Military reference books and manuals (2009-2023, Volume 3) - page 35

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 3)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     33      34      35      36     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 3) - page 35

 

 

clear. 18 U.S.C. § 2510(5)(a). Specifically, it is not obvious from the text of
the statute whether “telephone or telegraph” modifies all three objects—i.e.,
“instrument, equipment or facility”—or only
“instruments.” Te former
reading suggests that the exception could apply only to providers of telephone
or telegraph services, while the latter reading supports the conclusion that the
exception could apply to a computer service provider. Te Second Circuit has
resolved this ambiguity in favor of the more expansive interpretation in Hall
v. EarthLink Network, Inc., 396 F.3d 500, 504-05 (2d Cir. 2005), in which it
held that an ISP acted in its ordinary course of business when it continued to
receive and store messages sent to the account of a terminated customer.
Te exception in 18 U.S.C. § 2510(5)(a)(ii) that permits the use of “any
telephone or telegraph instrument, equipment or facility, or any component
thereof ” by “an investigative or law enforcement officer in the ordinary course
of his duties” is also a common source of confusion. Tis language does not
permit agents to intercept the private communications of the targets of a
criminal investigation on the theory that a law enforcement agent may need
to intercept communications “in the ordinary course of his duties.” As Chief
Judge Posner explained:
Investigation is within the ordinary course of law enforcement,
so if “ordinary” were read literally warrants would rarely if ever
be required for electronic eavesdropping, which was surely
not Congress’s intent. Since the purpose of the statute was
primarily to regulate the use of wiretapping and other electronic
surveillance for investigatory purposes, “ordinary” should not
be read so broadly; it is more reasonably interpreted to refer to
routine noninvestigative recording of telephone conversations.
. . . Such recording will rarely be very invasive of privacy, and for
a reason that does after all bring the ordinary-course exclusion
rather close to the consent exclusion: what is ordinary is apt to
be known; it imports implicit notice.
Amati v. City of Woodstock, 176 F.3d 952, 955 (7th Cir. 1999). For example,
routine taping of all telephone calls made to and from a police station or
prison may fall within this law enforcement exception, but non-routine taping
designed to target a particular suspect ordinarily would not. See id.; accord
Adams v. City of Battle Creek, 250 F.3d 980, 984 (6th Cir. 2001) (“Congress
most likely carved out an exception for law enforcement officials to make
clear that the routine and almost universal recording of phone lines by police
4. Electronic Surveillance
181
departments and prisons, as well as other law enforcement institutions, is
exempt from the statute.”); United States v. Lewis, 406 F.3d 11, 18-19 (1st Cir.
2005) (concluding that routine monitoring of calls made from prison falls
within law enforcement exception); United States v. Hammond, 286 F.3d 189,
192 (4th Cir. 2002) (same); United States v. Van Poyck, 77 F.3d 285, 292 (9th
Cir. 1996) (same).
f.
Te ‘Inadvertently Obtained Criminal Evidence’ Exception,
18 U.S.C. § 2511(3)(b)(iv)
Section 2511(3)(b) lists several narrow contexts in which a provider of
electronic communication service to the public can divulge the contents of
communications. Te most important of these exceptions permits a public
provider to divulge the contents of any communications that
were inadvertently obtained by the service provider and
which appear to pertain to the commission of a crime, if such
divulgence is made to a law enforcement agency.
18 U.S.C. § 2511(3)(b)(iv). Although this exception has not yet been applied
by the courts in any published cases involving computers, its language appears
to permit providers to report criminal conduct (e.g., child pornography or
evidence of a fraud scheme) in certain circumstances without violating Title
III. Cf.
18 U.S.C. § 2702(b)(7)(A) (creating an analogous rule for stored
communications).
g. Te ‘Accessible to the Public’ Exception, 18 U.S.C. § 2511(2)(g)(i)
Section
2511(2)
(g)(i) permits
“any person” to intercept an electronic
communication made through a system “that is configured so that . . . [the]
communication is readily accessible to the general public.” Congress intended
this language to permit the interception of an electronic communication
that has been posted to a public bulletin board, a public chat room, or a
Usenet newsgroup. See S. Rep. No. 99-541, at 36 (1986), reprinted in 1986
U.S.C.C.A.N. 3555, 3590 (discussing bulletin boards). Tis exception may
apply even if users are required to register and agree to terms of use in order to
access the communication. See Snow v. DirecTV, Inc., 450 F.3d 1314, 1321-22
(11th Cir. 2006) (electronic bulletin board that required visitors to register,
obtain a password, and certify that they were not associated with DirecTV was
accessible to the public).
182
Searching and Seizing Computers
E. Remedies For Violations of Title III
and the Pen/Trap Statute
Agents and prosecutors must comply with Title III and the Pen/Trap statute
when planning electronic surveillance. Violations can result in criminal penalties,
civil liability, and (in the case of certain Title III violations) suppression of the
evidence obtained. See 18 U.S.C. § 2511(4) (criminal penalties for Title III
violations); 18 U.S.C. § 2520 (civil action for Title III violations); 18 U.S.C.
§ 3121(d) (criminal penalties for Pen/Trap statute violations); 18 U.S.C. §
2707(a), (g) (civil action for certain Pen/Trap statute violations); 18 U.S.C.
§ 2518(10)(a) (suppression for certain Title III violations). As a practical
matter, however, courts may conclude that the electronic surveillance statutes
were violated even after agents and prosecutors have acted in good faith and
with full regard for the law. For example, a private citizen may wiretap his
neighbor and later turn over the evidence to the police, or agents may intercept
communications using a court order that the agents later learn is defective.
Similarly, a court may construe an ambiguous portion of Title III differently
than did the investigators, leading the court to find that a violation of Title
III occurred. Accordingly, prosecutors and agents must understand not only
what conduct the surveillance statutes prohibit, but also what the ramifications
might be if a court finds that the statutes have been violated.
1. Suppression Remedies
Title III provides for statutory suppression of wrongfully
intercepted oral and wire communications, but not electronic
communications. The Pen/Trap statute does not provide a
statutory suppression remedy. Constitutional violations may also
result in suppression of the evidence wrongfully obtained.
a. No Statutory Suppression for Interception
of Electronic Communications
Te statutes that govern electronic surveillance grant statutory suppression
remedies to defendants only in a specific set of cases. A defendant may only
move for suppression on statutory grounds when the defendant was a party to
an oral or wire communication that was intercepted in violation of Title III, or
when the intercepted oral or wire communications occurred on his premises.
See 18 U.S.C. §§ 2510(11), 2518(10)(a). See also United States v. Giordano,
416 U.S. 505, 524 (1974) (stating that “[w]hat disclosures are forbidden
4. Electronic Surveillance
183
[under § 2515], and are subject to motions to suppress, is . . . governed by
§ 2518(10)(a)”); United States v. Williams, 124 F.3d 411, 426 (3d Cir. 1997).
Section 2518(10)(a) states:
[A]ny aggrieved person . . . may move to suppress the contents
of any wire or oral communication intercepted pursuant to this
chapter, or evidence derived therefrom, on the grounds that—
(i) the communication was unlawfully intercepted;
(ii) the order of authorization or approval under which it was
intercepted is insufficient on its face; or
(iii) the interception was not made in conformity with the
order of authorization or approval.
18 U.S.C. § 2518(10)(a). An “aggrieved person” is defined in 18 U.S.C.
§ 2510(11) to mean “a person who was a party to any intercepted wire, oral,
or electronic communication or a person against whom the interception was
directed.” In Alderman v. United States, 394 U.S. 165, 176 (1969), the Supreme
Court held that a defendant has standing under the Fourth Amendment to
challenge intercepted conversations if he was a party to the conversations or if
the conversations occurred “on his premises, whether or not he was present or
participating in those conversations.”
Notably, Title III does not provide a statutory suppression remedy for
unlawful interceptions of electronic communications. See, e.g., United States v.
Jones, 364 F. Supp. 2d 1303, 1306-09 (D. Utah 2005); United States v. Steiger,
318 F.3d 1039, 1050-52 (11th Cir. 2003); Steve Jackson Games, Inc. v. United
States Secret Service, 36 F.3d 457, 461 n.6 (5th Cir. 1994); United States v.
Meriwether, 917 F.2d 955, 960 (6th Cir. 1990). Tere is one minor exception
to this rule: electronic communications intercepted pursuant to a Title III court
order may be suppressed for failure to seal the intercepted communications as
required by 18 U.S.C. § 2518(8)(a). See United States v. Suarez, 906 F.2d 977,
982 n.11 (4th Cir. 1990). In addition, the Pen/Trap statute does not provide a
statutory suppression remedy for violations. See United States v. Forrester, 512
F.3d 500, 512 (9th Cir. 2008); United States v. Fregoso, 60 F.3d 1314, 1320-21
(8th Cir. 1995); United States v. Tompson, 936 F.2d 1249, 1249-50 (11th Cir.
1991).
184
Searching and Seizing Computers
b. Suppression Following Interception with a Defective Title III Order
Under section 2518(10)(a), the courts generally will suppress evidence
resulting from any unlawful interception of an aggrieved party’s wire
communication that takes place without a court order. However, when
investigators procure a Title III order to intercept wire or oral communications
that later turns out to be defective, the courts will suppress the evidence obtained
with the order only if the defective order “fail[ed] to satisfy any of those statutory
requirements that directly and substantially implement the congressional
intention [in enacting Title III] to limit the use of intercept procedures to those
situations clearly calling for the employment of this extraordinary investigative
device.” United States v. Giordano, 416 U.S. 505, 527 (1974).
