Web evidence in litigation
Internet Defamation Expert Witness

About Bill Hartzer, Internet Defamation Expert Witness

Written for counsel deciding whether to retain anyone, and what that person has actually done with web evidence

Who this page is for

This page is written for an attorney handling an internet defamation matter who is deciding whether an expert is worth retaining at all, and if so, who. If you are the person the content is about rather than the lawyer, this site will not help you much; the first thing you need is a lawyer, not me.

I am Bill Hartzer. I am not an attorney and nothing on this site is legal advice. I am an internet and search technology consultant who serves as an expert witness in matters involving internet defamation, online content attribution, web evidence, search visibility, digital marketing and domain names. Whether something is actionable is a question for you. What I do is establish what the technical record shows and where it stops.

Working in internet technology and search since 1996

I have worked in search marketing and internet technology since 1996. That date is the only number on this page, and it matters for one reason: most of the records a defamation case runs on are records I watched get built.

In the late 1990s the web was small enough that you could see how it worked. Pages were served by identifiable machines, domains were registered by identifiable people with published contact records, and search engines said plainly what they had crawled and when. I spent that period doing search marketing and building and fixing websites, which meant reading server responses, redirect behavior, crawl logs and index status as routine.

Through the 2000s and into the 2010s the work became technical SEO and large website and domain migrations: moving a site from one domain, platform or URL structure to another without losing what it had. A migration is an exercise in provenance — you are constantly answering what was at this address before, what is there now, what redirects to what, and what does the outside record say happened. That is the question a defamation exhibit poses, asked commercially instead of forensically.

I founded Hartzer Consulting and later DNAccess, and began being retained as an expert witness in internet matters. The expert work sits alongside the consulting rather than replacing it, and the overlap is deliberate: an expert who stops touching live systems stops knowing how they currently behave.

What the search and migration work has to do with defamation evidence

The connection is not obvious from outside, so it is worth naming. In an internet defamation matter, some of the most contested questions are not about the words at all:

  • Is the page in the exhibit the page that was published? Content gets edited, moved, syndicated, mirrored and republished. Redirect chains, canonical tags, URL histories and archived captures are how you tell.
  • Was it ever actually visible? A page that existed is not a page that was served to the public, and a page that was served is not a page a search engine indexed.
  • Where else did it go? Scrapers, aggregators and mirrors reproduce material automatically, which changes both what a reach analysis measures and who published what.
  • What did search engines do with it? Impressions, positions and clicks are logged, but by a system with its own published definitions, and those definitions do not mean what a plaintiff usually assumes.

That is ordinary technical search work. It is only unusual to see it done inside litigation.

Domain names, registration records and the investigative side

The other half of the background is domain names. Through DNAccess I work on domain recovery, transfers and disputes, including domains taken by account compromise or by a departing insider. That work is investigative by nature and the methods carry into attribution questions:

  • Historical website analysis — what a site showed, and claimed, on a past date.
  • WHOIS and DNS history — who a domain was registered to and through, when it changed hands, what nameservers it used, and which other domains shared that infrastructure at the same time.
  • Archived internet data — third-party captures of pages, and what they do and do not attest to.
  • Website attribution — tying an anonymously operated site to an operator through the records left in setting it up, hosting it and paying for it, rather than the writing on it.

Attributing an anonymous site and an anonymous post are different problems with different evidence. A site has to be registered, hosted and paid for. A post leaves records too, but almost all of them sit with the platform and are reachable only by process.

What I have actually done with web evidence

Without naming a matter or a party, this is the substance of the work:

  • Collected pages while they were still live — full-page rendering, served source, post-script DOM and response headers together — and hashed the collection at the moment of capture.
  • Reconstructed what a website showed on a past date from archived captures, registration records and infrastructure history, stating which parts of that reconstruction are evidence and which are inference.
  • Traced a domain through registrars, privacy and proxy services, nameserver changes and hosting moves to the records identifying who controlled it.
  • Read platform data productions — the account archives that arrive after process — and worked the registration timestamps, addresses and session records for links between separate accounts.
  • Analyzed search and platform measurement data to say what exposure the records support, and why an impression, a view and a reader are three different things.
  • Examined patterns across groups of accounts posting about one target, separating what an outside analyst can observe from what only the platform can see.
  • Told counsel, in writing and early, that the records did not support the theory.

What I will not do

Naming this is more useful than another paragraph of qualifications.

  • I will not give legal advice. Not on whether a statement is actionable, not on what to plead, not on which rule governs in your forum.
  • I will not promise an outcome. Records show things, support things, or are consistent with things. Any finding can be challenged, and an expert who talks about proof as though it were settled is telling you something about himself.
  • I will not sign an opinion the records do not support. If the theory needs a fact the record does not contain, the answer is that the record does not contain it.
  • I will not estimate a number no operator publishes. Several widely repeated figures about how long platforms keep data trace back to blog posts rather than the platform.
  • I do not remove content or manage reputation in a matter I am retained on as an expert. Those are different jobs and mixing them damages the expert work.

A national practice, and why location is not part of it

The records this work runs on are held by platforms, registrars, hosting companies and search engines, and they are reachable the same way regardless of where a case is filed. I take matters nationally, and nothing about how the work is scoped or performed depends on proximity to anything.

How to tell whether I am the right expert for this matter

I am likely to be useful where the question is technical: what was published and when, whether an exhibit is what it purports to be, whether a page can still be collected defensibly, what a platform production actually contains, whether separate accounts share records, what exposure the measurement data supports, or who operated a site.

I am not the right person where the question is legal, where it turns on the fact-finder's judgment about meaning or reputation, or where the real dispute is an accounting one a financial expert should own. Some elements of an internet defamation case are not technical questions, and retaining a technical expert for them adds nothing. If that is where your matter sits, I would rather say so on a first call than after a retainer.

Top