Family law: shared devices, shared accounts, and the attribution problem they create
A marital household runs on equipment nobody separated in advance. One laptop, one login, a tablet the children use, a cloud account with both spouses signed in. That arrangement removes the single assumption most forensic attribution rests on, and it does so before any question about the evidence is reached — the authorisation question having usually arrived first.
- QUESTION
- Who used the device, and was access lawful
- CORE ARTIFACTS
- Per-user profiles · browser · sync
- CLOCK
- Devices are wiped, sold and reset fast
- USUAL POSTURE
- State court · often expedited
- DELIVERABLE
- Report or affidavit, then testimony
- ROLES
- Testifying · Consulting · Neutral
In a family law matter the forensic record normally establishes what a device or account was used for and when, and how that activity is distributed across user profiles. Where the spouses used separate accounts, most of it attributes cleanly. Where they shared one login, the machine holds no basis for distinguishing them and neither does an examiner — and no examination can establish that a device is free of monitoring software.
What is actually in dispute
The evidence questions in a matrimonial case are ordinary; the ownership of the evidence is not, because the parties held the devices and the accounts jointly right up to the moment they became adverse.
Four subjects recur. Assets, where the question is what a party has and has not disclosed. Conduct, where messages, browsing or photographs bear on the issues the forum treats as relevant. Monitoring, where one party alleges the other installed software or kept access to accounts after separation. And the evidence itself, where a party has already gone through a shared machine and produced what they found.
Underneath all four sits a problem this matter type has and the others largely do not. In a corporate case the account belongs to an employer, the permissions were configured by somebody, and there is a written policy to read against. Here the device is chattel that both parties owned, the password was on a note by the monitor, and the legal basis on which one spouse now reaches the other’s data is genuinely contested. Counsel resolves that before an examiner is instructed. An examiner who takes an instruction that skips it produces work product that may not be usable and may be worse than useless.
What a shared login does to attribution
Windows and macOS record most of the useful activity per user profile: shell history, document lists, browser data, application launch counts, and the folders each account browsed. Two profiles means two separable records, and in that configuration attribution is no harder than in a corporate matter. One profile used by two people means the operating system was never distinguishing them, so the examination produces a record of the household rather than of a person. That is not a limitation that better tooling overcomes; it is a fact about what was written at the time.
The same applies to shared cloud accounts, a shared password manager, a family plan with one Apple or Google identity across several devices, and a browser signed in on both spouses’ machines with history syncing between them. In each case the record names a credential that two people were entitled to use.
Which artifacts bear on it
The examination is a standard host examination. What changes is how each finding has to be qualified once the device turns out to have been shared.
Per-user activity
Logon events establish which local account was active in a session and whether it was at the console. RecentDocs, jump lists and shellbags record the documents and folders an account opened; UserAssist counts programs launched through the shell; and browser history, downloads and saved form data are frequently the most probative material on the machine, because they name institutions, services and search terms. On Apple hardware KnowledgeC records device and application usage over time in a form that supports a usage pattern rather than a single event.
Deletion, storage and what left
The Recycle Bin retains the original path and deletion time of items sent to it per user, and volume shadow copies often hold a version of a document or a database from before it was altered. Removable device history and sync client records show where material was moved, which matters when a party has been preparing for a proceeding for some time.
Signs of monitoring
Where the allegation is surveillance, the examination looks at installed applications and their execution records via Prefetch and Amcache, at configuration profiles and the permissions granted to them, at accessibility and screen-recording entitlements on macOS, and at the account’s own list of active sessions and trusted devices. A positive finding here is often decisive. A negative one carries very little, and should be written that way.
What this evidence cannot establish
- Which spouse did it, on a shared account. The system recorded a credential both parties were entitled to use. Where one login served the household, activity cannot be separated by profile, and attribution has to come from outside the machine or not at all.
- That a device is free of monitoring software. Commercial products are built to avoid notice, some run from the account rather than the device, and an examination reports what was searched for and what was found. “Nothing detected” is a description of the search, not a clean bill of health.
- What a party owns, or what it is worth. Local traces point at institutions and accounts. They do not establish balances, ownership, current existence, or that the trace is not a closed account from years ago. Valuation is someone else’s discipline.
- That a document or message is genuine, from a screenshot. A screenshot carries the metadata of the screenshot. It shows neither the surrounding conversation nor whether anything was deleted or edited before the picture was taken.
- Fault, credibility, or anything about parenting. Browsing history, message content and application use are facts on a device. What they say about a person, a marriage or a child’s interests is argument, and an expert who supplies it will be cross-examined on it rather than on the forensics.
Most of the message traffic in these matters lives on phones rather than computers, and phone extraction is a separate acquisition discipline covered at mobileforensicexpertwitness.com. The tool at can this artifact prove that? maps a proposition onto the records that bear on it and shows where the inference runs out.
