressional hearings. Most of us are not popular enough to warrant interest from the government. Still, the words on the page said one thing but the metadata said &#8220;here&#8217;s what we almost admitted.&#8221; Oopsie.</p>
<p>&nbsp;</p>
<h4>So, what to do?</h4>
<p>There&#8217;s no need to get paranoid about this. Depending on what you’re shopping for, your grocery list is not a national secret. But a few practical habits go a long way:</p>
<ul>
<li><strong>Before sending anything sensitive, look under the hood.</strong> In Word on Windows, &#8220;Inspect Document&#8221; should find and remove hidden data, comments, and tracked changes. Do it on the final version, not the draft.</li>
<li><strong>Turn off location tagging for your camera</strong> if you don&#8217;t need it — or scrub EXIF data from photos before sharing the originals. By the way, if litigation is foreseen that involves these photos, don’t scrub the EXIF metadata. It will be considered spoliation of data and will go poorly for you if and when it goes to court.</li>
<li><strong>Remember that &#8220;delete&#8221; inside a file often just means &#8220;hide.&#8221;</strong> Removing a comment from view is not always the same as removing it from the file.</li>
</ul>
<p>None of this requires becoming a hermit. It&#8217;s the digital equivalent of checking your pockets before you send the coat to the cleaners.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/hermit.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16163 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/hermit-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>Metadata isn&#8217;t sinister. It&#8217;s just honest — sometimes more honest than we&#8217;d like. The trick is knowing it&#8217;s there, so you decide what to share instead of the file deciding for you.</p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … </strong></em><a href="https://burgessforensics.com/subscribe/"><em><strong>Subscribe now</strong></em></a><em><strong>!</strong></em></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Metadata You Didn&#039;t Know You Were Sending' data-link='https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='The Metadata You Didn&#039;t Know You Were Sending' data-link='https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/">The Metadata You Didn&#8217;t Know You Were Sending</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</title>
		<link>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/</link>
					<comments>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 21:43:33 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16150</guid>

					<description><![CDATA[<p>The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: &#8220;produce as PDF, that&#8217;s fine.&#8221; Maybe not so fine when that same attorney later pays me to explain why the file on my screen can&#8217;t [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/">Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having' data-link='https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/' data-app-id-name='category_above_content'></div><p>The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: &#8220;produce as PDF, that&#8217;s fine.&#8221; Maybe not so fine when that same attorney later pays me to explain why the file on my screen can&#8217;t answer the question the case now turns on.</p>
<p>Here&#8217;s the thing the other side already knows: whoever picks the format picks what you get to see. It&#8217;s just how the rules work. Under Federal Rule of Civil Procedure 34(b)(2)(E), the party asking for the documents gets to specify the form they arrive in. Don&#8217;t specify, and the choice falls to the producing side, with &#8220;reasonably usable&#8221; form as the only floor — and reasonably usable is a long way from native. Say nothing about format and you&#8217;ve handed them the pen.</p>
<p>Native files vs. PDFs sounds like an argument for the IT department, right? It isn&#8217;t. It&#8217;s one of the quietest, most consequential fights in the whole discovery process, and it&#8217;s worth having on purpose.</p>
<h4>A PDF is a photograph of a document, not the document</h4>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/PDF-vs-Word-doc.jpg"><img loading="lazy" decoding="async" class="wp-image-16154 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/PDF-vs-Word-doc-300x164.jpg" alt="" width="347" height="190" /></a>A native file is the thing itself &#8211; the spreadsheet with its formulas still doing math, the email with its full routing header, the Word file that still remembers every draft, the photo that quietly wrote down where and when it was taken. I have a paragraph in my engagement letter saying so, albeit a bit more succinctly. A PDF or a TIFF is a picture of that file after someone chose the pose.</p>
<p>What really gets me is when evidence is produced as a printout of a PDF of a scan of a PDF created from the actual original file. Happens all the time. But it’s several steps away from what really happened and far from the metadata that tells the real story.</p>
