Jessica Hyde — Direct
394 linesJESSICA HYDE, sworn
JUDGE CANNONE: Good morning.
JUDGE CANNONE: All right. Mr. Brennan, whenever you're ready.
MR. BRENNAN: Thank you.
DIRECT EXAMINATION BY MR. BRENNAN:
MR. BRENNAN: Good afternoon.
MR. BRENNAN: Could you please introduce yourself to the jury and spell your last name for the record?
MR. BRENNAN: What do you do for a living?
MS. HYDE: I'm a digital forensics examiner. I'm also an associate -- I'm also an adjunct professor at George Mason University where I teach mobile device forensics in the graduate program. I also own a digital forensics company that does training, services, and research.
MR. BRENNAN: In addition to teaching at Georgetown University, do you teach in other ways?
MS. HYDE: Correction. I teach at George Mason University, not Georgetown. But thank you. I also teach -- my company writes and develops training courses. I teach a mobile forensic analysis course and a data structures course to their law enforcement, civilians, et cetera.
MR. BRENNAN: Do you engage in any other type of academics or research?
MS. HYDE: I do. I do other research as part of some the volunteer activities I do in the digital forensics field. So I'm the chair of DFIR review, which is a body that reviews practitioner created research so that it can go through peer-review. I often do reviews as a member of a reviewing for Forensic Science International Digital Investigations Journal, which I was a previous associate editor of.
COURT REPORTER: Can you please slow down?
MR. BRENNAN: What does peer review mean?
MS. HYDE: Peer review means that when a study is done or a research paper is down on a topic, that an assessment is done of it. There are three types of assessments that can be done. One is a methodological assessment where you read through the methodology of the academic or practitioner created paper and state if it is acceptable or not. The second is you conduct your own testing using the same methodology to conduct a peer review with your own generated datasets. And the third is if the original author has shared their datasets, reviewing their datasets and checking that against their work.
MR. BRENNAN: Has of your work been peer-reviewed in the past?
MS. HYDE: I've had two peer-reviewed journals. I've had an article that was peer-reviewed and published in "Forensic Science International Digital Investigations" regarding the standardization of file classification of recovered items. The layman's term of that would be talking about what deleted means. And then I have another paper that's been accepted that I was co-author on in terms of timelines and correlations of forensic evidence.
MR. BRENNAN: You mentioned you work in forensic data analysis. Generally, what does that mean?
MS. HYDE: It means that I look at evidence of digital forensics devices be them mobile phones computers, Internet of things, devices and do analysis to provide meaning and context to the data that's recovered from them, as well as performing data recovery of those same computer related devices.
MR. BRENNAN: Do you have any specific education or training to learn about forensic data?
MS. HYDE: Absolutely. I have professional training both from courses I've taken as well as I have a master's in digital forensics from George Mason University, a master's degree in that. I've taken multiple courses, advanced mobile analysis, IOS forensic courses from Sans, computer forensic courses from Sans. I have multiple certifications. I hold the GIACGCFE which is the GIAC certified forensics examiner. I also hold the NWC33CFE which is a certified forensics examiner.
MR. BRENNAN: Do you, through your company, teach other forensic examiners how to study forensic data?
MS. HYDE: Correct. I teach government agencies, both federal and state and local, how to do digital forensic analysis as well as private sector digital forensic examiners.
MR. BRENNAN: How do you teach private digital forensic examiners? What's the method?
MS. HYDE: I've developed an online virtual course that we teach virtual live, so I'm always there when I'm teaching, but I also have a team of instructors. So for example, the mobile forensic analysis course that I developed right now this week is being taught to a police department in Texas right at this moment.
MR. BRENNAN: Forensic data analysis seems like broad field. Are there certain parts that you focus in?
MR. BRENNAN: I want you to just give us a very basic, very general and brief background. When you're looking at a forensic device and you're analyzing it, do you rely on any tools?
MS. HYDE: That is a very interesting question. Reliance on tools is not precisely what we do. We utilize tools to extract data from a device, and then we utilize a variety of tools to attempt to parse results from the device. But the forensic examiner has to take the additional step to both understand, validate, and provide meaning to those results.
MR. BRENNAN: Is there any shortcomings or dangers in simply relying on a forensic tool for a result or an opinion?
MS. HYDE: There is absolutely a danger in just relying on just parsed results. When an algorithm is used to determine what data is stored as, it doesn't tell you what that data means and that's when you need a forensics examiner. Tools don't necessarily understand how the data got there and what causes the data to exist, and that takes deeper and further human analysis as well as, you know, if you think about it, if on your phone you can go to the Google play store or the app store and you can actually download millions of apps. There's like six million apps between the two stores. Digital forensic tools maybe support generally a thousand applications. So in order to be able to parse and understand the data from applications that the tools don't know how to support, you need a forensics examiner who knows how to dig into that data, conduct testing and determine the meaning of the data.
MR. BRENNAN: Were you asked by the Norfolk District Attorney's Office to analyze a phone that was related to a person by the name of Jennifer McCabe?
MR. BRENNAN: Were you asked during that scope and date range to analyze it and provide an opinion about whether there were any user initiated deletions of any web searches or Safari type searches? A Yes, I was asked to look for deletions of Safari searches within the scope of the time frame that was dictated by the purpose for the exam.
MR. BRENNAN: Were you asked to look at the phone device and determine whether or not there were any user initiated deletions of phone calls on the device?
MR. BRENNAN: And did you do both of those tasks?
MR. BRENNAN: Did you ultimately have opinions on both of those issues?
MR. BRENNAN: And engaging in the efforts to answer those two questions, did you necessarily have to review and analyze a web history that included searches on January 29, 2022 at 2:27 a.m.?
MS. HYDE: I did analyze web searches that occurred at 2:29 a.m. in local time here in Norfolk on January 29, 2022, from the device I was provided, yes. Not the device -- a forensic image for clarity.
MR. BRENNAN: So before we get to the two opinions that you were asked to consider or what your opinions were after analyzing the data, I want to begin by giving the background and having you share with us your analysis and your observations and opinions about the search on Safari relative to this 2:27 time frame. Before we begin that, let me just ask you one question. Did you do anything to ensure the integrity of the data that you were looking at?
MS. HYDE: Upon receiving the forensic image, the first thing I did was I did what's called a hash of the image. So a hash is an algorithmic representation of a file. So a forensic image, all the date from the phone, it comes in one file that can then be extracted and have the rest of the data. That singular file that's received, there's actually three, but focusing on the one that has all of the data, that archived file, you can run what's called a hash algorithm against it. There's actually multiple hash algorithms. And I hashed it and then I validated that hash to the document that was provided along with the image file the contained hashes that were contained in. Those hash values matched. Now, just for clarity if you change one bit in a file, it will not have the same hash. So the hash provides integrity and having used both hashes, which are available in that report and ran two different algorithms, they both matched.
Additionally, I reviewed the PDF that was received for signs of alteration. The PDF that comes with a Grey Key report is not signed by Adobe Acrobat; however, I was able take that PDF and then examine it just like I would a phone. So I'm using the same techniques on the phone. Using the tool called Exif tool, I was able to learn about the creation of that particular PDF, and what I was able to learn about it was that it was created by -- it's labeled it as being produced by Grayshift using a particular code based application to create the PDF called PYF PDF standing for Python framework PDF. It is on -- it's a program that you can download and developers who create tools, like Magnet Forensics who owns Gray Key, utilizes that script, which is why it says it's produced by it, to create the actual PDF. That's what the evidence there in the data tells me.
It also contains a time of when that is created, and that time was February 2, 2022 at global UTC, that's the global concept time - think what's in the UK - at 2249, which local time would be 5:49 p.m. So that says that it was created approximately two hours and forty-five minutes after the document said the image started and it correlated with the document information. So that provided some level of certainty that that document was factual. And on top of that, I further opened the file of that PDF in what's called a hex editor which lets me see, like, every bite, everyone and zero, and from doing that, I looked for tag markers that are made sometimes in some modifications of PDFs called XMPs, which is Adobe's format of mark up, and I did not find any evidence of those tags.
