Evidence Matters with Bui & Davis

Episode 2: Why Mobile Device Forensics Goes Sideways

Martha Season 1 Episode 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 29:39

Connect with Jerry or Steve

Your phone is not a tiny laptop, and treating it that way is how mobile device collections blow up in litigation and investigations. We talk through what actually makes mobile forensics hard: layered control across the device, iOS or Android, and the messaging apps where the evidence lives, plus constant changes in encryption, APIs, and forensic tooling.

We also get practical about what makes a mobile device collection defensible. From our kickoff and scoping calls to chain of custody and documentation, we explain how we set expectations with outside counsel, in house teams, and nervous custodians, especially in BYOD scenarios where personal and work data commingle. Privacy is always on the table, so we dig into when targeted acquisition can reduce risk and when you still need to collect to preserve because preservation in place is rarely an option on phones.

Then we break down the core decision points: targeted eDiscovery workflows versus full file system extraction for deeper forensic analysis, the real world disruption of taking a phone for hours or even days, and what to do when critical information is missing. Sometimes you cannot recover deleted artifacts, but you can analyze the gaps, correlate surrounding metadata, and assess whether the absence supports a spoliation narrative or an innocent explanation. We close by previewing the “what happens next” step: how Data Solutions normalizes raw mobile artifacts so reviewers can consume the data accurately across eDiscovery platforms, down to emoji fidelity and clean productions.

Subscribe, share this with your team, and leave a review if it helps. What’s the hardest part of mobile collections in your world: privacy, app coverage, or getting custodians comfortable?

Evidence Matters with Bui & Davis is a podcast for litigators, in-house counsel, legal operations professionals, and eDiscovery teams navigating today's complex data landscape. Hosted by digital forensics experts Jerry Bui and Steve Davis, the show explores digital evidence, investigations, mobile devices, AI, defensibility, data governance, and the evolving challenges shaping modern litigation and discovery. Practical insights, real-world experience, and conversations that help legal teams make better decisions when evidence matters most. 

Visit www.purposelegal.io for more information

Jerry Bui-(00:02.114)

Hi there, everyone. Welcome Evidence Matters with Bui and Davis. I am Jerry Bui. I am the senior vice president of digital forensics at Purpose Legal.

Steve Davis- (00:16.104)

And I am Steve Davis and I'm a VP in forensics and investigations for purpose legal.

Jerry Bui-(00:24.312)

Thanks, Steve. We are the co-hosts of this new podcast series, and we will on occasion have other digital forensics experts or stakeholders, a variety of guests that'll help make this discussion more colorful. But the goal is to tackle the digital forensics issues de jour, and the ones that I find coming up time and time again, Steve, is the issue around mobile device collections.

I thought I'd ask you since you interface a lot with clients and get feedback from them about mobile collections and how well they go or how badly they go, which is very often the case these days, and we'll get into the reasons why. But h you know, after a collection is performed, what is the most common reason that you see from your seat why mobile collections go poorly?

Steve Davis- (01:21.304)

Yeah, and I was thinking about this last night and this morning and we were just chatting off camera about, you know, trips to Italy and Greece. My family and I took one year or so ago and you know, I've been to Australia, I've been to Africa, I've been to France and England, but I hadn't been to Greece and Italy. So as a human, we kind of try to create expectations for what something's gonna be like. And so we borrow either we get online and we Google and look at things or we read magazines if we're old school, or we pull from our frame of reference. So for me, I pull from other trips I took to think about it. And I I analogize that with, you know, the the the normal thing a lot of people have done historically is get a bit by bit forensic image of a computer. So when phones and mobile devices started becoming more normative in terms of e discovery, I think people borrowed from their experiences much like I did on vacation, they did thinking about how a computer collection and parsing went compared to mobile device. And I think that right there creates a fracture because they're very disparate in different things. And I think technologically you know this at its heart because we're not dealing with a simple linear operating system with loose files, but rather we're dealing with in many occasions, a SQL like database and we have to mount data and then parse or normalize and extract out information from like an organic database, which is far different from doing a bit by bit image where it's pretty easy to get access to certain data.