The expert’s role and the deliverable
- Settle the basis for access first. Whose device, whose account, on what authority, and under which order — recorded in writing before anything is imaged. This step is counsel’s to resolve, and it is the one that determines whether the resulting examination is usable.
- Preserve before the household separates further. Devices in a divorce get factory reset, sold, given to children and replaced, and accounts get password-changed out from under the other party. The preservation deadline calculator sets out how quickly the common sources age out.
- Acquire under write-block, with a custody record. A forensic image taken through a write blocker, hashed at acquisition and again at verification, with a chain of custodyform that becomes an exhibit. Where a device must be examined at a neutral’s office rather than removed, that arrangement is recorded too.
- Map the profiles before reading the activity. Which accounts existed on the machine, when each was created and last used, whether any had a password, and whether the browser was signed in and syncing. That map decides how every subsequent finding has to be qualified, so it belongs at the front of the report rather than in a caveat at the end.
- Examine to the scope, and record what was excluded. Family matters draw narrow, negotiated scopes — a date range, a custodian, named categories — and often a court-appointed neutral rather than a party expert. What was searched, what was found and what was deliberately not examined all go in the report.
- Report, affidavit and testimony. State practice varies on the form; the discipline does not. Each assertion traces to a named artifact, the qualifications on shared-device attribution are stated as findings rather than buried, and another examiner working from the same image can reproduce the result.
The underlying examination is described on the computer forensics page, and the neutral and testifying roles on the expert witness testimony page.
Where the admissibility pressure falls here
Family matters are state-court matters, and the reliability standard depends on the forum: some states apply the federal framework as amended in December 2023, others the older general-acceptance test, and several apply a local hybrid. The Daubert or Frye lookup shows which standard a given jurisdiction applies. Whichever it is, the attacks in this matter type are consistent.
- Attribution asserted on a shared machine. The most common defect, and the easiest to avoid. If the report does not state the profile structure and what it permits, the cross-examination will establish it instead.
- How the evidence was obtained. Where access to an account or device is disputed, the argument often reaches the examination before it reaches the findings. Documenting authority at the point of collection is what keeps that argument about admissibility rather than about the examiner.
- Self-collected material presented as forensic. Files a party copied themselves have lost their original file system metadata and carry no custody record. They can still be examined and are frequently all there is, but the difference has to be disclosed rather than smoothed over.
- A clean scan offered as proof of no monitoring. Reporting that no monitoring software was identified is accurate. Reporting that the device was not monitored is not, and the distance between those two sentences is the whole opinion.
- Scope creep.A narrow instruction that becomes a general trawl through a household’s data produces both an admissibility problem and a relevance objection, and in a matter with children and third parties on the same device it produces a privacy problem as well.
| RECORD | WHAT IT ESTABLISHES | WHAT IT DOES NOT ESTABLISH |
|---|---|---|
| User profile structure | Which accounts existed on the device, when each was created and last used, and whether any was password protected | Whether the person named on a profile was the only person using it |
| Browser history, downloads and saved form data | Which sites and services an account reached, what it retrieved, and what was typed into search | Who typed it, on a shared profile — and a synced browser mixes activity from every signed-in device |
| RecentDocs, jump lists and shellbags | That a named document or folder was opened by a given profile | Whether it was read, changed or copied; absence does not show a file was never opened |
| Recycle Bin | The original path and deletion time of items sent to it, per user | What happened to files deleted by other means, or emptied before imaging |
| Volume shadow copies | An earlier state of a document, database or registry hive from before it was altered | That any particular version was the one relied on, or that copies exist for the dates you need |
| Installed applications and execution records | That monitoring or anti-forensic software was present, and where enabled, that it ran | That no such software is present. Absence of detection is not absence of monitoring |
| Cloud account session and device lists | Which devices held live sessions on an account and when they last connected | Who was operating them, on an account both parties were entitled to use |
Questions counsel ask
The computer is in both names and we both used it. Can you still tell who did what?
My client has the password to the other spouse's email. Can we just look?
Can you tell whether my client's phone or laptop is being monitored?
We have screenshots of the messages. Is that enough?
Can forensics find hidden accounts and assets?
Is this the same standard as a federal case?
Related reading
- Computer forensics
Write-blocked acquisition, the artifacts an operating system keeps, and the three distinctions that keep an opinion inside what the evidence supports.
- Daubert or Frye?
Which reliability standard a given state applies to expert evidence, and what that changes about how an opinion is presented.
- Browser history and downloads
What the record actually contains, how syncing mixes devices together, and how a finding drawn from it is attacked.
- How to hire and vet a forensic expert
Party expert versus court-appointed neutral, what to demand before retention, conflicts, timing, and cost.
Devices in a separating household are reset, sold and handed on within weeks, and account passwords change without notice. Send the matter, the county and court, the separation date, and whose devices and accounts are in issue — a conflicts check and a scoping call follow.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.