# Police retrieving computer search history (Brian Walshe case)

**URL:** <https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599>\
**Category:** Factual Questions\
**Created:** [December 10, 2025, 8:02pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599 "2025-12-10T20:02:57Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![mixdenny](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mixdenny/32/2962_2.png) [@mixdenny](https://boards.straightdope.com/u/mixdenny)\
**Post date:** [December 10, 2025, 8:02pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/1 "2025-12-10T20:02:57Z")

</div>

I have seen this several times before where the police are able to find that a suspect has searched the Internet for things like, “How long before a body starts to smell” and “How to dispose of a body”. Can’t the perp just search while in Private Browsing mode to prevent this? Are they that dumb? Or can forensic investigators retrieve even those searches?

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [December 10, 2025, 8:22pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/2 "2025-12-10T20:22:39Z")

</div>

> [@mixdenny](#):
>
> Can’t the perp just search while in Private Browsing mode to prevent this? Are they that dumb? Or can forensic investigators retrieve even those searches?

There are two separate issues there.

1. When you search Google for "How to dispose of a body”, _Google_ keeps a record of that. Which record includes what was asked and which computer did the asking.

2. When you search Google for "How to dispose of a body”, _your browser_ keeps various records of that. It’s in your url history, some images or cookies might be cached, etc.

“Private Browsing” mode (by various names in various browsers) is all about the second issue. In that mode the browser keeps no records. But that mode does nothing to remove your history from Google’s computers.

You have zero influence, much less control, over what Google decides to keep track of. That’s a treasure trove for the cops. Lest it sound like I’m picking on Google particularly, all the other search engines do the same thing.

---

<div class="post-metadata">

**Author:** ![md-2000](https://avatars.discourse-cdn.com/v4/letter/m/9d8465/32.png) [@md-2000](https://boards.straightdope.com/u/md-2000)\
**Post date:** [December 10, 2025, 8:45pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/3 "2025-12-10T20:45:36Z")

</div>

It is possible to hide your identity from Google by using a VPN, in a rudimentary manner. You share the same IP with every other user of that VPN service. Since private browsing does not share existing cookies etc. (and deletes any it receives during the session, when you close the browser) Google cannot identify you by your IP address or by other specific data.

Except - there’s the theory that computers can be fairly uniquely identified by their “signature” - the exact (sub)version of their browser, any add-ons like video players and what codecs they handle, available fonts, language settings, time zone, etc. One theory is that it is like DNA, there’s so many add-ons and possibilities that a computer is not likely to match many others - and who knows what personal data Google has memorized about your computer.

I suppose it boils down to the usual question - who wants to know? What powers and resources do they have to compel data from others? How much effort are they going to put into finding out?

---

<div class="post-metadata">

**Author:** ![saje](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saje/32/3631_2.png) [@saje](https://boards.straightdope.com/u/saje)\
**Post date:** [December 10, 2025, 9:17pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/4 "2025-12-10T21:17:09Z")

</div>

Isn’t there also Onion or Tor? My husband was a fan of that a while ago, not for anything truly nefarious, just access to some music streams, I think? Or maybe plane info - he’s got the flying bug.

---

<div class="post-metadata">

**Author:** ![Spiderman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/spiderman/32/230_2.png) [@Spiderman](https://boards.straightdope.com/u/Spiderman)\
**Post date:** [December 10, 2025, 9:34pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/5 "2025-12-10T21:34:11Z")

</div>

> [@LSLGuy](#):
>
> When you search Google for "How to dispose of a body”, _your browser_ keeps various records of that. It’s in your url history, some images or cookies might be cached, etc.

Does Google keep it by computer footprint or because they’re doing it while signed in?  
I always assumed if you use one browser & opened a private tab they still know who you are; however, if i opened a second/different browser & didn’t sign in then they couldn’t track me.

…Asking for a friend

---

<div class="post-metadata">

**Author:** ![markn\_1](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@markn\_1](https://boards.straightdope.com/u/markn_1)\
**Post date:** [December 10, 2025, 9:40pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/6 "2025-12-10T21:40:50Z")

</div>

They definitely have your IP address, so if you’re not using a VPN they can track you by that.

