Digital Evidence in Colorado Criminal Cases: Rules, Authentication, and Defense Strategies
By H. Michael Steinberg, A Colorado Criminal Defense Lawyer – Practicing Colorado Criminal Law in the courts of Colorado for over 40 years.
Introduction
Colorado criminal courts now see digital evidence in the majority of criminal prosecutions — from text messages and surveillance footage to social media posts and GPS location data. Understanding how that evidence is admitted, challenged, and potentially suppressed may make the difference between a conviction and a dismissal.
As is often the case in Colorado and in many criminal courts across our nation, the criminal justice system is slow to respond to the challenges posed by advances in technology, especially when those advances provide key evidence that may assist the state in establishing facts, identifying suspects, corroborating witness testimony, or reconstructing events.
Law enforcement provides prosecutors with social media content and other forms of digital evidence because it reveals communications, timelines, locations, and relationships relevant to a case.
As a criminal defense lawyer, it is clear that there are significant legal defense and even public concerns:
- Privacy: Many people worry that extensive collection of social media and messaging data gives government investigators too much access to personal communications.
- Authenticity and reliability: Digital messages can be altered, taken out of context, authored by someone else using an account, or misunderstood. Courts therefore require authentication before admitting such evidence.
- Fairness and bias: Critics argue that prosecutors may selectively present social media content that paints defendants negatively, while equally relevant contextual information may be overlooked or even intentionally left out.
- Influence of social media on justice: Studies have found concern that social-media-driven discussion of criminal cases can encourage “trial by public opinion,” vengeance-oriented attitudes, and pressure on the justice system.
What Counts as Digital Evidence in Colorado?
Digital evidence — sometimes called electronic evidence — is any data stored or transmitted in binary form that a party seeks to introduce at trial.
In Colorado criminal courts, that category includes:
- Text messages and direct messages (SMS, iMessage, WhatsApp, Snapchat).
- Emails.
- Social media posts, stories, and private messages (Facebook, Instagram, X/Twitter, TikTok).
- Photographs, audio recordings, and video (including body-worn camera footage and surveillance clips).
- Phone and computer metadata (GPS coordinates, timestamps, IP addresses).
- Cell-site location information (CSLI).
- Cloud storage files and deleted file remnants.
- Financial transaction records and browser history.
Each of the above categories raises distinct legal questions. Before any piece of digital evidence reaches a jury, it must clear multiple evidentiary hurdles under the Colorado Rules of Evidence (CRE) and, in some cases, constitutional protections under the Fourth Amendment.
The Threshold Question: Authentication Under Colorado Rule of Evidence – CRE 901
What Colorado Rule of Evidence (CRE) 901 Requires
Authentication is the gateway through which every exhibit — digital or otherwise — must pass. Colorado Rule of Evidence 901(a) states that the authentication requirement “is satisfied by evidence sufficient to support a finding that the matter in question is what its proponent claims.”
The standard is deliberately flexible: CRE 901 does not mandate any single method, and courts routinely remind parties that metadata, hash values, and forensic images are ways to meet the standard, not requirements written into the rule itself.
The rule, CRE 901(b, then lists non-exhaustive illustrative methods. The subsections most frequently applied to digital evidence are:
The Authentication Standard Is Not The Same as the Burden of Proof
One critical distinction practitioners must internalize: authentication is not the same as the burden of proof at trial. A court ruling that an exhibit has been sufficiently authenticated does not mean it is true, accurate, or that it proves guilt. The prosecution still must establish guilt beyond a reasonable doubt under C.R.S. § 18-1-402. Authentication only determines whether the jury gets to see and evaluate the evidence at all.
Common Authentication Issues
Courts in Denver, Jefferson, Arapahoe, and Douglas counties regularly see digital exhibits challenged on authentication grounds. Recurring problems include:
- Unreviewed metadata — Failing to explain file origin, creation date, or device serial number leaves the foundation wide open to attack.
- Gaps in handling records — While CRE 901 does not expressly require a chain of custody, gaps in handling records provide grounds to argue tampering.
- Bare screenshots — A screenshot of a social media post with no corroborating account information, login history, or testimony is frequently insufficient on its own.
- No process evidence — Introducing a forensic extract without testimony or documentation about the software used to produce it risks exclusion under subsection (b)(9).
Self-Authentication: CRE 902 and the 902(14) Certification
Traditional Self-Authentication Categories
CRE 902 removes the foundational witness requirement for certain categories of documents. Those most relevant to digital evidence include:
- CRE 902(4): Certified copies of public records (court documents, government databases)
- CRE 902(11): Certified domestic records of regularly conducted activity — the business records pathway. A custodian’s sworn affidavit certifying that a record was made at or near the time of the event, was kept in the ordinary course of business, and was created as a regular practice allows the record in without a live foundational witness.
