What does a linked-device record prove?¶
A messaging account may show that a named computer, tablet or browser was linked.
Evidential caution: that the record proves who used that device and what they did.
What this means¶
A linked-device record can show that the account authorised or maintained a connection with another device or session.
It may include a device label, platform, approximate linking date, last-active time or security status.
That can establish an additional access route to the account.
Be alert to time interpretation. “Last active” may refer to account contact with the service rather than a specific message.
In reports, distinguish evidence of an authorised session from evidence of personal use.
Where the position is unclear, compare device records, provider metadata and the account’s security history.
What to check or do next¶
- Preserve the record exactly as displayed, including dates, names, icons and status.
- Compare it with browser records, application installations, device identifiers, account alerts, IP activity and physical possession.
- Preserve the original source and collection method so another investigator can test the same conclusion.
Evidential limits¶
But the label may be user-defined or generic. It may not uniquely identify the physical device.
The record also does not prove who created the link or who later used the session. The device may be shared, stolen, remotely accessed or compromised.
Do not assume that absence from the current list proves the device was never linked. Sessions may have been removed or expired.
Operational takeaway
Use a linked-device record to establish an additional account access route, but identify the physical device, activity and user through separate corroboration.