Skip to main content
Reference

Methodology

How this investigation was actually conducted — including the places where the procedure failed. A methodology that is only published when it went well is marketing.

The self-interested reason

Web-capture evidence has exactly one viable defence: that traffic on our infrastructure was the investigator’s own. A contemporaneous record of what was touched, when, how, and whether anything was submitted forecloses that argument (W-1).

The honest one

This record includes a contamination event that cannot be fully explained, an interaction log where six of nine entries are unresolved, and nine findings that make the case smaller. Leaving them out would make everything else less believable.

Evidence grades

GradeSourcesWhy
HIGHESTRDAP registry records · authoritative DNS · upload-path timestamps and preserved source filenamesNeither user-editable narrative nor operator marketing. This is what makes the backdating findings work
MIDDLEPage Transparency panels · account-registration artifacts across independent platformsDerived from actual administrative sessions
LOWESTWebsite copy · testimonials · phone numbers the operation publishesTrivially provisioned or invented. A claimed founding date loses to a registry record, every time

Capture procedure

Four live sites crawled in full, publicly served pages only. Every retrieved file hashed with SHA-256 into a per-site manifest — 104 files (U). Page source saved, not just rendered output, because the findings live in the markup.

The 140-file collected corpus was hashed before it was reorganised, moved without modification, and re-hashed afterwards. 140 of 140 verified identical, zero integrity failures (L).

Original filenames preserved unchanged — platform media identifiers are themselves evidence; they group the corpus into 38 account clusters (K-3).

No original file was modified, cropped, enhanced, or re-encoded. Derived analysis is segregated and labelled as derivative (J, L).

Contamination controls

ControlThe failure it prevents
No submissions of any kindA populated form appears in a merchant’s admin panel: a signal to the operators and a defence argument that investigator traffic contaminated the record
No login attemptsA logged-in view attaches the investigator’s identity to the platform’s record of the visit
Reading public pages onlyKeeps every capture inside what any member of the public could retrieve — usable and repeatable
Clean machine or isolated profileAutofill and saved wallet state can submit real identity data without an explicit decision to submit anything
Log every contact, on the dayA log reconstructed from memory months later is worth a fraction of one kept contemporaneously
The credentials that were not used
One shipping front publishes its template vendor’s demonstration administrator credentials in plain text on a public page (T-1). No login was attempted and none should be — accessing that panel would be unauthorized access regardless of how the credentials were obtained. The evidentiary value is entirely in the fact that the string is published.