The 2024–2025 Addition: CRE 902(14) and Hash-Value Declarations
Colorado’s adoption of language paralleling Federal Rule of Evidence 902(14) represents the most significant recent shift in digital evidence practice. Under this framework, electronic records may be self-authenticated when accompanied by a written certification from a qualified person that:
- Identifies the file
- Specifies the cryptographic algorithm used (industry standard: SHA-256)
- States the hash digest value
- Identifies the device and software used
- Attests to the declarant’s qualifications
In practice, this means a firm that captured a verifiable SHA-256 hash at the moment of acquisition — and stored it in a tamper-evident log — can authenticate video, audio, or document evidence without calling a live forensic expert to the stand. That single change dramatically reduces trial costs and shifts authentication disputes from courtroom testimony to pretrial motion practice.
Chain of Custody Issues for Digital Evidence in Colorado
Why Chain of Custody Matters Even Though CRE 901 Doesn’t Require It
The chain of custody is not expressly mentioned in CRE 901. Yet it remains one of the most litigated aspects of digital evidence because gaps in the record of who handled a device or file create a powerful argument that the evidence was altered. A complete chain of custody does not guarantee admission; an incomplete one practically guarantees a challenge.
Best Practices in Digital Evidence Preservation
Colorado law enforcement agencies and forensic professionals follow a tiered preservation model:
- Forensic imaging at acquisition — A bit-for-bit copy of the original device is made using write-blocking hardware, so the original is never modified.
- Cryptographic hashing — A SHA-256 (or SHA-512) hash of the original file is generated immediately at intake and recorded in a tamper-evident log.
- Metadata capture — EXIF data, GPS coordinates, codec information, creation timestamps, and device serial numbers are extracted and stored alongside the hash.
- WORM storage — Write-once-read-many storage for the master copy prevents post-acquisition modification and simplifies chain-of-custody testimony.
- Access logging — Every transfer, copy, or access event is logged with who, when, and what hash value was verified.
C.R.S. § 16-3-303.5: Location Data Warrant Requirement
Colorado imposes a statutory warrant requirement for cell phone location data. Under C.R.S. § 16-3-303.5, a government agency generally may not obtain an electronic device’s location information — including GPS data, cell-site location information, and Wi-Fi/Bluetooth tracking data — without a search warrant, subpoena, or court order. Evidence obtained in violation of this statute is not admissible in any civil, criminal, or administrative proceeding. This is a bright-line suppression remedy that Colorado defense attorneys routinely pursue when the government relies on location evidence.
Social Media Evidence: The Unique Challenges
Authentication of Social Media Posts
Social media evidence sits at the intersection of several evidentiary problems. A screenshot of a Facebook post, Instagram story, or X/Twitter message is not self-proving. Colorado courts require the proponent to tie the content to the claimed account owner using one or more of these methods:
- Distinctive characteristics (CRE 901(b)(4)): Content that uses the defendant’s known nickname, references facts only the defendant would know, or is stylistically consistent with the defendant’s known communications.
- Testimony from someone with knowledge (CRE 901(b)(1)): The person who sent or received the message, or an investigator who directly accessed and captured the account.
- Platform compliance records: Account registration data (name, email, phone number, IP address at registration) obtained through a subpoena or court order to the platform can corroborate that the account belongs to the defendant.
- Login and access logs: IP address logs showing the account was accessed from devices associated with the defendant.
A bare screenshot — with no corroborating account metadata, no witness testimony, and no investigative documentation — is frequently insufficient and subject to exclusion.
The Fabrication Problem
Unlike a physical document, a social media screenshot can be edited with consumer-grade tools. Colorado defense counsel now routinely challenge social media exhibits by demanding the platform’s native export files rather than screenshots, and by requesting the government’s complete capture methodology.
The rise of AI-generated deepfakes and manipulated content has sharpened judicial scrutiny of image and video exhibits. This is precisely why the SHA-256 workflow under CRE 902(14) has become standard practice: a hash captured at the moment of acquisition is the only reliable proof that a media file has not been altered between collection and trial.
Account Access Without Permission
Colorado law separately criminalizes unauthorized access to social media and computer accounts. Knowingly accessing a computer system without authorization can constitute a crime under Colorado’s computer crime statutes. This creates a reciprocal risk: an investigator who accesses a suspect’s private account without legal process may have obtained the evidence unlawfully, opening the door to a suppression motion.
Context and the “Snippet” Problem
One of the most persistent challenges defense attorneys raise is that prosecutors offer digital communications out of context. A single threatening-sounding text, a screenshot of a conversation with the middle omitted, or a post that reads differently when the surrounding thread is available — all of these are susceptible to the argument that the jury is being given a misleading picture. Defense counsel should routinely demand complete conversation threads and full account activity logs in discovery.