Jerry Bui-(02:59.5)

Yeah, I think that gets to the root of the word forensic and how a collection through the mobile device isn't technically forensic because it's not bit for bit. It's not a bitstream that is ultimately under the forensic examiner's control. It is really under the device carrier's control. And if you talk about layering the different levels of control, you alluded to it. It's all the permutations that could happen on a logical collection involving the device itself.

The OS, the operating system of the device. So in with iPhones, it's iOS. With Pixels and Samsung Galaxies, it's gonna be Android provided by Google. And then all of the layers of applications on top of it. And we're primarily interested in messaging apps. And those have their own issues or challenges as well. So when you stack the device plus the OS plus the application of interest, there's a lot of navigating we need to do and

Order to get a defensible collection, a forensically defensible collection is not necessarily a physical forensic collection by definition, but it's what the industry deems as best practice in terms of our approach. And you also alluded to the fact that that best practice basically changes on a day-to-day basis. So Googling information is perfectly valid, but more so reaching out to your network. You and I have vast networks that we could tap into in order to learn or evolve our best practices on a day to day basis. So being tapped into the community makes a di big difference, right, Steve?

Steve Davis- (04:36.62)

Yeah, absolutely. And and I do think it takes a village when it comes to and that's the beauty of forensics. I think in the forensics, which is very scientific and I always love that part of it, that it's not just yapping about things, but it's actually empirically underwriting information. And I think you're exactly right. It's not a place where you need to be embarrassed because things are changing, including APIs and access and encryption day by day. And tools change and their ability to access information and parse it.

in a way that we can then put it into a platform for humans to review. I I think the flashing red light, the sore thumb, the red flag that comes to my mind is this is an area where you've got to lay a predicate. You've got to have communications with the stakeholders, with the end users, with the custodians, with the the law firms or or in-house counsel dealing with what expectations should be and then all these variables and parameters that you're talking about. And I think if you know at at our company, we're pretty rigid about having kind of a series of k kickoff calls. One is kind of a scoping call that really discussed about what we're trying to get to, right? It's my wife asking me, How long does it take to get there? And I ask her where we're going. Like once you know where you're going, then you can map it out, whether it's on, you know maps go thirty years ago or now it's on Waze or Google Maps or whatever. Now you have a pretty good idea what it's gonna take to get their satellite overlay tells you. Well the same thing's true in forensics. Once we know more and once we have actually gathered information about what you're after, because I think you'd agree, Jerry, hopefully that when we you know we talk to someone and we find out it's communication centric and even take it beyond that and say it's inherent native iMessage app we're getting that's probably a different mountain to climb than if you're dealing with Telegram and Discord and WeChat and and Viber and things like that.

Jerry Bui-(06:36.204)

Yeah, and this is where I think our clients tend to get overwhelmed. Cause already right there, you're scratching the surface around the nuances of the collection. And that's just one of many, many things to consider. And so while we do have these scoping calls, I think that you know, clients tend to get quickly overwhelmed with the information. And so being able to dissect that information in a way that's targeted for their purposes.

Right. We have the technical information that we could convey, but if we have the experience and the prove professional context, then we can like really customize or tailor the information delivery for what their needs are. Because if we gave them the full data dump on everything that could go wrong, all of the decision trees that, you know, in a a decision flow diagram that they might have to consider, I think that gets overwhelming. So I mean I think that the human interaction bolstered by what we do a purpose with our documentation by way of questionnaires, and setting those expectations gives them some ability to make decisions and to make them confidently based on what we're asking them to to to decide on, right? Because they certainly don't want to decide on something that they're unsure about. And that's where we come in and lend our experience and give them a comfort level. That is ultimately what white glove treatment ultimately applies to you. It's that bedside manner and being able to handle discussions with counsel, but also at the end of the day with the custodians who they themselves are very nervous about the mobile devices, especially in a growing, not a growing, but a very common bring your own device type scenario where they're using their personal devices for work related you know, work related communications. And that commingling of data can be very problematic. I don't know how you prefer to handle those conversations, Steve, but I know that that's as a company what we really you know, really emphasize and so getting the right people talking the right language to the stakeholders and the custodians and all the parties involved really make things go smoother.

