<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>John J. Irvine: Blog</title>
  <link>https://johnirvine.me/blog/</link>
  <atom:link href="https://johnirvine.me/feed.xml" rel="self" type="application/rss+xml"/>
  <description>Notes on digital forensics, ethics, insider risk and AI from John J. Irvine, AIGP.</description>
  <language>en-us</language>
  <lastBuildDate>Sun, 12 Jul 2026 12:00:00 +0000</lastBuildDate>
  <item>
    <title>The AI Reached the Conclusion, but You Answer for It</title>
    <link>https://johnirvine.me/blog/the-ai-reached-the-conclusion/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/the-ai-reached-the-conclusion/</guid>
    <pubDate>Sun, 12 Jul 2026 12:00:00 +0000</pubDate>
    <description>Over my break, I developed a new lecture for next semester about the use and ethics of AI in digital forensic investigations. I&#x27;ll open this lecture with a show of hands. &quot;Who in the room has used an AI tool for work…</description>
    <content:encoded><![CDATA[<p>Over my break, I developed a new lecture for next semester about the use and ethics of AI in digital forensic investigations. I'll open this lecture with a show of hands. "Who in the room has used an AI tool for work or school in the last 30 days?" Most hands will go up. The second question follows: "Who checked what that tool kept, or where the data went?" The hands will come down quickly, I'm sure.</p>
<p>That gap—between how fluently we use these tools and how little we examine them—is the whole subject. AI capability moves fast. Regulation moves slowly. Professional standards move slower still. Every problem I raise in this material lives somewhere in the space between those three speeds, and when capability outruns the rules, someone is still standing at the workbench who has to decide what to do. The absence of a rule is not the absence of a duty.</p>
<p>AI shows up in this profession wearing three different hats. Sometimes it's a tool you run to do the examination. Sometimes it's an actor that produces something carrying evidentiary weight. Sometimes it's the subject—the platform or the data you're investigating. The ethics change with the role, and tracking which one is in play is the first discipline, because most of the trouble starts when an examiner reaches for the tool without registering that it's also become the actor.</p>
<p>Start with the tool. The gains are real, and that's exactly what makes the rest of it matter. AI is good at triage at scale, malware behavioral classification, anomaly detection across network traffic, and language analysis over document sets no human team could read in a year. The catch arrives the moment the tool stops matching against material a human already identified and starts judging content it has never seen. A hash hit against a known set rests on a prior human decision, so your judgment can be light. A classifier that reports "92% likely contraband" has handed you a probability estimate and nothing more. A probability threshold is not an ethical framework, and the call—report, testimony, and charge—is still yours.</p>
<p>This is where explainability stops being academic. If you can't explain how the tool reached its result, you can't honestly call that result your expert analysis. The algorithm is not a co-author. You signed the report, you hold the certification, and you answer for it on the stand. Point the Daubert conditions at the tool the way a defense attorney will—reliability, testability, a known error rate, and peer review—and many AI forensic tools can't satisfy a single one. *State v. Loomis*showed the shape of the fight: a risk score used at sentencing with its methodology held as a trade secret, a defendant arguing he couldn't challenge what he wasn't allowed to see, a state court that let it stand with cautions, and a U.S. Supreme Court that declined to take the case. Same black box, same objection, now pointed at your evidence.</p>
<p>The fairness problem runs deeper than any single tool, because a model learns from history, and history carries every distortion of the world that produced it. The bias is built into the architecture. No patch is coming for it. Robert Williams spent a night in a Detroit cell in 2020 because a facial-recognition system returned a false match and the officers ran with it—during interrogation, he was told "the computer says it's you." NIST's testing has found demographic differentials across most algorithms it has examined, with false-positive rates running higher for some groups and the gap varying enormously by tool. Using a tool blind to its own error profile, on the face in front of you, is a choice with consequences. The same loop runs through predictive policing, where biased enforcement data trains the model, the model sends officers back to the same blocks, those patrols generate more of the same data, and the loop closes from the inside.</p>
<p>The habit the professional literature has barely touched is the LLM used off the books, mid-case. Examiners paste scripts, chat logs, emails, and metadata into ChatGPT, Claude, Gemini, Grok, or Copilot because it's fast and often useful. Commercial models keep what you give them, and the terms change without notice. Feeding live evidence to a public model raises real questions about whether you've broken chain of custody, waived privilege in a commercial matter, or violated a protective order in civil litigation. The doctrine is unsettled. The habit shouldn't wait for it—document the AI use now, before a court tells you what you should have done.</p>
<p>The hardest version of this is AI-generated child sexual abuse material, where the law splits on one question: whether a real child is involved. Material tied to an identifiable child, including face-swaps and morphs onto a real child, falls under the traditional statutes. Wholly synthetic material runs into the child-obscenity statute and the protection the Supreme Court extended to non-obscene virtual content in <em>Free Speech Coalition</em>.* United States v. Anderegg* is the live test, with a private-possession count dismissed in early 2025 on* Stanley v. Georgia* grounds while production and distribution counts proceed—a district-court ruling, not the last word. At discovery you usually can't tell origin or obscenity, so the defensible default is to preserve, decline to distribute, and report through proper channels. The volume tells its own story: NCMEC's AI-CSAM reports went from roughly 6,800 in 2024 to more than 440,000 in the first half of 2025. At that scale, automated triage stops being a convenience and becomes occupational health for the people doing the work.</p>
<p>Flip the script and the platform becomes the target. What an AI system holds—conversation history, prompts, outputs, account metadata, payment records, and usage logs—is potentially probative, if it was kept, and for how long. Retention varies by provider, by tier, and by the week. Whether an LLM transcript even counts as a "stored communication" under the Stored Communications Act is unsettled. Underneath all of it sits the attribution problem: when an autonomous system causes harm, the subject of your investigation could be the developer, the deployer, the operator, or the person who prompted it. ECPA dates to 1986. Fourth Amendment doctrine on AI-held records is barely sketched. These are the working conditions you graduate into.</p>
<p>This brings the whole thing back to the signature. Every ethics code in this field says stand behind what you sign, and the algorithm shares none of it—not your liability, not your oath, and not your need to keep your job. When an AI finding turns out to be wrong, the weight is supposed to distribute across examiner, agency, and vendor. Vendors disclaim by contract. Agencies point to procurement. Weight that won't distribute cleanly concentrates, and it concentrates on the name at the bottom of the report. The institution adopts the tool for throughput and cost. The individual carries it case by case and signs personally.</p>
<p>This is the part the field keeps deferring, and it can't defer much longer. The standards for AI in digital forensics will be written in the next few years, and everyone graduating into this work will operate under them regardless. Professions that fail to govern themselves get governed, and rules drafted by non-practitioners tend to be blunt instruments. The window to shape this is open right now. It won't stay open.</p>
<p>For practitioners reading this: what has your organization actually put in writing about AI use—tool validation, documentation of which models touched an analysis, and where live evidence is permitted to go—and where are the gaps you already know exist? For those in adjacent fields, where a finding still gets attached to a person's name, how is your profession handling the same gap between what the tools can do and what the rules have caught up to?</p>
<hr>
<p>This post is the eleventh and final in a series based on my course—DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. We started with the question every new class gets on day one—is digital forensics an art or a science—and worked through professional honesty, bias, the human dynamics of a search, Fourth Amendment scope, expert testimony, documentation, OSINT, commercial practice, and the mental model gap between law enforcement and intelligence work, before arriving here, where the tools themselves are generating the hardest questions. The ethical terrain underneath this field gets harder as the technology gets more capable. I hope you've enjoyed reading these as much as I've enjoyed writing them.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Mental Model That Built Your Career May Not Transfer</title>
    <link>https://johnirvine.me/blog/the-mental-model-may-not-transfer/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/the-mental-model-may-not-transfer/</guid>
    <pubDate>Mon, 06 Jul 2026 12:00:00 +0000</pubDate>
    <description>There&#x27;s a thought experiment I put to my class when we get to this lecture. You have a hard drive. You have a forensic examiner who has spent ten years getting evidence into courtrooms—excellent documentation, clean…</description>
    <content:encoded><![CDATA[<p>There's a thought experiment I put to my class when we get to this lecture. You have a hard drive. You have a forensic examiner who has spent ten years getting evidence into courtrooms—excellent documentation, clean chain of custody, conservative language, airtight methodology—and you drop that examiner, no briefing, into an intelligence environment where the target is active right now, the drive just came in from a field collection, and the team needs whatever you can surface in the next six hours. Does the examiner's experience help or hurt? The honest answer is both—and the ratio depends entirely on whether they can shift the mental model before touching the keyboard, because ten years of excellent instincts will not save you if you're optimizing for the wrong mission.</p>
<p>Judge Richard Posner, in <em>Uncertain Shield</em>, drew a distinction that I think is the cleanest entry point into this problem. Law enforcement performance, he wrote, is easily measurable: arrests, convictions, and cases closed. Intelligence performance is not. Law enforcement investigates crimes that have already been committed. Intelligence wants to surveil, analyze, and understand—oriented toward what is happening right now and what might happen next—and these are not the same job, not by a long way.</p>
<p>The "iron triangle" framing makes this concrete. In business, we say "good, cheap, and fast—pick two." What I've found in digital forensics (called "media exploitation" in Intelligence parlance) is a parallel: law enforcement, Intelligence, and commercial work lives inside a tension between <em>speed, factual detail, and analytic depth</em>. In law enforcement, the two you protect are factual detail and analytic depth—your report has to survive cross-examination, a Daubert challenge, and a defense attorney who has read it more carefully than you have in the week before trial. Speed is what you trade away, and a months-long examination is often appropriate because the findings have to hold up in court. Sometimes you might not even* see* the evidence in the lab for six months after it was obtained in the field. In Intelligence, the vertices shift: speed and analytic depth are what you protect. Recovering 60 to 80 percent of the data in six hours is often the right call when the alternative is 100 percent of the data back* after the window for action has closed.* Timeliness is a quality dimension in intelligence work—not a convenience, and not an excuse for sloppiness—but a genuine measure of whether the work serves its purpose.</p>
