Computer (including cell/mobile phone) text messages are sometimes used as evidence in legal proceedings. So what is the best way to save a text (or photo/video/audio) record as evidence? In other words, how can an investigator secure digital evidence today so he can prove its chain of custody later in a court?

Suppose your estranged spouse (husband/wife) cell phones you a photograph or text message relevant to a future divorce hearing. Or suppose a business partner (or manager, boss, politician, government official) sends you a video important to a dispute/lawsuit -- sexual harassment, employment discrimination, breach of contract.

There is no perfect way to save electronic evidence, but some techniques are better than others. The more you freeze the data to prevent its deletion and deter its modification, the better. And the more you capture timely information about its source, the better.

A new technique enables you to authenticate the text (or other mobile phone) message record with a voice signature. A service called My Electronic Evidence lets you memorialize an electronic record (like a record of a text, photo, video or e-mail message) with a date, a voice statement and a notation about where you think the message came from and how you preserved it.

To use the service, you need to store the content of the text message in a computer file like a pdf, a doc or a jpg. Then you upload the file (or if you're a techie, a hash of the file) to the service, and you record a statement about where the evidence came from, how you captured it and so on. The service calculates a "signature code" for the file. Then it allows you to speak a voice statement that says you sign the evidence, together with the "signature code" as of a stated date. Finally, the service sends you a self-explanatory archive showing that you authenticated the evidence with your unique voice.

If after that the evidence file is changed, it will no longer match the signature code contained in your dated voice record. Thus the service reliably links you (as evidence collector) to the evidence and establishes the existence of the evidence as of a date. This information can be invaluable when assessing evidence months or years later, such as in a lawsuit, when memories have faded or possibly when you are no longer available to vouch for the evidence.

Suppose you have a text or Twitter message (or photo) on your cell phone. How would you convert it to pdf or doc format? One way is to forward the message to your e-mail, where you can access it from your PC. Then you can save the e-mail content as a pdf. (I personally had to do this for my wife when, as part of a divorce/child custody battle, her friend's spouse subpoenaed the text messages between my wife and her friend. Although the messages didn't say anything more than "Let's go 2 lunch" and so on, we still had to turn the messages over.)

Update February 2013:  Forensics to recover deleted logs, images, geolocation and text messages,.

Update: Legal subpoena for information from Facebook.

Update July 2011:  See discussion about recovery of text messages from service providers.


