Wednesday, November 10, 2010

Search Unlawful But Evidence Not Excluded

As I assume everyone knows, courts in the United States use the exclusionary rule to enforce the 4th Amendment. As Wikipedia explains, the exclusionary rule is “a legal principle . . . which holds that evidence collected . . . in violation of the defendant’s constitutional rights is . . . inadmissible” in a prosecution of that defendant.


As Wikipedia also explains, the U.S. Supreme Court first adopted the exclusionary rule as a device for enforcing the 4th Amendment in Weeks v. U.S., 232 U.S. 383 (1914). The Weeks Court only applied the exclusionary rule to violations of the 4th Amendment – “unreasonable” searches and seizures – carried out by federal law enforcement officers. It wasn't until 1961, in Mapp v. Ohio, 367 U.S. 643, that the Supreme Court applied the rule to state law enforcement officers, as well. The combined effect of Weeks and Mapp has been that the exclusionary rule prevents states and/or the federal government from using evidence obtained in violation of the rule (subject to certain exceptions, such as if the evidence would “inevitably” have been discovered otherwise).


One more bit of context and we’ll get into the case this post is about. As I’ve noted in various other posts, the 4th Amendment creates a right to be free from “unreasonable” searches and seizures, which, by implication, means that “reasonable” searches and seizures are constitutional. As I’ve also noted, to be “reasonable” a search/seizure must be conducted pursuant to a warrant (search or arrest) or an exception to the warrant requirement.


And that brings us to U.S. v. Rosa, __ F.3d, 2010 WL 4227428 (U.S. Court of Appeals for the 2d Circuit 2010). This is how the case arose:

Late on September 26, 2007, the Oswego County Sheriff's Office began investigating possible child exploitation by Efrain J. Rosa after Deputy Sheriff Burke was dispatched to a local address upon receipt of a 911 call from two mothers reporting that their minor sons had just disclosed being sexually abused by a neighbor, whom the boys referred to as `J.’. . . . Burke learned ‘J’ had shown the boys files on his computer containing nude pictures of the boys and other children and had engaged in sexual conduct with the[m]. The boys [said] `J’ kept three laptop computers in his apartment, had a USB flash drive on which he kept images of nude children , a pistol in his bedside table and had sexually abused the boys on multiple occasions. . . . [A]t approximately 2:00 a.m., officers sought the assistance of Investigator Blake, who had specialized training in computer forensic exams in child pornography cases. . . . Blake prepared a search warrant application and affidavit, which he presented to Granby Town Justice Bruce Wells in connection with his request for a search warrant of Rosa's apartment. . . .

[A]t 4:10 a.m., Judge Wells issued a search warrant directing the Sheriff's Office to search `[t]he entire residence known as 30 West 11th Street Building E Apartment 1 Chateau West Apartments in the Town of Granby, County of Oswego, State of New York. This is to include any containers or rooms whether locked or otherwise[ ]’ . . .


for the following property: `. . . computer equipment, electronic digital storage media included but not limited to floppy diskettes, compact disc, hard drives whether mounted in a computer or otherwise, video or audio tapes, video surveillance systems, video and digital camera systems, printing devices, monitors, firearms and any written and/or printed and/or electronic stored notes or records which would tend to identify criminal conduct and any personal papers or documents which tend to identify the owner, leasee or whomever has custody or control over the premises searched or the items seized.’

U.S. v. Rosa, supra. The opinion notes that while “the search warrant itself did not incorporate any supporting documents, or set forth the nature of the suspected criminal activity,” section A of the application said the property to be searched was evidence of three New York sex offenses and one firearms offense. U.S. v. Rosa, supra. It also notes that the materials presented to Judge Wells included an affidavit by Black that incorporated the statements made by the two boys and their mothers, and Rosa’s “New York criminal history and lack of a pistol permit.” U.S. v. Rosa, supra.


After the judge issued the warrant, at approximately 5:00 a.m. Blake and a team of

officers proceeded to Rosa’s apartment, and . . . executed the warrant. . . . [They] seized numerous items, including . . . six computers, multiple USB thumb drives, USB cables, a Sony Playstation, two digital cameras, multiple external hard drives, a cassette recorder, two USB cameras, numerous compact discs, a pair of handcuffs, condoms, three marijuana pipes, a handgun, ammunition, and over seventy grams of marijuana.

U.S. v. Rosa, supra. When the computers and “related storage media” were analyzed, investigators found “several thousand images and over a hundred videos of child pornography” plus images of Rosa “engaging in sexual conduct with each of the” boys who had complained about him to police. U.S. v. Rosa, supra.


After a grand jury indicted Rosa multiple counts of producing, attempting to receive and possessing child pornography, he moved to suppress “the physical evidence seized from his apartment.” U.S. v. Rosa, supra. In his motion, Rosa argued, among other things, that the search violated the 4th Amendment because “the warrant lacked particularity and was overbroad because it allowed for the seizure of any items that `would tend to identify criminal conduct.’” U.S. v. Rosa, supra.


