FREE e-Newsletter
Important News - Hot Topics
Get them Now!
Brian Cain

Brian Cain

Brian Cain is a sergeant with the Holly Springs (Ga.) Police Department, and is known as the "Millennial cop" on Twitter. He has been in law enforcement since 2000. He hosts and produces a podcast for Millennials in law enforcement.



Michael Bostic

Michael Bostic

Mike Bostic, of Raytheon Corp.'s Civil Communication Solutions group, specializes in open architecture, systems integration of communications and data programs. Mike spent 34 years with the LAPD. He managed IT and facility development, as well as the SWAT Board of Inquiry, which developed new command-and-control systems.
Technology

Handling Cell Phones and Their Digital Evidence

Here are five tips for handling smartphone digital evidence recovered from subjects.

April 18, 2013  |  by Graham Kuzia

Mobile forensic devices can extract data from seized cellular phones. Photo by Graham Kuzia.
Mobile forensic devices can extract data from seized cellular phones. Photo by Graham Kuzia.

Using technology to collect evidence is no longer an option. It's a necessity. Yes, cell phones can provide investigators with a call history, text messages. and contact lists. They can also provide us with other valuable data that's sometimes overlooked.

Smartphones have operating systems; store data; access the Internet; and send/receive files that could be potential evidence. Smartphones also have the ability to use applications that can circumvent records subpoenaed through their service provider. An example of this is Skype and WhatsApp that use data plans instead of text messages to communicate. The service provider does not have a record of the conversation.

A 2012 study by Analysys Mason revealed that more than 45 percent of smartphone owners use a messaging application other than standard SMS text messaging.

The contents of smartphones can now be erased remotely. This means the phone could be in your patrol car on the way to the police department and your suspect can erase everything on it from a computer or another phone. This is done through a variety of programs such as iCloud for iOS or Google Sync for Android. If you think that this is beyond the capacity of offenders, think again. Apple currently has over 150 million iCloud users. That's roughly half the population of the United States.

So what can law enforcement do to ensure that the evidence on phones is not altered or destroyed? Here are five suggestions:

  1. Put on gloves. You don't want to put your DNA or fingerprints on the phone.
  2. If the phone is off, leave it off and photograph it.
  3. If the phone is on, photograph the screen and place it in a Faraday bag, aluminum foil or signal-blocking container. This will prevent a third party from connecting to the phone and being able to alter what's on it.
  4. Collect the phone charger if you can find it and place it in evidence with the phone. When the phone's signal is blocked, it will drain the battery rapidly trying to connect to the network. The correct phone charger will be important during extraction.
  5. Bring the phone to a law enforcement digital forensics specialist trained in proper extraction methods.

Here's one suggestion about what not to do. Don't attempt to look through the phone on scene. Incorrect password attempts may lock you out of the phone permanently. By navigating through the phone, you are also altering evidence.  

Seizing digital evidence properly can make or break a case. Without best practices being adhered to by law enforcement on the response level, evidence that may have been used to convict a violent offender could be found inadmissible in court. It's imperative that officers acknowledge the need for continued education and keep current with technology.

Graham Kuzia is a reserve Gaston County (N.C.) Police officer and digital forensics program developer at the American Academy of Applied Forensics. He was featured in a 2010 "Shots Fired" article.

Related:

Michigan ACLU Questions Troopers' Use of Cellphone Data Extractors

Tags: Smartphones, Computer Forensics, Evidence Collection


Comments (1)

Displaying 1 - 1 of 1

kbradford @ 4/25/2013 6:55 AM

Great Articel, Couple of other things to add, if a Faraday bag is not available and the phone is on, put it in "airplane mode" so that it can't be accessed by outside and data be erased. Here at our Exploited and Missing Children's (EMCU) and Internet Crimes Against Children Unit (ICAC) We have used cell phone information and texts to solve Child physical abuse crimes, Runaways, Missing Children and Homicides. Phones now are mini computers and it is amazing what can be found in them. Our Digital Forensics Investigators have gone into unallocated space and discovered evidence that suspects thought were long gone. I especially warn against unauthorized investigations into phones without consent or search warrants, Officers/Deputies can eliminate some of your best evidence in a case by "snooping" without the authority to do so!

Join the Discussion





POLICE Magazine does not tolerate comments that include profanity, personal attacks or antisocial behavior (such as "spamming" or "trolling"). This and other inappropriate content or material will be removed. We reserve the right to block any user who violates this, including removing all content posted by that user.

Other Recent Blog Posts

Fine Line Between Lawful and Unlawful Protests
There will always be issues and decisions that every citizen may not agree with – it is...
Aimpoint Micro T-2 Red-Dot Optic
With its Micro T-2, Aimpoint has taken a proven winner and made it even better by adding...
Fueling the Flames in Ferguson
So far I have exercised what I consider "commendable restraint" in holding back my public...

Get Your FREE Trial Issue and Win a Gift! Subscribe Today!
Yes! Please rush me my FREE TRIAL ISSUE of POLICE magazine and FREE Officer Survival Guide with tips and tactics to help me safely get out of 10 different situations.

Just fill in the form to the right and click the button to receive your FREE Trial Issue.

If POLICE does not satisfy you, just write "cancel" on the invoice and send it back. You'll pay nothing, and the FREE issue is yours to keep. If you enjoy POLICE, pay only $25 for a full one-year subscription (12 issues in all). Enjoy a savings of nearly 60% off the cover price!

Offer valid in US only. Outside U.S., click here.
It's easy! Just fill in the form below and click the red button to receive your FREE Trial Issue.
First Name:
Last Name:
Rank:
Agency:
Address:
City:
State:
  
Zip Code:
 
Country:
We respect your privacy. Please let us know if the address provided is your home, as your RANK / AGENCY will not be included on the mailing label.
E-mail Address:

Police Magazine