Tis standard requires the courts to distinguish technical defects from
substantive ones. If the defect in the Title III order concerns only technical
aspects of Title III, the fruits of the interception will not be suppressed. In
contrast, courts will suppress the evidence if the defect reflects a failure to
comply with a significant requirement of Title III. Compare Giordano, 416
U.S. at 527-28 (suppression required for failure to receive authorization from
Justice Department official listed in § 2516(1) for wire interception order in
light of importance of such authorization to statutory scheme) with United
States v. Radcliff, 331 F.3d 1153, 1162-63 (10th Cir. 2003) (suppression not
required for wiretap orders’ failure to specifically identify the Justice Department
officials who authorized the applications because, inter alia, this defect did
not subvert statutory scheme). Defects that directly implicate constitutional
concerns, such as probable cause and particularity, see Berger v. New York, 388
U.S. 41, 58-60 (1967), will generally be considered substantive defects that
require suppression. See United States v. Ford, 553 F.2d 146, 173 (D.C. Cir.
1977).
c. Te “Clean Hands” Exception in the Sixth Circuit
Section 2518(10)(a)(i) states that an aggrieved person may move to
suppress the contents of wire communications when “the communication
was unlawfully intercepted.” Te language of this statute is susceptible to
the interpretation that the government cannot use the fruits of an illegally
intercepted wire communication as evidence in court, even if the government
itself did not intercept the communication. Under this reading, if a private
citizen wiretaps another private citizen and then hands over the results to the
government, the government could not use the evidence in court. Five circuit
4. Electronic Surveillance
185
courts have so held. See United States v. Crabtree, 565 F.3d 887, 889-92 (4th
Cir. 2009); Berry v. Funk, 146 F.3d 1003, 1013 (D.C. Cir. 1998) (dicta);
Chandler v. United States Army, 125 F.3d 1296, 1302 (9th Cir. 1997); In re
Grand Jury, 111 F.3d 1066, 1077-78 (3d Cir. 1997) United States v. Vest, 813
F.2d 477, 481 (1st Cir. 1987).
Te Sixth Circuit, however, has fashioned a “clean hands” exception that
permits the government to use any illegally intercepted communication so long
as the government “played no part in the unlawful interception.” United States
v. Murdock, 63 F.3d 1391, 1404 (6th Cir. 1995). In Murdock, the defendant’s
wife had surreptitiously recorded her estranged husband’s phone conversations
at their family-run funeral home. When she later listened to the recordings,
she heard evidence that her husband had accepted a $90,000 bribe to award a
government contract to a local dairy while serving as president of the Detroit
School Board. Mrs. Murdock sent an anonymous copy of the recording to
a competing bidder for the contract, who in turn offered the copy to law
enforcement. Te government then brought tax evasion charges against Mr.
Murdock on the theory that Mr. Murdock had not reported the $90,000 bribe
as taxable income.
Following a trial in which the recording was admitted in evidence against
him, the jury convicted Mr. Murdock, and he appealed. Te Sixth Circuit
affirmed, ruling that although Mrs. Murdock had violated Title III by
recording her husband’s phone calls, this violation did not bar the admission
of the recordings in a subsequent criminal trial. Te court reasoned that Mrs.
Murdock’s illegal interception could be analogized to a Fourth Amendment
private search and concluded that Title III did not preclude the government
“from using evidence that literally falls into its hands” because it would have no
deterrent effect on the government’s conduct. Id. at 1403.
After the Sixth Circuit decided Murdock, several circuits rejected the
“clean hands” exception and instead embraced the First Circuit’s Vest rule
that the government cannot use the fruits of unlawful interception even if
the government was not involved in the initial interception. See United States
v. Crabtree, 565 F.3d 887, 889-92 (4th Cir. 2009); Berry v. Funk, 146 F.3d
1003, 1013 (D.C. Cir. 1998) (dicta); Chandler v. United States Army, 125 F.3d
1296, 1302 (9th Cir. 1997); In re Grand Jury, 111 F.3d 1066, 1077-78 (3d
Cir. 1997).
186
Searching and Seizing Computers
d. Constitutional Suppression Remedies
Defendants may move to suppress evidence from electronic surveillance
of communications networks on either statutory or Fourth Amendment
constitutional grounds. Although Fourth Amendment violations generally
lead to suppression of evidence, see Mapp v. Ohio, 367 U.S. 643, 655 (1961),
defendants move to suppress the fruits of electronic surveillance on constitutional
grounds only rarely. Tis is true for at least two reasons. First, Congress’s
statutory suppression remedies tend to be as broad or broader in scope than
their constitutional counterparts. See, e.g., Chandler, 125 F.3d at 1298; Ford,
553 F.2d at 173. Cf. United States v. Torres, 751 F.2d 875, 884 (7th Cir. 1984)
(noting that Title III is a “carefully thought out, and constitutionally valid . .
. effort to implement the requirements of the Fourth Amendment.”). Second,
electronic surveillance statutes often regulate government access to evidence
that is not protected by the Fourth Amendment. For example, the Supreme
Court has held that the use and installation of pen registers does not constitute
a Fourth Amendment “search.” See Smith v. Maryland, 442 U.S. 735, 742
(1979). Te Ninth Circuit recently confirmed that this holding applies equally
to computer surveillance techniques that reveal the “to” and “from” addresses
of email messages, the IP addresses of websites visited, and the total amount of
data transmitted to or from an account. See United States v. Forrester, 512 F.3d
500, 510-11 (9th Cir. 2008). As a result, use of a pen/trap device in violation
of the Pen/Trap statute ordinarily does not lead to suppression of evidence on
Fourth Amendment grounds. See United States v. Tompson, 936 F.2d 1249,
1251 (11th Cir. 1991).
It is also likely that a hacker would not enjoy a constitutional entitlement
under the Fourth Amendment to suppression of unlawful monitoring of his
unauthorized activity. As the Fourth Circuit noted in United States v. Seidlitz,
589 F.2d 152 (4th Cir. 1978), a computer hacker who breaks into a victim
computer “intrude[s] or trespasse[s] upon the physical property of [the victim]
as effectively as if he had broken into the . . . facility and instructed the computers
from one of the terminals directly wired to the machines.” Id.. at 160. A
trespasser does not have a reasonable expectation of privacy where his presence
is unlawful. See Rakas v. Illinois, 439 U.S. 128, 143 n.12 (1978) (noting that
“[a] burglar plying his trade in a summer cabin during the off season may have
a thoroughly justified subjective expectation of privacy, but it is not one which
the law recognizes as ‘legitimate’”); Amezquita v. Hernandez-Colon, 518 F.2d
8, 11 (1st Cir. 1975) (holding that squatters had no reasonable expectation
4. Electronic Surveillance
187
of privacy on government land where the squatters had no colorable claim to
occupy the land). Accordingly, a computer hacker would have no reasonable
expectation of privacy in his unauthorized activities that were monitored from
within a victim computer. “[H]aving been ‘caught with his hand in the cookie
jar,’” the hacker has no constitutional right to the suppression of evidence of
his unauthorized activities. Seidlitz, 589 F.2d at 160.
2. Defenses to Civil and Criminal Actions
Agents and prosecutors are generally protected from liability
under Title III for reasonable decisions made in good faith in the
course of their official duties.
Civil and criminal actions may result when law enforcement officers violate
the electronic surveillance statutes. In general, the law permits such actions
when law enforcement officers abuse their authority, but protects officers from
suit for reasonable good-faith mistakes made in the course of their official
duties. Te basic approach was articulated over a half century ago by Judge
Learned Hand:
Tere must indeed be means of punishing public officers who
have been truant to their duties; but that is quite another matter
from exposing such as have been honestly mistaken to suit by
anyone who has suffered from their errors. As is so often the
case, the answer must be found in a balance between the evils
inevitable in either alternative.
Gregoire v. Biddle, 177 F.2d 579, 581 (2d Cir. 1949). When agents and
prosecutors are subject to civil or criminal suits for electronic surveillance,
the balance of evils has been struck by both a statutory good-faith defense
and a widely (but not uniformly) recognized judge-made qualified-immunity
defense.
a. Good-Faith Defense
Both Title III and the Pen/Trap statute offer a statutory good-faith defense.
According to these statutes,
a good faith reliance on . . . a court warrant or order, a grand
jury subpoena, a legislative authorization, or a statutory
authorization . . . is a complete defense against any civil or
criminal action brought under this chapter or any other law.
188
Searching and Seizing Computers
18 U.S.C. § 2520(d) (good-faith defense for Title III violations). See also 18
U.S.C. § 3124(e) (good-faith defense for Pen/Trap statute violations). Tese
defenses are most commonly applicable to law enforcement officers executing
legal process and service providers complying with legal process, even if the
process later turns out to be deficient in some way. Similarly, Title III protects
a person acting under color of law when that person believes in good faith
that interception is warranted by the computer trespasser exception. See 18
U.S.C. § 2520(d)(3) (creating a defense for good faith reliance on a good faith
determination that, inter alia, § 2511(2)(i) permitted the interception).