After the trial judge denied his motion to suppress, Rosa pled guilty to 3 counts of producing child pornography and 1 count of witness tampering while reserving his right to appeal the denial of the motion to suppress. U.S. v. Rosa, supra. And he, of course, appealed.


On appeal, Rosa again argued that because the search warrant failed to state with

any level of particularity the specific criminal activity alleged or the type of digital evidence to be sought from the electronic items seized, [it] authorized the officers to conduct an unfettered search of the contents of his numerous electronic devices, any one of which might contain sensitive personal information unrelated to the suspected crimes of child pornography and child molestation. . . .

U.S. v. Rosa, supra. As I’ve explained before, the 4th Amendment requires that a search warrant particularly describe “the place to be searched and the . . . things to be seized.” The purpose of this requirement is to limit officer discretion, i.e., to ensure that officers who execute a warrant only look for the items specifically described in the warrant.


The Court of Appeals agreed with Rosa that the warrant in this case lacked “the requisite specificity. . . . The warrant was defective in failing to link the items to be searched and seized to the suspected criminal activity . . . and thereby lacked meaningful parameters on an otherwise limitless search of Rosa's electronic media.” U.S. v. Rosa, supra. The court therefore held that because “the warrant failed to describe the evidence sought and . . . to link that evidence to the criminal activity supported by probable cause, the warrant violated the” 4th Amendment. U.S. v. Rosa, supra.


So Rosa won . . . on that point.


The Court of Appeals then turned to the remedy for the violation, noting that, under the Supreme Court’s decision in Herring v. U.S., 129 S.Ct. 695 (2009), a violation of the 4th Amendment “does not necessarily result in the application of the exclusionary rule.” U.S. v. Rosa, supra.


The Herring Court held that the application of the exclusionary rule depends on the “efficacy of the rule in deterring 4th Amendment violations in the future” as well as a determination that the “benefits of deterr[ing unlawful police conduct] . . . outweigh the costs.” Herring v. U.S. supra. The Herring Court explained that (i) the “extent to which the exclusionary rule is justified . . . varies with the culpability of the law enforcement officers” and (ii) in deciding whether the rule should apply, a court looks to whether police conduct is “sufficiently deliberate that exclusion can meaningfully deter it, and sufficiently culpable that such deterrence is worth the price paid by the justice system.” Herring v. U.S. supra.


In applying Herring to Rosa’s motion to suppress, the 2d Circuit Court of Appeals found that after examining the circumstances at issue in the case,

we conclude that the officers acted reasonably and that the exclusionary rule would serve little deterrent purpose in this case. Given the time pressures and the content of the application and the affidavit, it is only reasonable to conclude that the failure to ensure that the items to be seized were properly limited under the express terms of the warrant was simply an inadvertent error that was the product of `isolated negligence.’ There is nothing to suggest deliberateness and culpability on the officers' part.

U.S. v. Rosa, supra (quoting Herring v. U.S. supra). The court therefore held that

[u]nder the facts of this case, we conclude that the benefits of deterrence do not outweigh the costs. In so holding, however, we reiterate the importance of law enforcement's compliance with the probable cause and particularity requirements of the Fourth Amendment and emphasize that application of the exclusionary rule will vary in accordance with the facts of each case.

U.S. v. Rosa, supra. So Rosa won on one issue and then lost on the other.

Monday, November 08, 2010

Peer Spectre Revisited

A few months ago, I did a post on the Peer Spectre program that was prompted by an email.

As I explained in that post, the person who sent the email to me said he/she had heard some things about how was used and asked if, IMHO, such activity would violate the 4th Amendment. I did a little research, found some information on what it seemed Peer Spectre does, and wrote that I didn’t see how its use would violate the 4th Amendment, if that, in fact, was how it was being used.

I recently found a reported case that addressed the use of Peer Spectre, so I thought I’d do a post about it.

The case is U.S. v. Willard, 2010 WL 3784944 (U.S. District Court for the Eastern District of Virginia 2010), and this is how it arose:

An undercover agent working for the . . . FBI conducted a keyword search on a peer-to-peer file-sharing network using terms known to be associated with child pornography. Her search revealed a file from Internet Protocol (`IP’) address 24.125.166.216. The agent conducted a search of other files available at this IP address and downloaded seven files, three of which depicted child pornography. Special Agent Howell of the FBI subsequently viewed the images and confirmed that they depicted child pornography. After being served with a subpoena, Comcast Corporation identified the owner of the IP address as John C. Willard, Sr., a resident of Mechanicsville, Virginia.


On September 11, 2008, U.S. Magistrate Judge Lauck authorized the installation of a pen register device on the Internet connections of John C. Willard, Sr., and [John Charles Willard], who had recently moved out of his father's home. In 2009, Special Agent Howell analyzed the pen data using the Wyoming Toolkit database. The database uses an automated software program called Peer Spectre which reads publicly available information from computers identified as sharing child pornography images. Howell queried Wyoming Toolkit regarding the IP addresses that communicated with [Willard’s] IP address in October and November 2008, and found that more than 2,200 of those IP addresses had been previously identified by Peer Spectre as advertising child pornography files available for sharing.