<p>That framing matters because it redefines what "thorough" means in each context. A law enforcement examiner who issues a partial report, or one that gets corrected and reissued, has created a serious professional problem. An intelligence examiner who withholds actionable findings because the examination is not complete yet has committed a different kind of failure—measured in missed opportunities rather than suppressed evidence. You need your report to be "left of boom," or it's essentially useless. Intelligence products are living documents, updated as understanding develops. Law enforcement reports are sealed, defensible records. Both approaches reflect the discipline appropriate to their purpose, and neither is a degraded version of the other.</p>
<p>The language itself signals the difference. Law enforcement reports hedge carefully: "is consistent with," "may indicate," "could potentially be." That phrasing is armor, not imprecision; it protects the examiner from the gap between what was found and what was claimed. Intelligence reports shed most of that hedging. When an analyst is 80 percent confident, the report says "is." The reader needs to make a decision, and language that reads like a deposition does not serve that purpose. Reports can be issued incrementally, corrected, and reissued as understanding evolves—in law enforcement, that sequence describes a catastrophic failure; in intelligence, it describes an honest process.</p>
<p>The legal terrain shifts entirely in intelligence work. No search warrant, typically no defense attorneys, and standard operating procedures slimmer than those in most law enforcement labs. FISA—the Foreign Intelligence Surveillance Act, enacted in 1978—is the governing framework for electronic surveillance against U.S. persons. Its history is worth understanding because it explains the shape of the current rules.</p>
<p>Congress passed FISA in response to the surveillance abuses exposed in the Watergate era: warrantless wiretaps, unauthorized surveillance of political opponents, and federal agencies turned on domestic targets without any judicial check. The law created a distinct legal architecture—a specialized court, a probable cause standard, and defined categories of who could be targeted—to put structure around intelligence collection inside the United States. The Patriot Act in 2001 loosened the purpose requirement; the USA Freedom Act in 2015 pulled back on bulk collection and required the FISA court to publish novel legal interpretations. If you work FISA-related cases, you generally will receive a formal agency briefing before you touch any data.</p>
<p>The last thing I tell the class on this material is about professional courage, and it has nothing to do with courtrooms. In an intelligence environment, you may be the only person who has seen the raw data on the submitted media. The agency around you is large, compartmented, and full of people with strong views about the targets they're tracking—views formed without access to what you just examined. That institutional weight will sometimes push against your findings, and the push will be quiet, political, and persistent rather than adversarial and formal.</p>
<p>The professional discipline is simple in principle. Stand behind what you found. Report it accurately. Let the analysts argue about what it means; that is genuinely their job. <em>Your job is to ensure they're arguing about real data.</em></p>
<hr>
<p>This post is the tenth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. With one article remaining, I'll next look at the ethical, legal, and practical issues that surround the use and investigation of AI from the digital forensic practitioner's point of view.</p>]]></content:encoded>
  </item>
  <item>
    <title>Trouble getting a phone screen? Fight AI with AI.</title>
    <link>https://johnirvine.me/blog/fight-ai-with-ai/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/fight-ai-with-ai/</guid>
    <pubDate>Sat, 04 Jul 2026 12:00:00 +0000</pubDate>
    <description>Looking for a new position and having trouble getting a call from a recruiter? The problem might not be you. It might be your resume&#x27;s format. To fix it, you need to fight AI with AI.</description>
    <content:encoded><![CDATA[<p>Looking for a new position and having trouble getting a call from a recruiter? The problem might not be you. It might be your resume's <em>format</em>. To fix it, you need to* <em>fight AI with AI.*</em></p>
<p>During my recent job search, I used AI heavily on my resume—not to create experience I didn't have, but to make sure my real experience came through and, more importantly, <em>made it to a human's eyes</em> <strong>(more on that toward the end of the article)</strong>:</p>
<p>I gave my existing resume to a couple of executive friends who really helped me take it to the next level (Chris, Michael—thank you). I'm eternally grateful for that help. However, I still wasn't getting noticed from the applications I submitted. I turned to Claude and asked it to help make my resume stronger for a human recruiter while keeping it honest, accurate, and tied to my actual experience. Specifically, I asked it to:</p>
<ol><li>Help me make my resume shine while still staying true to my experience and background.</li><li>Reformat and rewrite my resume to make it visually appealing and truly informative using highly relevant keywords a recruiter would want to see.</li><li>Generate a punchy executive summary block for the top based upon my background, work history, and major achievements.</li><li>Edit it down to two pages, keeping the most important and highest-value experience while removing duplicative or lower-value content.</li></ol>
<p>Claude gave me a revised version, and I gave that version to ChatGPT with the same instructions. I hand-tuned the result. <strong>I used the $20/month paid plans for both tools</strong> because I wanted access to the better models and higher reasoning limits. For me, turning them to the max my plan allowed was worth it.</p>
<p>At that point, I had a resume that looked good to me. Strong content. Clear story. Good executive summary. Relevant keywords. Two pages. Clean formatting. I turned it into a PDF.</p>
<p><strong>That is where things got interesting.</strong></p>
<p>After Claude and ChatGPT reviewed the resume for content and I made the appropriate changes, I gave Claude a request to review and parse my PDFed resume <em>like an automated applicant tracking system would</em>. I had (more than) a few rounds of back and forth, but to save you the trouble, here's a good canned prompt that will look for a lot of the issues that appeared from my efforts:</p>
<blockquote><p>This is my PDF resume. Pretend you are both a new and an antiquated HR applicant tracking system, both with and without AI capabilities. Review my PDF resume for anything that would trip-up parsing by an ATS, including, but not limited to, paragraph structure, tabular structure, multiple columns, oddly-formatted regions, confusing font ligatures, and anything else you think a parsing and processing engine would stumble upon. Also review the resume for ATS-friendly keywords, section headers, and other standard terms that ATS systems use when processing, scoring, or ranking resumes for review by a human reviewer.</p></blockquote>
<p>What came back surprised me. My resume looked good to <em>a person</em>. To an applicant tracking system, it was an absolute mess.</p>
<p>I had a skills section arranged in three clean columns. Claude flagged that an ATS might read the terms out of order, mash them together, or turn them into nonsense.</p>
<p>My font choice looked good visually. Once exported to PDF, it created ligature characters where certain letters blended together. That can confuse parsing engines and cause keywords to disappear. I had no idea this type of thing even existed; visually it looked normal. To an older ATS, <strong>a highly relevant keyword became a nonsensical set of characters.</strong></p>
<p>Claude also flagged structural issues around section formatting and hierarchy that could make the resume harder for an ATS to interpret. I fixed those issues, regenerated the PDF, and gave it to ChatGPT using the same criteria.</p>
<p>ChatGPT found a few different problems Claude missed, so I fixed those too.</p>
<p>Because I'm apparently the kind of person who turns resume formatting into a contact sport, I went back and forth a few more times with both tools until they basically came back with: this is good, the section headers are standard, the keywords are clear, and there is nothing obvious here that should trip up an ATS.</p>
<p><strong><em>Here is the damning reality: if your resume confuses the automated systems, your resume may get downgraded and a human recruiter will never see it.</strong></em></p>
<p>You could be the best thing since sliced bread and Claude’s Mythos model. If your resume cannot communicate that in both human-readable and machine-readable ways, your application may still end with the familiar automated email:</p>
<p><em>“Thanks for your application, but we’ve decided to move forward with other candidates.”</em></p>
<p>AI is already part of the hiring process. Use AI on your side of the table too. Use it to clarify your story, tighten your resume, test whether your PDF is actually parseable, and find where your formatting is working against you.</p>
<p>The goal is to make sure the system does not accidentally erase you before a person gets the chance to evaluate you.</p>]]></content:encoded>
  </item>
  <item>
    <title>When &quot;Who Is the Client?&quot; Is the Hardest Question in the Room</title>
    <link>https://johnirvine.me/blog/who-is-the-client/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/who-is-the-client/</guid>
    <pubDate>Mon, 29 Jun 2026 12:00:00 +0000</pubDate>
    <description>Over the years, my teams and I worked a wide range of commercial cases: intellectual property theft, suicide enlightenment, incident response after a breach, internal investigations for insider threat concerns, and…</description>
    <content:encoded><![CDATA[<p>Over the years, my teams and I worked a wide range of commercial cases: intellectual property theft, suicide enlightenment, incident response after a breach, internal investigations for insider threat concerns, and everything in between. No two of these engagements felt quite alike—not in their emotional weight, not in their legal terrain, and not in who was sitting across the table from us when the work was done. That variety is what makes commercial digital forensics genuinely interesting. It is also what makes it genuinely treacherous in ways that law enforcement practice is not.</p>
<p>In law enforcement, the legal architecture arrives pre-assembled. You get a search warrant. The Fourth Amendment defines what you can and cannot do with it. Chain of custody rules are codified. Courtroom procedures are known quantities. There is still enormous room for error—I've spent several weeks of this series documenting exactly how examiners get it wrong—but the framework is laid out before you touch the first drive. Commercial forensics dismantles that scaffolding entirely. In its place, you navigate a more complex web of relationships, privilege protections, licensing requirements, and obligations that can shift depending on the state, the nature of the engagement, and who retained you. The professional risk of getting that navigation wrong is real: evidence excluded, licenses revoked, civil liability, and—at the outer edge—criminal exposure...<em>for you</em>.</p>