Fourth Amendment Protections: Search Warrants and Digital Evidence
The Particularity Requirement: People v. Coke and Its Progeny
The Colorado Supreme Court’s landmark decision in People v. Coke, 2020 CO 28, fundamentally reshaped digital search warrant practice in the state. The Court held that a warrant authorizing law enforcement to search and seize the entire contents of a cell phone — with no subject matter, time frame, or category limitations — violates the particularity requirement of the Fourth Amendment and Article II, Section 7 of the Colorado Constitution.
Post-Coke, Colorado warrants must:
- Identify the specific categories of data to be searched (e.g., texts, photos, emails — not “all data”)
- Specify a time frame tied to the alleged conduct
- Connect the sought data to the alleged crime through the affidavit’s factual basis
- Avoid authorizing “general exploratory rummaging” through a device’s entire contents
Warrants that fail these requirements are invalid, and evidence seized under an overbroad warrant is subject to suppression. Notably, the Colorado Supreme Court has refused to allow prosecutors to cure constitutional defects by obtaining a subsequent narrower warrant and invoking good-faith or independent-source doctrines — if the initial warrant was invalid, the fruit is often suppressed.
The 2024 Court of Appeals Decision: Brute-Force PIN Extraction
In a significant 2024 ruling (People v. d’Estree, 2024 COA106), the Colorado Court of Appeals held that:
- A cell phone warrant executed more than fourteen days after issuance — in violation of Crim. P. 41(d)(5)(VI) and C.R.S. § 16-3-305(6) — combined with the warrant’s lack of particularity, rendered the initial search unconstitutional.
- Obtaining a cell phone PIN code via a digital “brute force attack” without consent constitutes a Fourth Amendment search and requires independent warrant authorization.
- The inevitable discovery doctrine did not save the evidence because police abandoned the lawful search path and expedited access using the illegally obtained PIN code.
The defendant’s convictions were reversed and remanded for a new trial. This case is essential reading for any Colorado practitioner whose case involves a cell phone extraction.
Reverse-Keyword and IP-Based Warrants
Colorado courts have addressed novel investigative techniques including reverse-keyword warrants (ordering platforms to identify accounts that searched for specific terms) and IP-address-based warrants.
The Colorado Supreme Court has upheld specific uses of these tools in child-exploitation investigations while deliberately declining to adopt sweeping new doctrinal frameworks — a fact-driven, case-by-case approach that leaves significant room for defense challenges in other contexts.
Defense Strategies for Challenging Digital Evidence
Experienced Colorado defense attorneys employ a layered approach to digital evidence, addressing constitutional, statutory, and evidentiary challenges simultaneously.
1. Move to Suppress Unlawfully Obtained Evidence
The first and most powerful remedy is exclusion at the source. Grounds include:
- Lack of a warrant for location data (C.R.S. § 16-3-303.5)
- Overbroad or non-particular warrant (People v. Coke and progeny)
- Warrant executed outside the 14-day window (Crim. P. 41(d)(5)(VI))
- Unlawful interception of real-time communications (C.R.S. § 16-15-102)
- Unauthorized account access without legal process
- Brute-force PIN extraction without a warrant (People v. d’Estree, 2024COA106)
A successful suppression motion can remove the government’s most damaging evidence before trial even begins.
2. Challenge Authentication
If suppression fails, attack the foundation at trial:
- Demand the full forensic methodology: which software was used, what version, what hash value was generated, and when.
- Challenge gaps in chain of custody: who had access to the device between seizure and trial? Was the evidence stored securely?
- Contest social media attribution: can the government actually prove the defendant controlled the account, or just that someone with access to that account posted the content?
- For video and audio, demand the native export with C2PA manifest rather than a re-encoded or compressed copy.
3. Contest Hearsay Classification
- Argue that third-party digital records are testimonial under the Confrontation Clause, requiring live witness testimony.
- Challenge the business records foundation: was the record actually made in the regular course of business, or was it generated specifically for litigation?
- Push back on out-of-context excerpts and demand the complete communication thread be admitted under the rule of completeness (CRE 106).
4. Attack Reliability and Interpretation
Authentication and hearsay do not end the inquiry. Even admissible evidence can be contested for reliability:
- Metadata manipulation: Timestamps can be changed, GPS coordinates spoofed, and file metadata altered by sophisticated actors. Defense experts can demonstrate how easily this occurs.
- Screenshot fabrication: Consumer apps exist that simulate fake text conversations. Challenge any screenshot that was not obtained via a direct forensic extraction or platform compliance process.
- Out-of-context presentation: Argue CRE 403 (unfair prejudice substantially outweighing probative value) when evidence is presented in misleading isolation.
- Deepfake and AI-manipulation concerns: As AI-generated content becomes more accessible, courts are increasingly open to expert testimony about the possibility of video or audio manipulation.
