Skip to content
AI-018 Accounts & Identity

Accounts & IdentityAI-018

Does a password prove ownership?

No. Finding a password on a device may show knowledge of, or potential access to, an account. It does not by itself prove that the account belongs to the device owner or that they used it.

Establish what was actually found

The evidential meaning depends on where and how the credential appeared. A password might be:

  • stored in a browser;
  • held in a password manager;
  • written in a note;
  • sent in a message;
  • copied to the clipboard;
  • recovered from an application database; or
  • collected by malware.

It may be current, historic, incomplete or incorrectly labelled. A stored value should not automatically be treated as a verified working password.

Why possession of a password is not ownership

Passwords are often shared, saved, copied, stolen and reused. A person may know the password to a partner’s account. An employee may be authorised to access an organisational account. Credentials may have been imported from another device or synchronised through a password manager.

The concept of “ownership” can also be misleading. An account may be registered in one person’s name, controlled by another and used by several people.

Look for evidence of use and control

The presence of the password becomes more significant when supported by evidence showing that the device or person actually accessed the account. Check for:

  • provider login records;
  • session cookies or access tokens;
  • application data linked to the account;
  • browser history;
  • downloaded or synchronised content;
  • notifications;
  • messages referring to the account;
  • password changes or recovery activity; and
  • account activity matching the device’s location or use.

The same unusual password appearing across several accounts may also support a connection between them, but it still requires careful interpretation.

Describe the conclusion precisely

These statements are not interchangeable:

  • the device contained credentials associated with the account;
  • the person knew or could access the password;
  • the account was accessed from the device; and
  • the person controlled or used the account.

Each requires a different level of supporting evidence. Avoid using the weakest finding to justify the strongest conclusion.

Key takeaway

A password is evidence of a credential and possible access. Establish where it came from, whether it worked and whether the account was actually used before drawing conclusions about control or attribution.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.