In the spring of 2009, another judicially-authorized pen register was installed on [Willard’s] Internet connection. Analysis of [his] Internet activity revealed that [his] IP address made thirty unique files of child pornography available for sharing on four separate occasions between May and July of 2009.


U.S. v. Willard, supra. As an FYI, maybe, the opinion explains that the Wyoming Toolkit

database was developed by the Wyoming Internet Crimes Against Children Task Force. Whenever an investigator identifies child pornography that is shared over a peer-to-peer file-sharing network, the observation is recorded into the Wyoming Toolkit database. The database record contains: (1) the date and time of the observation; (2) the SHA1 value of the files; and (3) the name of the files and the IP address sharing the files. SHA1 stands for Secure Hash Algorithm 1. It is essentially a fingerprint of a digital file. By comparing the SHA1 values of two files, investigators can determine whether the files are identical with precision greater than 99.9999 percent certainty.

U.S. v. Willard, supra.

On August 26, 2009 Agent Howell got a search warrant for John Charles Willard’s (hereinafter “Willard”) address that authorized a search for and seizure of his computer. U.S. v. Willard, supra.

The officers seized his computer and an external hard drive; then the hard drives were analyzed, they found “more than 300 still images and 67 videos of child pornography.” U.S. v. Willard, supra. As a result of the search, Willard was indicted on seven counts of transporting and receiving child pornography in violation of federal law. Indictment, U.S. v. Willard, 2010 WL 4092796 (2010).

He then filed a motion to suppress “evidence obtained during the child pornography investigation . . . because the pen register installed on his Internet connection was actually a wiretap that required a search warrant based on probable cause”. U.S. v. Willard, supra. The federal judge began his analysis of Willard’s motion to suppress by explaining that

[a] `pen register’ is `a device or process which records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted . . . . ‘ 18 U.S. Code § 3127(3). When using a pen register or trap and trace device on a computer, the government is not entitled to receive information from the device if that information reveals the contents of a communication. In re United States for an Order Authorizing the Use of a Pen Register, 396 F.Supp.2d 45 (U.S. District Court for the District of Massachusetts 2005).

U.S. v. Willard, supra. The judge then explained that Willard’s “primary argument” was based on the fact that the pen register statute only allows the government to collect

the origin or destination of a communication and not the contents of the communication. [He] contends that a search that includes the opening of files exchanged between two IP addresses is beyond the scope of an order authorizing the use of a pen register or trap and trace device. Thus, [Willard] argues, the orders obtained authorized a search only of information pertaining to routing, addressing and signaling.

He asserts that Special Agent Howell went beyond the scope of the order when he used software to monitor the flow of information and read and record the IP address, date, time, file names, and SHA1 values of files on Defendant's computer. To have properly engaged in this type of search, [Willard] contends, the Government should have obtained a warrant pursuant to 18 U.S. Code §§ 2510-2522 (`Wiretap Act’).

U.S. v. Willard, supra. As one source explains, the Wiretap Act prohibits the government form intentionally intercepting “wire and electronic communications” unless a statutory exception applies to permit the interception or unless the government obtains a wiretap order that must be based on probable cause to believe the interception will reveal evidence of a crime. Willard, as the federal judge pointed out, argued that the use of

Wyoming Toolkit and Peer Spectre to determine the nature of his computer files was analogous to installing a wiretap and went beyond the scope of the pen register orders. As such, [he] argues, the officers should have obtained a search warrant based on probable cause.

U.S. v. Willard, supra. In its response to Willard’s motion to suppress, the government disagreed with his argument and with his characterization of Peer Spectre:

Peer Spectre does not . . . intercept the contents of any communications. What the software does is read publically available advertisements from computers that are identified as offering images of child pornography for distribution, and . . . identify those IP addresses offering to distribute child pornography.


The function performed by Peer Spectre is akin to data-mining in that the software is merely collecting information that is captured once the defendant and others make publically available files for sharing on the network. It operates to identify and log IP addresses offering to distribute child pornography. Peer Spectre did not acquire any contemporaneous . . . from [Willard’s] IP address to any other computer. . . . [Willard] is utterly misinformed in his understanding of the function and operation of Peer Spectre. . . .


Response of the United States to Defendant’s Motion to Suppress, U.S. v. Willard, 2010 WL 4092798 (2010).

The federal judge agreed with the prosecution:

The Court finds that the use of Peer Spectre did not constitute a wiretap because the software does not intercept electronic communications. The functions performed by Peer Spectre and Wyoming Toolkit are more akin to mining data. The term `intercept’ as used in the Wiretap Act requires that the acquisition of contents be contemporaneous with the transmission of such contents. See Konop v. Hawaiian Airlines, Inc., 302 F.3d 878 (U.S. Court of Appeals for the 9th Circuit 2002) (`Congress . . . accepted and implicitly approved the judicial definition of “intercept” as acquisition contemporaneous with transmission. We therefore hold that for a website . . . to be “intercepted” in violation of the Wiretap Act, it must be acquired during transmission, not while it is in electronic storage.’).