<p>The starting question, which I put to students near the top of this lecture, is deceptively simple: <em>who is the client?</em></p>
<p>In law enforcement, the answer is obvious. In commercial practice, it frequently is not. When a company suffers a data breach today, the typical sequence might run something like this: the company contacts their cyber insurer, the cyber insurer selects or approves the incident response firm, and the IR team shows up to work what looks like a standard engagement. The problem is that the insurer and the insured have interests that can diverge sharply. The insurer wants to establish scope of loss and minimize payout. The company wants to understand the breach, recover from its damage, preserve its legal options, and avoid downstream liability. You were retained by the insurer, are physically present at the company's facilities, and are producing findings that both parties will read with different objectives. Courts have found, in precisely these circumstances, that the communications flowing through that engagement may not be protected by attorney-client privilege—because the insurer is a third party, and privilege requires confidentiality from third parties. The engagement structure created the problem before a single artifact was examined.</p>
<p>Attorney-client privilege in the digital evidence context deserves honest treatment, because practitioners in commercial forensics will encounter it constantly and often misunderstand what it actually protects. The core principle is straightforward: confidential communications between an attorney and client, made in the context of seeking or providing legal advice, are protected from compelled disclosure. Electronic communications are no less protected than paper ones—the fact that digital data may be easier to intercept does not weaken the privilege. What makes commercial practice complex is that the circle of people touching the case has expanded dramatically through decades of judicial decisions. As a forensic examiner retained by outside counsel, your notes may be protected as work product under FRCP Rule 26(b)(3) even when your final report is not. Whether that protection holds depends heavily on how the engagement was structured from the beginning. A post-breach forensic report prepared primarily to help the company understand and remediate what happened—rather than to support anticipated litigation—was found unprotected by a federal court in <em>Wengui v. Clark Hill</em>(2021), precisely because it served an ordinary business purpose.* How the engagement letter frames your scope of work matters enormously and cannot be fixed after the fact.*</p>
<p>Internal investigations add another layer to the client identity question. When corporate counsel retains you to investigate an employee, you work for the corporation. The employee has no attorney-client protection with that counsel, and the company can share your findings with government investigators without the employee's consent. The ethical framework around this—codified in <em>Upjohn Co. v. United States</em> and the Upjohn warnings that flow from it—exists precisely because the confusion is foreseeable and consequential. For you as an examiner, the practical instruction is direct: do not have informal conversations with the subject employee that the employee might interpret as confidential, because they were not. That confusion, when it surfaces later, is your problem to manage.</p>
<p>The unintended findings problem deserves its own treatment, because it arises across every type of commercial engagement and carries obligations that exist independently of what your client wants you to do with them. Conducting an intellectual property theft investigation and you find evidence of embezzlement. Working an HR matter and you discover what appears to be a crime against a third party. Running a typical eDiscovery collection and you find child sexual abuse material that is federal contraband. Digital evidence does not respect engagement scope, and neither do the legal and ethical obligations that follow from what you find. The question of whether you are obligated to report, and to whom, does not have a universal answer—it depends on what you found, the jurisdiction, and your role in the engagement. What is universal is this: you cannot make that decision alone or informally. Stop, document, and escalate to counsel immediately. A client instruction to handle the matter "internally" does not override obligations that exist in statute or professional rules. Following such an instruction can expose you to criminal liability rather than shield you from it.</p>
<p>The PI licensing question is the one that most reliably surprises practitioners who crossed over from law enforcement, and it deserves more attention than it typically gets. Depending on the state, performing commercial digital forensics—particularly work that might end up in court—may require you to be a licensed private investigator operating under a registered private investigation business. The regulatory patchwork is genuinely incoherent: some states require it by statute, some exclude examiners explicitly, some have issued opinions pointing one direction without a definitive ruling, and some have not addressed the question at all. Virginia, a state I know well, implicitly required PI registration for forensic examiners until 2011, when the Commonwealth explicitly carved out computer forensics by statute. Not every state has made that move. The consequence of getting it wrong ranges from nothing—to having your evidence excluded—to misdemeanor or felony exposure for performing investigative services without a license. Working directly for an attorney typically resolves the issue, because most states exempt attorneys and their employees from PI requirements. Before accepting a commercial engagement in an unfamiliar jurisdiction, verify the rules in that state. Then revalidate them before every case. The regulatory picture shifted materially between every published study on the subject—2008, 2012, and 2022—and it will shift again.</p>
<p>The through-line across all of it is something I put on the screen near the top of this lecture: commercial forensics is the same as law enforcement forensics, and it is entirely different. The technical work—imaging, artifact analysis, documentation, report writing—is the same. The web of relationships, obligations, and legal exposure surrounding that work is not. Technical competence is the prerequisite. Understanding the legal and ethical terrain you are operating in is what determines whether that competence produces durable, defensible results.</p>
<p>For those working in commercial practice: where has the client identity question created the most unexpected complications in an engagement, and how did you navigate it?</p>
<hr>
<p>This post is the ninth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the past nine articles, I've discussed the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>Your Face Is in the Database. You Put It There.</title>
    <link>https://johnirvine.me/blog/your-face-is-in-the-database/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/your-face-is-in-the-database/</guid>
    <pubDate>Mon, 22 Jun 2026 12:00:00 +0000</pubDate>
    <description>Here&#x27;s how the OSINT discussion usually starts, whether it&#x27;s in a graduate seminar or an IR team&#x27;s Slack channel: I can see it in a browser without logging in, so it&#x27;s fair game. That logic is intuitive, consistent,…</description>
    <content:encoded><![CDATA[<p>Here's how the OSINT discussion usually starts, whether it's in a graduate seminar or an IR team's Slack channel: <em>I can see it in a browser without logging in, so it's fair game.</em> That logic is intuitive, consistent, and deeply, reliably wrong. It fails for several independent reasons, and the failure mode isn't theoretical—it's the kind of thing that ends careers and cases.</p>
<p>The legal term for why that intuition fails is the aggregation problem. Individual data points can be entirely innocuous in isolation: a home address from public property records, a workplace from a LinkedIn profile, a daily schedule assembled from social media check-ins, a vehicle description from an Instagram photo, a children's school from a Facebook post celebrating a school play. None of those items, standing alone, creates a meaningful privacy concern. Combined, they produce a comprehensive surveillance profile that no single platform intended to enable, and that the subjects of those posts almost certainly never contemplated when they shared them. The Supreme Court put its finger on this directly in <em>Carpenter v. United States</em> (2018), when it held that the government's acquisition of cell-site location data required a warrant—rejecting the third-party doctrine argument that Carpenter had "shared" his location with the carrier and therefore surrendered his privacy interest in it. Courts are increasingly willing to treat aggregated digital data as deserving greater protection than any of its component parts, and the logical extension of* Carpenter* into the OSINT context has barely begun to be litigated. That's a feature of the developing law, not a reassurance.</p>
<p>The federal legal framework every OSINT practitioner needs to understand runs through three statutes: the Computer Fraud and Abuse Act (CFAA), the Stored Communications Act (SCA), and the Wiretap Act. They create independent liability. Compliance with one does not guarantee compliance with the others, and most practitioners who get into trouble don't think they were doing anything wrong under any of them.</p>
<p>The CFAA's central question for OSINT practice—when does accessing publicly available data become "unauthorized access"—got partially resolved in <em>Van Buren v. United States</em> (2021), when the Supreme Court held 6-3 that "exceeds authorized access" means accessing data you're not entitled to see, not using accessible data for an unauthorized purpose. Van Buren meaningfully narrowed the CFAA's reach, and* hiQ Labs v. LinkedIn* (2022) extended that reasoning to suggest that scraping publicly visible data likely doesn't violate the statute. Those are real developments, and practitioners should understand them. They should also understand what didn't get resolved: whether creating a fake account to bypass access controls constitutes unauthorized access, whether automated scraping at scale changes the analysis, and whether a cease-and-desist letter from a platform operator transforms the authorization picture entirely. On that last point, the case law is consistent—once you're told to stop and you continue, the legal calculus shifts dramatically against you. "No one has been prosecuted for this" is not a legal strategy.</p>
<p>The deception problem sits at the center of the most uncomfortable conversations in this area. Sock puppet accounts—fake personas created to monitor targets, join private groups, or follow subjects who've restricted their public visibility—are technically straightforward to create and operationally tempting in investigations where a subject has locked down their profile. They're also legally and ethically fraught in ways that practitioners routinely underestimate. The CFAA question after Van Buren is unsettled: if the gate is "up" because you logged in, but you logged in using a fabricated identity, did you have "authorization"? Platform Terms of Service universally prohibit fake accounts, which creates independent civil liability exposure. State anti-pretexting statutes may apply. Evidence obtained through deception faces admissibility challenges. For law enforcement practitioners, the DOJ's Attorney General Guidelines govern online undercover operations, and the entrapment doctrine travels seamlessly from physical to digital environments. For commercial IR practitioners operating outside the Fourth Amendment's constraints, the absence of a legal ceiling doesn't substitute for having an ethical floor. The engagement letter should define OSINT scope. The client should authorize aggressive collection techniques. Someone should be responsible, by name and in writing, for approving the sock puppet before it goes live.</p>
