Gates Rubber Company v. Bando Chemical Industries, Ltd., et al. [1] is a decision by the U.S. district court for the District of Colorado from May 1, 1996. It is considered a landmark decision [2] in terms of expert witness court testimony in questions of electronic evidence [3] and digital forensics.
In a nutshell, the decision states that the authenticity [4] of electronic evidence is accepted by courts only if the party adducing the evidence complied with the newest technical standards of electronic evidence acquisition. [5] Moreover, U.S. magistrate judge Schlatter commented on the factors he considered relevant in the process of weighing the qualifications of digital forensics experts when those present contrary opinions or conclusions to the court. Hence, Gates v Bando has set legal standards for examining electronic evidence that have remained relevant to this day. [6]
Gates Rubber Company and Bando Chemical Industries were both involved in the manufacture of industrial belts as direct competitors. Several defendants aside from Bando were former employees of Gates, who had signed written non-competition agreements before they left the company. In 1989, Gates learned that the latter used a computer program highly similar to one of its own, so that Gates suspected its former employees had stolen, copied and used it for Bando. Accordingly, Gates filed several actions on the grounds of unfair competition, misappropriation of trade secrets, infringement of copyright, and breach of contract. [7]
During the court proceedings, in 1992 Gates learned that N., one of its former employees, deleted a computer program from his computer at Bando, which Gates claimed to be an unauthorized copy of a copyright-protected software of his own. Furthermore, (and actually decisive as regards the influence of digital forensics in trial), N. also "deleted" several word-processing files on the same computer, testifying that he did not erase any materials relevant to the pending litigation. Consequently, Gates applied for disclosure, in order to examine whether or not the defendant had maliciously deleted files in an attempt to destroy evidence. The court granted Gates a court order that allowed Gates to copy the hard drive of Newman's computer in order to obtain as much information as possible from the "deleted", but reconstructible files. Gates then assigned the technician V. to execute the copying of the hard drive, whereas he subsequently also appeared as Gate's expert witness in the court procedure.
In retrospect, the technical method V. applied to create a copy of the hard drive of N.'s computer as well as his formal professional qualification as a digital forensics expert (particularly in comparison to the expert witness summoned by the defendant) turned out to be the crucial aspects that were decisive for the outcome of Gates claims arising from Bando's alleged violation of disclosure obligations through spoliation.
In the course of his examination, V. copied a software onto the hard drive of N.'s computer (which contained the evidentiary electronic files), in order to create a file-by-file copy of the hard drive. This conduct induced the court to extensively comment on the forensic methods that must be applied to electronic evidence to allow it to be used as a piece of evidence in court procedure:
First, the court stated that - as a general rule - any digital forensic examiner shall be obliged to "utilize the method which would yield the most complete and accurate results" [8] in order to comply with the legal prerequisites in regard to the admissibility of evidence in court procedure. As a result, several organizations started to continuously publish best practice literature for electronic evidence acquisition. [9] However, it should be kept in mind that such a best practise prerequisite must be considered a dynamic procedural hurdle, as the technical requirements and possibilities in analyzing and copying digital data change with the underlying hard- and software, and consequently the technical procedures to be applied in order to create a legally permissible piece of electronic evidence may change in the future.
Second, the judge held that the file-by-file copying procedure applied by Gates' forensic examiner fails to fulfil the court's "best practice" requirement. Instead, it had been necessary for a forensic investigation de lege artis to copy the hard drive by means of creating an image (or: mirror) copy:
"Gates retained V. as its technician to do the copying, and he attempted to do this through the use of a program called Norton's Unerase. Proper use of the program could yield information, or partial pictures, about files which were once present on the computer's hard drive, but were deleted.
Gates argued that V. did an adequate job of copying the Denver computer. W. (the defendant's expert witness, remark of author) persuaded me, however, that V. lost, or failed to capture, important information because of an inadequate effort. In using Norton's Unerase, V. unnecessarily copied this program onto the Denver computer first, and thereby overwrote 7 to 8 percent of the hard drive before commencing his efforts to copy the contents... Additionally, V. did not obtain the creation dates of certain of the files which overwrote deleted files. This information would have assisted in determining the deletion date of some files.
W. pointed out that V. should have done an "image backup" of the hard drive, which would have collected every piece of information on the hard drive, whether the information was allocated as a file or not. Instead, V. did a "file by file" backup, which copies only existing, nondeleted files on the hard drive. The technology for an image backup was available at the time of these events, though rarely used by anyone...
