Two More Courts Find In Favor Of The FBI And Its NIT Warrant; No Suppression Granted

from the malware-deployment-is-a-go dept

Two more rulings on suppression motions in FBI Playpen cases have been handed down. (h/t Riana Pfefferkorn) The ruling [PDF] in Tennessee agrees with the defendant that the FBI’s NIT warrant exceeded Rule 41 jurisdiction limits. The following quotes are from the more substantive “Report and Recommendation” [PDF] by the magistrate judge, which has been adopted by the court overseeing the criminal trial.

The undersigned agrees with the majority of courts to analyze the Virginia search warrant that it violates Rule 41(b) because the magistrate judge in the Eastern District of Virginia lacked authority to issue a search warrant to search property located outside of her district.

Defendant’s computer was never located in the Eastern District of Virginia. See Fed. R. Crim. P. 41(b)(1) & (2). Moreover, the FBI was not investigating a crime of terrorism in the Eastern District of Virginia, nor was it attempting to seize property located in a United States territory or foreign state. See Fed. R. Crim. P. 41(b)(3) & (5). The Government argues that Rule 41(b)(4) is persuasive because the NIT is analogous to a tracking device, which was installed on the Defendant’s computer when his electronic transmission “touched down” in the Eastern District of Virginia, where Playpen was hosted. However, as observed by the Western District of Washington, applying Rule 41(b)(4) to the Virginia warrant “stretches the rule too far…”

That being said, the court decides suppression is not the right remedy for this violation:

In balancing the present facts and circumstances, the magistrate judge first correctly concluded that suppressing the evidence in this case would not meaningfully deter future law enforcement misconduct. The defendant’s objections that officers acted deliberately, recklessly, or with gross negligence, and that it should have been apparent to law enforcement that the Virginia magistrate lacked authority to sign the warrant, are simply unsupported by the record.

[…]

To the extent that there was error in this investigation, such error “rests with the issuing magistrate, not the police officer, and ‘punish[ing] the errors of judges’ is not the office of the exclusionary rule.”

Interestingly (and a bit infuriatingly), the court grants good faith to the FBI for its apparent inability to fully comprehend the “intricacies of the jurisdictions of federal magistrates.” This gives the FBI credit for pretending to misunderstand the very statutes it’s in the process of trying to change. The FBI — and the DOJ above it — very much want the jurisdictional limitations of Rule 41 removed precisely for cases like these: where a search and seizure is performed on remote computers located far outside the jurisdiction where the warrant was issued.

The Nebraska decision [PDF] is much, much worse. First, the court finds there’s no expectation of privacy in an IP address, even if the defendant has taken affirmative steps to obscure it.

With or without Tor, Defendant was sharing his IP address with others—total strangers, to potentially include law enforcement officers—with the hope and belief that the users of the first “node” computer would keep his IP address secret. While Defendant’s choice to use Tor may be evidence of his “actual, (subjective) expectation of privacy” in his IP address, using Tor does not elevate that expectation to “one that society is prepared to recognize as ‘reasonable.’”

Not only that, but the court rules the NIT is not a search (nor a “tracking device,” as the government argued in the Tennessee case), even though it had to extract this information from the user’s computer.

But deploying the NIT to reveal the IP address was not a computer search. Defendant’s IP address is not a “physical component” of the computer or a file residing on his computer like electronic documents or pictures. Rather, the IP address is assigned to a user by the ISP and typically is “maintained on the internet modem that connects an internet device to the internet.” Thus, the NIT essentially compelled Defendant’s computer to produce its IP address (similar to a return address on an envelope) when the NIT instructed the computer to send other information identified in the Virginia Warrant. And the NIT was deployed only after Defendant sought out and visited the Playpen website. “The FBI did not come looking for Defendant. Instead it waited until he came to them and engaged in illicit activity by downloading content from Playpen.”

And here we have another reason why digital-to-analog so often fails. Comparing the compelled production of an IP address to a return address on an envelope is a non-starter because utilizing the postal service does not require the use of a return address, whereas an internet connection almost always requires an IP address.

Worse, the opinion cites Virginia judge Henry Morgan Jr.’s decision in another Playpen case — where he asserted the FBI could hack computers with invalid warrants because, hey, computers get hacked all the time.

See also Matish, — F. Supp. 3d —, 2016 WL 3545776 at *22-24 (holding that with the prevalence of computer hacking and the “compromise of unprecedented amounts of data previously thought to be private,” all individuals have a diminished expectation of privacy once they log onto the internet.)

The court also finds that the FBI’s NIT reach didn’t exceed Rule 41 geographical limitations. Instead, the defendant made a virtual “trip” to the warrant’s jurisdiction to access content stored on the seized server.