MR. BRENNAN: When you're trying to determine whether there's integrity in the data, are you able to tell whether or not there has been any alterations or tampering before the item is put on the Grey Key machine to make the extraction?
MS. HYDE: That would be -- when you're talking about if the physical device had been manipulated; is that correct?
MR. BRENNAN: Yes.
MS. HYDE: I cannot tell if the physical device has been manipulated prior to it being imaged. I can only validate if the image was correct. In theory, all of the data of any -- anything that you did on that device would still show in the evidence of device logs and whatever locations that were touched or communicated with, but at that point, it's the same as any user interacting with the device itself.
MR. BRENNAN: After the phone's extracted or at the time it's extracted, does it have the history of the device on that extraction?
MR. BRENNAN: Yes. At the time the phone is extracted and a copy is made and a PDF and a digital copy, does the digital copy and the PDF contain the history of searches and calls and other items on that phone?
MS. HYDE: The forensic image itself contains a variety of different artifacts or traces that are left behind by activities that a user does on a phone, yes.
MR. BRENNAN: You use the term artifact. What does that mean in a basic sense?
MS. HYDE: An artifact is any type of evidence that is left behind on your phone of an action. So, for example, if you receive a call, there are multiple places in the phone that show that a call was received. That can be in the call log, that could be in a notification, that could be in a unified log that tracks the activity that the phone is doing. There's multiple locations. And each one of those residue of the fact that the call came in, that's what I would refer to as an artifact. So you could have an artifact not just about a call, about a web search, about taking a photo, any action you take on your phone may create an artifact.
MR. BRENNAN: Before we get into those two questions about any alleged deletions from Safari or Google search or Internet search and any alleged deletions of phone calls, I want to start with your explanation or your sharing how the time stamp works relative to search beginning at 2:27 a.m. on January 29, 2022.
MS. HYDE: So for clarity, there's more than one search that happens actually at 2:27. There is some activity that's looking at -- and I don't want to mispronounce the name of the town. I'll try Hockomock sports. Looking at activities for the sporting events at that school system I assume or county location. There is a time stamp for the search, "hos long to die in cold," however, that time stamp isn't about active searches, it's about the time that a tab was either opened or moved to the background. So "hos long to die in cold," is the most current search in the tab that you open at -- that was opened at 2:27. So if you're using your phone, and you go to your browser, you have some choices. You can just open an existing tab or you can open a new tab. A new tab was opened at 2:27 a.m., and that search was done there. Another tab actually at 2:27 was moved to the background and its last search at the time it was moved to the background was for, I believe "It's Raining Men" the YouTube video. So those two searches both exist as what's called browser state searches. But that browser state isn't about the time that it was searched. It's about the time that the browser tab that you opened either went to the background or if it's never been moved to the background, the current search. So the time in the instance of "It's Raining Men" that video is the time that that video was moved to the background and the new tab took over as the tab that's active, and that tab, the last search done in that tab, is "hos long to die in cold" because that database holds the current search, it constantly gets updated, and the time that the tab was either opened if it's the first time it's opened or moved to the background if it's an existing tab.
MR. BRENNAN: Did you prepare exhibit that would help explain --
MR. BRENNAN: May I approach?
JUDGE CANNONE: Yes.
MR. BRENNAN: Handing you a piece of paper; do you recognize that?
MS. HYDE: I do. This is table one from the first report I created on this case on the phone that I was told was for Jen McCabe.
MR. BRENNAN: Is that the -- will that help you explain?
MR. BRENNAN: I'd move this into evidence.
MR. ALESSI: Can we approach, Your Honor? I'm going to object if you want --
JUDGE CANNONE: You can come on up.
(Sidebar commences:
MR. BRENNAN: It should be just the front page; it shouldn't be the back page.
MR. ALESSI: That's part of the objection.
MR. BRENNAN: I did not see that.
MR. ALESSI: It's okay.
MR. BRENNAN: It's just the front page.
MR. ALESSI: Your Honor, I've already just covered the first. It was more of a mechanical issue. The reason why I'm objecting is because this is assuming the opinion before the opinion is being given, so we would in effect be publishing a document -- it would be admitted with the opinion in it. The foundation has not been laid for the opinion --
JUDGE CANNONE: Okay.
MR. ALESSI: -- as to what is happening with this time stamp, whether it is attributable to a search at a certain time. I have other bases, but that's the key basis.
MR. BRENNAN: If I could use it as a chalk, and then after she gives her opinion, I'll move it as an exhibit.
MR. ALESSI: I'm fine with that as long as she's not giving opinions talking about that document.
MR. BRENNAN: She's going to give opinions.
MR. ALESSI: Then I'm going have to object to that going on any publication.
JUDGE CANNONE: So we will mark it for identification. You can use it with her, but the jury can't see it until she offers her opinion.
MR. BRENNAN: She'll just get right to the opinion then and then I'll introduce it.
MR. ALESSI: And then I'll object. You tell me how you want to do it, Your Honor. I'm going to be objecting. I don't --
JUDGE CANNONE: And what's the basis of the objection?
MR. ALESSI: The basis for the objection is there's no foundation has been laid for the opinion that's -- that are being expressed in here. All that's happening is she's testified what she has done, but she hasn't -- he hasn't -- Mr. Brennan hasn't established a foundation for that to go in. He hasn't established the foundation for her opinion, which I would object to. So just my last point by way of example. If we don't even have this document, and Mr. Brennan was going to ask her questions about the opinions in here, I would be objecting. I know I can't give the reason, but the reason would be because not a proper foundation. So what Mr. Brennan would effectively be doing here is trying to get this into evidence, try to show it which contains the opinions, and that is something that can't be done until he's established the foundation. Bottom-line, her opinion is embedded in this. When she just talks about, even if it's marked, he can't use this document as her opinion without her opinion being established.
JUDGE CANNONE: So what is the opinion that you intend to offer now? Speak into the microphone.
MR. BRENNAN: If I was going to offer an opinion before going through establishing it is that the time stamp of 2:27 is for Hockomock sports, and that the reason why this appears in this graph like this is because that is the last search term. She would then explain how she determined that. She determined that by looking at the different databases in the right-hand column, and from looking at those artifacts and those columns, she can tell, in her opinion, this was an open Safari tab at 2:27. There's a number of searches throughout the morning. And the last search is "hos long to die in cold" it contains the original time stamp because that tab time stamp doesn't change or get marked until it's closed. And so what the defense has asked me to do is to go through this entire thing and then after she gives her opinion, then I put it on and then we go through the entire same thing again in front of the jury, so we do it twice. It doesn't make a lot of sense. It makes more sense to use this as a chalk after she establishes her opinion. If he sustains the objection, then it should be admitted. Otherwise, it's not an exhibit.
JUDGE CANNONE: So she just explained it. Right. And so you think it needs be more of a --
MR. ALESSI: Oh, yes.
JUDGE CANNONE: -- foundation?
MR. ALESSI: Because, Your Honor, Mr. Brennan is correct that the subject matter, you may recall Mr. Whiffin I went over this with him --
JUDGE CANNONE: Right.
MR. ALESSI: -- and he said this is my opinion as to what Mr. Brennan just said as to what tab is associated with and what time it's associated. He said it's his opinion. Ms. Hyde, in essence, this is going to be used as her opinion that's going to appear on the screen that the jury is going to see before he's established the foundation.
JUDGE CANNONE: All right. So you're suggesting that when Mr. Brennan said the way that you're suggesting is it's twice. He has her testify to this and then puts it up.
MR. ALESSI: If he establishes a proper foundation, then this can go up on the screen and he can explain it subject to Your Honor's --
JUDGE CANNONE: All right. So if you have to do it twice, you have to do it twice.
MR. BRENNAN: Okay. Thank you.
end of sidebar.)
MR. BRENNAN: Before we look at any chalk, I want you to explain the entire basis for that chalk and your ultimate opinions that are reflected in the chalk. So let's start from the beginning.