Te cases interpreting the good-faith defense are notably erratic. In general,
however, the courts have permitted law enforcement officers to rely on the
good-faith defense when they make honest mistakes in the course of their
official duties. See, e.g., Kilgore v. Mitchell, 623 F.2d 631, 633 (9th Cir. 1980)
(“Officials charged with violation of Title III may invoke the defense of good
faith under § 2520 if they can demonstrate: (1) that they had a subjective
good faith belief that they were acting in compliance with the statute; and
(2) that this belief was itself reasonable.”); Hallinan v. Mitchell, 418 F. Supp.
1056, 1057 (N.D. Cal. 1976) (good-faith exception protects Attorney General
from civil suit after Supreme Court rejects Attorney General’s interpretation
of Title III). Te defense is also available to providers and other private parties
who conduct surveillance in good faith reliance on a court order obtained by
law enforcement. See Jacobson v. Rose, 592 F.2d 515, 522-23 (9th Cir. 1978)
(Congress established good-faith defense for Title III violations in part “to
protect telephone companies and other persons who cooperate under court
order with law enforcement officials”) (citation omitted). In contrast, courts
have not permitted private parties to rely on good-faith “mistake of law”
defenses in civil wiretapping cases. See, e.g.,Williams v. Poulos, 11 F.3d 271, 285
(1st Cir. 1993); Heggy v. Heggy, 944 F.2d 1537, 1541-42 (10th Cir. 1991).
b. Qualified Immunity
Te majority of courts have recognized a qualified immunity defense to Title
III civil suits in addition to the statutory good-faith defense. See, e.g., Lonegan
v. Hasty, 436 F. Supp. 2d 419, 430 n.5 (E.D.N.Y. 2006) (noting that courts
in Second Circuit have “routinely” allowed defendants to raise the qualified
immunity defense in Title III cases); Tapley v. Collins, 211 F.3d 1210, 1216
(11th Cir. 2000) (holding that public officials sued under Title III may invoke
qualified immunity in addition to the good faith defense); Blake v. Wright, 179
F.3d 1003, 1013 (6th Cir. 1999) (“a defendant may claim qualified immunity
4. Electronic Surveillance
189
in response to a Title III claim”); Davis v. Zirkelbach, 149 F.3d 614, 618, 620
(7th Cir. 1998) (qualified immunity defense applies to police officers and
prosecutors in civil wiretapping case). But see Berry v. Funk, 146 F.3d 1003,
1013-14 (D.C. Cir. 1998) (concluding that qualified immunity does not apply
to Title III violations because the statutory good-faith defense exists); Hepting
v. AT&T Corp., 439 F. Supp. 2d 974, 1009 (N.D. Cal. 2006) (disagreeing with
Tapley and Blake and holding that providers who assist the government are not
entitled to qualified immunity from Title III suits).
Under the doctrine of qualified immunity,
government officials performing discretionary functions
generally are shielded from liability for civil damages insofar as
their conduct does not violate clearly established statutory or
constitutional rights of which a reasonable person would have
known.
Harlow v. Fitzgerald, 457 U.S. 800, 818 (1982). In general, qualified immunity
protects government officials from suit when “[t]he contours of the right”
violated were not so clear that a reasonable official would understand that his
conduct violated the law. Anderson v. Creighton, 483 U.S. 635, 640 (1987);
Burns v. Reed,
500 U.S. 478, 496 (1991) (prosecutors receive qualified
immunity for legal advice to police).
Of course, whether a statutory right under Title III is “clearly established”
for purposes of qualified immunity is in the eye of the beholder. Te sensitive
privacy interests implicated by Title III may lead some courts to rule that a
Title III privacy right is “clearly established” even if no courts have recognized
the right in analogous circumstances. See, e.g., McClelland v. McGrath, 31 F.
Supp. 2d 616, 619-20 (N.D. Ill. 1998) (holding that police violated the “clearly
established” rights of a kidnapper who used a cloned cellular phone when the
police asked the cellular provider to intercept the kidnapper’s unauthorized
communications to help locate the kidnapper, and adding that the kidnapper’s
right to be free from monitoring was “crystal clear” despite § 2511(2)(a)(i)).
190
Searching and Seizing Computers
Chapter 5
Evidence
A. Introduction
Although the primary concern of this manual is obtaining computer records
in criminal investigations, prosecutors must also bear in mind the admissibility
of that evidence in court proceedings. Computer evidence can present novel
challenges. A complete guide to offering computer records into evidence is
beyond the scope of this manual. However, this chapter addresses some of the
more important evidentiary issues arising when the government seeks to admit
computer records in court, including hearsay and the foundation to establish
the authenticity of computer records.
B. Hearsay
Hearsay is “a statement, other than one made by the declarant while
testifying at the trial or hearing, offered in evidence to prove the truth of the
matter asserted.” Fed. R. Evid. 801(c) (emphasis added). “A ‘statement’ is (1)
an oral or written assertion or (2) nonverbal conduct of a person, if it is intended
by the person as an assertion.” Fed. R. Evid. 801(a) (emphasis added). Te
Rules of Evidence do not define an “assertion.” However, courts have held that
“the term has the connotation of a positive declaration.” See, e.g., United States
v. Lewis, 902 F.2d 1176, 1179 (5th Cir. 1990); Lexington Ins. Co. v. W. Penn.
Hosp., 423 F.3d 318, 330 (3d Cir. 2005).
Many courts have categorically determined that computer records are
admissible under Federal Rule of Evidence 803(6), the hearsay exception for
“records of regularly conducted activity”—or more commonly, the “business
records” exception—without first asking whether the records are hearsay. See,
e.g., Haag v. United States, 485 F.3d 1, 3 (1st Cir. 2007); United States v. Fujii,
301 F.3d 535, 539 (7th Cir. 2002); United States v. Briscoe, 896 F.2d 1476,
1494 (7th Cir. 1990).
Increasingly, however, courts have recognized that many computer records
result from a process and are not statements of persons—they are thus not
191
hearsay at all. See United States v. Washington, 498 F.3d 225, 230-31 (4th Cir.
2007) (printed result of computer-based test was not the statement of a person
and thus would not be excluded as hearsay); United States v. Hamilton, 413 F.3d
1138, 1142-43 (10th Cir. 2005) (computer-generated header information was
not hearsay as “there was neither a ‘statement’ nor a ‘declarant’ involved here
within the meaning of Rule 801”); United States v. Khorozian, 333 F.3d 498,
506 (3d Cir. 2003) (“nothing ‘said’ by a machine . . . is hearsay”) (quoting 4
Mueller & Kirkpatrick, Federal Evidence § 380, at 65 (2d ed. 1994)).
Tis section addresses hearsay issues associated with three categories of
computer records: (1) those that record assertions of persons (hearsay); (2)
records resulting from a process (non-hearsay); and (3) records that combine
the first two categories and thus are partially hearsay. Tis section also
addresses Confrontation Clause issues that may arise when seeking admission
of computer records. However, this section does not address in detail more
general questions regarding the admission of hearsay, which are thoroughly
addressed by other resources. See, e.g., Courtroom Evidence, 2nd, Article VIII,
United States Department of Justice, OLE (2001); Steven Goode and Olin G.
Welborn, Courtroom Evidence Handbook, Ch. 2, pp. 226-280 (2005-2006).
1. Hearsay vs. Non-Hearsay Computer Records
Records stored in computers can be divided into three categories: non-
hearsay, hearsay, and records that include both hearsay and non-hearsay. First,
non-hearsay records are created by a process that does not involve a human
assertion, such as: telephone toll records; cell tower information; email header
information; electronic banking records; Global Positioning System (GPS)
data; and log-in records from an ISP or internet newsgroup. Although human
input triggers some of theses processes—dialing a phone number or a punching
in a PIN—this conduct is a command to a system, not an assertion, and thus
is not hearsay. Second, hearsay records contain assertions by people, such
as: a personal letter; a memo; bookkeeping records; and records of business
transactions inputted by persons. Tird, mixed hearsay and non-hearsay
records are a combination of the first two categories, such as: email containing
both content and header information; a file containing both written text and
file creation, last written, and last access dates; chat room logs that identify
the participants and note the time and date of “chat”; and spreadsheets with
figures that have been typed in by a person, but the columns of which are
automatically calculated by the computer program.
192
Searching and Seizing Computers
Non-Hearsay Records
Hearsay rules apply to statements made by persons, not to logs or records
that result from computer processes. Computer-generated records that do not
contain statements of persons therefore do not implicate the hearsay rules.
Tis principle applies both to records generated by a computer without the
involvement of a person (e.g., GPS tracking records) and to computer records
that are the result of human conduct other than assertions (e.g., dialing a phone
number or punching in a PIN at an ATM). For example, pressing “send” on an
email is a command to a system (send this message to the person with this email
address) and is thus non-assertive conduct. See United States v. Bellomo, 176
F.3d 580, 586 (2d Cir. 1999) (“Statements offered as evidence of commands
or threats or rules . . . are not hearsay.”).
Two cases illustrate this point. In United States v. Washington, 498 F.3d 225
(4th Cir. 2007), lab technicians ran a blood sample taken from the defendant
through a gas chromatograph connected to a computer. Te test results, signed
by the lab director, indicated that the defendant had been driving under the
influence of both alcohol and PCP. Te lab director, who did not participate
in testing the sample, testified at trial. Te Fourth Circuit rejected a hearsay
objection to this evidence. Te court noted that the computer-generated test
result was “data generated by” a machine and observed that hearsay must be a
“statement” made by a “declarant.” Id. at 231. Further, “[o]nly a person may be
a declarant and make a statement.” Id. Since “nothing ‘said’ by a machine . . . is
hearsay,” the Fourth Circuit concluded that the test results were not excludable
based upon the hearsay rules. Id. (citation omitted).
