Last week I read a post from someone closing a LinkedIn group. It had more than fifty thousand members. Fewer than a hundred of them ever saw a new post, because the platform decides who hears you, and for that group it had mostly decided no. The owner was not angry at the members. They had run out of reasons to keep talking in a room where the microphone was off.
I have been thinking about that post for a reason that has nothing to do with social media. It is about where a professional field talks to itself, and that question has a long history in evidence law. It starts with a phrase every examiner eventually says on the stand, and a question a good cross-examiner asks in reply.
The phrase is "generally accepted." The question is "by whom?"
Where the phrase comes from
In 1923 the Court of Appeals for the District of Columbia decided a murder appeal in which the defense had offered an expert on the systolic blood pressure deception test, a crude ancestor of the polygraph. The court kept the expert out, and in doing so wrote the sentence that set the standard for scientific evidence in American courts for the next seventy years: "the thing from which the deduction is made must be sufficiently established to have gained general acceptance in the particular field in which it belongs."
That is Frye v. United States, and it is a short opinion. The court did not explain how a judge is supposed to find out what a field accepts. It assumed the field had a place where acceptance could be observed: journals, societies, textbooks, people who could be asked.
Seventy years later the Supreme Court decided Daubert v. Merrell Dow Pharmaceuticals and held that the Federal Rules of Evidence had displaced Frye as the exclusive test. Daubert asked judges to consider whether a technique "can be (and has been) tested," whether it has been "subjected to peer review and publication," its "known or potential rate of error," and "the existence and maintenance of standards controlling the technique's operation." But the Court did not throw general acceptance away. It kept it as a factor: "Widespread acceptance can be an important factor in ruling particular evidence admissible, and 'a known technique that has been able to attract only minimal support within the community' may properly be viewed with skepticism."
Six years after that, Kumho Tire v. Carmichael extended the same gatekeeping to testimony based on "technical" and "other specialized" knowledge, which is where digital forensics lives. It described the goal in a sentence worth memorizing. The point is to make certain that an expert "employs in the courtroom the same level of intellectual rigor that characterizes the practice of an expert in the relevant field."
Several states still apply Frye outright. Federal courts and most of the rest apply Daubert through Rule 702, which since December 2023 requires the proponent to show, more likely than not, that the testimony "is the product of reliable principles and methods" and "reflects a reliable application of the principles and methods to the facts of the case." Either way, the practice of the field is part of the test, which means that sooner or later someone gets to ask what the field actually does, and how you know.
Why the question is hard in our field
In DNA typing the answer is long, published, and decades old. In digital forensics the answer is harder, for a reason that has nothing to do with the quality of the work.
The method changes under us. An operating system update moves where an artifact lives. An application update changes how it is stored. A tool update changes what the parser recovers, and occasionally what it recovers wrongly. A technique that was generally accepted in March can be quietly obsolete by September, and the people who know that are the people who ran into it last week.
So where does acceptance in digital forensics actually get recorded?
Some of it is formal, and the formal record is better than it used to be. The Scientific Working Group on Digital Evidence publishes consensus documents, from best practices for evidence collection and mobile device analysis to requirements for report writing, and states its objective as fostering "communication, cooperation, consistency, and quality within the forensic community through consensus-based documents." NIST's Organization of Scientific Area Committees keeps the OSAC Registry, a repository of forensic standards that have been through a technical and quality review, with a Digital Evidence subcommittee and SWGDE documents on it. NIST's Computer Forensics Tool Testing program tests tool functions against written specifications and publishes the reports. Those are citable. You can put a document number and a version in a report and hand it across the table.
But most of what a working examiner actually knows about tool behavior was never in any of those documents. It came from a vendor forum thread, a closed listserv, a Discord server, a conference hallway, or a text from a colleague at another lab who hit the same parsing problem the week before. That is where "this version double-counts these records" and "this build drops the time zone on this artifact" get discovered and shared. It is real knowledge, and it is the closest thing our field has to a living record of what practitioners accept and reject.