Steve Davis- (08:44.332)

Yeah, and I I think that you bring up a lot of great and valid points. The the first one being that getting access to information kind of opens up a Pandora's box, right? And we have the potential to infiltrate and get access to information that's that's privatized. And so I think, you know, for us where some of the the technical jargon and language can overwhelm people. I think people are kind of reliant on our experiences and our testing, which is why we do so much testing internally on the latest and greatest, and what platforms are available to access both Android Android and iOS. And then do you get the totality of all the information out there? Are there now methodologies that allow you to just get targeted data?

And even if you can do it within a black box and only promote data that's relevant to the matter or the dispute at hand, I think that's gigantic. But as I always say, I think only in about 100% of the cases is privacy a concern. And you're right, nowadays we've kind of seen a transition of data that used to be housed on servers and maybe desktops and then more recently laptops. I would take it a step beyond that and say, you know, what we're seeing is is mobile devices from when we're doing communication-centric analysis house your email, although it's not readily accessible necessarily on the actual physical device, but it is synced there. Then we also have the textual communications that occur on a whole variety of third party apps as well as inherent apps. And then we also have collaboration platforms. So all those are fertile areas for us to get access to.

But I think our ability to be more finite and and go in and actually get what's relevant and not just do a data grab is gigantic. And maybe you can talk a little bit about kind of today versus five or ten years ago, that ability to get to information more readily.

Jerry Bui-(10:56.076)

Yeah, I think that we are still in the world of collect in order to preserve when it comes to mobile devices. There is no kind of preservation in place switch that you can flip that's occurring more readily on enterprise controlled data sources. But even if they are corporate issued devices and you have MDM installed on there, there's very little that you can actually preserve in place. So collect to preserve is still definitely the the mode that we operate in. And really you have to contemplate at the onset of any collection or any kind of mobile device forensics is three pathways. And sometimes those occur simultaneously. Sometimes you're afforded with just one of those workflows. But really the three involve preservation. That's usually like fundamental and how you preserve, right? Do you want to do a targeted preservation or a a much fuller or comprehensive full file system preservation? It's like what what do you how do you want to cover your bases when it comes to preservation? Number two, is you alluded to this is what do you extract f extract from that preser preservation image. So if this is an ESI e-discovery collection workflow, which is very kind of routine, then you can be a little bit more targeted and not worry about the full blown preservation piece. See how they interplay there. and but if you also require, for example, the recovery of deleted items, would say you have a forensic investigation analysis that's involved there. You're looking at the artifacts. I like to think about it in terms of, okay, e-discovery is more about what the custodian says, right? Or writes or composes. And forensic analysis is more about what the custodian does. It's more about the behavior. So if you're looking for what they say or or how they behave, you might need a much more fulsome preservation at as a basis to accomplish those goals. Right. So if it's only e discovery, then you can be much more targeted.

But if you want to do e discovery plus forensic analysis and you're under threat of things potentially being deleted and you wanna be much more fulsome, then you know, that dictates a a full file system collection. So that is kind of yeah.

Steve Davis- (13:06.094)

When you run it when you run into that full file system collection, you know and I know there's consequences to that, right? And especially from a standpoint of getting herding cats and getting custodians to turn over, first of all, this is their security blanket, this is their favorite toy is a toddler, whatever. Their phone feels differently than their desktop and laptop do. And so when they look at it, they're like, Hey, you can't have access to my phone. And if I do give you my phone, you can have it for a hot minute and do your work. But I think the implication that you know is that when we have to do a full file system, you know, i i it can take literally days sometimes or at least up to a day to do that collection, which is problematic for people that are used to having that in their grubby little fists and they don't want to let go of it.

