Is an internet messaging service device-based, account-based or both?¶
Most internet messaging services use both an online account and one or more devices. The account provides continuity within the service; each device or session can hold different credentials, content and activity records.
Account and endpoint have different functions¶
An account may be registered to a telephone number, email address or platform identifier. Provider records can associate that account with registration events, settings, contacts, groups or sessions.
The endpoint supplies the application, local database and, in some services, encryption keys. A phone, tablet, desktop client or browser may therefore hold evidence not visible in the online account record. Conversely, the account may reveal active sessions or service events absent from one seized handset.
Architecture varies. Some services depend closely on a primary phone; others allow several linked devices to operate more independently. Synchronisation may copy all, some or none of the earlier message history to a newly linked endpoint.
Attribute the right layer¶
Record the account identifiers, registered details, devices, session identifiers and link history separately. Establish which endpoint was active at the relevant time and who could control it.
An account association does not prove a particular device performed an action. A device artefact does not, by itself, prove the registered account holder was its user. Reporting should state whether the evidence establishes an account, an endpoint, a session or a person.
The point to remember
Treat a messaging service as an account joined to distinct endpoints, then attribute activity at the most specific layer the records support.