It is also fragile in every way that matters under oath. It sits behind logins. It cannot be cited. It disappears when a platform changes its mind, or when an algorithm decides that fewer than a hundred of fifty thousand people should see it. And when a cross-examiner asks how you know the method you used is the one the field uses, "I saw it on a forum" is a sentence you do not want to hear yourself say.
How to answer "by whom" on the stand
The answer that holds up is layered, and you should be able to give it in order of strength.
First, a published standard or best-practice document that describes the method, cited by number and version. SWGDE and OSAC documents, NIST publications, and the vendor's own documentation where it states what a function does and does not do.
Second, testing. A CFTT report on the tool function you used, if one exists, and your own lab's validation record for that tool, at that version, on that class of device. This is the layer Daubert put first, and it is the one most often missing.
Third, peer-reviewed literature, where it exists. In this field it is thinner than in others, and it is honest to say so. A court can weigh a thin literature, but not a pretended one.
Fourth, documented practice: other labs' procedures, training curricula, and the record of practitioners converging on a method. This is where general acceptance actually lives day to day, and it is the layer most examiners can only gesture at.
Two things not to say. Do not say "everyone does it this way" unless you can name someone. And do not say "the tool is the industry standard," because market share is a fact about the vendor, not about the method. I wrote a whole issue about that one, and it still gets said.
One distinction to keep straight: acceptance is not validation. A room full of practitioners can tell you what they do. Only testing tells you it works. Use the field's practice to decide what to test, and use your own validation record to show that it does.
How to ask the question without giving away the case
Here is the part that is practical for Monday morning.
Most examiners do not ask method questions in public because they cannot describe the problem without describing the case. That constraint is real and it should be. The discipline is to strip the matter and keep the technical shape.
Leave out: case and docket numbers, names, dates, device identifiers, hashes, exhibit numbers, the facts of the matter, and anything that would let a reader guess whose phone it was.
Keep: the platform and operating system version range, the application and version if you know it, the artifact type, the tool and version, what you expected to see, what you saw instead, and what you have already tried.
"How do you validate deleted message recovery for this messaging app on this OS version, and has anyone seen version X of this tool report a different count than version Y?" is a question you can ask anywhere. "In my case the phone showed..." is not.
Then treat the answer as a lead, not a finding. Take it back to your bench and test it on known data before it touches casework. Write the test into your validation record: date, tool and version, data set, what you checked, what you got, and where the idea came from. Now, when counsel asks "accepted by whom?", you have a document rather than a memory of a forum post. You also have something the field can use, because a validation record written without case facts can be shared.
When I mentor examiners overseas through the State Department's ATA program, the person in front of me is often one of only a handful in their whole agency doing this work. Their relevant community fits in a group chat. The question I hear most has nothing to do with a tool: has anyone else seen what I am seeing? Small agencies feel it first, but it is the shape of the whole field.
A room where the members decide
That brings me back to the post about the closed group.
I have opened a members community for people who have to make digital evidence hold up: examiners, investigators, prosecutors, defense counsel, expert witnesses, and students of my courses. It runs on Discourse, a forum platform, rather than on a social network, for one reason above the others. Every member chooses how they hear from it, by weekly digest, by email reply, or not at all, and the room honors that choice. A post reaches the people who opted in, not the people an algorithm selected.
There are four public rooms: Court-Ready Method, Tools and Validation, Report Writing and Testimony, and Training and Careers. Public topics are readable and searchable without an account, so an answer given once stays findable. There are four house rules, all of them about protecting people, and the first is the one this issue is about: no case material, ever. Ask the general question instead. Posts that cross the line are hidden and the author is told exactly what to remove so it can be reposted.