<p>Such “pictures” drop exactly the parts that tend to win cases. Most of the metadata, describing fields such as who made it, when, on what device, and sometimes where tends to get lost when a PDF is generated from it. This is the difference between &#8220;he says he wrote it in March&#8221; and knowing, to the minute, that he didn&#8217;t.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/4-million.jpg"><img loading="lazy" decoding="async" class=" wp-image-16151 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/4-million-300x167.jpg" alt="" width="314" height="175" /></a></p>
<p>A spreadsheet may show you a very precise value of 4,203,722.46 in the flattened PDF version but hides the formulae and structure that generated a possibly different number. A document that previously contained all the things people put in a document before they remembered other people would read the tracked changes, comments, hidden rows? Native format keeps them. The flattened copy forgets them, conveniently.</p>
<p>Hash values and container data are integrity signals that may let you and me confirm that the document produced is the same as the original are casualties of a PDF export. It snaps that verification thread and asks you to just take everybody&#8217;s word for it instead.</p>
<p>None of it comes back, either. You can&#8217;t un-flatten a PDF into the original any more than you can un-fry a flapjack. Once it&#8217;s produced that way, the missing data isn&#8217;t hiding from you. It&#8217;s gone.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/unfrying-a-flapjack.jpg"><img loading="lazy" decoding="async" class="wp-image-16156 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/unfrying-a-flapjack-300x164.jpg" alt="" width="476" height="260" /></a></p>
<p>I had a case where the “date digitized” EXIF metadata from a series of photos supported one side’s story. However, deeper in the metadata, there was satellite data that cast real doubt on the story being told. Satellites and their atomic clocks don’t lie about the time or the day.</p>
<h4>Why the other side is so agreeable about it</h4>
<p>Producing in PDF usually isn&#8217;t laziness. It&#8217;s control wearing the costume of laziness. A flattened production is easier to redact, easier to Bates-stamp, and, in a happy coincidence, easier to sanitize. The timestamp that wrecks the timeline, the author who wasn&#8217;t supposed to be within a mile of that memo, the formula that shows how a number really got built: all of it vanishes in the conversion, and it vanishes wearing the respectable coat of &#8220;routine document handling&#8221; rather than the orange jumpsuit of spoliation.</p>
<p>To be fair, imaged production isn&#8217;t always a dodge. Sometimes there are honest reasons for it — privilege review, redacting personal or protected information, or real proportionality under Rule 26(b)(1) when native would cost more than the whole dispute is worth. Those reasons are legitimate. The trick is to make the other side say so out loud, in the protocol, so that &#8220;we imaged it&#8221; has to be justified rather than simply assumed.</p>
<p>I should be clear that &#8220;save as PDF&#8221; is also a genuinely lousy way to strip metadata even when someone&#8217;s trying to be honest. It leaves things behind and takes things it shouldn&#8217;t. But that&#8217;s a different article. For today: the party that controls the format controls the evidence, and they know it even if your side doesn&#8217;t.</p>
<h4>The fight is won in the ESI protocol, not in a motion six months later. <a href="https://burgessforensics.com/wp-content/uploads/2026/08/Stripping-metadata.jpg"><img loading="lazy" decoding="async" class=" wp-image-16155 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/Stripping-metadata-300x167.jpg" alt="" width="337" height="188" /></a></h4>
<p>This is the part I most want attorneys to hear. By the time you&#8217;re standing in front of a judge complaining about a bad production, you&#8217;re asking to redo work the other side has every incentive to slow-walk into the next fiscal year — and you&#8217;re explaining to your client why the schedule, and the bill, went sideways. Nobody enjoys that conversation. Least of all the person who once said &#8220;PDF is fine.&#8221;</p>
<p style="text-align: left;">So specify the format on the front end, in writing:</p>
<ul>
<li><strong>Ask for native formats, with metadata, by default</strong> for anything data-rich — spreadsheets, databases, structured exports — with load files that actually carry the field data. Boring to negotiate. Priceless to have.</li>
<li><strong>Name the metadata fields you want.</strong> Custodian, author, created and modified dates, an MD5 or SHA-1 hash, and parent/child relationships so attachments stay tied to their emails. &#8220;With metadata&#8221; is an invitation for the other side to read the phrase as generously as their conscience allows.</li>
<li><strong>Reserve the right to request native format</strong> for anything produced as an image, and say so up front — so when you invoke it, it&#8217;s a term of the deal and not an ambush they get to act wounded about.</li>