<p>Facial recognition tools bring a distinct layer of legal exposure, and the consent problem they surface is one of the more instructive in the field. When a practitioner uploads a subject's photo to Clearview AI and searches against a database of reportedly 30-plus billion images scraped from social media, the underlying database was built from photos that people posted to share with friends and family—not to be enrolled in a permanent biometric surveillance infrastructure. The Illinois Biometric Information Privacy Act (BIPA) requires informed written consent before any biometric identifier collection, including face geometry, and it carries a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional one. Facebook's BIPA settlement ran to $650 million. Clearview's ACLU settlement required restrictions on commercial sales. Texas's $1.4 billion resolution with Meta over facial recognition should disabuse anyone of the notion that biometric privacy exposure is academic. There is no comprehensive federal biometric privacy statute yet—but the patchwork of state laws and the EU AI Act's classification of real-time biometric surveillance as "high risk" means that the legal obligations an OSINT practitioner carries depend heavily on where the subjects of that search happen to be located.</p>
<p>The international dimension of OSINT practice is where many practitioners are most dangerously underprepared. The GDPR applies to the processing of personal data on EU and EEA residents regardless of where the processor is located—and collecting personal data from public sources is processing under GDPR, full stop. Public availability of data does not create an exemption. Canada's PIPEDA, Brazil's LGPD, China's Personal Information Protection Law, and Australia's Privacy Act each have their own frameworks and enforcement postures, and the Five Eyes intelligence-sharing architecture means evidence collected in one jurisdiction can end up in the hands of authorities in another. Jurisdictional complexity is the norm in modern OSINT practice. Treating it as someone else's problem is a reliable way to turn a completed engagement into a compliance incident.</p>
<p>There's a principle I put on the screen at the beginning of this lecture that bears genuine weight: legal compliance is the floor, not the ceiling. Something can be entirely legal and profoundly unethical. Something that is common practice in the field can be both simultaneously. The question a practitioner should ask before any OSINT collection is not just "can I?" but "should I?"—and the answer to that second question has to be grounded in necessity, proportionality, and accountability. Collect what the investigation requires. Use methods proportionate to the seriousness of the matter. Document the methodology, the authorization chain, and the disposition of every piece of data collected, so the work can be reviewed and challenged by anyone who needs to. If a screenshot of what you're about to do appeared in a courtroom, a deposition, or a news story, would you be comfortable defending it?</p>
<p>If the answer is no—or even "maybe"—that's the answer.</p>
<hr>
<p>This post is the eighth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the series of articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Blank Letterhead That Led to a Domestic Terrorist—and Why Documentation is Important</title>
    <link>https://johnirvine.me/blog/the-blank-letterhead/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/the-blank-letterhead/</guid>
    <pubDate>Mon, 15 Jun 2026 12:00:00 +0000</pubDate>
    <description>There&#x27;s a line I put on a slide in class that I want to put here first, because everything in this article depends on it: one hundred percent of anything anyone else will ever know about your examination comes from…</description>
    <content:encoded><![CDATA[<p>There's a line I put on a slide in class that I want to put here first, because everything in this article depends on it: <em>one hundred percent of anything anyone else will ever know about your examination comes from reading your report.</em> Not from watching you work. Not from your institutional reputation. Not from the fact that you've been doing this for fifteen years. One hundred percent, from the document you write.</p>
<p>That's not a statement about writing skill (though that's an important and often overlooked part of forensics in general). It's a statement about professional obligation—one that begins well before the report in the notes you take the moment evidence arrives and the documentation you maintain every day through to the final page of your analysis.</p>
<p>In my experience, the mechanics of case documentation in law enforcement digital forensics cover four interlocking areas: chain of custody, note taking, worksheets and checklists, and forensic reporting. Each carries its own procedural requirements and its own ethical weight, and the ethical weight tends to get underemphasized in favor of the procedural. That imbalance is worth correcting. In Intelligence or commercial environments, notes are often left-up to the individual examiner or discouraged completely by highly-paid attorneys.</p>
<p>Chain of custody is the mechanism by which the law verifies that the evidence you analyzed is the same evidence that was seized, and that it arrived in your hands intact. The form is simple—a dated record of every person who received or released a piece of evidence, from seizure to court. What isn't simple is the discipline required to fill it out accurately, in real time, without gaps. A few things I tell every class: opposing counsel may not know the first thing about digital evidence artifacts or forensic methodology. They will absolutely know what a chain of custody form is supposed to look like, and they will find every anomaly in yours. Fill it out correctly. Fill it out immediately. Don't put it off. One more wrinkle worth noting: when evidence ships via commercial carrier, the carrier's name and tracking number become a "released to" on the sending end and a "received from" on the receiving end. Yes, evidence gets shipped. Your chain form needs to reflect that cleanly, and multiple chain forms may exist for a single piece of evidence depending on where it originated and how many hands it passed through on its way to your bench. The ends and beginnings have to match up.</p>
<p>In my opinion (which is often the source of argument amongst my colleagues), notes are the foundation everything else rests on. They need to be contemporaneous—meaning you write them as you go, not at the end of the day and certainly not at the end of the case—accurate, complete, unbiased, and clear enough that another examiner could follow your steps without having to call you. That last requirement matters more than most new examiners expect. You might not be the person who goes to trial on your own findings, or a higher-priority case might pull you away from this one for months, and when you return, "future you" will need to know exactly what "past you" already did.</p>
<p>I structure notes into sections: administrative details, a case summary, the analysis requested, a log of every piece of media submitted, a contact log, a tools list, a daily log, a keywords section, and a running list of people with their associated identifiers. Most of this is uncontroversial. One section, though, generates more genuine discussion in class than all the others combined.</p>
<p>I call it "Unknown Interest."</p>
<p>Unknown Interest is the section for things "that make you go <em>hmmmm"</em>—things that don't fit the current theory of the case. Things that seem irrelevant but feel like they might matter. Things you can't explain yet. The temptation, when you're deep in an examination, is to set aside the unexplained and focus on the evidence that's already speaking clearly. The discipline that section enforces is the opposite: write down the anomalies, return to them regularly, and review the full list before you close the case. Frequently, things that make no sense at the beginning make complete sense at the end. You're assembling a puzzle without the box lid, and you don't always know what fits where until something clicks into place.</p>
<p>Here's where it gets personal. Years ago, I was working a case and came across what appeared to be a blank company letterhead template sitting in Microsoft Word's templates directory on the subject's machine. The body of the document was empty—no text, no correspondence, no content of any kind. What it had was a company name, a PO Box address, and a footer at the bottom listing the organization's "corporate officers" by name. On a surface read, it looked like someone had built a template for business letters they'd never gotten around to writing (as I didn't find any saved on the computer), and there was no obvious connection to the conduct I was investigating. I almost moved past it. Something about the template—the company name, the PO Box format, the specificity of those officer names—made me log it under Unknown Interest instead. I noted the details and kept going.</p>
<p>As the case developed, I had the opportunity to fly out to the field office working the case and ended up reviewing progress with an intelligence analyst in the war room—the dedicated case space with the large whiteboard that looked exactly like every television procedural you've ever seen: names, photographs, and marker lines connecting individuals, groups, and entities into a web of known and suspected relationships. I was standing there taking it in when I noticed a gap. I asked her why there was no line from our subject to a cluster of names on the far corner of the board.</p>
<p>She said they'd been trying to make that link for years. They just didn't have anything that actually tied the two together.</p>
<p>"Oh, you do now," I said—and I pulled up the copy of the blank letterhead, which had every name she needed listed together in one place, right there in the footer.</p>
<p>She jumped out of her chair and screamed.</p>
<p>The connection wasn't sitting in a database. It was in a footer on an empty document in a templates directory, waiting for someone to log it and come back to it. The hunch cost me thirty seconds to document. <em>The documentation is what made it usable.</em></p>
<p>That is why Unknown Interest exists as a dedicated section and not as a mental note you plan to revisit. Mental notes dissolve under case pressure. Documented ones don't.</p>
<p>Worksheets and checklists draw eye-rolls from experienced practitioners who consider them beneath their skill level. I use an analogy to cut that short: commercial pilots fly 83 hours a month and still run a preflight checklist before every flight. The checklist doesn't reflect doubt about their skill. It reflects an honest understanding that even skilled people operating under normal pressure can miss things that a systematic review would catch. Digital forensics is no different. The worksheets in circulation today are almost all derived from one examiner's work at a DEA laboratory in 2003 (hi, Gerry!) which tells you something about how slowly foundational practices evolve. They don't dictate the way you work a case; they exist as a reminder not to skip the thing you do on every case but didn't consciously think about today. If you don't like the existing templates, make your own, but have <em>something</em>. The checklist isn't an "end-all, be all" to your analysis. It's a useful list of tasks to make sure you hit everything you needed to.</p>
<p>The forensic report is where everything converges. It needs to be correct—every assertion backed by cited evidence, every citation including the evidence item number, file path, file name, and MD5 hash at minimum. It needs to be clear—active voice, proofread out loud at your desk because your ear will catch what your eye misses, and accessible to someone who has never used a command line. It needs to be appropriate for its audience: the case agent, the judge, and the jury member who is going to make a consequential decision based on your ability to explain what you found in plain language. It needs to be unbiased—inculpatory and exculpatory evidence alike, because you are not the judge, and your job is to report what the evidence says, not to build the prosecution's case for them. The structure I use runs from a cover page through an executive summary (prime beef—clear, direct, no technical jargon, responsive to the actual question the case is asking), then the media submitted, the request for analysis, the detailed technical findings, the analyst's commentary, recommendations, and attachments.</p>