Peer Spectre does not acquire communications contemporaneously with the transfer of data from one IP address to another. Instead, it reads publicly available advertisements from computers identified as offering images of child pornography for distribution and identifies their IP addresses.


U.S. v. Willard, supra. The judge therefore denied Willard’s motion to suppress. U.S. v. Willard, supra.

Friday, November 05, 2010

More on Restitution and Proximate Cause

A few months ago, I did a post about an Iowa case in which a federal district court judge declined to order the defendant to make restitution to the victim in a child pornography case.


The Iowa judge declined to order restitution because she found the government hadn’t proven causation in the case, but noted that other courts have done so. She also noted that victims of child pornography and the government had “only recently begun” to seek restitution in these cases.


I decided to do another post on this issue because I found several recent cases in which the issue came up, again, and resulted in different outcomes. I’m not going to cover the statutory basis for restitution or the procedure involved in any detail in this post; I’ll refer you to the earlier post for those issues.


The first case is U.S. v. Rowe, 2010 WL 3522257 (U.S. District Court for the Western District of North Carolina 2010), and all I know about the facts in the case is that the defendant, Jeffery Michael Rowe, pled guilty to 1 count of possessing child pornography in violation of 18 U.S. Code § 2252(a)(4)(B). When it came time to sentence Rowe, the government sought an order requiring him to pay restitution to his victim. U.S. v. Rowe, supra. In this opinion, the federal judge explained that


among the 243 images and 9 videos found in [Rowe’s] possession were images from what has come to be known as the `Vicky’ series. `Vicky’ is a pseudonym for a known child victim of child sexual abuse. Now an adult, Vicky has submitted loss figures for the Court's consideration in imposing restitution. . . . Based on the victim's submissions, the Government contends [Rowe] should be held jointly and severally liable with all other defendants convicted of possessing images from the `Vicky’ series for the full amount of Vicky's losses-a total of $383,803.60.


U.S. v. Rowe, supra. In a footnote, the judge explained that “[t]o date, the victim has received $70,850.00 in restitution payments from other defendants. Therefore, the Government is requesting that the Court enter a restitution judgment in the amount of $312,953.60” for her “in this matter.” U.S. v. Rowe, supra.


In ruling on the government’s request, the judge explained that 18 U.S. Code § 2259 “mandates that the Court order a defendant convicted of [a child pornography] offense to pay `the full amount of the victim’s losses’ as restitution to the victim.” U.S. v. Rowe, supra. He also explained that (i) § 2259(c) defines “victim” as “someone harmed as a result of commission of a crime” under federal statutes that include child pornography crimes and (ii) § 2259(b)(3) defines “full amount of the victim’s losses” as including physical, psychiatric or psychological care or rehabilitation, lost income, “necessary” transportation, housing and child care expenses, attorney’s fees and court costs and “any other losses” that were a proximate result of the crime. U.S. v. Rowe, supra.


The judge then considered whether Vicky was a “victim” of Rowe’s crime. He found that Vicky “was depicted in some of the pornographic images” Rowe possessed, so she was a “`victim’ for the purposes of section 2259 if she was `harmed as a result of’” Rowe’s possession of those images. U.S. v. Rowe, supra. He explained that courts have found that child pornography creates “three distinct types of harm to its victims”: the abuse they suffer when the material is created; the violation of their privacy they suffer when others possess the material; and the victimization of children is a direct result of the existence of a demand for the material. U.S. v. Rowe, supra.


The judge held that Vicky was a “victim” under the statute: She was “raped and sexually exploited by her father beginning at age 10”, exploitation that included recording the abuse and distributing it to other pedophiles. U.S. v. Rowe, supra. When she was 17 she discovered the images were circulating, which was a traumatic experience for her. U.S. v. Rowe, supra. And she was talked by someone who had seen the images and who wanted “to make pornography with her.” U.S. v. Rowe, supra. Evidence presented to the judge showed that because of all this, Vicky “faces a long course of treatment” for “physical and emotional problems” caused by “the receipt, distribution and possession of her abuse images.” U.S. v. Rowe, supra.


The judge next took up the issue of whether “the Government ha[d] met its burden of establishing the requisite causal connection between [Rowe’s] conduct and the victim’s losses.” U.S. v. Rowe, supra. He explained that under the statute, he could only award restitution for the amount of Vicky’s losses “proximately caused” by Rowe’s conduct. U.S. v. Rowe, supra. The judge then quoted a legal dictionary’s definition of the term “proximate cause:” “Proximate cause is `[a] cause that directly produces an event and without which the event would not have occurred.’” U.S. v. Rowe, supra (quoting Black's Law Dictionary 250 (9th ed.2009)).