Similarly, in United States v. Hamilton, 413 F.3d 1138 (10th Cir. 2005), the
defendant made a hearsay objection to the admission of header information
associated with approximately forty-four images introduced in his child
pornography trial. Te header information circumstantially identified Hamilton
as the person who had posted the child pornography images to a “newsgroup.”
Specifically, the header information consisted of the subject of the posting,
the date the images were posted, and Hamilton’s screen name and IP address.
See id. at 1142. Te Tenth Circuit noted that the header information was
“automatically generated by the computer hosting the newsgroup” when images
were uploaded to the newsgroup. Id. Since the information was independently
generated by the computer process, there was no “statement” by a “declarant”
and thus the header information was “outside of Rule 801(c)’s definition of
‘hearsay.’” Id. (citing United States v. Khorozian, 333 F.3d 498, 506 (3d Cir.
5. Evidence
193
2003) (header information automatically generated by a fax machine was not
hearsay as “nothing ‘said’ by a machine . . . is hearsay.”)).
Occasionally, courts have mistakenly assumed that computer-generated
records are hearsay without recognizing that they do not contain the statement
of a person. For example, in United States v. Blackburn, 992 F.2d 666 (7th
Cir. 1993), a bank robber left his eyeglasses behind in an abandoned stolen
car. Te prosecution’s evidence against the defendant included a computer
printout from a machine that tests the curvature of eyeglass lenses; the printout
revealed that the prescription of the eyeglasses found in the stolen car exactly
matched the defendant’s. At trial, the district court assumed that the computer
printout was hearsay, but it concluded that the printout was an admissible
business record according to Rule 803(6). On appeal following conviction, the
Seventh Circuit also assumed that the printout was hearsay, but agreed with
the defendant that the printout should not have been admitted as a business
record. See id. at 670. Nevertheless, the court held that the computer printout
was sufficiently reliable that it could have been admitted under Rule 807, the
residual hearsay exception. See id. at 672. However, the court should instead
have asked whether the computer printout from the lens-testing machine
contained hearsay at all. Tis question would have revealed that the computer-
generated printout could not be excluded properly on hearsay grounds (or on
Confrontation Clause grounds—see Section B.2 infra) because it contained no
human “statements.”
Hearsay Records
Some computer records are wholly hearsay (e.g., a printed text document
describing observations of fact where the underlying file data is not introduced).
Other computer records contain both hearsay and non-hearsay components
(e.g., an email with both header information and content that includes factual
assertions). In each instance, the proponent must lay a foundation that
establishes both the admissibility of the hearsay statement and the authenticity
of the computer-generated record.
A number of courts permit computer-stored business records to be
admitted as records of a regularly conducted activity under Rule 803(6).
Where business records include hearsay, one must show through testing or
by a certification complying with Rule 902(11) or 18 US.C. § 3505 that the
records were contemporaneously made and kept in the normal and ordinary
course of business by a person with knowledge. Different circuits have
194
Searching and Seizing Computers
articulated slightly different standards for the admissibility of computer-stored
business records. Some courts simply apply the direct language of Rule 803(6).
See, e.g., United States v. Moore, 923 F.2d 910, 914 (1st Cir. 1991); United
States v. Catabran, 836 F.2d 453, 457 (9th Cir. 1988). Other circuits have
articulated doctrinal tests specifically for computer records that largely (but
not exactly) track the requirements of Rule 803(6). See, e.g., United States v.
Cestnik, 36 F.3d 904, 909-10 (10th Cir. 1994) (“Computer business records
are admissible if (1) they are kept pursuant to a routine procedure designed
to assure their accuracy, (2) they are created for motives that tend to assure
accuracy (e.g., not including those prepared for litigation), and (3) they are not
themselves mere accumulations of hearsay.”) (internal quotation marks and
citation omitted); United States v. Briscoe, 896 F.2d 1476, 1494 (7th Cir. 1990)
(computer-stored records are admissible business records if they “are kept in
the course of regularly conducted business activity, and [it] was the regular
practice of that business activity to make records, as shown by the testimony
of the custodian or other qualified witness.”). Notably, the printout itself may
be produced in anticipation of litigation without running afoul of the business
records exception. Te requirement that the record be kept “in the course of
a regularly conducted business activity” refers to the underlying data, not the
actual printout of that data. See United States v. Fujii, 301 F.3d 535, 539 (7th
Cir. 2002); United States v. Sanders, 749 F.2d 195, 198 (5th Cir. 1984).
In addition to the business records exception, other hearsay exceptions
may apply in appropriate cases, such as the public records exception of Rule
803(8). See, e.g., United States v. Smith, 973 F.2d 603, 605 (8th Cir. 1992)
(police computer printouts are admissible as evidence); Hughes v. United
States, 953 F.2d 531, 540 (9th Cir. 1992) (computerized IRS printouts are
admissible). Computer records, particularly emails or chat logs, may also
include admissions or adopted admissions, which are not hearsay under Rule
801(d)(2). For example, in United States v. Burt, 495 F.3d 733, 738-39 (7th Cir.
2007), the court found that logs of chat conversations between the defendant
and a witness were not hearsay—the defendant’s half of the conversation
constituted “admissions” while the witness’s half was admissible as context for
those admissions. Similarly, in United States v. Safavian, 435 F. Supp. 2d 36,
43-44 (D.D.C. 2006), the full text of some emails forwarded by the defendant
to others were admitted as “adoptive admissions” when their context clearly
manifested the defendant’s belief in the truth of the authors’ statements.
5. Evidence
195
2. Confrontation Clause
In Crawford v. Washington, 541 U.S. 36, 68 (2004), the Supreme Court held
that the Confrontation Clause of the Sixth Amendment bars the government
from introducing pre-trial “testimonial statements” of an unavailable witness
unless the defendant had a prior opportunity to cross examine the declarant.
Id. at 68. Te Crawford Court declined to define “testimonial statements,”
but the courts of appeals have subsequently interpreted “testimonial” to mean
those statements where the “declarant reasonably expected the statement to be
used prosecutorially.” United States v. Ellis, 460 F.3d 920, 925 (7th Cir. 2006)
(collecting cases).
In Melendez-Diaz v. Massachusetts, 129 S.Ct. 2527, 2532 (2009), the
Supreme Court recently held that “certificates of analysis” —affidavits from
the state’s forensic examiners—identifying substances found on a defendant as
cocaine were testimonial statements under Crawford. At trial, the prosecution
introduced the certificates to prove that the substance found on the defendant
was in fact cocaine, and the affidavits themselves “contained only the bare-
bones statement that ‘[t]he substance was found to contain: Cocaine.’” Id. at
2532. Tere was no dispute that the “certificates” at issue represented statements
of persons. Rather, the respondents had argued, inter alia, that testimony
concerning “neutral scientific testing” was more reliable and trustworthy than
testimony concerning historical events and thus was not the type of testimonial
statement that fell within the ambit of the Confrontation Clause. See id. at
2536-37. Te Court rejected this distinction in favor of uniform treatment of
all testimonial statements for Confrontation Clause purposes. See id. at 2532.
Although Confrontation Clause analysis is distinct from hearsay analysis,
records that are the output of a computer-generated process do not implicate the
Confrontation Clause for the same reason that computer-generated records are
not hearsay: they are not statements of persons. In United States v. Washington,
498 F.3d 225 (4th Cir. 2007), as described above, computer-generated lab
results indicated that the defendant had been driving under the influence of both
alcohol and PCP. Washington argued that the computer-generated lab results
were “testimonial hearsay” and thus violated his right to confront witnesses
against him—namely, the lab technicians who actually ran the lab test. Te
Fourth Circuit rejected the Confrontation Clause argument, holding that the
computer-generated test results were not statements “made by the technicians
who tested the blood.” Id. at 229. Rather, the “machine printout is the only
source of the statement, and no person viewed a blood sample and concluded
196
Searching and Seizing Computers
that it contained PCP and alcohol.” Id. Te Sixth Amendment guarantees the
right to confront witnesses; machines, not being persons, are not witnesses.
Since the technicians, independent from the machine, could not have affirmed
or denied the test results, the admission of the gas chromatography printout
did not implicate the defendant’s Sixth Amendment rights. In sum, the Fourth
Circuit held that the “raw data generated by the diagnostic machines are
‘statements’ of the machines themselves, not their operators. But ‘statements’
made by machines are not out-of-court statements made by declarants that are
subject to the Confrontation Clause.” Id.
Te Fourth Circuit’s analysis in Washington is distinguishable from
Melendez-Diaz. Te document at issue in Washington was raw, computer-
generated data, whereas the
“certificates” at issue in Melendez-Diaz were
plainly witness statements. Moreover, in Washington, the forensic scientist who
interpreted the raw data testified as an expert, and thus the defendant had a
full and fair opportunity to call into question the judgment and skills upon
which his interpretation of any underlying data was based. See Washington, 498
F.3d at 228. Te Fourth Circuit in Washington did not rely on the reliability of
“neutral” scientific testing, but on the fact that the machine generating the data
was not a person. Consequently, the Fourth Circuit’s reasoning in Washington
likely remains good law.
