Flash News: We’ve made it to Alltop! Thank you to all our readers for helping make that happen.
Cheers!
-The Next Gen eDiscovery Law and Tech team.
Flash News: We’ve made it to Alltop! Thank you to all our readers for helping make that happen.
Cheers!
-The Next Gen eDiscovery Law and Tech team.
Filed under Uncategorized
Tagged as Alltop, eDiscovery, Next Gen eDiscovery Law and Tech Blog
Thank you to all for the response and excellent feedback on our previous post outlining key Twitter metadata fields. As promised, here are some key metadata fields for each Facebook entry. These fields provide important evidence, investigation context and circumstantial evidence to establish authenticity, if properly collected and preserved. Facebook changes their APIs from time to time, so we will be reporting any such changes and updates when they occur:
| Metadata Field | Description | ||||||||
| Uri | Unified resource identifier of the subject item | ||||||||
| fb_item_type | Identifies item as Wallitem, Newsitem, Photo, etc. | ||||||||
| parent_itemnum | Parent item number-sub item are tracked to parent | ||||||||
| thread_id | Unique identifier of a message thread | ||||||||
| recipients | All recipients of a message listed by name | ||||||||
| recipients_id | All recipients of a message listed by user id. | ||||||||
| album_id | Unique id number of a photo or video item | ||||||||
| post_id | Unique id number of a wall post | ||||||||
| application | application used to post to Facebook
(i.e, from an iPhone or social media client) |
||||||||
| user_img | url where user profile image is located | ||||||||
| user_id | Unique id of the poster/author of a Facebook item | ||||||||
| account_id | unique id of a users account | ||||||||
| user_name | display name of poster/author of a Facebook item | ||||||||
| created_time | When a post or message was created | ||||||||
| updated_time | When a post or message was revised/updated | ||||||||
| To | Name of user whom a wall post is directed to | ||||||||
| to_id | Unique id of user whom a wall post is directed to | ||||||||
| Link | url of any included links | ||||||||
| comments_num | Number of comments to a post | ||||||||
| picture_url | url where picture is located | ||||||||
As mentioned earlier, you will not get all this key metadata from a printout, screen capture, or even most compliance archive tools. Best practices technology specifically designed to collect, preserve, search and produce social media for eDiscovery is required.
As discussed in our previous post, authentication of social media evidence can present significant challenges when you collect by screen shots, printouts or raw html feeds from an archive tool. This is just one reason why social media data must be properly collected, preserved, searched and produced in a manner consistent with best practices. When social media is collected with a proper chain of custody and all associated metadata is preserved, authenticity can be much easier to establish. As an example, the following are key metadata fields for individual Twitter items that provide important information to establish authenticity of the tweet, if properly collected and preserved:
| Metadata Field | Description | ||||||||
| created_at | UTC timestamp for tweet creation | ||||||||
| user_id | The ID of the poster of a tweet | ||||||||
| handle | User’s screen name (different from user name) | ||||||||
| retweet_id | The post ID of a retweet | ||||||||
| retweet_user | The username of the user who retweeted | ||||||||
| Reply | Indicates if this tweet is a reply | ||||||||
| direct_message | Indicates if this tweet is a direct message | ||||||||
| Hashtags | List of all hashtags in the tweet | ||||||||
| Description | Up to 160 characters describing the tweet | ||||||||
| geo_enabled | If the user has enabled geo-location (optional) | ||||||||
| Place | Geo-location from where user tweeted from | ||||||||
| Coordinates | Geo-location coordinates where tweet sent | ||||||||
| in_reply_to_user_id | unique id for the user that replied | ||||||||
| profile_image_url | location to a user’s avatar file | ||||||||
| recipient_id | unique id of direct message recipient | ||||||||
| recipient_screen_name | display name of direct message sender | ||||||||
| screen_name | display name for a user | ||||||||
| sender_id | unique id of direct message sender | ||||||||
| Source | application used to Tweet or direct message(i.e., from an iPhone or specific Twitter app) | ||||||||
| time_zone | a user’s time zone | ||||||||
| utc_offset | time between user’s time zone and UTC time | ||||||||
| follow_request_sent | Indicates request to follow the user | ||||||||
| Truncated | If the post is truncated due to excessive length | ||||||||
Any one or combination of these fields can be key circumstantial data to authenticate a single or group of social media items. US Federal Rule of Evidence 901(b)(4) provides that a party can authenticate electronically stored information (“ESI”) with circumstantial evidence that reflects the “contents, substance, internal patterns, or other distinctive characteristics” of the evidence. As outlined in our white paper, many cases have applied Rule 901(b)(4) to metadata associated with emails and other ESI. But you will not get all this key metadata from a printout, screen capture, or even most compliance archive tools. Best practices technology specifically designed to collect, preserve, search and produce social media for eDiscovery is required.
Facebook and Linkedin items have their own unique, but generally comparable, metadata. Stay tuned for our posting of key Facebook metadata in a few days.