<li><strong>Bring your examiner in before the language is set, not after the production disappoints.</strong> Format specs written without technical input have a real talent for asking, very precisely, for the wrong thing.</li>
</ul>
<h4>The bottom line</h4>
<p>This is not enhance-the-reflection-in-the-sunglasses forensics. It&#8217;s plumbing. It&#8217;s unglamorous, it&#8217;s easy to skip, and it is very often the only thing standing between evidence you can build a case on and a tidy picture of evidence you have to take on faith.</p>
<p style="text-align: left;">Courts increasingly expect native production where format carries meaning, and (hopefully) increasingly treat &#8220;well, we already gave you a PDF&#8221; as the weak answer it is. But you don&#8217;t drift there by luck. You get there by treating format as a substantive term of the case — argued with the same seriousness as scope and custodians, and about a thousand times more attention than it usually gets. <a href="https://burgessforensics.com/wp-content/uploads/2026/08/checkbook.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16152 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/checkbook-300x167.jpg" alt="" width="300" height="167" /></a></p>
<p>Have the fight early. It&#8217;s a great deal cheaper than the one you&#8217;ll have later, in front of a judge, with your client and their checkbook watching.</p>
<p><em>What&#8217;s the worst production-format surprise you&#8217;ve run into — native you wish you&#8217;d demanded, a PDF that turned out to be hiding the whole case, or something else entirely?</em></p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><strong><em>Don’t miss a single issue of our informative newsletter … </em></strong><a class="uRHgOlUNgMoEOwgGoLxklVwtWfKTKfVqDQxSCg " tabindex="0" href="https://burgessforensics.com/subscribe/" target="_self" data-test-app-aware-link=""><strong><em>Subscribe now</em></strong></a><strong><em>!</em></strong></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having' data-link='https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having' data-link='https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/">Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Your Smart Home Is Testifying Against You</title>
		<link>https://burgessforensics.com/your-smart-home-is-testifying-against-you/</link>
					<comments>https://burgessforensics.com/your-smart-home-is-testifying-against-you/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 20:54:30 +0000</pubDate>
				<category><![CDATA[Attorneuys]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16122</guid>

					<description><![CDATA[<p>A fitness tracker once told me the exact moment its wearer stopped moving. Not slowed down. Stopped. The device wasn&#8217;t built to establish a time of death. It was builtto count steps and nag its owner about standing up more often. But it kept a continuous record, and that record answered a question nobody had [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/your-smart-home-is-testifying-against-you/">Your Smart Home Is Testifying Against You</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Your Smart Home Is Testifying Against You' data-link='https://burgessforensics.com/your-smart-home-is-testifying-against-you/' data-app-id-name='category_above_content'></div><p style="text-align: left;">A fitness tracker once told me the exact moment its wearer stopped moving. Not slowed down. Stopped. The device wasn&#8217;t built to establish a time of death. It was builtto count steps and nag its owner about standing up more often. But it kept a continuous record, and that record answered a question nobody had thought to ask it.</p>
<p>I can&#8217;t reveal much about the case. The survivors believed the facility had let conditions get too hot for too long with too little warning. The other side believed close to the opposite: that the tracker&#8217;s own history showed the deceased knew better than to push that hard through a changing but controlled environment. Both sides were arguing about the same person&#8217;s habits, and the tracker had a record of them. Dueling cardiologists reached differing conclusions about the fitness level of the deceased.</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16127 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/heart-rate-300x164.png" alt="" width="300" height="164" />I did not expect a line chart to affect me. Heart rate climbing to a dangerous peak, dropping to zero, then flat and never moving again. Plain as any spreadsheet. Then I imagined what that jagged line meant on the floor of the event.</p>