C. Authentication
Before a party moves for admission of an electronic record or any other
evidence, the proponent must show that it is authentic. Tat is, the proponent
must offer evidence “sufficient to support a finding that the matter in question
is what its proponent claims.” Fed. R. Evid. 901(a). See United States v. Salcido,
506 F.3d 729, 733 (9th Cir. 2007) (data from defendant’s computer was properly
introduced under Rule 901(a) based on “chain of custody”); United States v.
Meienberg, 263 F.3d 1177, 1181 (10th Cir. 2001) (district court correctly found
that sufficient evidence existed under Rule 901(a) to admit computer printout
of firearms sold through defendant’s business). Te proponent need not prove
beyond all doubt that the evidence is authentic and has not been altered. United
States v. Gagliardi, 506 F.3d 140, 151 (2d Cir. 2007). Instead, authentication
requirements are “threshold preliminary standard[s] to test the reliability of the
evidence, subject to later review by an opponent’s cross-examination.” Lorraine
v. Markel American Ins. Co., 241 F.R.D. 534, 544 (D. Md. 2007) (citing Jack
B. Weinstein & Margaret A. Berger, Weinstein’s Federal Evidence § 900.06 [3]
5. Evidence
197
(Joseph M. McLaughlin ed., Matthew Bender 2d ed.1997)); see also United
States v. Tin Yat Chin, 371 F.3d 31, 37-38 (2d Cir. 2004). Once evidence has
met this low admissibility threshold, it is up to the fact finder to evaluate what
weight to give the evidence. United States v. Ladd, 885 F.2d 954, 956 (1st Cir.
1989).
1. Authentication of Computer-Stored Records
Te standard for authenticating computer records is the same as for
authenticating other records. Although some litigants have argued for more
stringent authenticity standards for electronic evidence, courts have resisted
those arguments. See, e.g., United States v. Simpson, 152 F.3d 1241, 1249-50
(10th Cir. 1998) (applying general rule 901(a) standard to transcript of chat
room discussions); In re F.P., 878 A.2d 91, 95-96 (Pa. Super. Ct. 2005) (“We
see no justification for constructing unique rules for admissibility of electronic
communications such as instant messages; they are to be evaluated on a case-
by-case basis as any other document to determine whether or not there has
been an adequate foundational showing of their relevance and authenticity.”).
Generally, witnesses who testify to the authenticity of computer records
need not have special qualifications. In most cases, the witness does not need to
have programmed the computer himself or even understand the maintenance
and technical operation of the computer. See United States v. Salgado, 250 F.3d
438, 453 (6th Cir. 2001) (“[I]t is not necessary that the computer programmer
testify in order to authenticate computer-generated records.”); United States
v. Moore, 923 F.2d 910, 914-15 (1st Cir. 1991) (holding that head of bank’s
consumer loan department could authenticate computerized loan data).
Instead, the witness simply must have first-hand knowledge of the relevant
facts, such as what the data is and how it was obtained from the computer
or whether and how the witness’s business relies upon the data. See generally
United States v. Whitaker, 127 F.3d 595, 601 (7th Cir. 1997) (holding that FBI
agent who was present when the defendant’s computer was seized appropriately
authenticated seized files).
Federal Rule of Evidence
901(b) offers a non-exhaustive list of
authentication methods. Several of these illustrations are useful in cases
involving computer records. For example, Rule 901(b)(1) provides that evidence
may be authenticated by a person with knowledge “that a matter is what it is
claimed to be.” See United States v. Gagliardi, 506 F.3d 140, 151 (2d Cir. 2007)
(witness and undercover agent sufficiently authenticated emails and chat log
198
Searching and Seizing Computers
exhibits by testifying that the exhibits were accurate records of communications
they had had with the defendant); United States v. Kassimu, 2006 WL 1880335
(5th Cir. Jul. 7, 2006) (district court correctly found that computer records
were authenticated based on the Postal Inspector’s description of the procedure
employed to generate the records).
Rule 901(b)(3) allows authentication of the item where the trier of fact or an
expert compares it “with specimens which have been authenticated.” See United
States v. Safavian, 435 F. Supp. 2d 36, 40 (D.D.C. 2006) (emails that were not
clearly identifiable on their own could be authenticated by comparison to other
emails that had been independently authenticated). Rule 901(b)(4) indicates
that evidence can be authenticated based upon distinctive characteristics such
as “contents, substance, internal patterns, or other distinctive characteristics.”
See United States v. Siddiqui, 235 F.3d 1318, 1322-23 (11th Cir. 2000) (email
was appropriately authenticated based entirely on circumstantial evidence,
including presence of the defendant’s work email address, information within
the email with which the defendant was familiar, and use of the defendant’s
nickname); Safavian, 435 F. Supp. 2d at 40 (distinctive characteristics for email
included the “@” symbol, email addresses containing the name of the person
connected with the email, and the name of the sender or recipient in the “To,”
“From,” or signature block areas).
Rule 901(b)(4) is helpful to prosecutors who seek to introduce electronic
records obtained from seized storage media. For example, a prosecutor
introducing a hard drive seized from a defendant’s home and data from that
hard drive may employ a two-step process. First, the prosecutor may introduce
the hard drive based on chain of custody testimony or its unique characteristics
(e.g., the hard drive serial number). Second, prosecutors may consider using the
“hash value” or similar forensic identifier assigned to the data on the drive to
authenticate a copy of that data as a forensically sound copy of the previously
admitted hard drive. Similarly, prosecutors may authenticate a computer
record using its “metadata” (information “describing the history, tracking, or
management of the electronic document”). See Lorraine v. Markel American
Ins. Co., 241 F.R.D. at 547-48.
When computer-stored records are records of regularly conducted business
activity, Rule 902(11) (domestic records) and 18 U.S.C. § 3505 (foreign
records) permit the use of a written certification to establish the authenticity
of the record. Some have questioned whether such certifications constitute
testimonial hearsay barred by Crawford v. Washington, 541 U.S. 36 (2004),
5. Evidence
199
which is discussed in Section B.2 above. See, e.g., United States v. Jimenez, 513
F.3d 62, 78 (3d Cir. 2008) (“Even assuming, without deciding, that the Rule
902(11) declarations are testimonial and subject to the Confrontation Clause,
their admission in this case for the purpose of authenticating the bank statements
was harmless.”). In dicta in Melendez-Diaz, the Supreme Court noted that
under common law, “[a] clerk could by affidavit authenticate or provide a copy
of an otherwise admissible record.” Melendez-Diaz v. Massachusetts, 129 S. Ct.
2527, 2539 (2009). Lower courts may follow this statement from Melendez-
Diaz and hold that the Confrontation Clause allows the introduction of
certificates of authenticity at trial. Moreover, even if the Confrontation Clause
did bar the introduction of certificates of authenticity at trial, the certificates
likely could still be used to establish the authenticity of the records under
Rule 104(a), which specifies that “[p]reliminary questions concerning . . . the
admissibility of evidence shall be determined by the court,” and that in making
admissibility determinations, the court “is not bound by the rules of evidence
except those with respect to privileges.” See United States v. Collins, 966 F.2d
1214, 1223 (7th Cir. 1992) (“In Bourjaily v. United States, 483 U.S. 171, 175-
76 (1987), the Supreme Court held that a judge can, without offending the
Sixth Amendment’s Confrontation Clause, consider another person’s out-of-
court statements in determining whether these statements are admissible as
coconspirator statements.”).
2. Authentication of Records Created by a Computer Process
Records that are not just stored in a computer but rather result, in whole or
part, from a computer process will often require a more developed foundation.
To demonstrate authenticity for computer-generated records, or any records
generated by a process, the proponent should introduce “[e]vidence describing
a process or a system used to produce a result and showing that the process or
system produces an accurate result.” Fed. R. Evid. 901(b)(9). See also United
States v. Briscoe, 896 F.2d 1476, 1494-95 (7th Cir. 1990) (the government
satisfied its burden where it provided sufficient facts to warrant a finding
that the records were trustworthy and the opposing party was afforded an
opportunity to inquire into the accuracy thereof ). Moreover, in addition to the
obvious benefit of getting the records into evidence, a developed foundation
will explain what the computer or program does, thereby enabling the finder of
fact to understand the soundness and relevance of the records.
In most cases, the reliability of a computer program can be established by
showing that users of the program actually do rely on it on a regular basis, such
200
Searching and Seizing Computers
as in the ordinary course of business.1 See, e.g., United States v. Salgado, 250
F.3d 438, 453 (6th Cir. 2001) (“evidence that the computer was sufficiently
accurate that the company relied upon it in conducting its business” was
sufficient for establishing trustworthiness); United States v. Moore, 923 F.2d
910, 915 (1st Cir. 1991) (“[T]he ordinary business circumstances described
suggest trustworthiness, . . . at least where absolutely nothing in the record in
any way implies the lack thereof.”). While expert testimony may be helpful
in demonstrating the reliability of a technology or computer process, such
testimony is often unnecessary. See Salgado, 250 F.3d at 453 (“Te government
is not required to present expert testimony as to the mechanical accuracy of
the computer where it presented evidence that the computer was sufficiently
accurate that the company relied upon it in conducting its business.”); Brown v.
Texas, 163 S.W.3d 818, 824 (Tex. App. 2005) (holding that witness who used
global positioning system technology daily could testify about technology’s
reliability).