MR. BRENNAN: Why don't --
JUDGE CANNONE: See if you can answer the questions, and if you can't, let us know.
MR. BRENNAN: When you looked at the phone to analyze it, were you trying to determine when a particular search was made, specifically the search "hos long to die in cold"?
MS. HYDE: Correct. I was looking for two searches both "how long to die in cikd" and "hos long to die at cold".
MR. BRENNAN: So as a forensic examiner, how did you begin the process to try to identify and determine when that search was actually made?
MS. HYDE: So the first thing we would want to identify is what application was being used at the time to make the search. So looking at that date and time stamp was able to on that date be able to determine that Safari was the application that was being used as the Google browser, and then you would begin looking at the artifacts for Safari, both those that are parsed by different forensic tools, but then further looking into the data structures that hold that data itself. And then ultimately, conducting testing to determine why a certain artifact exists.
MR. BRENNAN: So you mentioned you begin; the beginning step is the forensic tool or tools. Did you use forensic tools to get information to parse any data regarding this potential search at 2:27?
MR. BRENNAN: Can you share with us the multiple forensic tools that you used?
MS. HYDE: Absolutely. I used Cellebrite physical analyzer. I used Magnet Axiom. I used -- just the tools I used at first, I used iLeap. There are further tools I used later, but those were the three that I started with.
MR. BRENNAN: What tools did you use later?
MS. HYDE: Later, I used specifically Sanderson's forensics toolkit, the forensics browser in Sanderson's toolkit which helps exploit SQLite databases, and then I further reviewed in a tool called Rabbit Hole.
MR. BRENNAN: To begin with Cellebrite, is that a tool that you're familiar with?
MR. BRENNAN: Is it a commonly used tool in the industry?
MR. BRENNAN: Is it reputable?
MR. BRENNAN: Why did you use Cellebrite?
MS. HYDE: I use Cellebrite because on any mobile exam, I'm going to validate what is captured by Cellebrite and Magnet Axiom because they have the most robust parsing of what is in my tool arsenal, and then I would also follow up with iLeap closely behind because iLeap has a lot of artifacts that aren't supported by either of those tools. Using a variety of tools is going to give you different coverage and each tool has a different perspective on how they view and display data.
MR. BRENNAN: You said you also used Magnet Axiom?
MR. BRENNAN: Is that a leading forensic tool as well?
MR. BRENNAN: Are you familiar with that company?
MS. HYDE: I'm very familiar with Magnet Forensics. I was actually their director of forensic for five years, then continued to consult for them for an additional two years under my company Hexordia and my company continues to be a reseller of Magnet's products.
MR. BRENNAN: You mentioned different tools may present information in is different way. Do those tools change the underlying data at all?
MS. HYDE: That's a great question. So when we're talking about the results that a tools shows, the tools maintain the integrity of that original forensic image, and it's actually something we verify as we continue through our exams to make sure that the underlying data hasn't been changed. There are tools -- I did use some other tools. I apologize. I also used Artex and Mushy.
COURT REPORTER: Can you spell that?
MS. HYDE: I'm sorry. ArtEx is capital A lower case R-T, capital E lower case X. And then Mushy is M-U-S-H-Y.
COURT REPORTER: Thank you.
MS. HYDE: You're welcome. A I'm sorry. Could you repeat the question? I got -- the spelling threw me off.
MR. BRENNAN: I mentioned or I asked you about using multiple tools and whether or not the use of different tools changes the actual underlying data?
MS. HYDE: Oh, so the actual underlying data is always maintained, and we do validate that. Some tools allow you to see parsed results and then allow you to dig deeper into looking at the actual files and data structures. Those would be tools like Cellebrite, Physical Analyzer and Magnet Axiom. Some tools show you the parsed results and tell you where they got them like iLeap. It shows you the parsed results and tells you the file location. And then you would open that up in an external tool. And then some of the tools I used are not tools that parsed the results but are tools that allow me to manually look at the data structures. So they directly allow me to look at the data structures, and all of the tools I used in this instance are tools that do not change the underlying data.
MR. BRENNAN: Is it important or critical to go beyond the tools' presentations and actually analyze the data yourself?
MS. HYDE: It is absolutely critical. Actually, in the NIS Scientific Foundation's paper from the National Institute of Science and Technical that states the foundations of digital forensic science, it states that it is the examiner's duty to not only verify and validate tool results, but also to provide meaning to forensics parsed results.
MR. BRENNAN: Does software update regularly?
MS. HYDE: Oh, the software updates all the time. Typically, we get an update about once a month, and to be honest it's not enough to keep up with how many new apps are developed and how many new phones come out and how many of your applications get updates, new features, for example, maybe on Instagram or Facebook. So the tools update very, very regularly.
MR. BRENNAN: When you used the Cellebrite tool to analyze the 2:27 search, did the search "hos long to die in cold" have a time stamp on it?
MS. HYDE: There are actually multiple artifacts for "hos long to die in cold". Remember earlier, we defined an artifact, and we spoke about it was one of the types of traces. So there are multiple choices for that "hos long to die in cold". Only one of them is associated with the 2:27 time stamp, but there are other instances of evidence of that that was parsed by Cellebrite.
MR. BRENNAN: Is there any danger for an untrained eye to rely simply on the software when looking at a search like this "how long to die in the cold" and seeing the 2:27 time stamp?
MS. HYDE: Absolutely. There's a really scary danger that an examiner who has not dug into the artifact and tested to see what it means may assume, erroneously, that that 2:27 time stamp is the time that what is there is searched. The search in that field of that artifact is going to always be the most recent search in the tab, but that time stamp actually means either the time that that tab was backgrounded, or if it's the first time the tabs been opened, when it was opened. So you could erroneously implicate a search was done hours or some time period or even days before it actually occurred. Some of us leave our tabs open forever.
MR. BRENNAN: In your teaching, examiners and students, do you teach about this specific and concept?
MS. HYDE: Yes, I teach about this concern both in my mobile forensic analysis class, my mobile forensics course that I teach at George Mason University in a digital forensics master's program, and in the data structures course where we specifically learn how to analyze these databases in question.
MR. BRENNAN: In your experience, how common does an untrained examiner make this mistake?
MS. HYDE: I wouldn't be able to speak to how common an untrained examiner does it, but regularly my students get those questions wrong on earlier examples I give them in class to kind of indicate to them that they could easily make mistakes without understanding meaning, and I use it as a teaching aid. So teaching, you know, 90, 100 easy students a year, I regularly see that in untrained examiners that I'm teaching in my class, but I wouldn't be able to see that cross the discipline.
MR. BRENNAN: You mentioned that Cellebrite showed the search on the report as "hos long to die in cold" with a time stamp of 2:27, was it 2:27:40?
MR. BRENNAN: Do you know whether or not Cellebrite has updated its software?
MS. HYDE: In May, Cellebrite -- of last year, Cellebrite made an update to their software actually to remove this artifact because of its ambiguity and the risk that an examiner may overstate or misstate what it is.
MR. BRENNAN: Is this ambiguity reflected in other types of software?
MR. BRENNAN: Sure. For example, when you did a report in Axiom, did a tab similar reflection in the report?
MR. ALESSI: Objection, Your Honor.
JUDGE CANNONE: Ask it differently.
MR. BRENNAN: Did you run a report regarding this time frame through Axiom software?
MR. BRENNAN: When you did that, was it the same or a different result?
MS. HYDE: Axiom and Cellebrite really show their data very, very differently. So Cellebrite takes a perspective of alerting people to possible deletions by annotating either a question mark or a red X next to artifacts that come from different areas. Magnet instead marks if the artifact was parsed or carved. I feel like now I need to explain to you parsed or carved. So parsed means that the data was where it was expected to be found, and the algorithm was able to cleanly see that this is there. Carved means that it had to run that algorithm against the data structure as a whole and found it as a partial result. So carved it out, went and found it, instead of just sitting there exactly where it was expected to be and shows you both the results. So it will show all of the results of -- in this instance, the sessions -- tab sessions, but the data browser DB, the tab state, it's going to instead of telling you this has a red X, it will instead say it's carved. So it's a different presentation of the same data.