<p>On that last item: don't scrimp on attachments. Full email lists, contact lists, complete browsing histories, every file referenced in the report body—these go into the attachments in their entirety, even if they run long. The human reader probably won't work through all of them. That's not the point. The point is cross-correlation, and increasingly, the point is that investigative tools and analytical systems will index that data against other cases, other subjects, and other jurisdictions in ways you can't anticipate when you're writing the report. Put the data in. Let the downstream systems use it.</p>
<p>One technique worth naming explicitly: when you need to explain a technical point to a non-technical reader—what a registry setting does, what a particular software flag means—offset that explanation in an italicized block labeled clearly as an "Analyst's Note." It keeps the narrative readable at the top level while making the technical context available to anyone who needs it. It also forces you to be precise about what you actually know versus what you're inferring, which is a discipline that pays dividends on the witness stand.</p>
<p>The thread running through chain of custody, note taking, checklists, and reporting is a single, consistent obligation: documentation is not the administrative tax you pay on the interesting work. It is the interesting work. The examiner who treats it that way is the examiner whose cases survive scrutiny—and the examiner who catches the hunch that everyone else would have walked past.</p>
<hr>
<p>This post is the seventh in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>Being an Expert Witness Requires More Than Expertise</title>
    <link>https://johnirvine.me/blog/expert-witness-more-than-expertise/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/expert-witness-more-than-expertise/</guid>
    <pubDate>Mon, 08 Jun 2026 12:00:00 +0000</pubDate>
    <description>I show a clip from My Cousin Vinny in class every semester when the course reaches voir dire. The scene where Mona Lisa Vito—an automotive expert with zero formal credentials, a thick New York accent, and all the…</description>
    <content:encoded><![CDATA[<p>I show a clip from <em>My Cousin Vinny</em> in class every semester when the course reaches voir dire. The scene where Mona Lisa Vito—an automotive expert with zero formal credentials, a thick New York accent, and all the right answers—dismantles the prosecution's theory under hostile cross-examination is, technically, a more accurate illustration of Federal Rule of Evidence 702 in action than most material produced specifically for legal training. Marisa Tomei won the Oscar for it. The point I make to the class afterward is not that the performance is impressive (though it absolutely was, and Marisa earned every ounce of that Oscar). The point is that Mona Lisa Vito knew more about the subject than any reasonable layperson, she could explain it clearly to a room full of non-experts, and she held up under a skilled attorney's attempt to expose the limits of that knowledge. That combination—depth, clarity, and durability under pressure—is the whole job description.</p>
<p>Understanding <em>why</em> requires knowing the legal architecture that governs expert testimony, and that architecture has a history.</p>
<p>The original standard for admitting scientific evidence came from <em>Frye v. United States</em> in 1923, a case built around a systolic blood pressure lie detector. The logic of* Frye* was built on a kind of institutional humility: judges were not scientists, so they should not be asked to determine whether a scientific method was reliable. Experts in the relevant field would do that, by debating whether the method had achieved "general acceptance" among their peers. If the community accepted it, the court would admit it. If the community hadn't coalesced around it yet, the evidence stayed out. The standard served its purpose reasonably well for decades, until technology accelerated past it. New methods and techniques arrived faster than professional communities could establish consensus about them, which meant novel methodologies faced a circular trap—<em>nobody had enough experience with them to call them "generally accepted," so plaintiffs with valid claims that the underlying science supported couldn't get the evidence in front of a jury.</em></p>
<p><em>Daubert v. Merrell Dow Pharmaceuticals</em> (1993) broke that trap by changing the question. Scientific testimony no longer needed to pass a general acceptance test. It needed to be* relevant* and* reliable*. General acceptance was demoted from the sole determination to one factor among several in a reliability analysis. The Daubert factors—whether the principle had been tested, whether it had survived peer review in professional publications, and what the potential rate of error was—gave judges a more functional checklist, one that could accommodate newer methodologies without requiring them to have been around long enough to accumulate consensus. Six years later,* Kumho Tire Co. v. Carmichael* (1999) closed a loophole some attorneys had been threading by labeling digital and technical evidence "technological" rather than "scientific," which had allowed them to argue that Daubert didn't apply. The Supreme Court was not moved by this reasoning. Daubert now governs all expert testimony—scientific, technical, and otherwise.</p>
<p>Federal Rule of Evidence 702, as amended to codify these decisions, is the document that ties the structure together. It permits testimony by a qualified expert if the witness has the requisite knowledge, skill, experience, training, or education; if the testimony is grounded in sufficient facts or data; if it is the product of reliable principles and methods; and if the witness has applied those principles and methods reliably to the facts of the case. In digital forensics, that last clause is the one that gets people in trouble. Many labs treat imaging as the scientific and repeatable component of the work, and the reasoning is sound: a bit-by-bit image of a storage device, verified by matching MD5 hash values against the original, is a mechanically produced duplicate that courts recognize as legally equivalent to the original under the Best Evidence rule. The write blocker and the documented hash are not administrative formalities. They are the mechanism by which your copy achieves legal standing as evidence. Omit them, or fail to document them, and you have introduced a gap that a competent defense attorney will find.</p>
<p>The voir dire process—the examination through which a court determines whether to qualify you as an expert—is where the Daubert framework meets the individual examiner. To clear voir dire, you need a strong curriculum vitae (<em>not</em> a resume—they are different documents for different purposes), you need to know precisely what it says, and you need it to be accurate and free of errors. That sounds straightforward until you realize that opposing counsel will have read it more carefully than you have in the weeks before you take the stand. The bar for qualification, practically speaking, is knowing materially more about the subject than the average person on the street—not more than the other side's expert, not more than the judge, but more than a reasonable layperson. That bar is achievable. Clearing it repeatedly over a career, across a professional record that remains clean enough to survive scrutiny, is the work that actually takes time.</p>
<p>The Brady/Giglio/Henthorn cluster deserves attention here, because it touches the examiner directly in a way that Frye and Daubert do not. <em>Brady v. Maryland</em> (1963) established that the government must disclose to the defense all information that may be beneficial to them—not merely the information the prosecution finds helpful to its case. Withholding Brady material typically results in a reversed conviction on appeal.* Giglio v. United States* (1972) extended that obligation to include anything that could be used to impeach the character or credibility of a government witness—honesty, integrity, impartiality, prior inconsistencies.* United States v. Henthorn* extended it further still to include the personnel records of testifying officers.* *Read that again slowly:**when you testify on behalf of the government, your employment history is potentially discoverable by the defense. Prior findings of professional misconduct, prior instances where your credibility was questioned, prior cases where your methodology was challenged—these are not private records that disappear when a case closes. They are a file that follows you to the stand.</p>
<p>The practical instruction I give every student on this material is consistent: treat your professional record as a document that will eventually be read by someone whose job is to discredit you. Know what is in it. Keep it accurate. Resolve any legitimate questions about your conduct through the appropriate professional channels before they resolve themselves in open court. The see-no-evil approach to your own history is a liability strategy, and it fails at the worst possible moment.</p>
<p>What all of these frameworks—Frye, Daubert, Kumho, FRE 702, Brady, Giglio, Henthorn—share is a common underlying demand: the system wants expert witnesses who have done their technical work correctly, documented it rigorously, understand the legal boundaries of their own authority, and can be held publicly accountable for every aspect of their professional record. That is a higher standard than most training programs articulate, and it is why I spend an entire class session on the legal architecture rather than the tools. The tools change. The framework for what makes testimony credible, admissible, and durable under cross-examination has been remarkably stable for decades.</p>
<p>The courtroom is not where you work out what you believe about your own expertise. That work happens at the workbench—long before you raise your hand and take the oath.</p>
<hr>
<p>This post is the sixth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>Warrants, Scopes, and Tears on the Witness Stand</title>
    <link>https://johnirvine.me/blog/warrants-scopes-and-tears/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/warrants-scopes-and-tears/</guid>
    <pubDate>Mon, 01 Jun 2026 12:00:00 +0000</pubDate>
    <description>I watched a state police officer cry on a witness stand once. He was big, seasoned, and the kind of person you&#x27;d want backing you up in a dark parking lot. The defense attorney was small, calm, and methodical. She…</description>
    <content:encoded><![CDATA[<p>I watched a state police officer cry on a witness stand once. He was big, seasoned, and the kind of person you'd want backing you up in a dark parking lot. The defense attorney was small, calm, and methodical. She asked him, over roughly forty minutes of quiet, specific questions, to explain exactly which files he had examined during a forensic analysis of her client's computer, and exactly where in the search warrant the authority to examine those files was described. He couldn't. The warrant authorized him to look for evidence of one thing. He had looked at everything. When she finally got him to say out loud that he had exceeded the scope of his lawful authority—that he had, in effect, violated her client's Fourth Amendment rights—he broke down. This was a moot court training exercise. The "defense attorney" was a <em>genuine</em> defense attorney, and the examination of what he had done wrong was entirely real.</p>
