<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech Archives - Burgess Forensics</title>
	<atom:link href="https://burgessforensics.com/category/tech/feed/" rel="self" type="application/rss+xml" />
	<link>https://burgessforensics.com/category/tech/</link>
	<description>Computer Forensics, Electronic Discovery &#38; Expert Witness</description>
	<lastBuildDate>Mon, 28 Sep 2026 19:07:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://burgessforensics.com/wp-content/uploads/2016/08/burgess-42x42.png</url>
	<title>Tech Archives - Burgess Forensics</title>
	<link>https://burgessforensics.com/category/tech/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Your Client’s Shopping Bot Clicked “Buy.” Who (or What) Made the Contract?</title>
		<link>https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/</link>
					<comments>https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 19:07:43 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Shopping Agent]]></category>
		<category><![CDATA[Tech]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16269</guid>

					<description><![CDATA[<p>We have spent years teaching computers to answer our questions, although sometimes it is the other way around. Now we are teaching them to spend our money. The first time an AI shopping agent orders the wrong shoes, nobody will call a lawyer, but the first time it orders 4,000 of them for a company, [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/">Your Client’s Shopping Bot Clicked “Buy.” Who (or What) Made the Contract?</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Your Client’s Shopping Bot Clicked “Buy.” Who (or What) Made the Contract?' data-link='https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/' data-app-id-name='category_above_content'></div><p>We have spent years teaching computers to answer our questions, although sometimes it is the other way around. Now we are teaching them to spend our money. The first time an AI shopping agent orders the wrong shoes, nobody will call a lawyer, but the first time it orders 4,000 of them for a company, somebody will.<a href="https://burgessforensics.com/wp-content/uploads/2026/09/20000-shoes.jpg"><img loading="lazy" decoding="async" class="wp-image-16270 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/09/20000-shoes-300x157.jpg" alt="" width="434" height="227" /></a>This isn’t just a mental exercise. In September, Amazon blocked Meta’s Muse agent from shopping on its platform, citing a lack of authorization, an agent that didn’t identify itself, and the handling of customer credentials. Amazon has also blocked some agents from OpenAI and Google. Banks have separately warned that shopping agents may buy the wrong product, exceed a budget, steer customers toward weaker payment protections, or expose them to scams and fraud.</p>
<p style="text-align: left;">That raises a deceptively simple question: When the bot clicks “Buy,” who agreed to the contract?<a href="https://burgessforensics.com/wp-content/uploads/2026/09/amazon-block.jpg"><img loading="lazy" decoding="async" class=" wp-image-16271 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/09/amazon-block-300x157.jpg" alt="" width="323" height="169" /></a></p>
<p>The short answer is usually the person or company that deployed, authorized, or controlled the bot—not the bot itself. But the short answer rarely ends the argument. The longer answer, which is the one that could generate billable hours, is whether the bot acted within the authority it was given.</p>
<p>The federal E-SIGN Act provides that a contract involving interstate or foreign commerce cannot be denied legal effect, validity, or enforceability solely because its formation involved one or more electronic agents, so long as the agent’s action is legally attributable to the person to be bound. E-SIGN removes the <em>electronic-agent objection</em>; it does not itself establish agency, assent, scope of authority, or compliance with other applicable law. 15 U.S.C. § 7001(h).  State law may matter as well, including state enactments of the Uniform Electronic Transactions Act (UETA), whose § 14 addresses automated transactions.</p>
<p>So the fact that no human physically clicked the button does not automatically make the transaction disappear. We crossed that bridge years ago with automated ordering systems. Today’s bots are just crossing it with your credit card in their (virtual) hands.</p>
<p>The harder issue is authorization.</p>
<p>Suppose a client tells an agent, “Find me a laptop under $1,500 with at least 32 gigabytes of memory,” and the agent buys one for $1,425. That looks comfortably authorized. Now suppose it buys a $2,300 laptop because it decides the improved processor is “worth the investment.” Helpful initiative, perhaps. Also a decent opening paragraph for a complaint.<a href="https://burgessforensics.com/wp-content/uploads/2026/09/pricey-laptop.jpg"><img loading="lazy" decoding="async" class=" wp-image-16275 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/09/pricey-laptop-300x157.jpg" alt="" width="354" height="185" /></a></p>
<p>Agency principles will matter. What authority did the user actually grant? What limits appeared in the prompt, account settings, purchasing policy, or platform terms? Did the user authorize the transaction itself? Did the merchant’s terms allow this type of automated or third-party access? Did the agent have authority to manifest assent to the merchant’s terms on the user’s behalf? And did the merchant have reason to know that the agent was operating outside its instructions?</p>