---

<div class="post-metadata">

**Author:** ![DPRK](https://avatars.discourse-cdn.com/v4/letter/d/4491bb/32.png) [@DPRK](https://boards.straightdope.com/u/DPRK)\
**Post date:** [December 10, 2025, 10:49pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/7 "2025-12-10T22:49:47Z")

</div>

> [@saje](#):
>
> Isn’t there also Onion or Tor?

And are you positive you are _always_ running those for all of your internet traffic?

In any case, try this test : [https://coveryourtracks.eff.org/](https://coveryourtracks.eff.org/)

---

<div class="post-metadata">

**Author:** ![Jas09](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@Jas09](https://boards.straightdope.com/u/Jas09)\
**Post date:** [December 10, 2025, 11:17pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/8 "2025-12-10T23:17:28Z")

</div>

While the above posters are correct that both the internet search provider (e.g. Google) and the ISP (e.g. ATT) could provide information to the cops, it does appear that in this specific case the search history was retrieved from the laptop itself. Or at least the news articles about it all refer to the MacBook that was searched as the source of the information.

So yes, it does appear he was rather idiotic about covering his digital tracks.

Really the only “foolproof” way would be buy a new computer, never log into any accounts for it, and only use it on a public network somewhere without cameras. Then destroy the computer by dumping it in a lake or something. Then your search history probably couldn’t be traced back to you.

---

<div class="post-metadata">

**Author:** ![md-2000](https://avatars.discourse-cdn.com/v4/letter/m/9d8465/32.png) [@md-2000](https://boards.straightdope.com/u/md-2000)\
**Post date:** [December 10, 2025, 11:46pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/9 "2025-12-10T23:46:11Z")

</div>

Why would anyone sign in to Google? For email, yes - but then sign out. Why give them more data?

---

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [December 10, 2025, 11:48pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/10 "2025-12-10T23:48:32Z")

</div>

Because it’s convenient for using some of Google’s services, like their password manager. I can also share links from Chrome between my phone and my laptop this way. And logged on or not, I’ve long given up the illusion that Google doesn’t know who you are anyway.

---

<div class="post-metadata">

**Author:** ![Atamasama](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/atamasama/32/12961_2.png) [@Atamasama](https://boards.straightdope.com/u/Atamasama)\
**Post date:** [December 11, 2025, 12:17am UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/11 "2025-12-11T00:17:06Z")

</div>

> [@EinsteinsHund](#):
>
> Because it’s convenient for using some of Google’s services, like their password manager.

Another advantage is that many online places that require registration, such as stores, will accept Google logins and you don’t need to actually register a new account with the site. And it can carry things like a shipping address or payment info that just follow you.

There is a lot of convenience in staying logged into Google, but obviously there are privacy concerns as well.

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [December 11, 2025, 12:25am UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/12 "2025-12-11T00:25:14Z")

</div>

You’re not signed in just for GMail. You’re signed in for everything Google offers. Which means that if you want to avoid associating a search with your Google ID, you have to log out as soon as you’re done with GMail but also manually log back in when you want to see your GMail. A damned nuisance, and completely useless from a forensic perspective, because Google will record what computer at what network address is making that search, logged in or not. And if it’s recent enough, it’ll record that a certain Google login was used to read Gmail from that computer at that IP address a few minutes prior.

Leaving aside the significant traces left inside your browser (logged in or not) if you don’t purge browsing history info.

---

<div class="post-metadata">

**Author:** ![scudsucker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scudsucker/32/14101_2.png) [@scudsucker](https://boards.straightdope.com/u/scudsucker)\
**Post date:** [December 11, 2025, 12:11pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/13 "2025-12-11T12:11:02Z")

</div>

> [@md-2000](#):
>
> Except - there’s the theory that computers can be fairly uniquely identified by their “signature” - the exact (sub)version of their browser, any add-ons like video players and what codecs they handle, available fonts, language settings, time zone, etc

Yeah, the “Evercookie”, which is sufficiently diverse and multiply redundant enough to uniquely identify a single machine or device.

