The Certificate Authenticates the Copy, Not the Author
By the Legal Cyber Academy editorial team ·
A Rule 902(13) or 902(14) certificate does one narrow thing: it lets a machine-generated record, or a hash-verified copy of data, come in without a live witness on the stand. It does not prove who wrote the message inside the record. Authorship is a separate showing under Rule 901, and courts have repeatedly admitted the platform's certificate while still demanding extrinsic proof that the defendant was the person typing.
This article is educational. It is not legal advice, and it is not a substitute for reading the rules and the opinions themselves.
What does Rule 901 actually require of a proponent?
Rule 901(a) sets a threshold that lawyers routinely overestimate. The proponent must produce evidence sufficient to support a finding that the item is what the proponent claims it is. That is a conditional-relevance question under Rule 104(b), decided by the judge on a preponderance standard, with the ultimate question left to the jury. The judge is not finding that the exhibit is genuine. The judge is finding that a reasonable juror could find it genuine.
The Third Circuit put the mechanics plainly in United States v. Browne: because the relevance of Facebook chat logs turned on who wrote them, the proponent had to produce evidence from which a jury could find authorship by a preponderance. Once that is understood, most authentication fights stop being about technology and start being about which subsection of 901(b) you are using and what it can carry.
Rule 901(b) lists non-exclusive illustrations. Four matter for digital evidence:
| Subsection | What it establishes | Typical digital use |
|---|---|---|
| 901(b)(1) | Testimony of a witness with knowledge | The person who took the video, sent the message, or made the image |
| 901(b)(3) | Comparison by an expert or the trier of fact | Comparing a questioned file to a known specimen |
| 901(b)(4) | Distinctive characteristics, contents, substance, internal patterns | Content only the account holder would plausibly know |
| 901(b)(9) | Evidence about a process or system showing it produces an accurate result | Logging systems, automated capture, extraction tooling |
Lorraine v. Markel American Insurance Co. remains the most useful single opinion on the sequence, because it refused to consider either side's electronic exhibits — neither was supported by affidavit or any other foundation — and then worked through every evidentiary rule that governs electronically stored information. Its observation is the operative one for examiners: electronic evidence is so diverse that no single method of authentication works for all of it. The Grimm, Capra and Joseph article on authenticating digital evidence is the natural companion read.
Why does owning the account or the phone not authenticate the message?
This is the most common failure, and it is a legal failure dressed as a technical one. Access and authorship are different propositions, and the case law is consistent.
- In Commonwealth v. Koch, drug-sales text messages recovered from the defendant's own phone were held unauthenticated and inadmissible hearsay; ownership of the handset did not establish that the defendant authored the particular messages.
- In Griffin v. State, a MySpace printout carrying a resembling photograph, the purported author's birth date, her home town and a reference to the defendant's nickname was not a sufficient basis to find she created the profile or wrote the post.
- In Commonwealth v. Williams, testimony that messages arrived from an account bearing the sender's name and photograph established only that someone with access to that page sent them.
- In Commonwealth v. Mangel, Facebook posts and chats stayed out because a matching name and general identifiers, with no contextual clues identifying the sender, are not enough.
- In United States v. Vayner, a profile-page printout was admitted without adequate foundation under Rule 901, the error was not harmless, and the conviction was vacated.
The counter-line is not a different rule; it is a better record. Tienda v. State affirmed admission of MySpace printouts where the internal content — photographs, references to the victim's death, music and messages only the account holder would plausibly have posted — supplied circumstantial evidence of authorship, and expressly held that the proponent need not trace an IP address or produce expert testimony. Commonwealth v. Purdy authenticated email recovered from a computer the defendant admitted owning and for which he supplied all the passwords, absent persuasive evidence of fraud, tampering or hacking — while restating that a name on a message, or an account bearing that name, is not by itself enough.
The forensic mechanic that joins those two lines is attribution work: account-to-device linkage, session and login artefacts, credential and autofill stores, message-composition artefacts local to the sending device, and contemporaneous activity on the same device at the moment of sending. None of that is required by Rule 901. All of it is what turns a Griffin record into a Tienda record.
What do Rules 902(13) and 902(14) add, and when does a certificate fail?
The 2017 amendments added two self-authentication routes aimed squarely at the cost of flying custodians and examiners to hearings. In operation:
- Rule 902(13) covers a record generated by an electronic process or system, where a qualified person certifies that the process or system produces an accurate result. It is the certification analogue of Rule 901(b)(9).
- Rule 902(14) covers data copied from an electronic device, storage medium or file, where the copy is authenticated by a process of digital identification and a qualified person so certifies. In practice the process of digital identification is hash verification — an acquisition hash recorded at collection and a verification hash recomputed from the image.
Both borrow the procedural machinery of Rule 902(11): the certification must satisfy the same requirements, and the proponent must give the opponent advance written notice of the intent to offer the record and make the record and certification available for inspection. That notice requirement is the part most often missed, and missing it is not a technicality — it is the opponent's only chance to decide whether to demand the witness. The reference entry for Rules 902(13) and 902(14) sets out the provisions; the entry for Rule 901(b)(9) covers the live-testimony route these rules were built to displace.
Three things a certificate does not do.
It does not prove authorship. This is the holding to internalise. In Browne, a platform custodian's Rule 902(11) certificate attested only that the communications occurred between the named accounts — not that the defendant wrote them. The records came in anyway, because the government introduced ample extrinsic evidence of authorship. The Fourth Circuit ran the same two-step in United States v. Hassan: Facebook screenshots and YouTube videos were self-authenticating as business records under Rule 902(11) on custodian certifications, and the trial court separately required a Rule 901 showing linking the pages to the defendants before admitting them.