When the computer program is not used on a regular basis and the proponent
cannot establish reliability based on its use in the ordinary course of business,
the proponent may need to disclose “what operations the computer had been
instructed to perform [as well as] the precise instruction that had been given”
if the opposing party requests. United States v. Dioguardi, 428 F.2d 1033, 1038
(2d Cir. 1970). Notably, once a minimum standard of trustworthiness has
been established, questions as to the accuracy of computer records “resulting
from . . . the operation of the computer program” affect only the weight of
the evidence, not its admissibility. United States v. Catabran, 836 F.2d 453,
458 (9th Cir. 1988); see also United States v. Tank, 200 F.3d 627, 630 (9th Cir.
2000).
1 As discussed in the hearsay section of this chapter, federal courts that evaluate the
authenticity of computer-generated records sometimes assume that the records contain hearsay
and then apply the business records exception. See, e.g., Salgado, 250 F.3d at 452-53 (applying
business records exception to telephone records generated “automatically” by a computer);
United States v. Linn, 880 F.2d 209, 216 (9th Cir. 1989) (same). Although this analysis is
technically incorrect when the records do not contain statements of a person, as a practical
matter, prosecutors who lay a foundation to establish a computer-generated record as a
business record will also lay the foundation to establish the record’s authenticity. Evidence that
a computer program is sufficiently trustworthy so that its results qualify as business records
under Fed. R. Evid. 803(6) also establishes the authenticity of the record. Cf. United States v.
Saputski, 496 F.2d 140, 142 (9th Cir. 1974).
5. Evidence
201
3. Common Challenges to Authenticity
Alterations
Because electronic records can be altered easily, opposing parties often
allege that computer records lack authenticity because they have been
tampered with or changed after they were created. Importantly, courts have
rejected arguments that electronic evidence is inherently unreliable because of
its potential for manipulation. As with paper documents, the mere possibility
of alteration is not sufficient to exclude electronic evidence. Absent specific
evidence of alteration, such possibilities go only to the evidence’s weight, not
admissibility. See United States v. Safavian, 435 F. Supp. 2d 36, 41 (D.D.C.
2006). See also United States v. Whitaker, 127 F.3d 595, 602 (7th Cir. 1997);
United States v. Bonallo, 858 F.2d 1427, 1436 (9th Cir. 1988) (“Te fact that
it is possible to alter data contained in a computer is plainly insufficient to
establish untrustworthiness.”); United States v. Glasser, 773 F.2d 1553, 1559
(11th Cir. 1985) (“Te existence of an air-tight security system [to prevent
tampering] is not, however, a prerequisite to the admissibility of computer
printouts. If such a prerequisite did exist, it would become virtually impossible
to admit computer-generated records; the party opposing admission would
have to show only that a better security system was feasible.”).
Nevertheless, prosecutors and investigators should be wary of situations
in which evidence has been edited or is captured using methods subject to
human error. In United States v. Jackson, 488 F. Supp. 2d 866 (D. Neb. 2007),
an undercover agent had recorded chat sessions with the defendant by “cutting
and pasting” the log of each conversation into a word processing document.
After his investigation ended, the agent’s computer was wiped clean, leaving
the “cut and paste” document as the only record of the chat conversations.
Despite the agent’s testimony at trial that he had been careful to avoid errors
in cutting and pasting, the court excluded the “cut and paste” document based
on defense expert testimony that suggested errors in the agent’s transcript. Id.
at 869-71. Te court’s analysis relied, in part, on the defense expert’s testimony
that there were several more reliable methods that the agent could have used to
accurately capture the chat logs, including creating a forensic image of the agent’s
computer’s hard drive, using software to save the chats, or using a basic “print
screen” function. Id. Still, the ruling in Jackson is at odds with the prevailing
standard for authenticity, particularly given the agent’s testimony that no errors
were made and the defense’s inability to demonstrate any actual, as opposed to
hypothetical, errors. Under the prevailing standard, courts should admit even
202
Searching and Seizing Computers
“cut and paste” documents in many contexts. Cf. United States v. Gagliardi,
506 F.3d 140, 151 (2d Cir. 2007) (transcript of instant message conversations
that were cut and pasted into word processing documents were sufficiently
authenticated by testimony of a participant in the conversation).
Authorship
Although handwritten records may be penned in a distinctive handwriting
style, computer-stored records do not necessarily identify their author. Tis
is a particular problem with Internet communications, which can offer their
authors an unusual degree of anonymity. For example, Internet technologies
permit users to send effectively anonymous emails, and Internet Relay Chat
channels permit users to communicate without disclosing their real names.
When prosecutors seek the admission of such computer-stored records against
a defendant, the defendant may challenge the authenticity of the record by
challenging the identity of its author.
Circumstantial evidence generally provides the key to establishing the
authorship of a computer record. In particular, distinctive characteristics like
email addresses, nicknames, signature blocks, and message contents can prove
authorship, at least sufficiently to meet the threshold for authenticity. For
example, in United States v. Simpson, 152 F.3d 1241 (10th Cir. 1998), prosecutors
sought to show that the defendant had conversed with an undercover FBI
agent in an Internet chat room devoted to child pornography. Te government
offered a printout of an Internet chat conversation between the agent and an
individual identified as “Stavron” and sought to show that “Stavron” was the
defendant. On appeal following his conviction, Simpson argued that “because
the government could not identify that the statements attributed to [him] were
in his handwriting, his writing style, or his voice,” the printout had not been
authenticated and should have been excluded. Id. at 1249.
Te Tenth Circuit rejected this argument, noting the considerable
circumstantial evidence that “Stavron” was the defendant. See id. at 1250. For
example, “Stavron” had told the undercover agent that his real name was “B.
Simpson,” gave a home address that matched Simpson’s, and appeared to be
accessing the Internet from an account registered to Simpson. Further, the
police found records in Simpson’s home that listed the name, address, and
phone number that the undercover agent had sent to “Stavron.” Accordingly,
the government had provided evidence sufficient to support a finding that the
defendant was “Stavron,” and the printout was properly authenticated. See id.
5. Evidence
203
at 1250; see also United States v. Safavian, 435 F. Supp. 2d 36, 40 (D.D.C.
2006) (emails between defendant government official and lobbyist were
authenticated by distinctive characteristics under Rule 901(b)(4) including
email addresses which bore the sender’s and recipient’s names; “the name of
the sender or recipient in the bodies of the email, in the signature blocks at
the end of the email, in the ‘To:’ and ‘From:’ headings, and by signature of
the sender”; and the contents); United States v. Tank, 200 F.3d 627, 630-31
(9th Cir. 2000) (district court properly admitted chat room log printouts in
circumstances similar to those in Simpson); United States v. Siddiqui, 235 F.3d
1318, 1322-23 (11th Cir. 2000) (email messages were properly authenticated
where messages included defendant’s email address, defendant’s nickname, and
where defendant followed up messages with phone calls).
Authenticating Contents and Appearance of Websites
Several cases have considered what foundation is necessary to authenticate
the contents and appearance of a website at a particular time. Print-outs of web
pages, even those bearing the URL and date stamp, are not self-authenticating.
See In re Homestore.com, Inc. Securities Lit., 347 F. Supp. 2d 769, 782-83 (C.D.
Cal. 2004). Tus, courts typically require the testimony of a person with
knowledge of the website’s appearance to authenticate images of that website.
See id. (“To be authenticated, some statement or affidavit from someone with
knowledge is required; for example, Homestore’s web master or someone else
with personal knowledge would be sufficient.”); Victaulic Co. v. Tieman, 499
F.3d 227, 236 (3d Cir. 2007) (court cannot assume that a website belonged to
a particular business based solely on the site’s URL); United States v. Jackson,
208 F.3d 633, 638 (7th Cir. 2000) (web postings purporting to be statements
made by white supremacist groups were properly excluded on authentication
grounds absent evidence that the postings were actually posted by the groups).
Testimony of an agent who viewed a website at a particular date and time
should be sufficient to authenticate a print-out of that website.
Some litigants have attempted to introduce content from web pages stored
by the Internet Archive, a non-profit organization attempting to create a
“library” of web pages by using automated web crawlers to periodically capture
web page contents. Internet Archive provides a service called the “Wayback
Machine” that enables users to view historical versions of captured web pages
on a given date. Te various courts that have considered information obtained
through the Wayback Machine have differed over whether testimony about the
Internet Archive’s operation is sufficient or whether proponents must provide
204
Searching and Seizing Computers
testimony from someone with personal knowledge of the particular web pages’
contents. Compare St. Luke’s Cataract and Laser Institute v. Sanderson, 2006 WL
1320242, at *2 (M.D. Fla. May 12, 2006) (Internet Archive employee with
personal knowledge of the Archive’s database could authenticate web pages
retrieved from the Archive), and Telewizja Polska USA, Inc. v. Echostar Satellite
Corp., 2004 WL 2367740, at *6 (N.D. Ill. Oct. 15, 2004) (affidavit from
an Internet Archive employee would be sufficient to authenticate web pages
retrieved from the Internet Archive’s database if the employee had personal
knowledge of the Archive’s contents), with Novak v. Tucows, Inc., 2007 WL
922306, at *5 (E.D.N.Y. Mar. 26, 2007) (requiring testimony from the host
of a web page, rather than from the Internet Archive, to authenticate the page’s
contents).