MR. BRENNAN: So I want to talk about deletions in a little bit, but I want to give back to the 2:27 search.
MR. BRENNAN: So when you produced or you looked at the report from Cellebrite and it showed this time stamp as well as the phrase "hos long to die in the cold", where did you look, how did you make an analysis to determine whether or not that search was actually made at 2:27 or another time? What was your next step or process?
MS. HYDE: So in looking at that time stamp, the first thing I did was actually go and like at what literature exists on the artifact, if anybody had reviewed this artifact before. I also created my own data set and tested how we could get what that time stamp means. So if I make a search in a tab and then I make another search in the tab, which time stamp is it. If I make a search in a tab, and I open a different tab, what changes. I also looked at the documentation in the artifact reference guide for Axiom which does state -- it describes that time stamp as the time in which the tab is backgrounded, and it gives a stipulation that in certain circumstances, the time stamp can be earlier than the search.
MR. BRENNAN: Did you specifically look in any databases or for artifacts in the data to help make an analysis of when the search happened?
MS. HYDE: Of when the search happened as a whole? Absolutely. So there are multiple databases that I looked at that show search information for Safari. So I looked at the P list, mobile Safari P list. I looked at the browser state database. I looked for the history database. I also looked at the knowledge C DB. The knowledge C DB is a little bit different. That isn't a database for Safari. It's a database for all of Apple so it can predict your behavior. So it takes in information that Apple wants to take in, including browser history, and it saves that information so it can make predictive information. I also looked at the caches in the Safari which is the things that Safari is trying to make quick reference to. This would include suggested terms for commonly searched items.
MR. BRENNAN: When a URL or a search through Safari is typed in or if it connects, does it leave a trace in different parts of the computer or the phone?
MS. HYDE: Yeah. So when you actually do any search, you're going to leave traces. Now, it does depend if you are in private browsing on nonprivate browsing. So nonprivate browsing is what most of us use regularly. Private browsing might be what you elect to use -- well, some people would elect to use it if they're doing searches they wouldn't want their spouse to see, like maybe they're looking at porn, or maybe you're doing something secure like looking at your banking information. You may intentionally use a private browser. For Google users, this would be the equivalent of Incognito in Google Chrome, and you may intentionally use that. And so the artifacts for that are more limited than the artifacts for nonprivate searches. So some of these artifacts only exist for nonprivate searches, and some exist for private searches.
MR. BRENNAN: In this case this phone, was it on nonprivate or private?
MS. HYDE: So the specifically the two searches we're talking about "hos long to die in cold" and "how long ti die on cikld," excuse me differentiation there, both of those searches were done in nonprivate browsing.
MR. BRENNAN: So they weren't hidden?
MR. ALESSI: Objection, Your Honor.
JUDGE CANNONE: Sustained.
MR. BRENNAN: Was there any applications on to mask those searches?
MR. BRENNAN: We began with the 2:27:40 time stamp. The next recording on that tab; do you recall what time that was?
MS. HYDE: I believe the next -- and I'm trying to remember the chart from memory if that's correct. So I believe the next thing we're looking at is the 6:23 suggestion from Apple search terms for "how long to digest food"? Am I matching what you're seeing on your chart?
MR. BRENNAN: Well, let me ask you.
MR. BRENNAN: When you saw that, do you look on the same tab or a database? Where did you find that information?
MR. BRENNAN: Fair. Understood. So all of those databases I was just mentioning before were looking at all the parsed results from all of those, and I was looking in the entirety of the scope from the time of midnight until noon. That was the time frame of my scope of all of the content that was done in the tabs -- the tabs for browser state DB, cloud tabs, artifacts, history DB, mobile Safari P list, knowledge C, each one of those, and then I was combining them to timeline out the activity.
MR. BRENNAN: At 6:23:51, did you look into how long t-i d-i-e in c-i-k-d?
MS. HYDE: So that would be the next thing that we see after the -- after the Apple suggested term of "how long to digest food," that's the next thing we see is we see an entry of that. There's two immediately next to each other. I don't remember the precision on the seconds of which one is first off the top of my head, but one is a knowledge C and one is in the mobile Safari P list.
MR. BRENNAN: Can they appear in different rooms in the databank in different places?
MS. HYDE: Yeah. Searches appear in many different places. They can leave traces such as that knowledge C DB. I love that Apple calls that knowledge. It's like what it's trying to learn. So that knowledge C DB, what Apple is trying to learn about you, as well as in that mobile Safari P list, as well as the moment of that search, which I don't have the device in that moment, but just so there's understanding, that open tab, the URL would have been updated URL, or URL is the website would have been updated to that search at that moment. Had we imaged it at the moment, it would have been how long ti die in c-i-k-d – c-i-k-l-d -- c-i-k-d? C-I-K-D. Sorry.
MR. BRENNAN: Finally, at 6:24:47, did you identify any artifacts with that search that appears with the time stamp of 2:27:40, did you find the same?
MS. HYDE: Correct. At 6:24, we have two time stamps in the same two locations for "hos long to die in cold," the knowledge C and the mobile Safari P list.
MR. BRENNAN: So based on your analysis of that issue, did you come to an opinion whether or not the phrase "hos long to die in cold" was actually searched at 2:27 a.m. on January 29, 2022?
MR. ALESSI: Objection, Your Honor.
JUDGE CANNONE: So the answer yes or no. A Can you repeat the question, please?
MR. BRENNAN: Yes. And so based on your analysis of the phone and the data using all of those softwares, did you come to an opinion whether or not the phrase "hos long to die in cold" was searched at that time stamp tab of 2:27:40?
MR. BRENNAN: And what is your opinion?
MR. ALESSI: Objection, Your Honor.
JUDGE CANNONE: Rephrase the question as to the opinion.
MR. BRENNAN: I'm sorry?
JUDGE CANNONE: I'll see you at sidebar so, Mr. Alessi, you can put this on the record.
MR. ALESSI: Thank you, Your Honor.
(Sidebar commences:
JUDGE CANNONE: All right. Go ahead and put your objection on the record.
MR. ALESSI: Your Honor, my objection is that there is not a proper foundation laid for the opinion that's about to be raised. And there are three bases for my objection all coming to the fact that a proper foundation has not been laid. I'm not going to guide how to do it properly, but I think Your Honor knows where I'm going. First the basis for the objection is that she has not cited one peer-reviewed article for her methodology for this opinion she's about to give, not one. And we all know through the Polk factors; there's five Polk factors. I'm not going into them. I know the Court knows them well, but the bedrock focus of Polk as well as Daubert-Lanigan is you to have either find that the methodology is generally accepted - that's Commonwealth v. Davis - or you have to establish the five factors under Polk, and there's not even been -- begun to do that. But most important on the ones that haven't, there's no peer-reviewing. She has also not demonstrated that her methodology that she has subjected it to testing or replication, which is another requirement that you have to have. So what she has basically done here is what is commonly referred to in Daubert parlances, and it's -- because she says this is so way you do it, it must be so. The third basis for my objection, Your Honor, is that the methodology that she is attempting to use is not properly tethered to the facts which is a Polk fact, and it is also a Daubert factor. She is not tethering her opinion to the facts of this particular situation. So in conclusion, a proper foundation has not been laid, and additionally, Mr. Brennan, respectfully, has not asked the question properly with regard to how you elicit an opinion, and I'm not going to go into it further and give him the roadmap to do it.
JUDGE CANNONE: What do you say, Mr. Brennan?
MR. BRENNAN: I can her if she has an opinion to a reasonable degree of scientific certainty. She does not need to have a peer review to make this admissible. She can have the training and experience and she's done the study. There is no requirement that the defense suggests. There is no methodology that's at failure here. I can ask her to self-endorse, as you can any expert, is this the methodology that is currently accepted, but peer review is not a prerequisite. She's established her foundation and her experience.
MR. ALESSI: If I may, Your Honor.
JUDGE CANNONE: Okay.
