What does a successful login actually prove?¶
A successful login normally proves that the service granted access after accepting the credentials, device, session or authentication process presented to it. It does not automatically prove which person was behind the device.
The technical event¶
The provider’s description may cover several different situations. Access may follow:
- a password entered by a person;
- a saved password supplied by a browser or application;
- approval of a multi-factor prompt;
- recognition of a trusted device;
- reuse of an existing session cookie;
- automatic refresh of an access token; or
- recovery of the account through another process.
The word “login” can therefore conceal important differences. In some cases, no password is entered during the event recorded by the service.
What the record may support¶
A login record can be valuable when it includes details such as:
- date and time;
- account identifier;
- IP address;
- browser or application;
- device information;
- authentication method;
- session identifier;
- multi-factor activity; and
- nearby password-reset or recovery events.
These details may place account access on a particular connection or device and may help build a chronology of subsequent activity.
Moving from access to attribution¶
To assess who obtained the access, compare the login with the wider evidence. Consider:
- who possessed or controlled the device;
- who controlled the relevant telephone number, authenticator application or security key;
- whether other personal accounts were used on the same device;
- whether location evidence is consistent with the login;
- whether account activity immediately afterwards reflects knowledge, purpose or communications associated with a person; and
- whether compromise, sharing, automation or remote access remains a realistic alternative explanation.
A login may strongly support attribution when several independent strands point in the same direction. The login record alone, however, ordinarily identifies a technical access event rather than a named human user.
Use accurate language¶
It may be correct to say:
The account was successfully accessed from the recorded connection or device at the stated time.
That is different from saying:
The named person logged in.
The second statement requires evidence linking the technical event to that person.
Key takeaway
A successful login proves that access was granted. Personal attribution requires evidence showing who controlled the credentials, device, session or authentication factor at the time.