D. Other Issues
Te authentication requirement and the hearsay rule usually constitute
the most significant hurdles that prosecutors will encounter when seeking
the admission of computer records. However, some agents and prosecutors
have occasionally considered two additional issues: the application of the
best evidence rule to computer records and whether computer printouts are
“summaries” that must comply with Fed. R. Evid. 1006.
1. Te Best Evidence Rule
Te best evidence rule states that to prove the content of a writing, recording,
or photograph, the “original” writing, recording, or photograph is ordinarily
required. See Fed. R. Evid. 1002. For example, in United States v. Bennett, 363
F.3d 947, 953 (9th Cir. 2004), in an effort to prove that the defendant had
imported drugs from international waters, an agent testified about information
he viewed on the screen of the global positioning system (GPS) on the
defendant’s boat. Te Ninth Circuit found that the agent’s testimony violated
the best evidence rule. Te agent had only observed a graphical representation
of data recorded by the GPS system; he had not actually observed the boat
following the purported path. Because the United States sought to prove the
contents of the GPS data, the best evidence rule required the government to
introduce the GPS data itself or the printout of that data, rather than merely the
agent’s testimony about the data. See id. Alternatively, the government could
have sought to demonstrate that the original GPS data was lost, destroyed, or
5. Evidence
205
otherwise unobtainable under Fed. R. Evid. 1004, but the court ruled that the
government had failed to do. See id. at 954.
Agents and prosecutors occasionally express concern that a mere printout
of a computer-stored electronic file may not be an “original” for the purpose
of the best evidence rule. After all, the original file is merely a collection of 0’s
and 1’s; in contrast, the printout is the result of manipulating the file through
a complicated series of electronic and mechanical processes.
Te Federal Rules of Evidence have expressly addressed this concern.
Te Rules state that “[i]f data are stored in a computer or similar device, any
printout or other output readable by sight, shown to reflect the data accurately,
is an ‘original’.” Fed. R. Evid. 1001(3). Tus, an accurate printout of computer
data always satisfies the best evidence rule. See Doe v. United States, 805 F.
Supp. 1513, 1517 (D. Haw. 1992). According to the Advisory Committee
Notes that accompanied this rule when it was first proposed, this standard was
adopted for reasons of practicality:
While strictly speaking the original of a photograph might
be thought to be only the negative, practicality and common
usage require that any print from the negative be regarded as
an original. Similarly, practicality and usage confer the status of
original upon any computer printout.
Advisory Committee Notes, Proposed Federal Rule of Evidence 1001(3)
(1972).
However, as with demonstrating authenticity, a proponent might need to
demonstrate that the print out does accurately reflect the stored data in order
to satisfy the best evidence rule. Compare Laughner v. State, 769 N.E. 2d 1147,
1159 (Ind. Ct. App. 2002) (AOL Instant Message logs that police had cut-and-
pasted into a word-processing file satisfied best evidence rule) (abrogated on
other grounds by Fajardo v. State, 859 N.E. 2d 1201 (Ind. 2007)), with United
States v. Jackson, 488 F. Supp. 2d 866, 871 (D. Neb. 2007) (word-processing
document into which chat logs were cut-and-pasted was not the “best evidence”
because it did not accurately reflect the entire conversation).
Similarly, properly copied electronic data is just as admissible as the original
data. Rule 1003 states that a “duplicate is admissible to the same extent as an
original” unless there is a genuine question about the original’s authenticity
or there is some other reason why admitting the duplicate would be unfair. A
“duplicate” is defined, by Rule 1001(4), as “a counterpart produced by the same
206
Searching and Seizing Computers
impression as the original . . . or by mechanical or electronic re-recording . . . or
by other equivalent techniques which accurately reproduces the original.” Tus,
a proponent can introduce, for instance, an image of a seized hard drive, where
the proponent can demonstrate that the imaging process accurately copied
the data on the original hard drive. Tis demonstration is often accomplished
through testimony showing that the hash value of the copy matches that of the
original.
2. Computer Printouts as “Summaries”
Federal Rule of Evidence 1006 permits parties to offer summaries of
voluminous evidence in the form of “a chart, summary, or calculation” subject
to certain restrictions. Agents and prosecutors occasionally ask whether a
computer printout is necessarily a “summary” of evidence that must comply
with Fed. R. Evid. 1006. In general, the answer is no. See United States v. Moon,
513 F.3d 527, 544-45 (6th Cir. 2008); United States v. Catabran, 836 F.2d
453, 456-57 (9th Cir. 1988); United States v. Sanders, 749 F.2d 195, 199 (5th
Cir. 1984); United States v. Russo, 480 F.2d 1228, 1240-41 (6th Cir. 1973).
Of course, if the computer printout is merely a summary of other admissible
evidence, Rule 1006 will apply just as it does to other summaries of evidence.
See United States v. Allen, 234 F.3d 1278, 2000 WL 1160830, at *1 (9th Cir.
Aug. 11, 2000).
5. Evidence
207
208
Searching and Seizing Computers
Appendix A
Sample Network Banner Language
Network banners are electronic messages that provide notice of legal rights
to users of computer networks. From a legal standpoint, banners have four
primary functions. First, banners may eliminate any Fourth Amendment
“reasonable expectation of privacy” that users might otherwise retain in their use
of the network. Second, banners may generate consent to real-time monitoring
under Title III. Tird, banners may generate consent to the retrieval of stored
files and records pursuant to the SCA. Fourth, in the case of a non-government
network, banners may establish the network owner’s common authority to
consent to a law enforcement search.
CCIPS does not take any position on whether providers of network services
should use network banners, and, if so, what types of banners they should use.
Further, there is no formal “magic language” that is necessary. Banners may be
worded narrowly or broadly, and the scope of consent and waiver triggered by
a particular banner will in general depend on the scope of its language. Here is
a checklist of issues to consider when evaluating a banner:
a) Does the banner state that a user of the network shall have no reasonable
expectation of privacy in the network? A user who lacks a reasonable expectation
of privacy in a network will not be able to claim that any search of the network
violates his Fourth Amendment rights. See Rakas v. Illinois, 439 U.S. 128, 143
(1978).
b) Does the banner state that use of the network constitutes consent
to monitoring? Such a statement helps establish the user’s consent to real-
time interception pursuant to 18 U.S.C. § 2511(2)(c) (monitoring by law
enforcement agency) or § 2511(2)(d) (provider monitoring).
c) Does the banner state that use of the network constitutes consent to
the retrieval and disclosure of information stored on the network? Such a
statement helps establish the user’s consent to the retrieval and disclosure of
such information and/or records pursuant to 18 U.S.C. §§ 2702(b)(3) and
2702(c)(2).
209
d) In the case of a non-government network, does the banner make clear
that the network system administrator(s) may consent to a law enforcement
search? Such a statement helps establish the system administrator’s common
authority to consent to a search under to United States v. Matlock, 415 U.S.
164 (1974).
e) Does the banner contain express or implied limitations or authorizations
relating to the purpose of any monitoring, who may conduct the monitoring,
and what will be done with the fruits of any monitoring?
f ) Does the banner state which users are authorized to access the network
and the consequences of unauthorized use of the network? Such notice makes
it easier to establish knowledge of unauthorized use and therefore may aid
prosecution under 18 U.S.C. § 1030.
g) Does the banner require users to “click through” or otherwise acknowledge
the banner before using the network? Such a step may make it easier to establish
that the network user actually received the notice that the banner is designed
to provide.
Network providers who decide to banner all or part of their network
should consider their needs and the needs of their users carefully before
selecting particular language. For example, a sensitive government computer
network may require a broadly worded banner that permits access to all types
of electronic information.
Broad Banners
Here are three examples of broad banners:
(1) You are accessing a U.S. Government information system, which
includes this computer, this computer network, all computers connected to
this network, and all devices and storage media attached to this network or
to a computer on this network. Tis information system is provided for U.S.
Government authorized use only. Unauthorized or improper use of this system
may result in disciplinary action, as well as civil and criminal penalties. By
using this information system, you understand and consent to the following:
you have no reasonable expectation of privacy regarding communications or
data transiting or stored on this information system; at any time, and for any
lawful government purpose, the Government may monitor, intercept, search,
and seize any communication or data transiting or stored on this information
210
Searching and Seizing Computers
system; and any communications or data transiting or stored on this information
system may be disclosed or used for any lawful government purpose.
(2) WARNING! Tis computer system is the property of the United
States Department of Justice and may be accessed only by authorized users.
Unauthorized use of this system is strictly prohibited and may be subject
to criminal prosecution. Te Department may monitor any activity or
communication on the system and retrieve any information stored within
the system. By accessing and using this computer, you are consenting to such
monitoring and information retrieval for law enforcement and other purposes.
Users should have no expectation of privacy as to any communication on or
information stored within the system, including information stored locally on
the hard drive or other media in use with this unit.
(3) You are about to access a United States government computer network
that is intended for authorized users only. You should have no expectation of
privacy in your use of this network. Use of this network constitutes consent
to monitoring, retrieval, and disclosure of any information stored within the
network for any purpose, including criminal prosecution.
Narrower Banners
In other cases, network providers may wish to establish a more limited
policy. Here are three examples of relatively narrow banners that will generate
consent to access in some situations but not others:
(4) Tis computer network belongs to the Grommie Corporation and may
be used only by Grommie Corporation employees and only for work-related
purposes. Te Grommie Corporation reserves the right to monitor use of this
network to ensure network security and to respond to specific allegations of
employee misuse. Use of this network shall constitute consent to monitoring
for such purposes. In addition, the Grommie Corporation reserves the right to
consent to a valid law enforcement request to search the network for evidence
of a crime stored within the network.