MR. ALESSI: There are two bases to establish the basis for foundation for an opinion of an expert. The first, as I stated moments ago, is general acceptance. She has not given one statement as to how her methodology is generally accepted in the scientific community. The only thing she has said, is this is how I do it. She hasn't said, this is how it's accepted in my scientific community. It's general. You can cite this article. She has not done that. So the foundation for general acceptance has not been established. One can, if you can establish general acceptance, you can do it under the five Daubert factors, but the five Daubert factors include -- one of them is peer review in publication. Another one is general acceptance. I already covered that. The other one is that there's a standard or a regulation that she can point to as to how she's coming to this conclusion that you tether the 2:27 time stamp to a search occurring at 6:23. She has given not one publication, not one standard to tether it to. She has failed every one of the Daubert-Lanigan factors, and she's fielded the general acceptance of Commonwealth v. Davis and that is the basis for my objection.
JUDGE CANNONE: So she's testified to using the Cellebrite tool that is in evidence through Dr. Whiffin or Mr. Whiffin, and she testified as to using that. And I believe earlier she testified to that being -- when she talked about the various forensic tools that she used and that they're used in the industry and that they're generally accepted without using a general acceptance language.
MR. ALESSI: Your Honor, that is what she has testified to, however, this is the big shortcoming. Yes, she's testified that she used Cellebrite tools, and frankly she testified she used other tools.
JUDGE CANNONE: Right.
MR. ALESSI: She used Axiom, she used Sanderson. I get all that. What she didn't do is to say that it is -- that those tools can be used to determine when a search occurs. Those tools only show the time stamp. So you can use any one of those tools to say that that time stamp is present. I have no objection to that. But the key opinion she is willing to give and ready to give is that the presence of that time stamp, she can then determine when the search occurred. Those tools do not allow you to do that. There's nothing in the literature for that. So in conclusion on this, yes, you can use the tools to show the time stamp, but then the next question is with a shown time stamp, how do you establish that that time stamp is associated to a search at a given time, and she hasn't even begun to address that.
MR. BRENNAN: Well, she has. She's explained that the artifacts leave traces in different databases. She's explained that the artifacts leave traces in different databases. She's explained the different databases. Also on this chart are those artifacts exist, and through that, that is the basis of her opinion that that time stamp doesn't accurately reflect that search. So she has gone through her methodology. She has gone through an explanation of how she made the determination, and she has given specific examples of her process and why this time stamp does not apply to this search.
MR. ALESSI: And, Your Honor, I'm going to even -- I'm going to accept for just purposes of this argument what Mr. Brennan said, which is she's given a methodology to come to that conclusion. The problem is the methodology that she has given is not generally accepted. There's not been established, and the methodology that she used has not met any of the five Daubert factors. So even assuming that she has explicated a methodology, you -- that doesn't get you to an opinion. You to show that it's either generally accepted or that it satisfies the five Daubert, and she hasn't done it.
JUDGE CANNONE: So you can ask her and we'll take it from there.
MR. BRENNAN: Thank you.
MR. ALESSI: Thank you, Your Honor.
end of sidebar.)
MR. BRENNAN: You've explained to us the analysis you engaged in and the process you engaged in. In forensic data analysis, is there a methodology that you use, not just looking at the printout of the programs, a methodology you use that is accepted in the industry for experts to analyze this data and come to your opinion?
MS. HYDE: Absolutely. Beyond looking at what was in the tool results, I further looked at those databases independently and conducted testing of the artifacts.
MR. BRENNAN: In addition to what you did, can you share with us how and why this methodology is accepted in your practice as a forensic analyst?
MS. HYDE: This methodology is accepted by NIST and by organizations like the Scientific Working Group of Digital Evidence. I'm intimately familiar as both a member of the scientific working group on digital evidence who helps work towards the building and development of these consensus- based documents of procedures to be followed in digital forensics analysis and as a member of the National Institute of Science and Technology, NIST, Organizational Scientific Area Committees, OSAC, Digital Evidence Subcommittee where we also produce guidelines such as the dataset guidelines for generation -- the guidelines for a dataset generation which is how you do your actual testing and creation of datasets. And I was also a part of the subcommittee that drafted that. So I'm intimately familiar with the accepted policies and procedures because I am also a member of the groups that help author these as well as review them and look and use them.
MR. BRENNAN: Are there articles and guidance in the industry about this particular practice of analysis?
MS. HYDE: For analysis, just for clarification, are you talking about for analysis of Safari artifacts of mobile forensics, of browser state DB, just for clarity on the question.
MR. BRENNAN: Let's work our way through.
MR. BRENNAN: How about for Safari?
MS. HYDE: For Safari, there are multiple different blogs that talk about Safari as well as I have analysis of Safari through classes I took such as Sans 4508 which is their -- I'm sorry 518. Sans 4518 which is the Mac and iOS analysis course, which I took.
MR. BRENNAN: How about the specific guidance regarding searching the different databases for artifacts?
MR. BRENNAN: Yes.
MS. HYDE: There are multiple -- again, I've taken courses from -- throughout my master's program courses on how to analyze digital forensic artifacts, including mobile device artifacts, throughout my GIAC certifications. I've taken multiple instructor led courses on how to do these as well -- specifically that cover mobile Safari history in mobile forensics at GMU in a master's program, as part of the Sans 4518 class, and in terms of data structures, I've taken study on how to analyze databases like SQLite and P list are covered in those courses.
MR. BRENNAN: There are books on study on this methodology?
MS. HYDE: There are multiple books on digital forensics, many of which I've read, and including books specifically on analysis of SQLite databases such as Sanderson, SQLite forensics, which is probably the most authoritative because not only was it written by Sanderson, who makes a tool, it was tech edited by three renowned forensics examiners as well as Dr. Richard Hick who created SQLite itself.
MR. BRENNAN: The methodology, the technique you used difficult to look past the report to actually look at the data to make your determination and provide your opinions, is that methodology regularly accepted within the forensic data community?
MS. HYDE: Absolutely. Again, using the methodology from the consensus-based documents from the community, from the Scientific Working Group Digital Evidence on best practices for analysis as well as specifically for the SQLite databases I was looking at, I do that deeply verifying and in accordance with the understandings from Sanderson's book.
MR. BRENNAN: Now, you shared with us that you had an opinion regarding the time stamp and whether that it was applicable to the search term "hos long to die in cold"?
MR. BRENNAN: Now, I wanted to ask you to a reasonable degree of forensic data scientific certainty, what is your opinion about whether the phrase "hos long to die in cold" was made at the time of the time stamp 2:27:40?
MR. ALESSI: Objection, Your Honor. May we approach?
JUDGE CANNONE: This is the last time, Mr. Alessi, on this issue, okay?
(Sidebar commences:
JUDGE CANNONE: The answer is going to be no. I said earlier --
MR. ALESSI: Your Honor, you can't make that statement in front of a jury. I'm sorry.
JUDGE CANNONE: All right.
MR. ALESSI: You cannot make that statement in front of a jury.
JUDGE CANNONE: All right. This is the last time on this issue.
MR. ALESSI: I'm going to Your Honor that that statement -- that any of my objections never be made in this trial.
JUDGE CANNONE: Fair enough. I apologize, Mr. Alessi.
MR. ALESSI: Accepted. Accepted. The reason why I'm objecting, Your Honor, is because all this witness did, she never once said -- Mr. Brennan kept saying your methodology, your methodology. He never elicited from her the methodology that she is trying to use where she says how I determine whether the 2:24 time stamp is tethered to 2:27:40 or 6:23, this is how I did it. She's explained how she did it, but I'm going to go through each one quickly. She basically -- her first answer when he said, "Isn't it accepted in the literature," it. She said, "Dataset generation." That's what she said her first answer. That's not at all close to you can take a time stamp and determine whether the time stamp is associated with either search term. The next she said. She said, "You can go to Safari and you can use Sans which is a certification," what she only talked to -- here is what she said. She said, "Logs for Safari." She never came close to either one to say, okay, here's the time stamp and that means the search occurred here. The third thing she said the basis for her methodology. You can search for artifacts, multiple ways to do that, how to analyze it. That begs the question that was her third reason. Her last reason was, you can -- there's multiple books on -- this is what she said multiple books on digital forensics, how to analyze Sanderson SQLite which is a tool. Multiple books on digital forensics has nothing to do with informing how she took a time stamp and is concluding that that occurred at 6:23 as opposed to 2:30. So in conclusion, Your Honor, the four reasons that she gave, not one time did she say time stamp you can use any of these to go from a time stamp to a conclusion as to when the search occurred. She hasn't moved the needle at all.