<p>I've thought about that moment many times while teaching this material, because it captures something that rarely makes it into policy briefings or certification prep courses: scope violations in digital forensics are not exotic. They are not committed by rogue examiners with bad intentions. Scope violations happen to competent, well-meaning people who lost track of the line between thorough and unlawful, and they happen in part because digital evidence is unlike any other kind.</p>
<p>The Fourth Amendment's particularity requirement is one of its oldest features. A warrant must describe "the place to be searched, and the persons or things to be seized." That language dates to 1791, and its purpose is to prevent the general warrant—the British instrument of colonial-era harassment that let an official search wherever he liked for whatever he found. Founding-era courts were not subtle about why this mattered. The particularity requirement is the Constitution's structural answer to the fishing expedition.</p>
<p>Physical searches have natural constraints. A warrant to search a house for a stolen rifle does not authorize the officer to open medicine cabinets or read the letters on the kitchen table. The physical scope of the rifle keeps the search honest in a way that doesn't require the officer to exercise much discipline. The rifle is either in the closet or it isn't. He's done.</p>
<p>Digital evidence has no such structure. A forensic image of a hard drive authorized for one purpose makes the entire contents of a person's life available to the examiner's tools. Years of personal email. Financial records. Medical notes. Photographs. Conversations that took place in what the subject reasonably believed was private space. Chief Justice Roberts put his finger directly on this in Riley v. California (2014), when the Supreme Court unanimously held that officers need a warrant to search cell phones incident to arrest: "Modern cell phones are not just another technological convenience. With all they contain and all they may reveal, they hold for many Americans 'the privacies of life.' The fact that technology now allows an individual to carry such information in his hand does not make the information any less worthy of the protection for which the Founders fought."</p>
<p>That passage should be laminated and taped to the top of every computer forensic workstation in the country.</p>
<p>What Roberts articulated is precisely the problem the moot court exercise was designed to surface. In traditional forensics, the physical nature of evidence disciplines the search. In digital forensics, the discipline has to come from within the examiner—from a careful reading of the warrant, a clear understanding of its scope, and the professional integrity to stop when the warrant stops. There is no physical wall to run into. There is only the examiner's judgment and the question of whether that judgment holds up under scrutiny.</p>
<p>The affidavit is the instrument that sets the outer boundary. The agent or officer writes what they know, how they know it, and what they expect to find. The judge reviews it, signs the warrant, and defines the lawful scope of the search. Every examination that follows exists inside that box—not outside it, and not somewhere in the vicinity of it. An examiner who treats scope as a rough approximation rather than a precise legal boundary is not being thorough. They are being unlawful, and they are exposing the entire case to suppression.</p>
<p>The suppression risk is real and the case law is clear. Courts have excluded consequential evidence because an examiner ran a hash set the warrant didn't authorize, or followed a thread the warrant didn't permit. Cases that were otherwise well-built have collapsed because someone decided that finding something important justified going somewhere the warrant didn't allow. "I found something useful" has never been a successful legal argument, and the body of precedent on this point grows with every year that more of human life migrates into digital storage.</p>
<p>The practical instruction I give every student is simple: when doing law enforcement cases, demand a copy of the search warrant before you touch the evidence. Not after. Before. If your supervisor won't give it to you, ask to speak with your government attorney. This is not a bureaucratic nicety. It is the document that defines your lawful authority, and working without it is not just procedurally risky—it is a choice to operate blind on the most important constraint in the examination. If you don't know the scope, you cannot stay within it.</p>
<p>On the witness stand, scope compliance is usually the first place a skilled defense attorney goes looking. The examiner who can walk through their analysis methodically—here is what the warrant authorized, here is what I examined, and here is why each piece falls within that authorization—is largely unassailable. Being able to articulate where you searched and why is key. The examiner who can't do that is vulnerable in ways that rarely manifest as a clean admission, but more often as a slow accumulation of "I don't recall" and "I may have also looked at" that the attorney in that moot court session had turned into a full confession by the end of forty minutes.</p>
<p>The officer who cried that day knew, on some level, what had happened before the attorney asked the first question. The examination had felt justified at the time. He had found something he thought mattered. He had followed it. That sequence—feeling justified, finding something, and following it—is exactly the sequence the Fourth Amendment was designed to interrupt, and it is exactly the sequence that digital forensics makes easiest to slip into.</p>
<p>The warrant says what it says. <em>So does the Constitution.</em></p>
<hr>
<p>This post is the fifth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>Digital Forensics is a...People Business?</title>
    <link>https://johnirvine.me/blog/digital-forensics-is-a-people-business/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/digital-forensics-is-a-people-business/</guid>
    <pubDate>Tue, 26 May 2026 12:00:00 +0000</pubDate>
    <description>There&#x27;s a story I tell in class that doesn&#x27;t start with a hard drive. It starts with a grocery store.</description>
    <content:encoded><![CDATA[<p>There's a story I tell in class that doesn't start with a hard drive. It starts with a grocery store.</p>
<p>A small Midwest chain—one you've never heard of—became, for a stretch of weeks, the unwitting patient zero in what would eventually become one of the most destructive retail breaches on record. The malware that later crippled a major national retailer's point-of-sale infrastructure ran its first laps through this unremarkable regional chain before anyone realized what it was or where it was headed. By the time examiners arrived to work the case, they didn't walk into a sterile lab environment. They walked into a functioning grocery store. In that store were a frightened store manager trying to protect his job, an IT contractor who knew perfectly well that something had been mishandled on his watch, a corporate attorney observing from a corner, and employees going about their shifts—even though most of the registers were down—because the chicken wasn't going to stock itself.</p>
<p><em>Welcome to the field.</em></p>
<p>Most technical training in digital forensics is built around a clean abstraction: evidence comes in, evidence gets analyzed, evidence goes out. The machine is the puzzle; you solve it. What that model almost entirely glosses over is that you will rarely work in isolation, and the people surrounding the evidence will complicate your work in ways that no standard operating procedure fully anticipates.</p>
<p>The taxonomy of people you'll encounter on a search is worth thinking through clearly, because each category carries its own dynamics and its own ethical weight. Law enforcement officers and agents are your operational partners. They generally want what you want, but they are working from different information and under different pressure than you are—pressure that will sometimes get redirected at you when results are slow. Subjects occupy a legal category unto themselves. Some are guilty. Some are not. The overwhelming majority will be scared, defensive, or calculating—sometimes all three at once—and none of them are obligated to make your job easier. Witnesses saw something or know something, and their willingness to share it will depend entirely on who else is in the room and what they believe is in their own interest. Assistive third parties (like the vendor who administered the system or the employee who holds the passwords) may genuinely want to help, or may be quietly steering your attention away from something they'd prefer you not find. Bystanders are the wild card: people adjacent to the scene who have no formal role in the investigation but excellent situational awareness and, in the current era, the ability to broadcast whatever they observe in real time.</p>
<p>Everybody on scene has a social media account, a phone in a pocket, a TikTok, a Snapchat, or a YouTube channel with an audience that would find a Federal search warrant execution genuinely compelling content. The professional discipline required to conduct a search without generating a quotable moment—a frustrated comment, a visible shortcut, a careless gesture observed by someone who is absolutely going to post it—is not a soft skill. It is a survival skill. Reputations in this field are <em>built slowly and damaged quickly</em>, and the damage doesn't just happen inside a courtroom. It also happens in a parking lot video that goes up at midnight.</p>
<p>The ethical obligations you carry into the field are not separate from the procedural ones; they run through them. Staying within the scope of your search authority is a <em>constitutional obligation</em>, not a bureaucratic preference. Search warrants define what you are legally permitted to examine, and an examiner who drifts beyond that scope—even with good intentions and technically sound methods—has violated the rights of a real person. "I found something useful" is not a legal defense. Courts have excluded consequential evidence because an examiner ran a hash set the warrant didn't authorize, or followed a thread the warrant didn't permit, and the cases that fell apart as a result were no less serious for having been procedurally fouled. Unlike other most forensic disciplines, it's* extremely* easy to accidentally (or intentionally) veer out of scope.</p>
<p>Standard operating procedures exist, in part, to put guardrails around exactly these moments. A well-constructed SOP tells you how to approach evidence, what to document, when to stop, and how to conduct yourself when the situation is genuinely ambiguous. The honest caveat is that many SOPs are written by people who have never stood in a room with a hostile subject and a chain of custody form, and it shows on every page. Following a poorly written SOP is still your professional obligation. Recognizing that it is poorly written—and working through the appropriate channels to improve it—is also your professional obligation. Two things can be true at the same time.</p>
<p>On the subject of the courtroom: the primary rule is to tell the truth, and I mean that as an operating instruction rather than a platitude. Tell the truth when you are fully prepared. Tell the truth when your memory has gaps. Tell the truth when opposing counsel has constructed a question specifically designed to make you look incompetent, because "I don't recall" is a complete and legally defensible answer, and watching a witness improvise their way around a gap in their preparation is one of the more painful things to watch in a forensic career. The examiner who survives cross-examination intact is not the one with the most aggressive responses. It's the one who knows precisely what the evidence shows, states it clearly and without embellishment, and stops there. <em>You</em> are not on trial. Treat the experience accordingly.</p>
<p>The technical fundamentals matter enormously. The tools, the documentation, the scope discipline, the clean workstation, the bias-free notes—all of it matters. The field is not forgiving of sloppiness. The examiners I've watched struggle most, however, were not the ones who couldn't image a drive or interpret an artifact. They were the ones who couldn't read the room they were standing in.</p>