After reviewing the evidence submitted by the prosecution, the judge held that the government had “failed to carry its burden of proving the amount of losses proximately caused by [Rowe’s] conduct with any reasonable certainty”. U.S. v. Rowe, supra. He explained that he could not ignore the fact that a


significant portion of the psychological harm inflicted upon Vicky -- as well as the entirety of the physical harm that she suffered -- was inflicted by her father, who not only committed the original abuse but also distributed photographs and videos of that abuse on the internet. The harm caused to Vicky by her father's physical and sexual abuse obviously is distinct from the psychological harm inflicted by the untold numbers of individuals (including [Rowe]) who subsequently received and possessed images of that abuse. In light of these distinct injuries, it would be absurd to hold, as the Government suggests, that [Rowe] jointly and severally liable for the entire amount of Vicky's damages.


U.S. v. Rowe, supra. The judge therefore denied the request for restitution. U.S. v. Rowe, supra.


A North Dakota district court judge did essentially the same thing in U.S. v. Solsbury, __ F.Supp.2d __, 2010 WL 3023913 (U.S. District Court for the District of North Dakota 2010). Like Rowe, Solsbury pled guilty, though he pled to receiving child pornography, and, as in the Rowe case, the government sought an “award of restitution [on behalf of Vicky] in the amount of $312.953.60.” U.S. v. Solsbury, supra. This went through the same statutory and causation analysis as the North Carolina district court judge but also noted that


[t]his is not the first case in which Vicky has filed a claim for restitution after receiving notice that a defendant was indicted for possession, access, receipt and/or distribution of her image. . . . [T]here have been claims submitted on behalf of Vicky in more than eighty different cases to date. In August of 2009, the Department of Justice began aggressively pursuing claims of restitution. In at least one case, the court awarded Vicky restitution in excess of $200,000. See United States v. Trantham, No. 09-cr-072 (N.D.Tex. Jan. 26, 2010)(ordering defendant [convicted of attempted receipt and transporting and possession of child pornography] to pay $219,546.10 in restitution to `Vicky’ . . . ). See also United States v. Fluitt, No. 09-14014-cr-Graham (S.D.Fla. Dec. 30, 2009)(ordering defendant to pay $147,000 in restitution to `Vicky’ in a case in which the defendant possessed sexual exploitation images of her as a child).


U.S. v. Solsbury, supra. Like the North Carolina judge, this judge found the government had not shown “what specific losses” Vicky suffered as a result of Solsbury’s conduct. U.S. v. Solsbury, supra. The North Dakota judge specifically pointed out that Solsbury did not produce or distribute the images of Vicky, did not create any online postings or contribute comments about Vicky to any chat rooms or blogs, has never attempted to contact Vicky and Solsbury was not mentioned in any of the expert reports submitted in support of restitution. U.S. v. Solsbury, supra.


That brings us to the third case, which had a rather different outcome: U.S. v. Baxter, 2010 WL 3452537 (U.S. Court of Appeals for the 9th Circuit 2010). All I know about Baxer is that he was sentenced for receiving child pornography, so he either went to trial and was convicted or pled to some charge(s). U.S. v. Baxter, supra. As part of his sentencing, the district court judge ordered Baxter to pay $3,000 in restitution to Vicky, presumably because at least some of the images of child pornography he received were of her. U.S. v. Baxter, supra.


Baxter appealed that order, arguing that “the record contains no causal link between Vicky’s losses and his actions”. U.S. v. Baxter, supra. The 9th Circuit, however, did not agree: “Baxter's argument . . . is not supported by the record. The United States met its burden of establishing proximate cause by showing how Vicky's harm was generally foreseeable to casual users of child pornography like Baxter.” U.S. v. Baxter, supra.


The opinion then briefly explains why the Court of Appeals found that the government had met its burden of establishing proximate cause in this case:


In a civil suit against Baxter, Vicky's actual damages would be presumed to be at least $150,000, and the government has articulated approximately $128,000 in counseling costs Vicky faces as she works to repair the damage done by the continued possession of images depicting her abuse. . . . [T]he government requested a restitution order in the amount of $3,000, articulating its recommendation by comparing it to the number of therapy sessions Vicky is estimated to need in the coming years and their cost, and recommending that $3,000 would cover 18 sessions, or one and one-half years of therapy, at one session per month -- an amount the government suggested `seems to be more than fair and reasonable’ for Baxter to pay. We agree. There is sufficient context to support the district court's order granting restitution in the amount of $3,000.


U.S. v. Baxter, supra.


For whatever it's worth, I think the first two courts got it right, given the magnitude of the restitution demands at issue in those cases. . . . I don’t see how A defendant could be held “jointly and severally” liable for all of the losses Vicky has incurred. Aside from anything else, that seems to open up the possibility that she could recover more than her actual losses. If, say, A is ordered to pay her $300,000 in restitution and B is ordered to pay her roughly the same amount, as are C and D, I don’t see how that is consistent with the policies behind ordering restitution to victims. I also think the Baxter court's resolution of the restitution issue makes sense, given the restitution issue before it.

Wednesday, November 03, 2010

Hacking and Chess

This post is about a recent decision from the U.S. District Court for the Northern District of California: U.S. v. Alexander, 2010 WL 3238961 (2010).


As this news story explains, “Gregory Alexander, of Everett, Wash[ington] was indicted in July 2009 and charged with breaking into the e-mail account of Randall Hough . . . on at least 34 occasions.”