MR. BRENNAN: She said that the methodology is regularly accepted in her industry. She gave cites to different sources including NIST. She also has provided specific methodology and then she is engaging in a process where she's looking at different databases to see if they relate to that time stamp. She has said very clearly this is regularly accepted in the community. There's not much more she can say. She is qualified. She has tied her methodology to her process and has cited that it is regularly accepted in the community.
MR. ALESSI: The most apt thing Mr. Brennan just said was she said what her methodology is, and there's nothing more she can say. I couldn't agree more. It's an -- she has said this is my methodology. She did mention NIST, Your Honor, and she basically -- the only thing she said about NIST was it governs digital evidence. She didn't even come close to saying NIST says that when you have a time stamp, this is the way you go about determining when the search occurred and it supports my opinion. And that's the basis for the objections, Your Honor. She has not cited one example of where her methodology to say that this time stamp is associated with a search. She has never once said where that is establish in any literature, any standard, or that it's generally accepted anyplace at all.
JUDGE CANNONE: Okay. Your objection is very well stated. I'm letting the evidence in.
end of sidebar.)
JUDGE CANNONE: All right. Go right ahead, Mr. Brennan.
MR. BRENNAN: I'm now going to ask you for your first opinion. So you shared that you have an opinion about whether or not that time stamp 2:27:40 was -- whether or not that was the time to search "hos long to die in the cold" occurred. Can you tell us to a reasonable degree of scientific certainty your opinion about whether that search "hos long to die in cold" occurred at 2:27:40 a.m. on January 29, 2022?
MR. ALESSI: Same objection, Your Honor.
JUDGE CANNONE: Okay. The objection is overruled.
MS. HYDE: What I can state to a scientific degree of certainty is that that search occurred at 6:24 a.m., and was the last search in the tab that had been opened at 2:27.
MR. BRENNAN: Do you have an opinion to a degree of scientific certainty whether there was any other searches similar to "hos long to die in cold" that evening on that tab?
MR. ALESSI: Objection, Your Honor.
JUDGE CANNONE: I'm going to allow it.
MR. BRENNAN: I meant morning, yes.
MS. HYDE: Just clarifying, I did not look at evening searches. I -- can you repeat? I apologize. I disrupted my own train of thought.
MR. BRENNAN: Do you have an opinion to a reasonable degree of scientific certainty whether there were any other searches on that tab before the final search at 6:24:47 "hos long to die in cold"?
MR. ALESSI: Objection, Your Honor.
JUDGE CANNONE: Overruled.
MR. BRENNAN: Please.
MR. BRENNAN: Yes.
MR. BRENNAN: Did you develop a chalk --
MR. BRENNAN: I'd like to approach.
JUDGE CANNONE: Yes.
MR. BRENNAN: Again, I show you the same document. Do you recognize it?
MR. BRENNAN: And what is it?
MS. HYDE: It is the exhibit that I created that was label table 1 and the first report I delivered.
MR. BRENNAN: And does that provide information that will assist us in understanding your opinion?
MR. BRENNAN: I'd move subject to redaction that this be introduced into evidence.
MR. ALESSI: Your Honor, I have no issue with regard to the redaction aspect, but consistent with my prior objection, I would object to that.
JUDGE CANNONE: Okay. I'm going to allow this into evidence. Your rights are saved, Mr. Alessi.
MR. ALESSI: Thank you, Your Honor. I appreciate it.
(Whereupon Exhibit No. 82, Chart of Ms. Jessica Hyde, was marked as an exhibit.)
MR. BRENNAN: With the Court's permission I'd like to show Exhibit 82 to the jury?
JUDGE CANNONE: Okay.
MR. BRENNAN: Could we enlarge the first two? We're going to need to get to the right column if we can, please. Ms. Hyde, can you see it from there?
MR. BRENNAN: If you could walk us through how this exhibit assists us in understanding your explanation and the basis for your opinion?
MS. HYDE: This exhibit shows the Safari artifacts on artifacts of Google searches in Safari related to the two searches in question "how long to die in cilkd" and "hos long to die in cold" that occurred on the morning of November 29, 2022, on the device under examination.
MR. BRENNAN: If I look at this chart and I see in the top left it says 2:27:40 a.m., and then under the search term it says, "hos long to die in cold". How do I understand your opinion that that search didn't happen at 2:27:40?
MS. HYDE: This document is showing you the data that is the parsed result. The source of that artifact that you see in the last column is a little bit cut off. The browser state DB/WAL file, that database does store how the data is stored, the search term "hos long to die in cold" with an associated Mac Absolute Epoch time stamp that translates to 2:27 a.m., that is what is physically stored. That does not annotate the meaning of that artifact. That was determined through testing following the NIST data generation guidelines for testing.
MR. BRENNAN: In the second row, we see a time stamp on the left-hand column 6:23:49, and it provides an artifact a cache record?
MR. BRENNAN: What is the term and what does that mean under the search term?
MS. HYDE: IOS Safari cache records. A cache refers to something that a computer program wants quick and easy access to. When me search on phones, anything a lot of times be it in Google or in Safari, depending on what type of phone you own, it will suggest what it thinks you're going to type, right? So you can click it. It's trying to be helpful. In this instance at 6:23:49, we have a cache record that indicates that Apple suggested the phrase how long does it take to digest food?
MR. BRENNAN: And then under that 6:23:51, it appears this is a recent web search and the spelling has changed, how long T-I D-I-E I-N C-I-K-D?
MS. HYDE: So this in reference to these two search terms, this is the first actual search that occurs at 6:23:51 a.m. Upon beginning the typing of that phrase, Apple provided the suggested search and the person inputting into the phone at that time continued to type out a phrase and finished it as how long TI D-I in C-I-K-D, which that is available to us in the mobile Safari P list which tracks recent web searches, and then we'll see is six seconds later we get that reference in that knowledge C database that I mentioned before. That's the next line. So the knowledge C database is Apple's way of keeping knowledge about what the user is doing. It sees and holds your knowledge. It's an easy way to remember it. That's what I teach my students. So that knowledge C DB tracks a lot of things for predictive purposes, and so six seconds later, it's logging that same search. So that search is being tracked in two places.
MR. BRENNAN: So one search can be left as artifacts in different locations on the database?
MS. HYDE: Correct. There can be multiple traces or artifacts of the same user action in different places on a mobile device.
MR. BRENNAN: If we go down to the bottom, the last column at 6:24:47, we can again see "hos long to die in cold". If you look in the first column, it's the same phrase. Is that a coincidence that it appears at the bottom at 6:24:47 and also appears up at 2:27:40?
MS. HYDE: As mentioned before, through testing of the artifact for browser state DB, that artifact will hold the most recent search that happened in the tab. So it is logical that how long -- hos, H-O-S, long to die in cold was searched at 6:24:18, tracked in that mobile Safari P list, repeated in knowledge C. Knowledge made its tracking in the knowledge C DB and then that table for browser state DB, which again has the time that the tab was opened, or the last time it was backgrounded and updated just the website that was visited. So the website that is why we get that 2:27 time, that's actually, as far as the data storage is, the first thing I have in there because I wanted to put it in chronological time order for exhibit purposes is actually the last thing to happen because it's the update to what's in the tab.
MR. BRENNAN: You offered that "hos long to die in cold" was the last thing to happen. Do you have an opinion to a reasonable degree of scientific certainty the time when that death search was made?
MR. ALESSI: Objection, Your Honor.
JUDGE CANNONE: Overruled.