<p><em>For practitioners in the field: what's the most complicated human dynamic you've had to navigate on a search or in a lab, and what did it cost you to work through it?</em></p>
<hr>
<p>This post is the fourth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Bias You Bring to the Bench</title>
    <link>https://johnirvine.me/blog/the-bias-you-bring-to-the-bench/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/the-bias-you-bring-to-the-bench/</guid>
    <pubDate>Mon, 18 May 2026 12:00:00 +0000</pubDate>
    <description>Three weeks into the semester, I put two colored circles on a screen. &quot;A big part of forensics,&quot; I tell the class, &quot;is looking carefully at the small differences between things that look similar...finding the needle…</description>
    <content:encoded><![CDATA[<p>Three weeks into the semester, I put two colored circles on a screen. "A big part of forensics," I tell the class, "is looking carefully at the small differences between things that look similar...finding the needle in the needle-stack." The circles, except for the color, appear identical. I tell them, "One of these circles is actually slightly larger than the other," and I ask for a show of hands. "Red?" About a third of the room goes up. "Blue?" Another third. Some students keep their hands down.</p>
<p>"I know it's hard to see," I tell them reassuringly, "but one really <em>is</em> bigger," and we try again. "Red?" Half the room. "Blue?" The other half. Then I advance the slide. The two circles drift across the screen and settle on top of each other, and they line up perfectly. Same size. "You all knew they were the same the first time you looked," I tell them. "You let me talk you out of what your own eyes were telling you. I* biased* your decision, and I did it just by standing at the front of the room, being the one holding the grade book."</p>
<p><em>(If you're one of my future students reading this—no you didn't.)</em></p>
<p>In fifteen years of teaching this course, exactly one student has refused to budge, pushing back against my influence and maintaining that the circles were the same. <em>One</em>. She impressed me that day. Everyone else folded.</p>
<p>That moment is the doorway into our bias conversation, and it's the part of the course that tends to land hardest. The material itself is conceptually simple. What carries forth is the way the implications continue to unfold for the rest of a person's career.</p>
<p>In the dictionary sense, a bias is <em>a prejudice in favor of or against one thing, person, or group, usually in a way considered unfair.</em> That definition is clean enough to teach, but it doesn't capture how biases actually behave inside a forensic examination. They sit underneath language. They steer adjective choices. They quietly encourage a finding that flatters whatever theory was on the table when the evidence arrived. They do this even when the examiner is competent, well-meaning, and convinced of their own neutrality.</p>
<p>We carry biases for a reason that has nothing to do with character. There's an evolutionary case, sometimes invoked through Darwin and the survival-of-the-fittest framing, that snap pattern matching kept our ancestors alive long enough to pass on their genes. The cave dweller who paused to deliberate the rustle in the brush became lunch. The one who ran first and asked questions later got to have grandchildren. We're descended from the runners. That same machinery that protected our great-great-greats from large cats now interferes with our ability to read an email thread or evaluate a chat log without slipping a thumb onto the scale.</p>
<p>Two flavors of bias are worth distinguishing. <em>Implicit biases</em> live below conscious awareness and are shaped by everything we've absorbed about race, age, ethnicity, appearance, and social signaling. They don't necessarily match our stated values, which is part of what makes them so disorienting when you finally catch one of yours in the act.* Explicit biases* sit on the surface, often dressed up as logic, usually triggered by some perceived threat, whether physical, financial, professional, or reputational. Both kinds influence the work, and neither announces itself politely.</p>
<p>Digital forensic practice can borrow usefully from clinical research, which has spent decades cataloging how biases corrupt scientific output, and the same categories map onto our field with very little tailoring. Selection biases shape which evidence we even decide is worth looking at. Exposure or performance biases reflect the skill differential analysts bring to the work, since a practitioner with years on the bench will generally produce a stronger examination than someone fresh to the craft. Interpretation biases color how we read what we've found. Publication bias—which sounds like a purely academic concern—has a forensic cousin: the parts of a case we choose to feature in the report, the parts we let recede into the appendix, or the parts we don't mention at all.</p>
<p>Inside an actual examination, the giveaways are subtle. Adjective and adverb choices that color a finding in one direction. A narrative that nudges the reader toward a weakly substantiated conclusion. The decision to keep working a case past its honest stopping point because something in the data feels like it ought to mean more than it does. The quiet assumption that a subject is guilty before the artifacts have been allowed to speak. Each of these is the kind of small drift that—multiplied across a career—separates examiners whose work holds up from examiners whose work eventually doesn't. They rarely look like dramatic ethical failures from the inside, which is exactly why they're so easy to miss.</p>
<p>The hopeful part is that biases respond to attention. Awareness lets you be mindful, and mindfulness gives you a fighting chance to challenge your own first read before it hardens into a conclusion. There's nothing mystical about the mechanism. Mostly it comes down to slowing down at the points where speed feels rewarded, asking whether the evidence is leading you or you're leading the evidence, and accepting that your discomfort with that question is itself a piece of useful data.</p>
<p>Peer review is the other half of the answer, and I'll say plainly that it helps even when your organization doesn't formally require it. If your shop has no peer-review program, build one for yourself. Trade reports with a trusted colleague. Ask someone whose judgment you respect to read your draft conclusions cold and tell you where the seams show. The examiner who invites that scrutiny tends to be the examiner whose work survives cross-examination on the witness stand intact. Some people may use AI to perform a peer review, but since AI has been trained on data <em>generated by humans</em>, it can be biased too.</p>
<p>What makes this hard, and what I tell every cohort, is that biases aren't a problem you solve once. As you outgrow some, others form in their place, shaped by the cases you draw, the colleagues you talk to, and the algorithms that decide what shows up in your feed at night. The work is ongoing. The discipline is the point.</p>
<p>For practitioners reading this, where do you most often catch yourself slipping, and what do you do in that moment to course-correct? For people in adjacent fields, whether that's law, security, journalism, medicine, or any discipline where a finding gets attached to a person's name, I'd be curious to hear how your profession handles the same problem.</p>
<hr>
<p>This post is the third in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>Colonel Colt and GenAI</title>
    <link>https://johnirvine.me/blog/colonel-colt-and-genai/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/colonel-colt-and-genai/</guid>
    <pubDate>Fri, 15 May 2026 12:00:00 +0000</pubDate>
    <description>Yesterday, I worked through Allie K. Miller&#x27;s guide to developing a personal constitution for AI—a structured exercise in articulating your values so that a model can engage with you more thoughtfully. What I didn&#x27;t…</description>
    <content:encoded><![CDATA[<p>Yesterday, I worked through Allie K. Miller's guide to developing a personal constitution for AI—a structured exercise in articulating your values so that a model can engage with you more thoughtfully. What I didn't anticipate is that it would help me uncover something I didn't consciously realize.</p>
<p>What I learned was this: I am obsessed with access. Knowledge and opportunity should flow <em>toward</em> people, not be rationed by circumstance, geography, or the family someone happened to be born into. I've been watching those barriers come down, one by one, across my entire career in technology.</p>
<p>That career started with an Atari 400, then a Coleco ADAM, and then an IBM PC clone I built from parts around a 4.77 MHz processor. By my teens, I'd learned to speak a language almost nobody around me understood—one that lived in hobbyist magazines and photocopied manuals, not classrooms. You had to be motivated, resourceful, and fortunate enough to have the hardware. The barriers were still mostly there.</p>
<p>Then the Internet arrived, and access to information stopped being a function of who you knew or where you lived. I watched that happen in real time and never got over it. I remember being able to visit every website that Yahoo! listed—before there was search—to see what people had built with this new technology.</p>
<p>Across the decades, I saw the same framework when I try to describe what technology has actually done for us:</p>
<ul><li>The personal computer democratized <em>technology</em>.</li><li>The Internet democratized <em>information</em>.</li><li>AI, particularly Generative AI, is <strong><em>democratizing * * skills</em>.</strong></li></ul>
<p>Last week, I asked Claude why a cream sauce breaks—and got an answer that used to require culinary school or a very patient mentor. When my AC unit started behaving badly, I described the symptoms to ChatGPT and arrived at a conversation with the repair tech that was genuinely informed. Researching a company, I asked Perplexity to tell me about its products and competitors. A first-generation college student in rural Virginia can now access the quality of career coaching and strategic thinking that used to require an expensive professional or a well-connected family. A new job hunter can practice a job interview at two in the morning, as many times as needed, without embarrassment or cost. None of that required a credential, a consultant, or a family that already knew how these games were played. It required only curiosity and access.</p>
<p>I'm also aware this story has a dark shadow. Generative AI is expensive at the point of production—the energy consumption is substantial and growing, the water requirements are measured in millions of gallons per year, and those costs fall unevenly on communities that didn't choose to host them. Companies are terminating employees en masse to pay for AI investment. GenAI, like any powerful tool, can be used for the greater good or for abject evil. (I have a particular interest in that topic.) Anyone who hand-waves those issues away isn't acting honestly. What I'd argue, however, is that <em>we</em> hold these problems with* <em>the same seriousness that we</em> hold the promise,* and then get to work solving them. Every major civilizational shift has suffered costs on its way to something better, and now—more than ever—we have the tools to figure out how to mitigate them.</p>
<p><strong>Access has always been the point. The technology just keeps getting better at delivering it.</strong></p>
<hr>
<p><em>John Irvine is a software product leader, a former digital forensic investigator and cyber profiler, an AI Governance Certified Professional, and an Adjunct Professor of Ethics and Law of Digital Forensics in George Mason University's Masters of Digital Forensics program.</em></p>]]></content:encoded>
  </item>
  <item>
    <title>What the Field of Digital Forensics Owes the People Who Enter It</title>