According to that same news story, the alleged “breaking into the e-mail account” arose from a “feud” between the United States Chess Federation and “two of its former board members.” If you want to learn a lot more about what the feud was about and how it apparently resulting in the charges against Alexander, I suggest you check out this story, which predates the filing of the indictment against Alexander.


According to the opinion we’re going to examine, the indictment alleged that


on thirty-four separate occasions, Alexander accessed, without authorization, the Yahoo! email account of Randall Hough, one of the board members of the United States Chess Federation (`USCF’). These thirty-four intrusions into Hough's account correspond with the thirty-four counts of violations of the [Computer Fraud and Abuse Act, 18 U.S. Code § 1030] and also form the basis for the aggravated identity theft charge. Although none of the factual background related to this allegedly criminal conduct is included in the indictment, the government, in its late-filed opposition to Alexander's motions, describes how Alexander's actions were part of an internal power struggle among the USCF board members.


U.S. v. Alexander, supra. As you may have gathered from that paragraph, Alexander filed several pre-trial motions seeking various things from the court and the government. U.S. v. Alexander, supra. The indictment against him says that he “was a resident of Everett, Washington, and worked in the Internet Technology offices of the University of Washington” and that he “also served as a volunteer web developer who maintained and moderated the Chess Discussion Forum on the website known as chessdiscussion.com.” Indictment, U.S. v. Alexander, 2009 WL 4704875 (2009).


The indictment, as the paragraph quoted above noted, charged Alexander with 34 counts of violating the basic federal computer crime statute, 18 U.S. Code § 1030(a)(2)(C) and with 1 count of aggravated identity theft in violation of 18 U.S. Code § 1028A(a)(1). Indictment, U.S. v. Alexander, supra. Alexander only moved to dismiss the identity theft count, but in ruling on that motion to dismiss the judge noted some other problems with the indictment. U.S. v. Alexander, supra.


To understand why the judge dismissed that count, and what the other problems were, we need to start with the 18 U.S. Code § 1030 charges against Alexander: He is charged (in 34 counts) with violating “18 U.S. Code § 1030(a)(2)(C) and [§1030](c)(2)(B)(ii). U.S. v. Alexander, supra.


Section 1030(a)(2)(C) makes it a crime to intentionally access a computer without authorization or by exceeding authorized access and thereby obtain “information from any protected computer”. As I’ve noted in earlier posts, a “protected computer” is a computer that is used in interstate or foreign commerce; any computer hooked to the Internet qualifies as a protected computer. As we will see below, § 1030(c)(2)(B)(ii) makes it a felony to commit the § 1030(a)(2)(C) offense if certain requirements are met.


This is where the federal judge to whom this case is assigned found problems with the indictment. As she explained, the


indictment filed by the government in this case is as factually and legally deficient as any the court has seen in its experience. Counts 1 through 34 charge Alexander with accessing another individual's Yahoo! email account and thereby obtaining information [in violation of 18 U.S. Code § 1030(a)(2)(C)]. . . . A violation of subparagraph (a)(2) is a misdemeanor, see 18 U.S. Code § 1030(c)(2)(A), unless the government proves that

(I) the offense was committed for purposes of commercial advantage or private financial gain;

(ii) the offense was committed in furtherance of any criminal or tortious act in violation of the Constitution or laws of the United States or of any State; or

(iii) the value of the information obtained exceeds $5,000.


Id. § 1030(c)(2)(B). If the government establishes any one of those three aggravating circumstances, a violation of subsection (a)(2) is a felony, punishable by a fine or imprisonment not more than five years.


U.S. v. Alexander, supra.


The judge then found that the indictment included


only one allegation that could possibly be construed as alleging a violation of [18 U.S. Code § (a)(2)(C)]. Paragraph 7 of the indictment states that `Gregory Alexander intentionally and without authorization accessed a protected computer, to wit: the email server operated by Yahoo administering the e-mail account randallhough@yahoo.com, by means of interstate communications, and thereby obtained information from said protected computer, . . . All in violation of 18 U.S. Code §§ 1030(a)(2) and (c)(2)(B)(ii).’


Although the indictment purports to allege a violation of the [statute’s] felony provision, subsection (c)(2)(B)(ii), nowhere does it allege the statutory language of that provision, nor does it include any factual allegations from which it could be inferred that Alexander's computer intrusions were `in furtherance of any criminal or tortious act in violation of the Constitution or laws of the United States or any State.’ In other words, it fails to allege any tortious or criminal conduct that would invoke subsection (c)(2)(B)(ii). This obvious facial shortcoming in the indictment, for which the government, at the hearing on the motion, had no explanation, requires that the court construe counts 1 through 34 as charging Alexander with misdemeanor violations of [§ 1030]. In fact, the government conceded as much at the hearing.


U.S. v. Alexander, supra.


The federal judge then explained that since she had found that


the indictment only alleges misdemeanor violations of [§1030], the court must dismiss count 35. Count 35 of the indictment charges Alexander with aggravated identity theft in violation of 18 U.S. Code § 1028A(a)(1).