I find that the duty was on Gates, and not Bando, to utilize the best technology available." [10]
The standards outlined above have become the general standards in computer forensic examination. [11] According to these statements, electronic data, which is recovered from computer hard disk (or any other form of electronic storage unit for digital information) is permitted to be used in court procedures only, if the data is duplicated and verified in a forensically sound manner. The forensic examiner in Gates v Bando (V.) failed to create such a forensically sound duplication since the installation of the examiner's software could have overwritten existing files on the hard drive, this is the constitution of the evidence was altered even before the copy was made. Correct duplication, however, requires that any alteration of the data during the process of copying is reliably excluded. This requires that: [12]
In practise, proper duplication is usually warranted by write-blocking of the original storage device. [13] Correct verification means that the electronic evidence presented to the court must be provably identical to the one originally investigated, which usually is warranted by means of a hash value, an algorithm that calculated a number based on the content of the respective piece of electronic evidence. [14] In the present, compliance with this "best practise" requirement can usually be achieved by using a proprietary software for imaging, as this will admittedly preserve the evidential value of the electronic information recovered. [15]
Expert qualifications are considered by both lawyers and experts to be very important, and in the case of Gates v Bando, the court reaffirms that widely accepted belief. [16] Judge Schlatter stated in this context:
"Bando's expert on matters associated with computer science was W., who holds a Ph.D. in computer science from Stanford. W.'s credentials, experience and knowledge were impressive, and I relied upon his opinions. Gates failed to obtain a similar expert in timely fashion. Gates did offer the testimony of V., the technician who was hired by Gates to copy the hard drive of the computer at Bando's Denver facility. His credentials, experience and knowledge were nowhere near those of W., and I placed much less weight on his testimony than on W.'s." [17]
The court strongly relied on the experts' formal professional qualification, as it was obviously the most distinguishable criterion in this case. However, most cases in litigation are not that unambiguous. Then, the factor of an expert's actual professional appearance - including but not limited to the ability to impart non-legal knowledge to the court, the thoroughness of the report and the traceability of the expert's inferences - will play a larger role. Additionally, a major practical issue for judges dealing with issues of electronic evidence remains in the lack of measurability of IT expertise, partly due to the absence of uniform formal professional qualification [18] in this field. [19]
The case of Gates v Bando surely highlights the necessity of selecting a given digital forensics expert carefully when it comes to civil litigation involving digital evidence issues, as such expert's opinion often turns out to be decisive for the outcome of a case. But the parties' due diligence in such cases even goes further: it is not only the selection of an expert witness in the litigation stage, but already in the pre-litigation phase attorneys and experts are obliged to ensure the correct acquisition of electronic evidence which is potentially relevant to their case. Moreover, they have to develop and apply an evidential reasoning that could both professionally withstand an opponent forensic expert's testimony and factually persuade the judge and/or the jury in the courtroom.
Apart from that, the course of the court procedure has (relatively early [20] ) illustrated the potential economic impact of E-discovery issues on litigation: originally initiated as a secondary theatre of war in an IP litigation, these issues soon snowballed to a case of its own that finally achieved economically and temporally dimensions exceeding the original matter in dispute. Today, more than 90% of all corporate information is stored electronically. [21] Typically enough, digital forensics has become a big business with an estimated market value of 780 Mio. $ in 2011. [22] Generally speaking, the outcome of an increasing number of cases in all fields of law will depend on issues of digital evidence. [23]
To the same extent which Gates v Bando illustrates the necessity for litigation parties to carefully plan and execute a sophisticated strategy in terms of electronic evidence, however, it must be realized that it ultimately describes a recurrent practical problem: as IT and its relating tools and techniques will progress and the courts will (presumably) carry on to demand the application of the very best method available to warrant an electronic evidence's authentity, the absence of commonly court-accepted standards will emerge again and again. One potential solution for litigators to avoid the repeated occurrence of this issue might lie in entering into pre-trial agreements with their opponent, in which they agree upon certain conditions for the mutual recognition of their electronic documents' authenticity. [24]
Reliability of digital evidence in general:
Authentification of E-mails:
Authentification of electronic document printouts:
Authentification of website-content:
An expert witness, particularly in common law countries such as the United Kingdom, Australia, and the United States, is a person whose opinion by virtue of education, training, certification, skills or experience, is accepted by the judge as an expert. The judge may consider the witness's specialized opinion about evidence or about facts before the court within the expert's area of expertise, to be referred to as an "expert opinion". Expert witnesses may also deliver "expert evidence" within the area of their expertise. Their testimony may be rebutted by testimony from other experts or by other evidence or facts.
A deposition in the law of the United States, or examination for discovery in the law of Canada, involves the taking of sworn, out-of-court oral testimony of a witness that may be reduced to a written transcript for later use in court or for discovery purposes. Depositions are commonly used in litigation in the United States and Canada. They are almost always conducted outside court by the lawyers themselves, with no judge present to supervise the examination.
Attorney–client privilege or lawyer–client privilege is the common law doctrine of legal professional privilege in the United States. Attorney–client privilege is "[a] client's right to refuse to disclose and to prevent any other person from disclosing confidential communications between the client and the attorney."
Discovery, in the law of common law jurisdictions, is a pre-trial procedure in a lawsuit in which each party, through the law of civil procedure, can obtain evidence from the other party or parties by means of discovery devices such as interrogatories, requests for production of documents, requests for admissions and depositions. Discovery can be obtained from non-parties using subpoenas. When a discovery request is objected to, the requesting party may seek the assistance of the court by filing a motion to compel discovery.