    <link>https://johnirvine.me/blog/what-the-field-owes/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/what-the-field-owes/</guid>
    <pubDate>Mon, 11 May 2026 12:00:00 +0000</pubDate>
    <description>In my last post, I argued that the hardest questions in digital forensics are not technical ones. They are ethical ones. I want to build on that today, because there is a layer of ethical obligation that this…</description>
    <content:encoded><![CDATA[<p>In my last post, I argued that the hardest questions in digital forensics are not technical ones. They are ethical ones. I want to build on that today, because there is a layer of ethical obligation that this profession almost never examines out loud: <em>the obligation the field owes to the people it recruits into it.</em></p>
<p>I open the second session of my graduate course at George Mason with a statement that tends to land quietly in the room: digital forensics is not a well-mannered, comfortable, or tidy profession. I put it on the screen before we talk about case law or methodology, and I mean it as an ethical act. Honest disclosure, made early, before someone has already invested years and emotional capital into a path they were never fully told the truth about, is itself a form of professional responsibility.</p>
<p><em>This is something the field does not do consistently, or well.</em></p>
<p>Recruitment narratives for digital forensics tend to lean heavily on the compelling parts. You will catch bad actors. You will reconstruct events that nobody else can reconstruct. You will be the person in the room who actually knows what happened. All of that is true. What tends to get quietly omitted is what else comes with the territory.</p>
<p><strong>In law enforcement digital forensics,</strong> roughly 80 percent of a typical caseload involves child sexual abuse material. Not occasionally. Routinely. And if you think moving into a corporate or private sector environment means you avoid it entirely, the more honest answer is that you reduce the frequency, <em>not the likelihood</em>. Digital contraband has a way of finding you regardless of the lane you choose. This is not a detail buried in a footnote. It is a foundational reality of the profession, and it should be disclosed plainly, before someone signs an offer letter, not discovered six months into their first lab assignment.</p>
<p>In one interview I had years ago with a prospective employer for a contracted law-enforcement forensics position, I had to tease out that not only was the actual position contingent upon a contract award, while "on the bench" waiting for that award, I would be handling CSAM defense cases. The hiring manager was attempting to hide that fact until I joined the team—which I did not do.</p>
<p>That kind of disclosure is an <em>ethical responsibility.</em></p>
<p>There is also the question of what sustained exposure to disturbing content does to a person over time, and whether the profession has been honest with itself about that. Based on more than twenty years of observation, roughly half of the people who enter this field leave it within two years of starting. Half. That number should prompt serious reflection, not as a recruitment filter, but as an ethical indictment of how the field supports, prepares, and sustains the people doing the work. The graveyard humor that develops as a coping mechanism, the emotional numbness that accumulates over years of examining what human beings do to each other at their worst, the institutional tendency to call that "toughening up" rather than secondary traumatic stress: these are not personality quirks. They are warning signs. A field that demands rigorous ethical behavior from its practitioners has an obligation to extend some of that same ethical rigor toward their wellbeing.</p>
<p>Honesty about the career path itself is equally important. Digital forensics is, and probably always will be, an apprenticeship discipline. Formal degree programs have made the field more accessible, but a master's degree does not substitute for the kind of judgment that develops over years of casework under experienced supervision. Entry-level salaries are modest. Federal lab positions can require clearance timelines that stretch well beyond a year. A vendor certification picked up over a weekend can, somewhat alarmingly, open doors at certain employers. The field is inconsistent in how it defines competence, which creates real ethical risk: examiners who are credentialed but not yet genuinely capable, working cases that will end up in court, in congressional testimony, or in someone's personnel file.</p>
<p>Here is where the technical and the ethical intersect in a way that matters to every practitioner, regardless of specialty. When a digital forensics examiner examines a device, the computer or phone or server under examination can play multiple roles simultaneously. It may be the victim of an intrusion. It may have been used as an instrument to carry out an attack or facilitate a crime. It may hold records of what happened, making it a witness to events it had no control over. Depending on the case, it can be all three at once. The examiner's job is to determine which roles apply and document the findings accordingly. That sounds straightforward until you realize how much interpretation, judgment, and professional candor are required to do it correctly, and how much can go wrong when any of those things are compromised by pressure, inexperience, or motivated reasoning.</p>
<p>There is also an underrated ethical dimension to the documentation side of the work. An examination that is technically impeccable does not serve anyone if the resulting report is incomprehensible to the people who need to act on it. The attorney, the executive, the judge, the jury member who has never used a command line: these are the people whose decisions get shaped by the examiner's ability to translate technical findings into plain, honest language. Writing well is not a soft skill in this field. It is an ethical obligation. If your report obscures more than it reveals, that is a failure of professional responsibility, not just communication style.</p>
<p>Digital forensics does important work. It puts people in prison who belong there and keeps people out of prison who do not. It recovers stolen intellectual property, stops data breaches in progress, and surfaces the truth in disputes where the truth has been deliberately hidden. The "ah-ha" moments are genuinely the best part of the job, and the satisfaction of making a case land correctly is hard to replicate in most other careers.</p>
<p>The field deserves an honest account of itself. Not a sanitized one, and not a discouraging one. An honest one. That kind of honesty is how we attract the right people, prepare them properly, and actually keep them.</p>
<p><strong>For those of you who are in this field or have been: what do you wish someone had told you before you started? And for those who are hiring: how honest are you being in your job postings?</strong></p>
<hr>
<p>This post is the second in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
  <item>
    <title>Digital Forensics Ethics: Why Trust Is the Real Evidence</title>
    <link>https://johnirvine.me/blog/trust-is-the-real-evidence/</link>
    <guid isPermaLink="true">https://johnirvine.me/blog/trust-is-the-real-evidence/</guid>
    <pubDate>Sat, 02 May 2026 12:00:00 +0000</pubDate>
    <description>Digital forensics has a reputation for being technical, precise, and evidence-driven. That reputation is mostly deserved. We image drives. Parse artifacts. Validate timestamps. Recover deleted files. Correlate logs.…</description>
    <content:encoded><![CDATA[<p>Digital forensics has a reputation for being technical, precise, and evidence-driven. That reputation is mostly deserved. We image drives. Parse artifacts. Validate timestamps. Recover deleted files. Correlate logs. Explain what happened, when it happened, and sometimes who was sitting behind the keyboard when it happened.</p>
<p>Yet the longer I have worked in this field, the more convinced I have become that the hardest questions in digital forensics are not always technical. They are ethical.</p>
<p>The opening quote I use in my Digital Forensics Ethics and Law class is attributed to Friedrich Nietzsche: <strong>“I am not upset that you lied to me. I am upset that from now on, I cannot believe you.”</strong></p>
<p>In the realm of digital forensics, trust is paramount, as it forms the foundation of the entire process.</p>
<p>A forensic examiner’s work may end up in a criminal case, a civil dispute, an intelligence matter, an internal investigation, a boardroom, or a congressional hearing. The audience may include attorneys, executives, judges, juries, regulators, victims, suspects, journalists, or the public. In every one of those settings, the examiner’s credibility matters just as much as the tool output.</p>
<p><em>Maybe more.</em></p>
<p>A tool can produce a result. A human being has to decide whether that result is reliable, whether it is complete, whether it is being overstated, whether important context is missing, and whether the truth is being bent to serve a desired outcome.</p>
<p>This is why I discuss with students early in the course that digital forensics is not simply a “push button, receive truth” profession. Different practitioners bring different perspectives. Some work closer to laboratory-style examination. Some perform deeper analysis and interpretation. Some support eDiscovery. Some work in media exploitation, incident response, intelligence, or corporate investigations. Those roles can lead to very different instincts about procedure, privacy, scope, judgment, and risk.</p>
<p>That does not mean “anything goes”; it means we need to be honest about the fact that <em>perspective shapes decision-making</em>.</p>
<p>The field often lives in uncomfortable gray areas:</p>
<ul><li>How much data should we collect?</li><li>When does investigation become overreach?</li><li>What do we do when the evidence says something inconvenient?</li><li>How do we communicate uncertainty without sounding weak?</li><li>What happens when a boss, client, investigator, or agency wants a cleaner answer than the evidence can support?</li><li><em>When should we say, “I don’t know?”</em></li></ul>
<p><strong>That last one may be the most important sentence in the profession.</strong></p>
<p>“I don’t know” can be uncomfortable. It can feel risky. It can disappoint people who expected certainty. It may even slow down a case.</p>
<p>It's still better than fishing for an answer that might be unsupported or completely incorrect.</p>
<p>Mistakes in this field are not always private mistakes. Bad forensic judgment can damage investigations, careers, companies, court cases, public trust, national security, and real people’s lives.</p>
<p>Ethics keeps us from becoming advocates when we are supposed to be examiners.</p>
<p>Ethics reminds us that evidence has context.</p>
<p>Ethics forces us to document what we did, not what we wish we had done.</p>
<p>Ethics makes us disclose limitations instead of hiding them in footnotes no one will read.</p>
<p>Ethics protects the people who rely on our findings, including people we may never meet.</p>
<p>The Roman emperor Marcus Aurelius put it more cleanly than most modern compliance training ever will: <strong>“If it is not right, do not do it. If it is not true, do not say it.”</strong> That’s a pretty good operating model for digital forensics.</p>
<p>Digital forensics is about finding facts. Ethics is about making sure we deserve to be believed when we present them.</p>
<p>If you work in or around digital forensics, incident response, or cybersecurity, I’d be curious:</p>
<p><em>What’s an ethical gray area you’ve run into that doesn’t get talked about enough?</em></p>
<hr>
<p>This post is the first in a series based on my course, <em>DFOR 671: Topics of Ethics and Law in Computer Forensics</em>, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I’ll be looking at the ethical and legal issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.</p>]]></content:encoded>
  </item>
</channel>
</rss>
