Could logging in from another device alter the evidence?¶
Yes. Logging into an account from another device can create new records and change the account state.
Why this matters¶
The dangerous assumption is that a second-device login is a neutral way to preserve or inspect the account. It may create sign-in alerts, new sessions, device records, IP logs and security checks.
What to record and do¶
The login may terminate or challenge existing sessions, trigger multi-factor authentication or alert another user.
It may also synchronise data, change recent-activity lists or expose the investigation.
Before logging in elsewhere, preserve the original session and account state.
Record the account identifier, current device, visible page, active session and any security warnings.
Consider whether provider preservation, native export or specialist assistance can achieve the objective with less evidential disturbance.
If a second-device login is necessary, use an approved and controlled device and record the time, network, credentials, authentication steps and resulting changes.
Do not use a personal device or ordinary browser session without considering contamination, account linking and security risks.
Capture any alert, new-device notification or terminated session.
A new login can also change the apparent location, trusted-device list, recovery options or risk score applied by the provider. In some services it may cause account content to download onto the new device, creating a second evidential copy that must be controlled and documented.
If multi-factor approval is requested on another device, do not prompt or approve it without recording who controls that device and why the action is necessary.
Operational takeaway¶
Treat a new-device login as a significant account event, and use it only where justified after preserving the original session and documenting every resulting change.