Jerry Bui-(13:59.17)

Yeah, the newer phones are two terabytes, Steve. Two terabytes in storage capacity nowadays. That will and if they're full, they will take days. Right. And so I think that the privacy issue is important. And you just mentioned it. Disruption is also a key consideration if they have to send their phone in or if we have to arrive on site. Is it going to involve taking away an entire day's worth of productivity? It could, but again, that's the trade off. Right. And So those are important considerations. and you know, the nuances and the variables are are plentiful. so I want to take a moment, Steve, shifting gears and talk about the team or the village. You know, it takes a village because a solo forensic practitioner might be very, very good at one thing, but only that one thing. The specialties can vary. And so depending on what you're looking for on a device, especially as the intersection point to more data.

That you want to discover and analyze and investigate, you require it requires a team, a team that might be specializing in, you know, Android versus iOS at a very high level. You know, the things, the intersection point of messaging and all the different messaging apps. are you finding artifacts around nefarious behavior that you need to get collections from the cloud separately? And so I think that from the forensic analysis standpoint, ultimately the expert testimony.

This is where the team matters above and beyond just e-discovery type of workflows. If you want to do forensic analysis and you ultimately want to defend your you know, your methodologies, your preservation methodologies, I think the team of experts who can testify and have experience on the hot sea in the hot seat, like you and I do, Steve, really matters.

Steve Davis- (15:45.196)

Yeah, I think that's a gigantic point. And I I think, you know, you mentioned earlier, and I think it's right on point, that even the smartest attorneys that are far brighter than me, they don't get some of the technological gobbledygoop. They don't understand a lot of the idiosyncrasies that we deal with. And so it it what we really need to do is not regurgitate everything and and educate them so much because I don't think they want to know that. What they need to know is that we have the experience to do it and that we have a process and a procedure and the human element that can do that. And I think it's rinse repeat as I call it. Like your experience testifying and mine exp testifying, everyone knows you're a scarecrow and they're trying to knock you off your perch, right? And they're going to try to find any weakness they can. So we know it's got to be programmatic, got to be procedural and it's got to go by a process that we've used before and that we can rely on. And I think once you do that, you kind of scare them off from tackling process and procedure and get them more worried about facts and law. And that's what we really want. And and what I always say is what we are is we're scientists. We're data scientists. And and it's not we're not we're not advocates and we're not taking positions. All we do is we see black and white. We see this is information available, and we let other people draw conclusions, not necessarily editorialize.

But it's very important. And I think that is the beauty of kind of the teamwork approach when you have people and you can involve data solutions, people that do nothing but manage data. I mean, you think about information coming off a phone, yeah, there's loose files, but there's a ton of textual communication. So when you talk about any of our communications with one of our kids, are we going to get ad infinitum, everything under the sun for the last 20 years? Are we going to get the last month? Are we going to get 20 lines above and below? I mean, those are issues that are also important because we're dealing with kind of an elusive amount of data since it can go forever and ever, amen. We've got to figure out how to represent that in an intelligent way. So it's got to be something that you've already planned. And I think what we've discussed here in the, you know, first 15 minutes or so is this importance of communication.

Steve Davis- (18:02.924)

With the stakeholders, be they corporate representatives, be they underlying custodians, or be they outside counsel, we've got to communicate with them and explain the procedure, the process, and what the end game. And I'll tell you, every time I've done that, and I imagine you as well, the angst, you know, over the process drops dramatically.