It does not make the contents admissible. Authentication is one hurdle. Hearsay, the original-writing rules, and Rule 403 are the others. A hash-verified image of a mail store authenticates the copy; whether a given message inside it comes in still depends on Rule 801 and its exceptions.
It does not survive a genuine challenge to the process. A certificate is an offer of proof about a system, and an opponent who puts the system genuinely in issue forces the proponent back to a witness. The realistic attacks are narrow and specific: an acquisition hash that was never recorded, a verification hash that does not match, a write-blocking gap, a logical extraction described in the certificate as a physical image, or a certifying person whose knowledge of the tool does not extend past pressing start.
Does an authenticating certificate raise a Confrontation Clause problem?
In federal criminal practice the answer has been no, at least for the authenticating function. United States v. Brinson held that admitting a Rule 902(11) certificate for debit-card records did not violate the Confrontation Clause, because the certificate was not testimonial — it was prepared to authenticate records rather than to prove a fact at trial — and no cross-examination of the certifying custodian was required.
The line the court drew is worth stating precisely, because it marks the boundary of the holding: the distinction is between authenticating a record and asserting a substantive fact about the defendant. A certificate that stays on the authentication side of that line is on solid ground. A certificate drafted to smuggle in a conclusion — that the extracted messages are the defendant's, that the artefacts show deliberate deletion — has crossed into opinion, and a certificate is the wrong vehicle for it. How that boundary constrains Rule 902(13) and 902(14) certifications specifically has not produced a settled body of appellate law, and a practitioner relying on one in a criminal trial should expect the question to be live rather than closed.
What about the copy standing in for the original?
Forensic practice almost never produces the original. It produces a forensically sound duplicate, and the evidentiary question is whether that duplicate may stand in. Rule 1003 permits a duplicate to be admitted to the same extent as the original unless a genuine question is raised about the original's authenticity, or the circumstances make it unfair to admit the duplicate. Hash verification is what converts a bare assertion that the copy is faithful into a demonstrable one, and it is why ISO/IEC 27037 and the SWGDE best practices for computer forensic acquisitions treat hash recording as a step you document rather than merely a step you perform.
Courts are not, however, impressed by theoretical alterability. People v. Goldsmith admitted automated traffic-enforcement photographs and video on an investigating officer's testimony, held that testimony from a technician with expertise in the system's computers was not a prerequisite, and declined to require a greater authentication showing for digital images merely because digital images can in theory be altered. Perceived errors in a particular computer's operation go to weight rather than admissibility unless specifically challenged. That is the practical answer to the cross-examination that begins "but digital files can be edited, can't they?"
How should a proponent actually build the record?
Working backwards from the failures above:
- Identify the claim. "This is a true copy of the phone's data" and "the defendant sent this message" are different claims requiring different proof. Decide which one the exhibit is offered to establish.
- Pick the subsection and match the evidence to it. Rule 901(b)(4) needs content, not identifiers. Rule 901(b)(9) needs evidence about the system's accuracy, not the examiner's résumé.
- Serve the Rule 902 notice early. Late notice converts a paper foundation into a witness you may no longer have available.
- Record the hashes at acquisition and preserve the tool logs. A verification hash computed months later from an image whose acquisition hash was never captured proves nothing about the source device.
- Build attribution separately. Login artefacts, device-account linkage, corroborating contemporaneous activity, admissions, and testimony from a participant in the conversation. This is the work Rule 902 cannot do for you.
- Anticipate the hearsay and best-evidence layer before the authentication argument is won, because winning it does not get the exhibit in.
The Sedona Conference Commentary on ESI Evidence and Admissibility and the FJC Reference Manual on Scientific Evidence are the two references most likely to be useful to a judge reading your brief, which is a reason to cite them in it. For lawyers who want the forensic side taught rather than absorbed by osmosis, the Digital Forensics for Lawyers track and the evidence-rules self-study path cover the same ground in sequence.
One closing caution about scope. The authentication case law on social-media and messaging evidence is state-court-heavy, and the standards, though textually similar, are not uniform in application — the Pennsylvania decisions in Koch and Mangel are visibly more demanding than Tienda in Texas on comparable records. If your forum has not spoken, treat the range as real and build to the stricter end.
Go deeper — courses on this
Digital ForensicsFrom Feed to Evidence: A Lawyer's Guide to Authenticating Social Media Posts
This course covers how social media data functions as litigation evidence, including how to access…
Daniel B. Garrie · 1h 1m
FreeDigital Forensics(Digital) Forensic Files: Computer Forensics (Part 2 of 2)
Part 2 of a two-part seminar covering how digital forensics reports are structured and produced, what…
Daniel B. Garrie
Digital ForensicsPremium(Digital) Forensic Files: Computer Forensics
A practical introduction to how digital evidence is collected, preserved, and contested, written for…
Daniel B. Garrie
Keep reading
- What a RAM Capture Proves That a Disk Image CannotOnly memory holds decrypted content, fileless code and live process context. The price is a capture that is unrepeatable and true of one ins…
- What a Forensic Hash Actually GuaranteesA hash proves the data has not changed since you computed it. It does not prove fidelity, authenticity, or that a mismatch means tampering.
- Regulation S-P: The Incident Response Obligations Advisers Keep MissingHow amended Regulation S-P works in practice: when the 30-day clock starts, what the notice must say, the 72-hour vendor rule, and the recor…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.