An assistant, clearly labeled as an AI, reads each new public post within about a minute. It screens for case material and personal data, gives a short first pointer on questions, and flags anything that needs a practitioner to the hosts. It is not me, it gives no legal or forensic advice, and it never has the last word. I read the room every week.
Joining is free with an email address, and if you are a student in any of my courses your course login already works there. The two questions this issue keeps circling, how you validate a tool version change and what belongs in the record, each have a thread open in Tools and Validation:
community.thewaldrepcompany.com/t/how-do-you-validate-a-tool-version-change/23
community.thewaldrepcompany.com/t/what-goes-in-your-validation-record/24
The front door is here:
community.thewaldrepcompany.com
The field has to meet somewhere. Make sure the record of what it accepts is one you can hand across the table.
Take it further
A housekeeping note first, because it has a date on it. On October 1 the two fundamentals courses, Computer Forensics Fundamentals and Mobile Device Forensics Fundamentals, move from $497 to $697 each. Drone Forensics for Law Enforcement stays $997, the Certified OSINT Investigator, Court-Ready Practitioner program stays $2,497, and All-Access stays $2,997. The $497 price holds through 11:59 pm Central on Wednesday, September 30. The reason is plain: the courses include more than they did at launch, including the full template libraries, the 30-Day Look guarantee in writing, and the tuition-credit path into All-Access. I do not plan to discount them back.
If your training money moves through a purchase order, September 30 is also the federal fiscal close, which makes this the busiest week of the year for a procurement office. Written agency quotes issued before the change hold their price for 90 days. If a quote in hand would help you get it through, email info@thewaldrepcompany.com and I will send one, along with a W-9 or a sole-source letter if your file needs them.
Course pages: Computer Forensics Fundamentals · Mobile Device Forensics Fundamentals
All-Access is all four online courses in one enrollment: four separately verifiable certificates, 86 CPE hours, every template library we teach from, and twelve months of access per course. All four are listed in the CISA National Initiative for Cybersecurity Careers and Studies (NICCS) Education and Training Catalog; a listing is not an endorsement, but it is often what a training officer needs to see. Purchased separately, the four courses total $4,488 today and $4,888 from October 1. All-Access is $2,997 either way, so the arithmetic gets better after the change, not worse. Government purchase orders, net-30 invoicing, and agency licensing are available, and if you already bought one of the four, your tuition credits in full toward the bundle for 90 days: email info@thewaldrepcompany.com from your enrollment address and we will send an upgrade link for the difference.
If this issue was useful, subscribe to Digital Forensics Today below and send it to the examiner who is about to be asked "accepted by whom?", or to the attorney who is about to ask it. Every issue is about doing OSINT and digital forensics that stands up when someone asks how you know.
Sources and further reading
- Frye v. United States, 293 F. 1013 (D.C. Cir. 1923). static.case.law/f/293/html/1013-01.html
- Daubert v. Merrell Dow Pharmaceuticals, Inc., 509 U.S. 579 (1993). www.law.cornell.edu/supct/html/92-102.ZO.html
- Kumho Tire Co. v. Carmichael, 526 U.S. 137 (1999). www.law.cornell.edu/supct/html/97-1709.ZO.html
- Fed. R. Evid. 702, as amended effective December 1, 2023. www.law.cornell.edu/rules/fre/rule_702
- Scientific Working Group on Digital Evidence, published documents and stated objective. www.swgde.org/
- NIST, Organization of Scientific Area Committees for Forensic Science, OSAC Registry. www.nist.gov/organization-scientific-area-committees-forensic-science/osac-registry
- NIST, Computer Forensics Tool Testing Program (CFTT). www.nist.gov/itl/ssd/software-quality-group/computer-forensics-tool-testing-program-cftt
- Digital Forensics Today Community, house rules. thewaldrepcompany.com/community/#guidelines
- Earlier issue referenced: Nobody Cross-Examines the Tool. thewaldrepcompany.com/newsletter/nobody-cross-examines-the-tool/