Industry Insights

FRE 902(13) and 902(14): Self-Authenticating Digital Photo Evidence

Since 2017, hash-verified copies of digital files can be authenticated by written certification instead of live testimony under Federal Rules of Evidence 902(13) and 902(14). What the rules say and how photo workflows produce the records they ask for.

ByLumethic Team
8 min read
Share

Authentication Before Admission

A disclaimer first: Lumethic builds software and does not give legal advice. This article describes two evidence rules and the records they refer to, so that photographers and legal teams can talk about the same things with the same words. How the rules apply to a specific matter is a question for the lawyers running it.

Under the Federal Rules of Evidence, an item must be authenticated before it is admitted: Rule 901 requires the proponent to produce evidence sufficient to support a finding that the item is what the proponent claims it is. For photographs, the traditional route is testimony, typically the photographer or another witness with knowledge stating that the image fairly and accurately shows what it claims to show.

For digital files there is a second layer of the same question. Beyond what the image shows, the proponent may need to establish that the file itself is what it is claimed to be: an unaltered copy of specific data. Historically this also ran through live testimony, often from a technical witness explaining collection and handling. That is the layer the 2017 amendments addressed.

What the 2017 Amendments Added

Rule 902 lists categories of evidence that are self-authenticating, meaning they require no extrinsic evidence of authenticity to be admitted. Effective December 2017, two categories were added for digital evidence.

Rule 902(13) covers a record generated by an electronic process or system that produces an accurate result, shown by a certification of a qualified person. Rule 902(14) covers data copied from an electronic device, storage medium or file, if authenticated by a process of digital identification, again shown by a certification of a qualified person. Both rules borrow their certification mechanics from the business records provisions, and both carry a notice requirement: the proponent must give the other side reasonable written notice and make the record and certification available for inspection, so objections can be raised before trial rather than during it.

The practical effect is that foundation which once required a live witness can be established by a written certification, provided the underlying process actually supports the certification's claims.

Rule 902(14) and Hash Verification

Rule 902(14) is the one that maps directly onto photographic practice, because it is about copies. The committee note names the mechanism the rule has in mind: identification by hash value. It describes a hash value as a number, usually written out as a sequence of characters, computed from the digital contents of a drive, medium or file, and treats identical hash values for original and copy as reliable attestation that the copy is an exact duplicate. The note also states the rule is flexible enough to accommodate other reliable identification processes that future technology may provide.

Read against a photography workflow, the rule describes a familiar operation. Files are copied from a memory card; checksums are computed; the copy is verified against the original. That is precisely what professional offload tools do on every card backup, and the manifest they write, a checksum list of every file, is the record of it. A qualified person can then certify that the copy was verified by hash comparison, and the certification stands in for testimony about the copying.

The strength of that certification depends on details the rule itself does not spell out. A checksum with known collision attacks invites an obvious challenge, which is why the checksum type in the offload tool matters; the checksum settings guide covers the difference. And a hash record that exists only in the proponent's hands leaves a timing question open: nothing outside the proponent's own records fixes when the list was made. An anchored offload receipt, where an independent timestamp authority countersigns the manifest on the day of the backup, closes that question with a date no party to the dispute controls.

Rule 902(13) and Process-Generated Records

Rule 902(13) addresses records generated by a process or system, and its committee note gives examples like machine-produced records and logs. In a photographic chain of custody, records of this character accumulate around the images: the manifest a transfer tool generates during a backup, and reports produced by an automated verification process, such as the output of a forensic RAW comparison that documents whether a delivered JPEG derives from its RAW without content manipulation.

For such a record, the certification speaks to the process: that the system produces an accurate result. Systems designed for this use make that certification easier to support, in the same way an audited clock supports a timestamp. A verification report whose every statement can be independently rechecked with standard cryptographic tools gives the certifying person something concrete to stand on.

What a Photo Workflow Must Produce

Working backwards from the rules, the workflow has to produce three kinds of records, all of them created at the time of the events rather than reconstructed later.

First, a hash record of the copying: the manifest written during the card offload, on a checksum that binds contents. Second, a fixed date for that record: the timestamp authority's countersignature on the manifest, which puts the existence of every file on the card beyond argument from the backup day onward. Third, documentation connecting delivered images to originals: verification reports for the selects that actually go to the legal team or become exhibits.

This is the same structure described in our chain of custody guide and implemented end to end in the legal evidence workflow. The point of building it during the shoot rather than after a challenge is simple: certifications describe records that exist. A record created contemporaneously, with independent dates, gives the certifying person clean statements to make. Reconstruction gives them qualified ones.

Because receipts and reports are shareable by link and verify without an account, the notice requirement's practical side, making the record available for inspection, costs nothing: the opposing side can check the same receipt and rerun the same verification the proponent relies on.

The Limits of Self-Authentication

Rule 902 removes one hurdle, not all of them. A self-authenticating record can still be challenged on relevance, hearsay, completeness or weight, and the opposing party can still contest the facts a certification asserts, which is part of what the notice period is for. Authentication of the file as an accurate copy also says nothing about whether the photograph fairly depicts the scene; that remains the photographer's testimony.

State courts have their own evidence rules. Many have adopted analogues of 902(13) and 902(14), many have not, and the details differ. Which rules govern a given matter, and what a certification there needs to contain, is exactly the kind of question to put to the attorneys running the case, ideally before the first shoot.

FRE 902 FAQ

Does Rule 902(14) make my photos automatically admissible? No. It can remove the need for live foundation testimony about the authenticity of a copied file. All other requirements for admission still apply, and the depicted content still needs its ordinary foundation.

Who is a qualified person for the certification? The rules require someone in a position to attest to the process, in the same manner as business records certifications. Who that should be in a concrete case is a decision for counsel.

Is a checksum list I generate myself enough? It is the starting point the rule contemplates. Its weight depends on the checksum's strength and on whether anything outside your own records fixes its date. An independently timestamped manifest addresses both.

Do these rules apply outside US federal courts? Directly, no. Rule 902 governs federal proceedings; states and other jurisdictions have their own rules, some similar and some not. The underlying records, hashes, timestamps and verification reports, are useful across jurisdictions even where the certification shortcut is not available.

Related Reading

#Legal#FRE 902#Digital Evidence#Chain of Custody#Hashing#Admissibility