MS. HYDE: To a reasonable degree of certainty, I can say that "hos long to die in cold" was searched at approximately 6:24 a.m.
MR. BRENNAN: Now, moving on from the 2:27 search. There were two other issues that you were asked to analyze, and we talked about it at the beginning. Let's begin with whether or not you looked at the data and analyzed the data and came to any opinions about whether that phrase "hos long to die in cold" was user deleted on that device?
MS. HYDE: So there's two really key elements as to if that was user deleted. If the question is, did I come to an opinion? Yes. I'm good to say --
MR. BRENNAN: Can you explain how you came to that opinion that we'll ultimately share with the jury?
MS. HYDE: The first line in that exhibit, the ending of that if you remember it said, "browser state.DB-wal" that's important. So we'll talk about that in a second. But the first thing I want to bring up is kind of how the database works because I didn't just look at the tool result. I extracted that database, and I did a deeper analysis on it using Sanderson's tool because that information was in that dash WAL file. So when a SQLite database, which is a specific way of storing, very, very common on mobile phones, actually one of the most common, when that database stores data, it has two versions. The most recent version and the version in use here uses what's called a write ahead log. So before data is committed, it is written to a write ahead log. I'll kind of explain it. So let's say we're in a restaurant, and we're sitting at a table and we're ordering food. Our table is the table. Data is going to come to the table and that's going to be our food.
So when we order food, let's say we've got a chicken sandwich, a burger, and a pizza coming to the table. The chicken sandwich, the burger, and the pizza, the kitchen puts it in the warming area. This is the write ahead log. The server grabs it from there. It where data sits before it goes to the table, just like your food goes to that serving station before your server brings it to your table. Table server brings it to the table, that table's got it's burger, it's chicken, and it's pizza. Another table orders waffles and pancakes. They think it's breakfast. The waffles and pancakes are made by the kitchen. They're put on the serving area. Waitress comes over. This pizza has pepperoni. I don't eat pepperoni. Can you send it back? The waitress picks up that pepperoni and sends it back. That's a deletion. Pepperoni pizza was just removed from the table, right? We're deleting it. We're moving -- we said it's not what we wanted. The waitress is removing it.
She brings it back to that serving area. At that moment, that serving area has the deleted pizza, but also the waffles and pancakes that are waiting to go out to the table. That's how a write ahead log works. Any changes that are happening sit in the write ahead log until the database is closed and then when it's re-opened, all those changes are made - both additions and deletions. So often when a phone is imaged, when we make a forensic image, the applications are still open so we have those WAL files. When we look in our Safari browser, the database knows to read it to you in its current state. So it tells you where the waffles and pancakes are going. They're going to that table so it shows as if it's in the table, but it's not on the table yet. So if when we parse the data and we look at the restaurant and we don't look at the back kitchen, we would only at that time see the chicken and the burger, right? Pizza got sent back. Waffles and pancakes haven't come out yet.
So when we get the data, we get two files - we get the restaurant - that's the database, and we get the serving area - that's the WAL file. Just because it's in the WAL file does not mean it's deleted. It means that that record wasn't where it naturally sits yet. It could be that WAL file can contain deleted and food or data that hasn't yet been delivered to the database. So the WAL file consists of both. So an assumption that the data was deleted just because it's in the WAL file is actually not true. And the peer- reviewed paper I mentioned earlier that I had accepted in Forensic Science International, actually has a section that explains this exact presence for SQLite databases about how we refer to that is recovered and not deleted. Actually, through that entire document, we don't use the phrase deleted. We refer to things in statement of recovery because we need to determine why it's there. So we can't say that it's deleted just because it came from the WAL file.
Some tools will automatically indicate to the examiner that they need to dig deeper into that. I did do further analysis by looking at the WAL file. That particular item, and it's a little bit more complex, actually exists on multiple pages because it moves as the database is being created, but all of them have the same unique identifier. So it's the same entry. It's not more than one search of "hos long to die in cold". If there was more than one search that had occurred where it became the top element in that database, we would see that. There are, as I mentioned, other carved from the
MS. HYDE: database from the WAL file elements such as a search for the YouTube video "It's Raining Men" because at some point that was the last viewed item in a tab when that tab was retired right before -- also at 2:27 a.m., but a couple of seconds before the "hos long to die in cold" search. So we can see that that table is put to the rear. The newest tab that's open, which is why it's in the WAL file. It's the most recent thing because it's like our waffles and pancakes hasn't been delivered to the table yet, so it can sit in that WAL file for that reason. It doesn't indicate it's deleted. The second reason is there is no user interaction in the interface to delete a tab. You can open and close a tab and open and closed tabs are tracked in that database, but you cannot delete a tab. There's no -- if you were to pick up your iPhone, I know you don't have them right now, but if you were to pick up your iPhone and look that wouldn't be a physical option you have in the interface. So it could not be deleted by a user through the interface for that most basic reason.
MR. BRENNAN: So the user, could they delete a tab if they wanted to?
MS. HYDE: There's no actual option to delete a tab. For your web history, you could clear the cache for example. Most of us are familiar of clearing the cache in your web history. You might do it because you don't want your kids to see what you searched or maybe your kids don't want you to see what they searched, so they'll delete it, but you can't delete the tab history. It's just what tabs are there. The device is tracking that.
MR. BRENNAN: When you looked at the software, whether it was Axiom or Cellebrite, when you looked just at the report, not the data itself, do either of those reports have any indication noting that that web or that Safari search is characterized as deleted?
MS. HYDE: The tools -- Cellebrite denotes it with a red X which means that it is recovered. Axiom indicates that it is carved. In the same paper that I referenced earlier that I authored, there's a chart in there that shows the distinction between how different tools. Some will use red X's, some will use question marks, some will list carved or parse. So every tool chooses to do that differently. That does not mean deleted. It means it needs further analysis.
MR. BRENNAN: Should an examiner who looks just at the reports of the software assume that if it is marked as recovered in Cellebrite or carved in Axiom, should --
MS. HYDE: An examiner should never assume something's deleted without doing a manual examination.
MR. BRENNAN: A manual examination, is that a method that's used that's generally accepted in the forensic data field?
MS. HYDE: The NIST Science Foundation paper as well as the dataset generation guidelines both speak to conducting testing to verify and validate, and it states clearly that an examiner is to verify and validate findings and to determine meaning.
MR. BRENNAN: So given that you've used multiple tools to look at tools regarding this phrase "hos long to die in cold", and have seen indications or characterizations of recovered and carved, in addition to the fact that actually analyzed the data, did you arrive at an opinion to a reasonable degree of scientific certainty whether or not the user deleted, any user, deleted the phrase "hos long to die in cold"?
MR. BRENNAN: Pardon me. Did you come to a reasonable degree of scientific certainty whether any user deleted the phrase "hos long to die in cold"?
MR. BRENNAN: And what is your opinion?
MS. HYDE: My opinion is there was no deletion that occurred by the user because it is not something a user can delete.
MR. BRENNAN: Finally, I want to ask you about your analysis of the phone records on this phone attributed to Ms. McCabe. Did you go through an analysis of the phone logs and the phone record?
MS. HYDE: I analyzed the call logs and the phone logs on the device that I was given that I was told belonged to Ms. McCabe, yes.
MR. BRENNAN: Would a suggestion or a claim that a user deleted irregularly a number of phone calls, would that be accurate or inaccurate in your experience?
MS. HYDE: It is inaccurate in this instance. Can you explain to us why and how you came to that conclusion? A Yeah, this is actually really interesting. Because of what it appears in the forensics tools and additional artifacts that I looked at that are not parsed by the forensic tools. So the call logs, when you look at it, it appears -- I don't remember if it's 8:57 or 8:59 a.m. in my mind at the moment, but approximately either 8:57 or 8:59 is the earliest phone call we see on the 29th of January. We see no call logs before, but we do see FaceTime logs before. So if an examiner, again, was making assumptions without testing or reviewing, the first assumption might be, well, things must have been deleted because there's data that exists before but not current data. So then you have to go - how do phone logs work and again create test data and review. What the situation here is that there are three types of call logs on this particular phone. There's regular calls - incoming and outgoing.