<p>That case is the whole of digital forensics in one artifact. People imagine this work is about clever adversaries planting evidence. I hear that concern regularly, and it is rarely what actually happened. The real story is duller and much harder to argue with: an ordinary device did exactly what it was built to do, and nobody remembered that what it was built to do includes keeping a record.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/COnnected-house.png"><img loading="lazy" decoding="async" class="size-medium wp-image-16124 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/COnnected-house-300x167.png" alt="" width="300" height="167" /></a>Your house is full of these. A video doorbell logs every motion event with a timestamp, whether or not itsaved any video.A voice assistant logs when it woke up, and sometimes what it heard in the few seconds on either side, depending on a setting its owner has never opened or knew existed. A thermostat infers occupancy from temperature adjustments and motion, which turns out to be a decent proxy for whether anyone was home. A robot vacuum holds a floor plan of every room it has ever cleaned. A car knows where it went and how fast it got there. It is getting harder and harder to have a good ol&#8217; dumb home.</p>
<p>None of this was designed to be evidence,<img loading="lazy" decoding="async" class="size-medium wp-image-16126 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/dumb-house-300x164.png" alt="" width="300" height="164" /> which is one reason it can become powerful evidence when properly authenticated and interpreted. There may still be questions about reliability, chain of custody, retention settings, incomplete logs, and similar issues, but the device itself has no made-up story to keep straight. It is not shaped by human memory in the way witness recollection is, though it still has to be interpreted carefully. Someone can be careful about what they say out loud and still be wearing a watch that logged a heart rate spike at the moment in question.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/crook-in-the-themrostat.png"><img loading="lazy" decoding="async" class="size-medium wp-image-16125 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/crook-in-the-themrostat-300x164.png" alt="" width="300" height="164" /></a>The law is still catching up. Carpenter v. United States narrowed the old assumption that anything you hand to a company is fair game without a warrant, at least for cell site location records. Aside from preservation duties, discovery scope, and the need to meet and confer, there is a live question whether that reasoning will narrow access to data from a thermostat, a vacuum&#8217;s floor map, or a year of refrigerator door-open events. Those boundaries are being worked out one motion and one court at a time as we speak. I would not bet on the answers looking the same in five years as they do today.</p>
<p>For lawyers, the lesson is simple: ask early what connected devices were present, where the data is stored, how long it is retained, and who controls it.</p>
<p>In the meantime, the practical reality is simpler. Your home has more employees than you think, and all of them are taking notes. None of it is malicious. Much of it may be discoverable or obtainable, if someone thinks to ask.</p>
<p>What smart-device data point has surprised you most, in a case or in your own house? I&#8217;d love to hear about it.</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Your Smart Home Is Testifying Against You' data-link='https://burgessforensics.com/your-smart-home-is-testifying-against-you/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Your Smart Home Is Testifying Against You' data-link='https://burgessforensics.com/your-smart-home-is-testifying-against-you/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/your-smart-home-is-testifying-against-you/">Your Smart Home Is Testifying Against You</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/your-smart-home-is-testifying-against-you/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Metadata Your Client Is Accidentally Sending to Opposing Counsel</title>
		<link>https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/</link>
					<comments>https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 21:20:25 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Evidence Preservation]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15429</guid>

					<description><![CDATA[<p>Your client didn&#8217;t leak anything on purpose. That&#8217;s usually how it goes. The confidential settlement number, the internal complaint about a coworker, the photo that was supposed to prove they were out of town — all of it can arrive at opposing counsel&#8217;s desk wrapped in a bow, because nobody thought to ask what was [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/">The Metadata Your Client Is Accidentally Sending to Opposing Counsel</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Metadata Your Client Is Accidentally Sending to Opposing Counsel' data-link='https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/' data-app-id-name='category_above_content'></div><p>Your client didn&#8217;t leak anything on purpose. That&#8217;s usually how it goes. The confidential settlement number, the internal complaint about a coworker, the photo that was supposed to prove they were out of town — all of it can arrive at opposing counsel&#8217;s desk wrapped in a bow, because nobody thought to ask what was riding along with the file.</p>