Filed under Authentication, Preservation & Collection, Social Media Metadata
Tagged as archive tool, authentication, best practice, best practices technology, chain of custody, collect, electronically stored information, ESI, Facebook, LinkedIn, metadata, metadata fields, preserve, Rue 901(b), search, social media evidence, Twitter, US Federal Rule of Evidence, whitepaper
There has been a lot of discussion on the recent case of State of Connecticut vs. Eleck, 2011 WL 3278663 (Conn.App. 2011), which highlights the importance of employing best practices technology to collect, preserve and produce social media evidence. In this case, defendant Robert Eleck sought to admit Facebook evidence at trial that would have impeached a prosecution witness, Simone Judway. Judway denied authorship of the Facebook messages in question, claiming someone must have hacked her account, even though the evidence revealed that the hacking occurred after the subject messages were sent. The court determined that Eleck, who offered only a simple printout of the Facebook items, failed to adequately authenticate the data, ruling that “it was incumbent on the defendant, as the proponent, to advance other foundational proof to authenticate that the proffered messages did, in fact, come from Judway and not simply from her Facebook account.”
Importantly, the court noted that while the emergence of social media evidence does not necessarily require new rules of evidence, “circumstantial evidence that tends to authenticate a communication is somewhat unique to each medium.” The court cited precedent cases where emails, chat logs and texts were properly admitted based upon their supporting and unique metadata and other circumstantial evidence that provide “identifying characteristics.” See, e.g. United States v. Siddiqui, 235 F.3d1318, 1322-23 (11th Cir.2000) (e-mails properly authenticated when they included defendant’s e-mail address, the reply function automatically dialed defendant’s e-mail address as sender, messages contained factual details known to defendant, messages included defendant’s 625*625 nickname, and other metadata.) Dickens v. State, 175 Md.App. 231, 927 A.2d 32, 36-38 (2007) (threatening text messages received by victim on cell phone were properly authenticated when circumstantial evidence provided adequate proof message was sent by defendant); In re F.P., 878 A.2d91, 93-95 (Pa.Super.Ct.2005) (instant messages properly authenticated through circumstantial evidence including screen names and context of messages and surrounding circumstances).
State v. Eleck clearly illustrates why it is important to collect and preserve Tweets, Facebook and LinkedIn entries in a thorough manner with best-practices technology specifically designed for litigation purposes. For instance, there are over twenty unique metadata fields associated with individual Facebook posts and messages. Any one of those entries or a combination of them contrasted with other entries can provide unique circumstantial evidence that can establish foundational proof of authorship. (We identify the nearly two dozen fields of unique Twitter metadata in our social media evidence white paper).
When lawyers and their service providers rely on simple screen captures, printouts or even compliance archiving solutions that fail to collect and preserve all key metadata to admit social media into evidence, they run a significant risk of having key evidence in support of their client’s case disallowed by the court.
Filed under Authentication, Case Law
Tagged as authenticate, case, collect, Connecticut vs. Eleck, court, data, defendant, Dickens v. State, evidence, Facebook, hacked, LinkedIn, metadata, preserve, proponent, Simone Judway, social media, technology, trial, Tweets, United States v. Siddiqui, white paper, witness
With over 800 million Facebook users and 200 million people with Twitter accounts, evidence from social media sites can be relevant to just about every litigation dispute and investigation matter. Social media evidence is widely discoverable and generally not subject to privacy constraints when established to be relevant to a case, particularly when that data is held by a party to litigation or even a key witness. However recent court decisions reflect that the main pressing concern for attorneys, eDiscovery practitioners and investigators is the authentication of social media data for admission into evidence in court.
We have devoted a whitepaper to this important topic (download it here) with some good feedback. The bottom line is that absent uncontroverted and cooperative witness testimony, lawyers must turn to circumstantial evidence to help establish an evidentiary foundation for social media evidence. This is where utilizing best practices technology that 1) establishes an effective chain of custody of the collected social media; and 2) captures all available metadata without alteration is essential.
Metadata is particularly important as under US Federal Rule of Evidence 901(b)(4) evidence, including electronic data, can be authenticated through circumstantial evidence that reflects the “contents, substance, internal patterns, or other distinctive characteristics” of the proffered evidence. And social media items contain a wealth of key meta data that represent or can establish “internal patterns or other distinctive characteristics” of the social media items in question. I will be posting more specifics concerning social media metadata and its potential importance in court in a few days.
Filed under Authentication, Best Practices, Social Media Metadata
Tagged as admission, attorney, authenticate, authentication, authenticity, case, chain of custody, claims, cloud-based, collected, computer forensics, court, data, discovery, disk images, dispute, eDiscovery, ESI, evidence, Facebook, hash, investigation, investigator, litigation, matter, metadata, practitioner, preservation, preserved, privacy, relevant, rule, social media, spoliation, testimony, trial, trial judge, Twitter, uncontroverted, US Federal Rule, witness