There are FaceTime video chats - incoming and outgoing, and FaceTime audio chats - incoming and outgoing. The storage for that is actually 200 records. So you can only store up to 200 of each. Now, if you were a user of let's say WhatsApp or Signal or Telegram, those would each count, too, and they'd get their own logs. So when we look at the database for the number of calls between 8:59 a.m. or 8:57, again, I apologize. I'm not looking at that precise time, on the 29th of January in 2022, there are exactly 200 calls still in that record from then until the imaging of the phone. There are 199 FaceTime video calls and only 27 FaceTime audio calls. So the question is how do you validate that that's what's happening.
So we actually have call logs that we can pick up in other places for recent call logs in the last seven to thirty days depending on the exact version of the device and how the biomes are running, we can actually see incoming call logs, the number they go to, and if they're incoming or outgoing in the biomes. So we actually can see the history going back for the entirety of that day on January 29th until midnight. Again, my scope was from midnight until noon. So we can actually see all of the calls. They're just not all on the call history state DB. Now, the call history state DB from a user perspective, that button on your phone doesn't say call history. It actually says recents, and what is determining is recents is the most recent 200 of each category. Now, how did I determine this further? There is a running log that exists in a phone, lasts about three days, it's called the unified log. The unified log tracks multiple things are happening on the phone and manual analysis of the unified log from this phone, I can clearly see each time a 201st call comes in the 200th call gets deleted. So it's constantly just the last 200 calls. It may not be typical that we see two hundred calls in three days, but on this device we do see two hundred regular phone calls in the three days between 8:59 a.m. on the 29th and when the phone was imaged.
MR. BRENNAN: Do you have an opinion to a reasonable degree of scientific certainty whether there was any user deletions from the phone call log that morning?
MR. BRENNAN: What is that opinion?
MS. HYDE: The opinion is that I can see that it's done by the device itself utilizing the unified logs, that the system is deleting the 201st every time a new call is received or outgoing.
MR. BRENNAN: Thank you. I have no further questions.
JUDGE CANNONE: All right. Can I see counsel at sidebar regarding scheduling and a few things?
(Sidebar commences:
JUDGE CANNONE: Do you want to start, Mr. Alessi, or do you want to wait --
MR. ALESSI: I'd prefer to wait after lunch, please.
JUDGE CANNONE: All right. So one thing I do -- a couple of things I want to put on the record, too. When we were here on the last sidebar conference, and Mr. Alessi put his objections on the record that I agree were very well stated, I was not abandoning my gatekeeper function. I just wanted to get the case to the jury, the evidence back to the jury. There was no Daubert challenge to this witness filed pretrial, correct?
MR. ALESSI: We didn't have her PowerPoint until just before this trial started, so the basis for the Daubert challenge was not possible because we just got the documents before she -- when she served -- we got the PowerPoint.
JUDGE CANNONE: All right. So the PowerPoint was not used. Was that a slide?
MR. BRENNAN: That was a slide. I think that leads to a PowerPoint.
MR. ALESSI: I just want to make it clear.
JUDGE CANNONE: Okay.
MR. ALESSI: I called it a PowerPoint what was put up. If he called -- whatever it was that was up for the demonstration, we didn't have that until recently so I couldn't have given a Daubert challenge.
JUDGE CANNONE: All right. So I just want to say that I did not abandon my gatekeeper function. I found that this witness certainly is qualified to testify as an expert in forensic digital evidence. I've applied the Daubert factors. Your objection focused or your defendant's objection focused on the lack of tethering methodology used by this witness to her opinion. I do find, so that the record is clear, that the Commonwealth has met its burden, has established general acceptance within the relevant community and otherwise has met its burden under Canavan and Daubert, so I just wanted to make that clear. So we'll start you up after the lunch break.
MR. ALESSI: Yes, Your Honor. I'll be ready, and it'll be a while with this witness just so Your Honor knows through cross.
JUDGE CANNONE: I expect it will probably be at least the rest of the day.
MR. ALESSI: At least the rest of the day.
JUDGE CANNONE: All right. Thank you.
end of sidebar.)
JUDGE CANNONE: All right. Ms. Hyde, I'm going to let the jurors how lunch. You can walk out after the jurors. The jurors have lunch, too.
JUDGE CANNONE: We'll see you back here in about 45 minutes.
JUDGE CANNONE: Jurors, we'll recess for 45 minutes for the lunch recess.
(Court in recess at 12:50 p.m.)
(Court in session at 1:39 p.m.)
(Defendant is present with counsel.)
(Jury in.)
JUDGE CANNONE: I was told counsel wanted to see me at sidebar. MR. ALESSI: Yes, Your Honor.
(Sidebar commences:
JUDGE CANNONE: So the jury's in its box.
MR. ALESSI: Yes. Yep, thank you, Your Honor. The reason I wanted to see the Court is over the lunch break I went and watched a video of the comment that Your Honor made that was the subject of a sidebar that we had. In the video, and Your Honor can watch it if Your Honor chooses, to me is quite egregious as to what Your Honor said and more importantly, the disdain and the facial expression Your Honor used in front of the jury and then pointing saying this will be the last time, Mr. Alessi. I can take all of that. I don't think it's appropriate, I can take it, but my client can't, and I have essentially 90 percent of the expert case in this case. I'm bookending this case. I'm the ambassador to my client on what the prosecution has called one of the key aspects of this case, the date of the science. And I believe based upon the comment, and it's been a bit cumulative with defense counsel, but I'm going to focus on this one. I believe it has caused an impression upon the jury that I am giving either baseless objections, I am either wasting the Court's time, wasting their time, that they draw that conclusion from it. And what I believe and what I'm questioning, Your Honor --
JUDGE CANNONE: That's what I want to know. What do you want me to do?
MR. ALESSI: Yeah, I would like a curative instruction.
JUDGE CANNONE: What do you want me to say?
MR. ALESSI: What I would like you to say to the jury is, you know, members of the jury, I had made a comment in response to Mr. Alessi requesting a sidebar conversation. I do not want you to take anything from that. Mr. Alessi is representing his client according to his best representation. I'm very concerned about making good use of the jury's time. That is of interest to the Court, and Mr. Alessi came over, he gave -- and I just want you to say what you said, he gave well-stated objections and it was an appropriate use of the time, and I want the jury to make sure that they disregard any comments that the Court has made with regard to him asking for sidebar. He's just doing his job or any version of that.
JUDGE CANNONE: I'll say some version of me getting frustrated with counsel. It doesn't mean anything or something like that.
MR. ALESSI: What I want to have is not put that there's a basis for the frustration because Your Honor said when I came here that my objections were well stated.
JUDGE CANNONE: That last one. I said it at the end.
MR. ALESSI: Well, I don't make many of them, and I think that was my second request the entire trial to ask for a sidebar, and there's been other people who have asked for a lot of them. That was just my second request ever in this trial.
JUDGE CANNONE: That's why I figured I would paint a broader brush where you said it's happened more. Okay.
MR. ALESSI: Appreciate it.
JUDGE CANNONE: So I will address it. I don't have to but I certainly will.
MR. ALESSI: And I hope I got a little bit in the bank also, Your Honor. I didn't have Guarino and I cut my Whiffin short because I try cases different than I do motions.
JUDGE CANNONE: Okay. Thank you.
end of sidebar.)
JUDGE CANNONE: Jurors, as you know I told you in the beginning, one of my functions is to make sure a case is tried fairly and efficiently and not to waste anybody's time. So if I get frustrated at lawyers about something, I try not to and I don't think I am, but if I seem to cut somebody short, the lawyers are just doing their job. When they request sidebar conferences, they're just doing their job. I am going to try and keep all sidebar conferences to a minimum but the lawyers are doing their job. Okay. All right. Go ahead, Mr. Alessi. Let's bring in the witness.
MR. ALESSI: I just need the witness.
JUDGE CANNONE: All right. Good afternoon.
MR. ALESSI: May I, Your Honor?
JUDGE CANNONE: Yes.