Jerry Bui-(18:24.898)

Yeah, I agree. And and and I think where we're effective is that as experts, our own reputation is at stake. So we're invested, right? We have been under the hot seat. We have had methodologies challenged. So we know how to shore up those gaps. We can see around the corners. And so if there is any kind of potential deficiency in the upfront preservation step, we see it. And we make sure our chain of custody is intact. We make sure that we're using best practices. We make sure we document, document, document, and more importantly, communicate all of those risks to the client so they have a little bit of of a preview of what could be happening down the road. Sometimes there's trade-offs that you just have to accept, but it's better be to be prepared because we're looking out for ourselves at the same time that we're looking out for the client. We're looking out for the team as well in-house at the service provider, trying to make their you know, make us better at the end of the day. because the feedback we get while, you know, on the stand, any of those gaps or shortcomings can be shared with the team. And it's a real life story that they can understand and they learn that, hey, I wanna, if I wanna follow this career path, I want to you know, shore up my capabilities and get real disciplined around what I do. And that helps us evolve from a standard order taker to real experts. And so I think that's what we have to ultimately offer at the end of the day is the strength of the team, but also the expert consulting that we can provide to our our clients, which matter. So it's process and people and of course the technology which we have, you know, plenty f a a really robust toolbox to help solve problems.

Steve Davis- (20:02.178)

Yeah, you you mentioned something earlier I wanted to kind of follow up on, which is the notion that data that's that's housed inside a database can be ephemeral or transient and it can leave, right? It can leave through human interaction and deletion. It can leave like LIFO FIFO, you know, first in and accounting and pushed out the door as additional data gets there. And I know we run into that. I always make the joke about like if you've got a eighteen year old daughter and she's a serial user to a phone, her data is gonna be more transient than it's gonna be with the old gray mare like me that that doesn't use it as much and push it out. So when you have, obviously, when you have deletion issues, I know there's more advanced techniques like full file system extracts to get to. But if you can't find data that's been deleted, what are your thoughts about are there other methodologies to get back to that data? Because I think one of the disconnects I hear is when someone says, We want you to this project, and we do it, and we provide to them the outcomes and the results and they're like, it's not here. And so how do you get to that? And and the answer may be a full file system, but what if it's truly been deleted and it's not recoverable from that source? Are there other ways to get to it?

Jerry Bui-(21:16.898)

Yeah, you can kind of back into it. you know, you might not be able to recover the information, but at least you can identify the gaps. And identifying the gaps is important, the absence of if information, and see if it coincides with anything else that might you know, indicate nefarious intent or corrupt intent. And so that matters too, is like you know, sometimes you're looking for a adverse inference, which can be a a big deal when it comes to spoliation type claims.

And so identifying those gaps is is important too. Why an entire day's worth of geolocation information is missing, for example, is one way. Why there's a big gap in Google searching and you know, web browsing history. Was there any kind of intentional deletion there? And sometimes there is, sometimes there isn't. It could be machine related or more so today, AI related, because AI is also messing with a lot of metadata and information. So, you know, you don't automatically jump to conclusions, but you look at the surrounding information to try to understand the context. They might have been on maternity leave. That's why you don't have any that you might have a g a gap, or parental leave rather, th which is why could explain a gap. So, you know, having kind of that thought process and the ability to look at the constellation of artifacts that would give you the right context is important. If you're just analyzing based on a single artifact, you're more prone to making mistakes and some quote unquote experts are doing out there and not spending the time. And so that's where bouncing off these findings with other team members also really helps too. And that's where it further takes in takes a village.

Steve Davis- (22:58.062)

Yeah, and I think I think one of the challenges in our business is is especially probably more for you than me, is y you've got back to back to back to back analyses, investigations, collections that you deal with. And at the same time this whole notion of having a process that you know is good as of today, not yesterday, means you've got to do a lot of testing. You you've got to empirically underwrite alternative solutions, new software programs, latest beta versions that have been released. And so it's kind of a you know, one hand you're out there breaking, you know, rocks in the prison yard. And then the other hand, you also need to underwrite and be a science in a you know, a scientist in an enclosed environment where you can do testing with a control group and prove up what the real delta or difference is with a given tool or the latest version of a tool or a peculiar app that we're dealing with to see how it works. And that's that's gotta be a conundrum and a difficulty for kind of you and the team.

