What should be recorded if a passcode is supplied?¶
Record who supplied it, how it was obtained, what it was said to unlock, every attempt made and what happened afterwards.
The characters alone are not enough. The evidential value sits in the provenance and effect.
Preserve the context around the code¶
Record:
- supplier;
- requester;
- exact wording used;
- date, time and location;
- whether it was spoken, written or entered by the person;
- whether the device was already unlocked;
- consent, authority or other applicable basis; and
- anything said about what the code was for.
A code may unlock:
- the whole device;
- a SIM;
- a work profile;
- one application; or
- another protected area.
Do not assume one code applies to everything.
Record every attempt separately¶
A useful record might look like:
If several possible codes are supplied, distinguish them clearly before any attempt.
Could repeated unlock attempts cause data loss? explains why guessing through multiple values is risky.
Handle the code securely¶
Do not place passcodes casually in widely shared messages or notes.
Restrict the record to those who need it and preserve the fact of pressured, compelled or disputed disclosure accurately.
The practical point is: record the passcode as an evidential event, not just a string of digits. Provenance, scope and effect matter as much as the code itself.