<p>Metadata is the paperwork a document fills out about itself. Every photo carries a record of when and where it was taken, and often what device took it.<a href="https://burgessforensics.com/wp-content/uploads/2026/07/metadata-forms.jpg"><img loading="lazy" decoding="async" class=" wp-image-15432 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/metadata-forms-300x169.jpg" alt="" width="279" height="157" /></a>Every Word document remembers who created it, who edited it, and sometimes what earlier drafts looked like — because &#8220;track changes&#8221; doesn&#8217;t always mean what people think it means. Every email carries routing information that shows exactly which server it passed through and when, which is a problem if someone&#8217;s story about when they &#8220;first learned&#8221; something doesn&#8217;t match the timestamps.</p>
<p>I&#8217;ve spent more hours than I&#8217;d like counting looking at metadata that a client&#8217;s own attorney didn&#8217;t know was there. A &#8220;final&#8221; contract whose revision history documented every negotiating position the client took before landing on the last one. A deposition exhibit — a screenshot, no less — whose EXIF data placed the photo three weeks earlier and 200 miles away from where the witness swore it was taken.</p>
<p>None of this requires opposing counsel to be Sam Spade. It requires them to right-click and select &#8220;Properties,&#8221; or open the file in a tool built for exactly this purpose. Metadata review is the price of admission in any competent discovery practice now, and if your side isn&#8217;t doing it, you can safely assume the other side is.</p>
<p style="text-align: left;">The fix isn&#8217;t complicated, but it does require actually doing it before production, not after a client calls you in a panic. Native files should be scrubbed of unnecessary metadata before they go out the door, using proper redaction and metadata-removal tools — not just &#8220;save as PDF&#8221; and hope for the best, because that conversion process is notoriously bad at actually stripping what needs stripping. Track changes and comments need to be resolved and cleared, not just hidden from the default view. <a href="https://burgessforensics.com/wp-content/uploads/2026/07/judge-grimm.jpg"><img loading="lazy" decoding="async" class=" wp-image-15430 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/judge-grimm-300x169.jpg" alt="" width="318" height="179" /></a>Photos being produced as exhibits should have their embedded location and device data reviewed before anyone decides whether that data helps or hurts the case — because sometimes it helps. You don&#8217;t want to accidentally destroy evidence (or let your client do it accidentally on purpose) when you’re just trying to be tidy. Frankly, destroying evidence when litigation is anticipated is a very large no-no at which a judge may frown deeply – sometimes with sanctions.</p>
<p style="text-align: left;">The flip side of all this, of course, is that the same sloppiness that burns your client can work in your favor against the other side. A produced document with intact metadata is a gift. It tells you who really wrote it, when, and whether the &#8220;contemporaneous&#8221; memo was actually drafted three days after the fact. I&#8217;ve had more than one case where a &#8220;Created&#8221; timestamp that didn&#8217;t match anyone&#8217;s testimony blew the case open.</p>
<p style="text-align: center;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/metadata_rail.jpg"><img loading="lazy" decoding="async" class="wp-image-15433 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/metadata_rail-300x200.jpg" alt="" width="294" height="196" /></a></p>
<p style="text-align: left;">The broader point is that a document isn&#8217;t just what you can see on the screen. It&#8217;s a small forensic record of its own life, and that record travels with it whether anyone remembers to look or not. Attorneys who treat metadata review as a routine part of both production and receipt catch things that attorneys who don&#8217;t simply never see.</p>
<p style="text-align: left;">What&#8217;s the closest call you&#8217;ve had — metadata that almost went out the door, or metadata you caught on the other side that changed the case?</p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><strong><i>Don’t miss a single issue of our informative newsletter … <a title="https://burgessforensics.com/subscribe/" href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener" data-outlook-id="f80e5241-8c12-4ddf-9750-a82b56a522dd">Subscribe</a>!</i></strong></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Metadata Your Client Is Accidentally Sending to Opposing Counsel' data-link='https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='The Metadata Your Client Is Accidentally Sending to Opposing Counsel' data-link='https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/">The Metadata Your Client Is Accidentally Sending to Opposing Counsel</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