U.S. v. Alexander, supra. She noted that 1028A(a)(1) provides as follows:


Whoever, during and in relation to any felony violation enumerated in subsection (c), knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person shall, in addition to the punishment provided for such felony, be sentenced to a term of imprisonment of 2 years.


U.S. v. Alexander, supra (emphasis in the opinion).


And the judge explained that a


felony violation of . . . 18 U.S. Code § 1030, is among the felony violations enumerated in 18 U.S. Code § 1028A(c) that can serve as a predicate for a prosecution for aggravated identity theft. However, counts 1 through 34 of the indictment only allege misdemeanor violations of [§1030]. Accordingly, count 35 must be dismissed, as it fails to include any allegations that the identity theft engaged in by Alexander was committed `during and in relation to any felony violation. . . . '


U.S. v. Alexander, supra.


She then dismissed Count 35 and held that


within thirty (30) days of the date of this order, the government must inform defendant and the court whether it intends to seek a superseding indictment or proceed on the remaining thirty-four misdemeanor counts for violations of [§1030].


U.S. v. Alexander, supra.


It’s been over two months since the judge entered this order. But since I don’t have access to the current docket in the case, I don’t know if the government decided to seek a superseding indictment (i.e., a replacement indictment that might include allegations that Alexander’s conduct was committed in violation of the Constitution, federal or state law. And I can’t find any news stories that mention whether the government is going for a superseding indictment on intends to proceed on this one.

Monday, November 01, 2010

Dynamic IP Address and Probable Cause

This post examines a recent Connecticut case in which the defendant claimed a search warrant application was invalid because it did not indicate that the IP address linked to child pornography was “most likely dynamic”. State v. Shields, 124 Conn. App. 584, ___ A.3d ___, 2010 WL 4069147 (Connecticut Court of Appeals 2010).


This is how the issue arose:


[O]n November 4, 2005, [Officer] Grillo [of the Southbury police department] received a call from Brian Sprinkle, a detective with the Ferguson Township police department in State College. . . . Sprinkle [said] that through his investigation of Brian Gayan . . . he learned of an online conversation between Gayan and Jerome Cariaso, of 141 Rocky Mountain Road. . . . Cariaso made comments regarding sexual contact between him and his eight year old son. . . . Grillo confirmed that Cariaso resided at the address provided by Sprinkle.


On November 10, Grillo received a letter from Sprinkle that revealed that Trooper Brad of the Pennsylvania state police executed search warrants at Gayan's place of residence and place of employment. A search of his computers revealed that Gayan, using the screen name `Centralpamaster,’ had contact with seventy-five screen names belonging to minors or suspects who had spoken with him about abusing . . . children. . . . Sprinkle obtained a court order, which asked Yahoo . . . to provide log-in Internal protocol (IP) addresses for the screen name `Bi06488.’ Yahoo . . . revealed there was a recent log of IP addresses listed under that screen name. . . . [T]he IP addresses were owned by Charter Communications, and, on November 4, 2005, Charter Communications indicated that Cariaso, of 141 Rocky Mountain Road, Southbury, was the subscriber for the IP address of 24.151.2.100, the IP address in question.


Additionally, Sprinkle provided Grillo with a transcript of a Yahoo messenger conversation between `Centralpamaster’ and `Bi06488,’ in which `Bi06488” asked `Centralpamaster’ for pornographic photographs of `Centralpamaster's’ son. The person using the `Bi06488’ screen name informed `Centralpamaster’ they could not swap photographs because he did not currently have pornographic photographs of his son on his computer.

On November 14, Grillo obtained land records from the Southbury assessor's office indicating that the property at 141 Rocky Mountain Road was owned by Cariaso and Rosalie Shields. . . . . Grillo submitted a search warrant application seeking to search the subject residence.


State v. Shields, supra. (The opinion notes that “[p]ostal records show[ed] that” Robert Shields, Rosalie Shields and Carlaso all received mail at 141 Rocky Mountain Road. State v. Shields, supra.)


A judge issued the warrant, which authorized officers a search of “computer systems” for evidence of possession of child pornography and other crimes. State v. Shields, supra. Officers “seized numerous computer systems” which were later examined by computer forensics experts; the examination “revealed extensive evidence that the computers were used by” Robert Shields, not Carlaso. State v. Shields, supra. So Shields was charged with possessing and importing child pornography in violation of Pennsylvania law. State v. Shields, supra.


He moved to suppress the evidence seized from the residence, claiming the “search was unlawful because the warrant failed to establish probable cause to believe child pornography was located within the subject residence. [Shields] argued that the affidavit attached to the warrant failed to establish a connection between the screen name `Bi06488,’ the IP address and” 141 Rocky Mountain Road. State v. Shields, supra.


The trial judge denied his motion, Shields was convicted “following his conditional plea of nolo contendere” to the charge of possessing child pornography and appealed to the Connecticutt Court of Appeals. State v. Shields, supra. The opinion doesn’t make this clear, but I’m assuming he pled guilty on the condition that he could challenge the trial court’s ruling on his motion to suppress. State v. Shields, supra. (He actually filed, and appealed from the denial of, two motions to suppress, but we’re only concerned with one of them.)


