Francesco ZinghinìParty-appointed technical expertise

Mobile devices

A phone now holds more information about a person than any other object. It is also the object about which the most mistaken expectations circulate, in both directions.

What a phone actually contains

Beyond what is visible — messages, photographs, contacts, call history — a mobile device keeps a considerable number of automatic records: which wireless networks it has encountered, which applications were installed and when, which notifications arrived, which devices were paired, and in many cases a location history collected by the operating system or by individual applications.

It is often these secondary records, rather than the content originally sought, that settle a question: the presence of a device in a place, the time it was switched on, the moment an application was installed or removed.

The three levels of extraction

Not all extractions are equal, and the difference determines what can be looked for. In increasing order of depth:

LevelWhat it yieldsWhen it is possible
Logical The data the operating system exposes: contacts, messages, calls, photographs, user files. Almost always, if the device can be unlocked. Does not reach deleted data.
File system The whole tree of user and application files, including the internal databases of messaging apps. On a subset of models and OS versions. This is usually the level that matters.
Physical A full copy of memory, including unallocated space where deleted data survives. Increasingly rare: on recent devices memory is encrypted and a raw copy is unreadable.

The constraint that changes everything: encryption

On modern devices memory is encrypted by default, and the key derives from the user's passcode. The consequences are stark and worth putting in writing before starting, so that a defence is not built on an examination that cannot be carried out:

  • Without the passcode, on a recent device, generally nothing can be extracted. This is not a question of better tools.
  • A device powered off and never unlocked since boot is in a more closed state than one that is on and has been unlocked at least once. That is why, when a device is seized while running, how it is handled in the first few minutes matters more than everything that follows.
  • Vulnerabilities permitting access do exist, are specific to particular models and versions, and are closed by updates. Anyone promising access to any device is selling something they do not have.

What survives deletion

The most frequent question. The honest answer is: it depends on what was deleted and how long the phone kept being used afterwards.

Many applications do not really delete: they mark the record as removed in an internal database, and the content stays recoverable until that space is reused. Photographs often survive in thumbnails and in copies created by synchronisation services. Conversely, after a full device reset recovery is generally excluded: on encrypted systems the procedure destroys the key, and what remains in memory from then on is noise.

The dominant factor remains time. A phone that continues to be used continually rewrites its own memory. If data matters, the device must be set aside at once.

A word on proportionality

A full extraction from a phone also yields correspondence with people who are strangers to the proceedings, health data, and material with no bearing on the case. That is a real problem, it concerns the rights of third parties, and courts weigh it. Working by keyword, by date range or by individual application, where that suffices, is almost always the better choice: faster, cheaper and less exposed to objection.

Further reading: recovering deleted messages →
Further reading: is the phone being spied on? How to verify — and how to prove it →

Do you have a matter under way?

Tell me what happened and what you need to prove. In a first reply I will tell you whether there is a technical route, what data is needed and how long it takes — before any commitment.

Request an assessment