> **[Evercookie](https://en.wikipedia.org/wiki/Evercookie)**
>
> Evercookie (also known as supercookie) is an open-source JavaScript application programming interface (API) that identifies and reproduces intentionally deleted cookies on the clients' browser storage. This behavior is known as a zombie cookie. It was created by Samy Kamkar in 2010 to demonstrate the possible infiltration from the websites that use respawning. Websites that have adopted this mechanism can identify users even if they attempt to delete the previously stored cookies.
> In 2013, Edwar...

Being a nerd, and having worked in online gambling - which as you can imagine, has a fair amount of attempted fraud - we were on it.

I’m not sure how far I want to go into details for the general public, although it is open source for us nerds to peruse.

I mean they use steganography to hide data in images in your browser cache. It is way, way clever.

---

<div class="post-metadata">

**Author:** ![griffin1977](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@griffin1977](https://boards.straightdope.com/u/griffin1977)\
**Post date:** [December 11, 2025, 1:50pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/14 "2025-12-11T13:50:21Z")

</div>

> [@md-2000](#):
>
> Google cannot identify you by your IP address or by other specific data.

Although the VPN company can (sometimes). In a case like the OP it would be pretty straightforward for the cops to get a warrant from the VPN company for your IP address. Though what data is stored depends on the company…

> Other documented instances include a data request in 2016 to PIA and a 2017 request for logs from [PureVPN](https://www.pcworld.com/article/407274/purevpn-vpn-review.html), both by the FBI. PIA [remained true to their no-logs word](https://go.skimresources.com/?id=111346X1569483&xs=1&url=https://torrentfreak.com/vpn-providers-no-logging-claims-tested-in-fbi-case-160312/&xcust=2-3-2367508-1-0-0-0-0&sref=https://www.pcworld.com/article/2367508/vpns-and-the-law-how-often-does-law-enforcement-actually-request-vpn-logs.html) by proving they had nothing to give the authorities, while PureVPN went on to [secretly work with the FBI](https://go.skimresources.com/?id=111346X1569483&xs=1&url=https://betanews.com/2017/10/09/purevpn-logs-fbi/&xcust=2-3-2367508-1-0-0-0-0&sref=https://www.pcworld.com/article/2367508/vpns-and-the-law-how-often-does-law-enforcement-actually-request-vpn-logs.html) to provide an IP address of a user leading to an arrest

> **[VPNs and the law: How often does law enforcement actually request VPN logs?](https://www.pcworld.com/article/2367508/vpns-and-the-law-how-often-does-law-enforcement-actually-request-vpn-logs.html)**
>
> VPNs regularly field requests for data when illegal activity is suspected. But what sorts of activities make up the bulk of those requests, and more importantly, how do the VPN providers respond? Those details are revealed here.

---

<div class="post-metadata">

**Author:** ![msmith537](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@msmith537](https://boards.straightdope.com/u/msmith537)\
**Post date:** [December 11, 2025, 2:08pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/15 "2025-12-11T14:08:12Z")

</div>

It’s been about 15 years since I worked in that space, but if it’s on your computer, chances are a computer forensics expert can reconstruct it. Even using disk-wiping software leaves traces of its use, creating circumstantial evidence that you tried to hide something.

Unless a suspect is particularly tech-savvy, they typically aren’t thinking about hiding their digital trail beyond maybe deleting their browser history.

My advice is if you need to research your crime, do it from a public computer at the local library. If you think you have incriminating evidence on your personal computer, physically destroy the hard drive with acid or something and then toss it in the river.

> [@saje](#):
>
> Isn’t there also Onion or Tor? My husband was a fan of that a while ago, not for anything truly nefarious, just access to some music streams, I think? Or maybe plane info - he’s got the flying bug.

Using a dark web browser to look up airplane info shouldn’t raise any red flags 😉

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 11, 2025, 10:13pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/16 "2025-12-11T22:13:27Z")

</div>

> [@msmith537](#):
>
> My advice is if you need to research your crime, do it from a public computer at the local library.