Computer forensics is a branch of digital forensic science pertaining to evidence found in computers and digital storage media. The goal of computer forensics is to examine digital media in a forensically sound manner with the aim of identifying, preserving, recovering, analyzing and presenting facts and opinions about the digital information.
In United States federal law, the Daubert standard is a rule of evidence regarding the admissibility of expert witness testimony. A party may raise a Daubert motion, a special motion in limine raised before or during trial, to exclude the presentation of unqualified evidence to the jury. The Daubert trilogy are the three United States Supreme Court cases that articulated the Daubert standard:
In evidence law, digital evidence or electronic evidence is any probative information stored or transmitted in digital form that a party to a court case may use at trial. Before accepting digital evidence a court will determine if the evidence is relevant, whether it is authentic, if it is hearsay and whether a copy is acceptable or the original is required.
Demonstrative evidence is evidence in the form of a representation of an object. This is, as opposed to, real evidence, testimony, or other forms of evidence used at trial.
Digital forensics is a branch of forensic science encompassing the recovery, investigation, examination, and analysis of material found in digital devices, often in relation to mobile devices and computer crime. The term "digital forensics" was originally used as a synonym for computer forensics but has expanded to cover investigation of all devices capable of storing digital data. With roots in the personal computing revolution of the late 1970s and early 1980s, the discipline evolved in a haphazard manner during the 1990s, and it was not until the early 21st century that national policies emerged.
In United States law, the Frye standard, Frye test, or general acceptance test is a judicial test used in some U.S. state courts to determine the admissibility of scientific evidence. It provides that expert opinion based on a scientific technique is admissible only when the technique is generally accepted as reliable in the relevant scientific community. In Daubert v. Merrell Dow Pharmaceuticals, 509 U.S. 579 (1993), the U.S. Supreme Court held that the Federal Rules of Evidence superseded Frye as the standard for admissibility of expert evidence in federal courts. Some states, however, still adhere to the Frye standard.
Richardson v. Perales, 402 U.S. 389 (1971), was a case heard by the United States Supreme Court to determine and delineate several questions concerning administrative procedure in Social Security disability cases. Among the questions considered was the propriety of using physicians' written reports generated from medical examinations of a disability claimant, and whether these could constitute "substantial evidence" supportive of finding nondisability under the Social Security Act.
EnCase is the shared technology within a suite of digital investigations products by Guidance Software. The software comes in several products designed for forensic, cyber security, security analytics, and e-discovery use. EnCase is traditionally used in forensics to recover evidence from seized hard drives. It allows the investigator to conduct in-depth analysis of user files to collect evidence such as documents, pictures, internet history and Windows Registry information.
Denise Louise Cote is a senior United States district judge of the United States District Court for the Southern District of New York.
Zubulake v. UBS Warburg is a landmark decision in the area of electronic discovery and the burden of costs for such discovery. It was released on May 13, 2003 and was written by Judge Shira A. Scheindlin of the United States District Court for the Southern District of New York. It is the first in a series of Zubulake judgements relating to discovery issues, and is also referred to as "Zubulake I". See section "Other Proceedings" for information on other Zubulake decisions.
The digital forensic process is a recognized scientific and forensic process used in digital forensics investigations. Forensics researcher Eoghan Casey defines it as a number of steps from the original incident alert through to reporting of findings. The process is predominantly used in computer and mobile forensic investigations and consists of three steps: acquisition, analysis and reporting.
RealNetworks, Inc. v. DVD Copy Control Association, Inc., 641 F. Supp. 2d 913 (2009), is a United States District Court case involving RealNetworks, the movie studios and DVD Copy Control Association regarding the Digital Millennium Copyright Act (DMCA) claims on the manufacturing and distribution of RealDVD, and a breach of license agreement. The district court concluded that RealNetworks violated the anti-circumvention and anti-trafficking provisions of the DMCA when the DVD copying software RealDVD bypasses the copy protection technologies of DVD.
Einstein v 357 LLC is a United States New York Supreme Court landmark decision which addresses a party's discovery obligations and the safeguarding of evidence. In particular, this decision addresses the issue of the intentional destruction of digital evidence when litigation has commenced or is reasonably anticipated. In short, this decision eradicates the excuse of ignorance in terms of how electronically stored information is saved, deleted, and retrieved.
Andy Johnson-Laird is an English-American computer scientist. He was the president of digital forensics firm Johnson-Laird Inc. in Portland, Oregon, where he lived with his wife, Kay Kitagawa.
The Trojan horse defense is a technologically based take on the classic SODDI defense, believed to have surfaced in the UK in 2003. The defense typically involves defendant denial of responsibility for (i) the presence of cyber contraband on the defendant's computer system; or (ii) commission of a cybercrime via the defendant's computer, on the basis that a malware or on some other perpetrator using such malware, was responsible for the commission of the offence in question.
Audio forensics is the field of forensic science relating to the acquisition, analysis, and evaluation of sound recordings that may ultimately be presented as admissible evidence in a court of law or some other official venue.