Digital evidence must be authenticated before being relied upon: CCC Prez Dr Herald D Costa
Hyderabad, Oct 4(TNT) : Digital evidence in cyber sexual offence cases must be properly identified, authenticated and preserved before being relied upon in investigations or courts, President of Cyber Security Corporation Dr Herald D Costa said while addressing the technical session on the last day of the tw0-day NALSA South Zone Regional Conference here on Sunday.
Speaking on digital evidence in cyber sexual offences, Dr Costa cautioned investigators against assuming that electronic records were tamper-proof and said even end-to-end encrypted platforms such as WhatsApp could be manipulated.
During a live demonstration, he showed how an image shared through WhatsApp could differ between the sender and recipient devices. In another demonstration, an SMS regarding free legal assistance was shown to have the word “free” altered to “paid” upon delivery, highlighting the need to verify the authenticity of digital communications.
He said investigating agencies must establish whether digital records were genuine, fabricated, manufactured or spoofed before treating them as evidence.
Referring to CCTV footage, Dr Costa said investigators should first ascertain whether the original recording stored in a DVR had been tampered with before cloning or extracting it.
He stressed that establishing the source, authenticity, relevance and reliability of electronic evidence was the first and most critical stage of forensic identification.
Dr Costa also emphasised strict maintenance of the chain of custody, including details of the device seized, data cloning process, generation of hash values and the identity of officers handling the evidence.
He called for immediate preservation of volatile digital content from social media platforms, particularly one-time-view videos and other material that could be deleted from servers.
Cautioning against reliance on screenshots, he said screenshots were not primary documents and could be easily manipulated or spoofed.
He said statutory certificates relating to electronic records addressed admissibility requirements but did not by themselves guarantee judicial acceptance or establish proof beyond reasonable doubt.
Dr Costa also cautioned that mobile phones could be rooted and their internal databases, application data and files altered before a certificate was generated.
In POCSO cases, where fabricated chats could be created, printouts should not be relied upon in isolation and original physical devices should be sent to forensic science laboratories for comprehensive examination and source authentication, he added.
TNT TS .