At my library at least, you have to log in with your library card number. And you need ID to get that card.

---

<div class="post-metadata">

**Author:** ![Lucas\_Jackson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lucas_jackson/32/303_2.png) [@Lucas\_Jackson](https://boards.straightdope.com/u/Lucas_Jackson)\
**Post date:** [December 11, 2025, 11:58pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/17 "2025-12-11T23:58:38Z")

</div>

> [@Jas09](#):
>
> Really the only “foolproof” way would be buy a new computer, never log into any accounts for it, and only use it on a public network somewhere without cameras. Then destroy the computer by dumping it in a lake or something.

A very quick search of Amazon turned a [Dell Chromebook 3180 Laptop Computer](https://www.amazon.com/Dell-Chromebook-Computer-Celeron-Bluetooth/dp/B0CKN6R3X7/ref=sr_1_3?crid=2DGW8V4VMFAM9&dib=eyJ2IjoiMSJ9.7JoQvNkFKpMzCo5f-qJvwRUWeyZvCoLsK0TctQRqb10R6EwXgerWMwfrbiGFlldC9RaALb9WJAKzdLubMSmmAm8BGIZrB9JrZnzN_D4cK-NBBwOGbEEDaK1uiL5lXSXOcSrhG3MvCrbXMaB-ghpaqInI6iYsaujbheAg4a9u3p8RNvUr8dZCzafrazz9fzF4ZJBS4QZ3Tz0Cqw3N9yrSdB94UhgKrJ70KY8Tcs09uo8.kQRriH4LwRcuYik8NPYChr8P2JJA-iuFw5MUjgKa90o&dib_tag=se&keywords=inexpensive%252Bcomputer%252Blaptop%252Bdragon&qid=1765497283&sprefix=inexpensive%252Bcomputer%252Blaptop%252Bgragon%252B%252Caps%252C161&sr=8-3&th=1), 11.6 Inch Laptop PC, Intel Celeron N3060, 4GB RAM, 16GB SSD, Web Camera, Wi-Fi, Bluetooth, HDMI, Chrome OS for $86. That’s cheap insurance.

---

<div class="post-metadata">

**Author:** ![Cugel](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cugel/32/1199_2.png) [@Cugel](https://boards.straightdope.com/u/Cugel)\
**Post date:** [December 12, 2025, 6:17am UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/18 "2025-12-12T06:17:24Z")

</div>

I use Startpage, which purportedly hides your search info from Google, and doesn’t hold logs.

---

<div class="post-metadata">

**Author:** ![Spiderman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/spiderman/32/230_2.png) [@Spiderman](https://boards.straightdope.com/u/Spiderman)\
**Post date:** [December 12, 2025, 3:28pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/19 "2025-12-12T15:28:56Z")

</div>

> [@BigT](#):
>
> At my library at least, you have to log in with your library card number. And you need ID to get that card.

At our local libraries one must sign in; however, they have slips of paper sitting there with one-time use temp IDs that anyone can pick up & use.  
Also, given how many small town libraries there are in this country, I wonder how many are saving logs of who logged into which computer when to even be able to tie it back that _you_ searched for “how to get rid of a body” within hours of your SO/ex/boss/neighbor last being seen alive

---

<div class="post-metadata">

**Author:** ![jnglmassiv](https://avatars.discourse-cdn.com/v4/letter/j/f07891/32.png) [@jnglmassiv](https://boards.straightdope.com/u/jnglmassiv)\
**Post date:** [December 12, 2025, 6:01pm UTC](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599/20 "2025-12-12T18:01:19Z")

</div>

> [@msmith537](#):
>
> My advice is if you need to research your crime, do it from a public computer at the local library.

I don’t provide advice to criminals but would recommend, say, friendly intelligence gathering sources to avoid any sort of sensitive covert activity using what must be among the target government’s best photo/videographed and staffed public PCs around. And that’s setting aside the risk of using the enemy’s devices at all.

[Next page](https://boards.straightdope.com/t/police-retrieving-computer-search-history-brian-walshe-case/1025599.md?page=2)