<p>These disputes will be won or lost on the digital record, and much of that record is logs.</p>
<p>Attorneys should stop thinking of the receipt as the complete record. It’s not a piece of paper in your pocket. The relevant evidence may include the user’s original prompt and follow-up instructions; spending limits and product filters; whatever agent action history exists, tool-call logs, audit trails, and system events; model and software versions; authentication records; cart changes; confirmation screens; and the merchant’s server logs.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/09/evidence-trail.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16273 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/09/evidence-trail-300x157.jpg" alt="" width="300" height="157" /></a>Collect it early. AI systems and their vendors do not necessarily retain every step indefinitely. A clean-looking final confirmation can conceal ten earlier decisions, three rejected products, a changed budget, and one hallucinated free-shipping offer. Hallucinated by the bot, that is.</p>
<p>Then there is the chargeback problem. Consumers may assume that “the AI did it” means “unauthorized.” Card issuers and banks may see a more complicated record. A purchase made through credentials deliberately supplied to an agent is not automatically equivalent to a stolen-card transaction. Whether a customer has a chargeback right, an error-resolution claim, or some other remedy may depend on the payment method, the issuer’s and network’s rules, the authentication record, the instructions given to the agent, the merchant’s conduct, and whether the agent made an unauthorized purchase or merely made an authorized purchase badly.<a href="https://burgessforensics.com/wp-content/uploads/2026/09/preserve.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16274 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/09/preserve-300x157.jpg" alt="" width="300" height="157" /></a></p>
<p>In other words, buyer’s remorse does not become a stolen-card case just because software was involved.</p>
<p>Fraud and privacy add another layer. A shopping agent may see card details, purchase history, addresses, brand preferences, and perhaps the contents of an email account or calendar. A compromised agent could make an unauthorized purchase. A perfectly functioning agent could also be manipulated by a fraudulent listing, a poisoned recommendation, or a merchant designed to look legitimate to software rather than to a human.</p>
<p>For attorneys advising businesses, now is the time to ask practical questions. Are agent-made purchases permitted? Is human approval required above a stated amount? Are transaction logs preserved? Can the system explain which instruction caused it to choose a product? Can the agent accept arbitration clauses, subscriptions, or recurring charges? And who receives the alert when it gets creative?</p>
<p>Like agency law, consumer protection, and the rules of evidence, contract law isn&#8217;t going anywhere. It just has a new participant: one that works quickly, reads terms instantly, and has never once felt the healthy hesitation that comes from entering a credit-card number. Has it ever felt anything?</p>
<p>The bot may have clicked “Buy.” The case may turn on who told it that it could.</p>
<p>Questions about the digital trail behind an automated transaction? Burgess Forensics examines system logs, account activity, metadata, and other digital evidence. (866) 345-3345 | <a href="mailto:steve@burgessforensics.com">steve@burgessforensics.com</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Your Client’s Shopping Bot Clicked “Buy.” Who (or What) Made the Contract?' data-link='https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Your Client’s Shopping Bot Clicked “Buy.” Who (or What) Made the Contract?' data-link='https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/">Your Client’s Shopping Bot Clicked “Buy.” Who (or What) Made the Contract?</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/your-clients-shopping-bot-clicked-buy-who-or-what-made-the-contract/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access</title>
		<link>https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/</link>
					<comments>https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 20:20:38 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[iCloud]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16173</guid>

					<description><![CDATA[<p>“It’s encrypted, so I guess we’re just out of luck.” I hear some version of that from attorneys and other clients more often than you’d think, usually said with a kind of resigned finality, as though the phone in evidence had sealed itself inside a block of concrete. Sometimes it’s true (well, not the part [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/">Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access' data-link='https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/' data-app-id-name='category_above_content'></div><p>“It’s encrypted, so I guess we’re just out of luck.” I hear some version of that from attorneys and other clients more often than you’d think, usually said with a kind of resigned finality, as though the phone in evidence had sealed itself inside a block of concrete. Sometimes it’s true (well, not the part about the concrete). More often, it isn’t — and treating encryption as the end of the inquiry leaves evidence on the table that the other side may be perfectly happy to collect.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/02-one-locked-door.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16175 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/02-one-locked-door-300x200.jpg" alt="" width="300" height="200" /></a>Here’s the thing worth understanding: encryption locks the front door. It rarely locks the windows, the copies, and the spare key under the mat.</p>
