Skip to content
Skip to main content
Mobile Devices & Apps Technical Explainer

Does a saved account prove who used the device?

No. It shows that the handset was configured to access the account, not who controlled a particular session or caused an event.

Accounts can persist and travel

An account may belong to the usual user, be shared, remain from a previous user or return through backup restoration. Session tokens can keep it authenticated without a new password. The same account can operate across several devices and synchronise content created elsewhere.

Preserve account ID, first-link or login history, trusted devices, sessions, network addresses and device or app installation identifiers. Ask whether the relevant action was local, remote or synchronised.

Connect session to person and time

Use possession, location, notifications, application databases, message context, payments and witnesses to identify who controlled the relevant device and account session. Consider compromise or remote access only where evidence supports the mechanism.

A saved account is a useful link between handset and service, but provider records and local artefacts must be compared before attributing authorship.

Key takeaway

Treat a saved account as evidence of configured access, then establish which device and session caused the event and who controlled them at the relevant time.

Reference: MDA-033Mobile Devices & Apps