Data Recovery Case File · Trust, Practice & Honest Limits · A Different Discipline
Reading a Timestamp Is Easy and Proving What It Means Is Not
Her enquiry asks for something narrower and harder than a recovery. "We need the date and time when photos were downloaded onto an external hard drive from a laptop. This is for a court hearing, as we need to prove exactly when these photos were put onto the drive. Can you do this, and also provide a report" of the evidence. The reading is straightforward and the proving is not — and what she actually needs is a forensic examiner instructed properly, not a recovery service.
| Media | External hard drive holding photographic content — file timestamps to be established and evidenced for proceedings; original transfer dating from over a decade previously |
| Reported situation | Photographs transferred from a laptop to an external drive some years previously · date and time of transfer required · requirement arising from court proceedings · written report of findings requested · evidential standard required |
| Fault class | Evidential examination rather than recovery — forensic imaging and expert reporting required; timestamp interpretation subject to material limitations |
| Equipment used | Requirement identified as forensic examination rather than recovery before any work · instruction route through the party's legal representatives established · forensic-standard imaging with hash verification · original medium not altered · findings and their limitations stated together |
The decode: what a timestamp is, and what it will not carry
What can be read: filesystems record times against each file — commonly when it was created, when it was last modified, and when it was last accessed. Those values exist and extracting them is simple.
What a creation timestamp on a destination drive actually records: when the filesystem on that drive made the entry. Which is a good proxy for when the file arrived there, and is not the same as when the photograph was taken, nor evidence of who performed the copy, nor of which machine it came from.
Why that distinction matters in proceedings: the question she describes is when photographs were put onto the drive, and a creation timestamp addresses that reasonably directly. But it is a record made by a computer, and records made by computers can be altered — trivially, by changing a system clock before copying, or by tools that set timestamps to any value.
So what an examiner can honestly say: what the timestamps are, whether they are internally consistent with each other and with other artefacts on the drive, and whether there are signs of manipulation. Consistency across independent records is what makes a timestamp persuasive, rather than the timestamp alone.
Why the corroboration is where the real work is: a drive holds far more than file dates — filesystem journals, allocation patterns, and other artefacts that either agree with the timestamps or do not. An examination that only reads the dates is not worth much; one that tests them against everything else is.
What matters procedurally, and it should happen first: examination for proceedings should be instructed through her legal representatives, so that the examiner is properly instructed, the scope is defined, and the report meets the requirements for expert evidence. Work commissioned informally beforehand can complicate matters, and the report format required by a court is specific.
What must happen to the drive meanwhile, and this is the urgent part: nothing. Every connection updates access times and may alter the very records in question — so it should be left disconnected until it is imaged to a forensic standard with the original unaltered.
The honest summary: a recovery service can image it properly; the report needs somebody who will stand behind it.
On the bench
The requirement was identified as forensic examination rather than recovery before any work — timestamps being readable trivially while their evidential weight depends on corroboration against filesystem journals, allocation patterns and other independent artefacts, since system clocks and timestamps can both be altered. The instruction route through the party's legal representatives was established, and forensic-standard imaging with hash verification performed with the original medium unaltered.
The outcome
The requirement identified as forensic rather than recovery, instruction routed appropriately, and imaging performed to a forensic standard with the original unaltered. Free assessment, one fixed written figure including VAT. The decode: reading the timestamps is simple. What carries weight is whether they agree with everything else on the drive, because a date recorded by a computer can be altered — and for proceedings you need an examiner instructed through your solicitors who will stand behind the report.
Needing file dates as evidence
Disconnect the drive and leave it alone — every connection updates access times and may alter the records you're relying on. Then instruct through your solicitors rather than commissioning informally, because an examiner needs a defined scope and the report has to meet the requirements for expert evidence. Understand what a timestamp carries: a creation date records when the filesystem made the entry, which is a reasonable proxy for when a file arrived, but not who copied it or from where — and it can be altered by changing a clock. What makes it persuasive is corroboration against journals and allocation patterns that either agree with it or don't.
Leave the drive disconnected — call Oxford Data Recovery on 01865 593000; forensic-standard imaging with hash verification, original unaltered, and an honest account of what timestamps can and cannot carry.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.