Mobile Device Discovery Stories from the Experts
The story about Michigan State Police officers collecting forensic snapshots of mobile phones during traffic stops back in April kicked off my long research journey into whether corporate mobile discovery was really feasible. After lengthy interviews with leading experts in mobile phone forensics, I can assure you that a full physical acquisition of your iPhone, iPad, BlackBerry or Android device is just not going to happen during a typical 30 minute custodian interview or a traffic stop. The connectors and communication protocols of mobile devices were not designed for high speed data exports that we have come to expect from enterprise back up systems and disk imaging devices like Logicube. The ‘pipe’ is just too small to copy 8+ GB without taking custody of the device. You can grab the active call log, text messages and other phone elements quickly, but that kind of logical extraction may not suffice to ‘preserve’ your custodian’s ESI in some matters, especially if that device may be the only source of deleted items that are critical to proving your case.