On appeal, Shields renewed his argument that because the search warrant affidavit


failed to link the IP address, 24.151.2.100, to the subject residence at the exact time `Bi06488’ had the incriminating conversation with `Centralpamaster’ on July 1, 2005, the affidavit could not support a finding of probable cause. Specifically, he argues that the information provided by Charter Communications, that he was the subscriber to the IP address, failed to show there was a direct connection between the IP address and the subject residence at the exact time the incriminating conversation occurred. [Shields] argues that the affiants also failed to inform the court that the IP address was most likely dynamic and subject to change, thus rendering the affidavit insufficient to establish probable cause.


State v. Shields, supra. Shields relied, in part, on the fact that newly discovered


evidence provided that the incriminating conversation between `Bi06488’ and `Centralpamaster’ occurred on May 5, 2005, not on July 1 or August 3, 2005. It was further revealed that July 1, 2005, was the date the conversation was decoded and recorded. . . . [and] that the IP address of 24.151.2.100 was dynamic and not static. Additionally, Charter Communications confirmed that the IP address was leased to Cariaso on July 15, 2005, and also on August 3, 2005. Also, when Charter Communications leased IP addresses, it was possible that the leases could continue for several months in duration.


State v. Shields, supra. In making this argument, Shields was relying on the Supreme Court’s holding in Franks v. Delaware, 438 U.S. 154 (1978). In Franks, the Court dealt with the consequences of an officer’s including a false statement in an affidavit used to obtain a search warrant. The Franks Court held that when a defendant makes a


substantial . . . showing that a false statement knowingly and intentionally, or with reckless disregard for the truth, was included . . . in the warrant affidavit, and [that] the allegedly false statement is necessary to the finding of probable cause, the Fourth Amendment requires that a hearing be held at the defendant's request. In the event that at that hearing the allegation of perjury or reckless disregard is established by the defendant by a preponderance of the evidence, and, with the affidavit's false material set to one side, the affidavit's remaining content is insufficient to establish probable cause, the search warrant must be voided and the fruits of the search excluded to the same extent as if probable cause was lacking on the face of the affidavit.


Franks v. Delaware, supra. Lower courts have held that the Franks standard applies to information omitted from a search warrant application, as well as to false statements. U.S. v. Scott, 610 F.3d 1009 (U.S. Court of Appeals for the 8th Circuit 1010). So Shields was claiming that not including the information about the dynamic IP address in the warrant triggered the Franks requirements.


The Connecticut Court of Appeals, however, didn’t buy his argument. It held, first, that as to Shields’ argument that the affidavit


inaccurately suggested the . . . conversation took place on a date other than May 5, 2005, the trial court determined that `it may have been a bit misleading, but it wasn't an inaccuracy. The affidavit indicated that the conversation was decoded on July 1 [2005], not that [it] occurred on July 1 [2005]. And July 1 [2005] was the date [o]n which . . . police were able to seize the computer and review the conversation. So, it wasn't inaccurate, though it may have implied that the conversation took place on that date. But even with respect to that information, it's not material, one way or the other, whether the conversation, in fact, took place on May 5 [2005], or July 1 [2005], but I don't find it to be an inaccuracy.’


State v. Shields, supra. With regard to Shields’ argument that the failure to tell the judge that the IP address


was dynamic and . . . obtained for the date of August 3, 2005, not May 5, 2005, the trial court . . . did not `find the . . . . omission . . . was reckless or made the warrant misleading. . . . The fact there was a dynamic IP address doesn't necessarily mean that the person using the computer on August 3 [2005] was different than the person using the computer on May 5 [2005]. And, . . . evidence . . . indicates they were . . . the same person. . . . [T]hat evidence includes the Yahoo [Inc.] document . . . which indicates that on May 5 [2005] the IP address at issue here, 24.151.2.100, that the user of that IP address was a person using the screen name Bi06488, that that's the same IP address that was used on May 5 [2005] and on August 3, 2005. The Charter Communications documents indicate that. And the Charter Communications documents also indicate that Charter Communications leased its IP address -- its dynamic IP addresses for a significant period of time, for months. . . . And so the fact that it was a dynamic IP address . . . is not dispositive of anything. I also find telling that . . . [Shields] made no offer of proof that the IP addresses were . . . or the user of the IP address on May 5 [2005] was . . . different from the user of the IP address on August 3 [2005]. . . .


[T]he fact that it was a dynamic IP address, the fact that they asked for the IP address for a different day than the offending conversation . . . were not material. . . . [I]t’s still reasonable . . . given that Charter Communications leased its IP addresses for months at a time, given that the user on May 5 [2005] was the same screen name as the user on August 3 [2005. . . all of those . . . facts [make it] reasonable to infer that it was the same user on those two dates, and if the judge had before . . . him the information [Shields] claims was omitted, it would still be reasonable to infer that they were the same person and to find probable cause to search [the residence] and to seize the computer. . . . ‘


State v. Shields, supra.