Finally, even if the defendant had raised a Fourth Amendment challenge the court found valid, the good faith exception would have prevailed. As in the Tennessee decision, the court finds the FBI held up its side of the deal by providing the magistrate with an affidavit full of technical language and specifics about the search method to be deployed.

This appears to be the broader finding across the large number of Playpen/NIT cases. The FBI’s warrant may be invalid but either there’s no expectation of privacy in the information obtained or the good faith exception prevents suppression of the obtained evidence.

The first is less problematic than the latter. While some users may undertake efforts to obscure their IP addresses, their expectation of privacy is no more “reasonable” than that of those who don’t. Either the info has an expectation of privacy or it doesn’t. The legal justifications used by judges, however, haven’t been all that great, with the worst being that having your anonymity stripped and your information absconded with is just the price of doing business on the internet — whether it’s a criminal or law enforcement performing the actions apparently matters very little.

The latter part — the reliance on the FBI’s good faith — is more of an issue. The FBI clearly knew its NIT would travel far beyond the jurisdiction the warrant was issued in. It apparently felt that it benefited heavily from good faith rulings as it made little attempt to obscure this fact from the magistrate judge it presented its affidavit to. But it still withheld some information, including the fact that it would actually be delivering a malware package that would “phone home” once it reached its destination. Just because the search sort of originated at a seized server in Virginia does not excuse seizures performed all over the nation utilizing a single, jurisdictionally-limited warrant.





Filed Under: , , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Two More Courts Find In Favor Of The FBI And Its NIT Warrant; No Suppression Granted”

Subscribe: RSS Leave a comment
16 Comments
Anonymous Coward says:

The exclusionary rule is there to prevent misbehavior by law enforcement. Misbehavior by judges? Their attitude is apparently that it can’t happen. They can only make mistakes, and would never ever have a motive to violate someone’s rights.

But, now that there is an obvious precedent that they can’t do this, perhaps if they ever try this again it WILL be suppressed, and the FBI won’t get away with saying it didn’t know.

Anonymous Coward says:

Re: Re: what did you expect?

Well… its fucking working. The founders are generally hated and ignored for their extensive wisdom.

As one of the few that understand the Constitution, its purpose and having read the founders on multiple subjects I feel at though I am surrounded by very spoiled fucking idiots that have just exactly no clue how much they are fucking this shit up with their ignorance and hubris!

The constitution is clear as a fucking bell, however many have “allowed” those in power to pull the wool over their eyes for political expediency.

That One Guy (profile) says:

Re: My Take on the first case's response

Pretty much. “Yeah they broke the law, but punishing them for doing so isn’t likely to result in them doing anything different next time, so we won’t bother.”

An argument like that makes it pretty clear that the judge sees nothing wrong in breaking the law if the ones doing so have a badge.

Uriel-238 (profile) says:

Re: Re: My Take on the first case's response

Suppressing evidence is not punishment for the FBI, it’s the protection of the rights of the people.

And if anything, it’s punishment for the state as a whole, for allowing the FBI to continue with its blase attitude regarding proper procedure.

If this doesn’t change the FBI’s behavior, then continued enforcement of the fourth amendment would push the rest of the system to change the FBI.

…or they can settle for a short term victory at the expense of further damage in the future.

Uh Huh says:

The Big Bang

What it ultimately comes down to is: Power comes from the barrell of the biggest, baddest (fill in the blank), which is directed by the persons having the most (fill in the blank), usually obtained by clandestine, criminal, predatory activities, and executed by minions of limited intellectual and moral capacity, of which there is an abundance without end. Have a nice day.

Anonymous Coward says:

Re: The Big Bang

and executed by minions of limited intellectual and moral capacity

This should read more like…

“and executed by opportunistic minions of limited moral capacity”

There are many very intelligent “minions” taking their slice of the pie as they pass it along to the “big man”, so it’s not entirely fair to plaster them all as low intelligence.

Uriel-238 (profile) says:

Re: The Big Bang

Free states have to be protected. Otherwise it falls back to feudalism and divine right (e.g. the right of might).

Our nation of men is the natural state. We do what is possible. Those with power dominate those without.

But then they can’t really complain when terrorists fly planes into buildings or madmen shoot up schools can they? Hatred-fueled subterfuge and having no moral high ground is the consequence of ruling by force.

Christenson says:

Dear Judges:

Dear Judges:
The FBI concealed material facts from the magistrate. Think through the implications of that — if they are willing to lie to judges (not only about this, but also “parallel construction”) — then *no* evidence they give can be credible! Falsus in Unum, Falsus in Omnes has been in many a jury instruction, and it should apply to the FBI just as it does any other witness.

The FBI has basically chosen some people to destroy; whether they are actually bad people who did what they claim has become completely immaterial to them, and you should treat their testimony accordingly.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...