<p>Modern devices encrypt data at rest. When an iPhone or a current Android phone or a laptop running FileVault or BitLocker is powered off or locked, the data on it is scrambled and, without the key, is effectively unreadable. That part is real, and it’s strong – it’s real strong. But “the data on that specific device, while it is locked” is a much narrower thing than “the information you’re after,” and the gap between those two is where most access actually happens.</p>
<p><strong>The passcode is the whole ballgame — and people are careless with it.</strong> Full-disk encryption is only as strong as the credential protecting it. People reuse passwords, write them on sticky notes, store them in a notes app, share them with a spouse or an assistant, or pick something guessable. When access to a<a href="https://burgessforensics.com/wp-content/uploads/2026/08/03-copies-everywhere.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16176 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/03-copies-everywhere-300x200.jpg" alt="" width="300" height="200" /></a> device is lawfully available — through consent, a cooperating party, or a court order — the encryption stops being an obstacle the moment the passcode is in hand.</p>
<p><strong>And by the way, the data usually lives in more than one place.</strong> This is the point often missed. A message exists on the sender’s phone and the recipient’s. When the message’ sender deleted it from their phone, it doesn’t do anything to the recipient’s copy of the message. Photos sync to iCloud or Google Photos. Documents sync to cloud storage. Phones back up to a computer or to the cloud, sometimes automatically, sometimes in a form far easier to access than the locked handset itself. The encrypted device in the evidence bag may be the hardest copy of the data to reach — and the least necessary, once you map where else that same information lives.</p>
<p><strong>Cloud accounts are their own doorway.</strong> When the data has synced to a provider, the relevant credential may be an account password rather than a device passcode, and the legal path may be a subpoena or <a href="https://burgessforensics.com/wp-content/uploads/2026/08/04-different-lock-different-key.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16177 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/04-different-lock-different-key-300x200.jpg" alt="" width="300" height="200" /></a>warrant to the provider rather than an attempt on the hardware. Different lock, different key, often a more productive one.</p>
<p><strong>The law here is genuinely unsettled, and that’s your department, not mine.</strong> Whether a person can be compelled to disclose or enter a passcode touches the Fifth Amendment, and courts around the country have landed in different places on it — some applying a “foregone conclusion” rationale, others declining to. Compelled use of a fingerprint or face has its own tangled line of cases. I’m a forensic examiner, not a lawyer, and I won’t pretend the doctrine is settled when it plainly isn’t. But knowing that these avenues exist — and that they’re contested — is the difference between assuming a device is unreachable and asking the right questions about how it might lawfully be reached.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/05-evidence-beyond-the-lock.jpg"><img loading="lazy" decoding="async" class=" wp-image-16178 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/05-evidence-beyond-the-lock-300x200.jpg" alt="" width="287" height="191" /></a>So what should you actually do? Stop treating “it’s encrypted” as the end of the road, as a verdict. Treat it as one locked door in a building with several entrances. Ask where else the data lives — the other party’s device, the cloud, a backup, a synced computer. Preserve all of it early, before someone decides to tidy up. And bring in a forensic examiner before you conclude anything is impossible, because what’s feasible depends heavily on the specific device, the operating system version, and how the data was stored — details that change constantly and that a competent examiner tracks for a living.</p>
<p>Encryption is a strong lock. It is not a force field. The attorneys who understand the difference get to the evidence; the ones who don’t talk themselves out of it.</p>
<p><em>Have you ever had a case when a locked or encrypted device in your case was or was not actually a dead end? I’d love to hear about it.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … </strong></em><a href="https://burgessforensics.com/subscribe/"><em><strong>Subscribe now</strong></em></a></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access' data-link='https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access' data-link='https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/">Encrypted Doesn’t Mean Untouchable: What Attorneys Should Know About Device Access</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/encrypted-doesnt-mean-untouchable-what-attorneys-should-know-about-device-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