Jerry Bui-(24:01.154)

Yeah, yeah, i it is, but it's it's fun, it's challenging, it would keep what keep it keeps our job interesting. And I attend a lot of conferences, do a lot of thought leadership and that's really a way to get the information out there. and so we can start to show our latest R and D results and get everyone educated and informed about the latest forensic issues. and so that's another part of the equation as well is a you know, improving our own skills, improving the team's skills, making sure we communicate and document, follow best practices, but also share the latest and greatest with the community. And so that's that whole ecosystem of activities is important. We emphasize that across the board at purposely.

Steve Davis- (24:47.628)

And I think I think the circle of life as you mentioned that is once you do that and you get that feedback and then you utilize that feedback, that's that very predicate meeting, the kickoff meeting. We then are empowered to go into those meetings and be able to talk about what's the latest and greatest. Have you heard of this product? Does it work this way? Should we do a full file system? Is an advanced logical good enough? I think that very feedback you're talking about that you guys are doing a lot of the empirical testing on nonstop, then feeds into the communication style for all of us on kickoff calls and introductory calls where people are, can we do this? Well, we've learned through this feedback loop that you can or can't based on our experiences, not just on projects we've done, but also on the testing we're doing daily.

Jerry Bui-(25:38.892)

Yeah, it's definitely a virtuous life cycle for sure. And so that's what we're trying to get better at. you know, we we try to minimize mistakes. mistakes do occur, but that's part of the learning process. And we like to be involved in fixing those issues and also communicating those fixes out to the broader community because a rising tide does lift all ships.

Steve Davis- (26:05.016)

So when you think about this, we could talk for, you know, 17 hours on this one subcomponent of the topic of mobile devices. Kind of what does this beg the issue for maybe the next conversation or a future conversation that we have? We've we've dealt with like these are some of the fear factor items you gotta deal with up front when you communicate with attorneys. But then what does this lead to in terms of like next steps in your mind in in terms of this whole discussion on mobile device data and how people can utilize that in the confines of a dispute and investigation or litigation.

Jerry Bui-(26:43.416)

So, Steve, I think that presents a very good segue to our next episode. you know, because collecting the data is one thing. How does the presentation of that data look like? And we do have a great team at Purpose called Data Solutions, and they are really good at interacting with us. We're on very frequent meetings, sharing the latest and greatest, and they're the ones that actually make the data that we collect understandable by reviewers and by the other stakeholders and ultimately a problem free production at the end of the day. So I wanna perhaps highlight a team of ours, Steve, known as Data Solutions. Do you wanna just give a quick preview of what that team does for us at Purpose Legal?

Steve Davis- (27:28.598)

that so I think I think data solutions these are the brainiacs that go in and they actually normalize the data and they make it consumable. So they're the ones that take the round peg and put it into the square hole and and allow us across a whole variety of platforms because remember there's you know when you think about the EDRM and the life cycle of data across that there are viewing platforms that allow laymen and and practitioners to get in and kind of view information and you know, we're taking things and we're kind of unbundling them and then we're ingesting them into those platforms. So you gotta normalize data, you gotta ensure that things like emojis are being represented accurately. and that's what they do. They basically are the scientists that go in, take the raw data, apply their tools and techniques to it, and then get it into a fashion that people are allowed to consume it and and make sense out of it. And I think that's gigantic and I think is is busy and as smart as they are, there's also these third party platforms we have to deal with. And so I wanna I wanna hear more from them about what are their challenges when they run into the variety of different viewing e discovery platforms that exist. Are there challenges? Are they all uniform? And I I think that would be a good rabbit hole to go down.

Jerry Bui-(28:49.976)

So if you enjoy these topics and they are of interest to you, if you subscribe to our podcast on any number of popular platforms, you will get insight and you'll see how we're able to work and collaborate with other internal teams at Purpose Legal and how we streamline that data pipeline to make your life easier at the end of the day.

Steve Davis- (29:12.664)

Sounds great.

Jerry Bui-(29:14.424)

Thanks for joining us today, y'all, and give us a follow and we'll see you on the next episode.