5. Exploit Discovery Rights Under Crim. P. 16
Colorado Rule of Criminal Procedure 16 governs discovery in criminal cases. Defense counsel should affirmatively demand:
- Complete forensic extraction reports and underlying data.
- Full chain-of-custody logs.
- All platform compliance records and the subpoena or warrant used to obtain them.
- Investigator notes and documentation of the acquisition methodology.
- Any deleted files or metadata the government recovered but does not intend to introduce.
Incomplete disclosure is itself grounds for sanctions and, in egregious cases, dismissal.
Practical Takeaways for Colorado Defense Practitioners
Conclusion
Digital evidence is not the infallible, objective record that prosecutors sometimes portray it as. Every piece of digital evidence introduced in a Colorado criminal case must survive authentication, hearsay analysis, constitutional scrutiny, and reliability challenges before a jury is permitted to weigh it. The rules are demanding — and intentionally so.
Colorado courts have shown a willingness to suppress digital evidence obtained without warrants, seized under overbroad authorizations, or extracted through constitutionally questionable techniques like brute-force PIN attacks.
Effective defense requires engaging all of these fronts simultaneously: filing suppression motions early, demanding full discovery, challenging the foundations of authentication, and, where necessary, retaining digital forensics experts to expose the limitations and vulnerabilities of the government’s evidence.
If you or someone you know is facing criminal charges in Colorado involving digital evidence, the time to act is early — before evidence is lost, forensic opportunities close, and strategic options narrow.
FAQs (Frequently Asked Questions)
What is the main purpose of Colorado Rule of Evidence 901 (CRE 901)?
CRE 901 addresses the question of how to establish that a piece of evidence is what its proponent claims it to be before it can be considered by the jury. It sets a low bar for authentication, requiring only sufficient evidence to support a reasonable juror’s finding that the item is authentic.
How does CRE 901 differentiate between authentication and admissibility?
Authentication under CRE 901 is just one gate in admitting evidence. Even if an item is authenticated as genuine, it may still be excluded for reasons like hearsay, relevance, or unfair prejudice. Authentication confirms the item’s identity or origin but does not guarantee overall admissibility.
What are the basic steps to authenticate evidence in Colorado courts under CRE 901?
The typical workflow involves someone identifying the item, explaining how they know what it is, confirming it hasn’t been meaningfully altered or explaining its chain of custody, and then the judge deciding if there’s enough foundation for the jury to consider it. The judge’s role is to assess sufficiency for jury consideration, not to definitively rule on authenticity.
What are some common methods of authenticating evidence according to CRE 901(b)?
CRE 901(b) provides examples including: (1) Testimony from a witness with knowledge; (2) Non expert opinion about handwriting; (3) Comparison by an expert or trier of fact; (4) Distinctive characteristics and circumstances; (5) Voice identification; and (6) Telephone conversations. These methods serve as a menu rather than an exclusive list.
How can digital evidence like texts or screenshots be authenticated under CRE 901?
Digital evidence can be authenticated using distinctive characteristics and circumstances under CRE 901(b)(4). For example, texts referencing shared events known only to specific people, emails with typical sign-offs or internal language, or messages from known phone numbers, when combined with contextual testimony, strengthen authentication. Multiple signals together provide a stronger foundation than a screenshot alone.
Can someone identify handwriting in court without being an expert? How does CRE 901 address this?
Yes. Under CRE 901(b)(2), a lay witness familiar with handwriting—not for litigation purposes—can identify it. This includes coworkers, spouses, or landlords who have seen the handwriting regularly over time.
Colorado Criminal Law – Digital Evidence in Colorado Criminal Cases: Rules, Authentication, and Defense Strategies
The reader is alerted that Colorado criminal law, like criminal law in every state and at the Federal level, changes constantly. The article above was accurate when it was drafted, but it cannot account for changes that occurred after it was uploaded.
ABOUT THE AUTHOR: H. Michael Steinberg – Email the Author at: hmsteinberg@hotmail.com
A Denver, Colorado Criminal Defense Lawyer – call his office at 303-627-7777 during business hours, or call his cell at 720-220-2277 if you cannot wait and need his immediate assistance.
“A good criminal defense lawyer is someone who devotes themselves to their client’s case from beginning to end, always realizing that this case is the most important thing in that client’s life.”
Putting more than 40 years of Colorado criminal defense experience to work for you.
One should be careful when selecting a Colorado criminal defense lawyer. We encourage you to “vet” our firm. Over the last 40 years – by focusing ONLY on Colorado criminal law – H. Michael has had the time to continually update himself in nearly every area of criminal law, including procedure, trial, and courtroom practice.
H. Michael works hard to deliver the best possible results for his clients, both in and out of the courtroom. He has written extensively on Colorado criminal law and continues to do so, and he hopes this article helps you in some small way.
Colorado Criminal Lawyer Blog

