WhatsApp and the potential break in the chain of custody. #2756
Replies: 1 comment 2 replies
-
|
I conducted further research and found other messages in the same situation. From the data I gathered, the messages that came from a backup sent by Apple have a different sender. The only possibility I see in this situation is that, after this backup, the user changed their name and phone number, so the new name would appear on the phone. Is there a WhatsApp record of when the person changed their number to see if that makes sense? When a person changes their name and phone number, do the old messages then show the new name, meaning the old name is not preserved? For forensic purposes, this is a very relevant situation because lawyers claim that the data was tampered with and want to characterize a breach of chain of custody, so it's important to find an explanation. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I have an interesting situation on WhatsApp.
After indexing several files, I did a search with text, and the result showed the screen below.
First, I don't know the difference between the green WhatsApp and the blue WhatsApp.
Focusing specifically on the 3 green WhatsApp files, there's a strange situation because the messages are identical: same size, date, time, second, Communication:From, Communication:Date, Message-Body, but in the Communication:To field of one of them, there's a different name.
Looking at the metadata in the Communication:Participants field, person A to person B, I have person B in all 3 files, but person A is the same in two of them, and in the third file, it's a different name.
Another interesting detail. The two that have the same participants originate from:
1 - xxx/TELEMATICA/Resposta Decisão Judicial/Apple/4 - Processamentos - IPED/iped/subitens/6/0/6026347E7CA3C26A99FDFFAE92801381.sqlite>>WhatsApp Chat - ~XXXXXX - 551199999994_1
2 - [email protected]_2023-07-18_Report.ufdr/iPhone de xxx (iPhone 7 Plus)/ChatStorage.sqlite>>WhatsApp Chat - ~XXXXXX - 551199999994_1
The third one appears to be a backup provided by Apple:
3 - xxx/TELEMATICA/Resposta Decisão Judicial/Apple/1 - Arquivos GPG/877272-BACKUP-10271244.zip>>1186890263/877272/[email protected]/backup/D_80358d2904967974121d0ef180b7ed4bcac8d7d7/S_CF797D59...
Anyway, I haven't seen it yet because there's this Apple one with different participants.
Any ideas?
paulo
Beta Was this translation helpful? Give feedback.
All reactions