(5) Warning: Patrons of the Cyber-Fun Internet Café may not use its
computers to access, view, or obtain obscene materials. To ensure compliance
with this policy, the Cyber-Fun Internet Café reserves the right to record the
names and addresses of World Wide Web sites that patrons visit using Cyber-
Fun Internet Café computers.
Appendix A
211
(6) It is the policy of the law firm of Rowley & Yzaguirre to monitor the
Internet access of its employees to ensure compliance with law firm policies.
Accordingly, your use of the Internet may be monitored. Te firm reserves the
right to disclose the fruits of any monitoring to law enforcement if it deems
such disclosure to be appropriate.
212
Searching and Seizing Computers
Appendix B
Sample 18 U.S.C. § 2703(d)
Application and Order
Note that this sample 2703(d) application and order are for the disclosure of
both content and non-content information associated with an email account
at an ISP.
When using a 2703(d) order to compel disclosure of content, the government
is required either to give prior notice to the subscriber or customer or to
comply with the procedures for delayed notice in 18 U.S.C. § 2705(a). Tis
order authorizes the delay of notice to the account holder under 18 U.S.C. §
2705(a). A 2703(d) order can be used to compel disclosure of the content of
communications not in “electronic storage” or the content of communications
in “electronic storage” for more than 180 days. As discussed in Chapter 3.C.3,
courts disagree on whether previously retrieved communications fall within
the scope of communications in “electronic storage.”
When a 2703(d) order is used to compel disclosure only of non-content
information, no notice to the customer or subscriber is required.
UNITED STATES DISTRICT COURT
FOR THE [DISTRICT}
)
IN RE APPLICATION OF THE
)
UNITED STATES OF AMERICA FOR
)
MISC. NO. ____
AN ORDER PURSUANT TO
)
18 U.S.C. § 2703(d)
)
)
Filed Under Seal
APPLICATION OF THE UNITED STATES
FOR AN ORDER PURSUANT TO 18 U.S.C. § 2703(d)
Te United States of America, moving by and through its undersigned
213
counsel, respectfully submits under seal this ex parte application for an Order
pursuant to 18 U.S.C. § 2703(d) to require ISPCompany, an Internet Service
Provider located in City, State, which functions as an electronic communications
service provider and/or a remote computing service, to provide records and other
information and contents of wire or electronic communications pertaining
to the following email account: sample@sample.com. Te records and other
information requested are set forth as an Attachment to the proposed Order.
In support of this application, the United States asserts:
LEGAL AND FACTUAL BACKGROUND
1. Te United States government is investigating [crime summary]. Te
investigation concerns possible violations of, inter alia, [statutes].
2. Investigation to date of these incidents provides reasonable grounds
to believe that ISPCompany has records and other information pertaining to
certain of its subscribers that are relevant and material to an ongoing criminal
investigation. Because ISPCompany functions as an electronic communications
service provider (provides its subscribers access to electronic communication
services, including email and the Internet) and/or a remote computing service
(provides computer facilities for the storage and processing of electronic
communications), 18 U.S.C. § 2703 sets out particular requirements that
the government must meet in order to obtain access to the records and other
information it is seeking.
3. Here, the government seeks to obtain the following categories of
information: (1) records and other information (not including the contents of
214
Searching and Seizing Computers
communications) pertaining to certain subscribers of ISPCompany; and (2)
the contents of electronic communications held by ISPCompany (but not in
electronic storage for less than 181 days).
4. To obtain records and other information (not including the contents of
communications) pertaining to subscribers of an electronic communications
service provider or remote computing service, the government must comply
with 18 U.S.C. § 2703(c)(1), which provides, in pertinent part:
A governmental entity may require a provider of electronic
communication service or remote computing service to disclose
a record or other information pertaining to a subscriber to
or customer of such service (not including the contents of
communications) only when the governmental entity—
(B) obtains a court order for such disclosure under
subsection (d) of this section.
5. Under 18 U.S.C. § 2703(a)(1) and 18 U.S.C. § 2703(b)(1), to obtain
the contents of a wire or electronic communication in a remote computing
service, or in electronic storage for more than one hundred and eighty days in
an electronic communications system, the government must comply with 18
U.S.C. § 2703(b)(1), which provides, in pertinent part:
A governmental entity may require a provider of remote
computing service to disclose the contents of any wire or
electronic communication to which this paragraph is made
applicable by paragraph (2) of this subsection—
(B) with prior notice from the governmental entity to the
subscriber or customer if the governmental entity—
Appendix B
215
(ii) obtains a court order for such disclosure under
subsection (d) of this section;
except that delayed notice may be given pursuant to section
2705 of this title.
6. Section 2703(b)(2) states that § 2703(b)(1) applies with respect to
any wire or electronic communication that is held or maintained in a remote
computing service—
(A) on behalf of, and received by means of electronic
transmission from
(or created by means of computer
processing of communications received by means of electronic
transmission from), a subscriber or customer of such remote
computing service; and
(B) solely for the purpose of providing storage or computer
processing services to such subscriber or customer, if the
provider is not authorized to access the contents of any such
communications for purposes of providing any services other
than storage or computer processing.
7.
Section 2703(d), in turn, provides in pertinent part:
A court order for disclosure under subsection (b) or (c) may be
issued by any court that is a court of competent jurisdiction1
and shall issue only if the governmental entity offers specific and
articulable facts showing that there are reasonable grounds to
believe that the contents of a wire or electronic communication,
or the records or other information sought, are relevant and
material to an ongoing criminal investigation
A court
issuing an order pursuant to this section, on a motion made
promptly by the service provider, may quash or modify such
order, if the information or records requested are unusually
1
18 U.S.C. § 2711(3) states that “the term ‘court of competent jurisdiction’ has the
meaning assigned by section 3127, and includes any Federal court within that definition,
without geographic limitation.” Section 3127 defines the term “court of competent jurisdiction”
to include “any district court of the United States (including a magistrate judge of such a
court).” 18 U.S.C. § 3127(2)(A).
216
Searching and Seizing Computers
voluminous in nature or compliance with such order otherwise
would cause an undue burden on such provider.
Accordingly, this application sets forth specific and articulable facts
showing that there are reasonable grounds to believe that the materials sought
are relevant and material to an ongoing criminal investigation.
THE RELEVANT FACTS
8.
[Factual paragraph(s) here]
9. Te conduct described above provides reasonable grounds to believe
that the materials sought are relevant and material to an ongoing criminal
investigation.
10. Records of customer and subscriber information relating to this
investigation that are available from ISPCompany, and the contents of
electronic communications that may be found at ISPCompany, will help
government investigators to identify the individual(s) who are responsible for
the events described above and to determine the nature and scope of their
activities. Accordingly, the government requests that ISPCompany be directed
to produce all records described in Attachment A to the proposed Order. Part
A of the Attachment requests the account name, address, telephone number,
email address, billing information, and other identifying information for
sample@sample.com.
11. Part B requests the production of records and other information relating
to sample@sample.com through the date of this Court’s Order. As described
in more detail in that section, this information should include connection
Appendix B
217
information, telephone records, non-content information associated with any
communication or file stored by or for the account(s), and correspondence and
notes of records involving the account.
12. Part C requests the contents of electronic communications (not in
electronic storage) in ISPCompany’s computer systems in directories or files
owned or controlled by the accounts identified in Part A. Tese stored files,
covered by 18 U.S.C. § 2703(b)(2), will help ascertain the scope and nature of
the activity conducted by sample@sample.com from ISPCompany’s computers.
Pursuant to 18 U.S.C. § 2703(a), Part C also requests the contents of electronic
communications that have been in electronic storage in ISPCompany’s
computer systems for more than 180 days.
13. Te information requested should be readily accessible to ISPCompany
by computer search, and its production should not prove to be burdensome.
14. Te United States requests that this application and Order be sealed by
the Court until such time as the Court directs otherwise.
15. Te United States requests that pursuant to the preclusion of notice
provisions of 18 U.S.C. § 2705(b), ISPCompany be ordered not to notify any
person (including the subscriber or customer to which the materials relate) of
the existence of this Order for such period as the Court deems appropriate. Te
United States submits that such an order is justified because notification of the
existence of this Order would seriously jeopardize the ongoing investigation.
Such a disclosure would give the subscriber an opportunity to destroy evidence,
218
Searching and Seizing Computers
change patterns of behavior, notify confederates, or flee or continue his flight
from prosecution.
16. Te United States further requests, pursuant to the delayed notice
provisions of 18 U.S.C. § 2705(a), an order delaying any notification to the
subscriber or customer that may be required by § 2703(b) to obtain the contents
of communications, for a period of ninety days. Providing prior notice to the
subscriber or customer would seriously jeopardize the ongoing investigation, as
such a disclosure would give the subscriber an opportunity to destroy evidence,
change patterns of behavior, notify confederates, or flee or continue his flight
from prosecution.
WHEREFORE, it is respectfully requested that the Court grant the
attached Order (1) directing ISPCompany to provide the United States with
the records and information described in Attachment A; (2) directing that the
application and Order be sealed; (3) directing ISPCompany not to disclose
the existence or content of the Order or this investigation, except to the extent
necessary to carry out the Order; and (4) directing that the notification by the
government otherwise required under 18 U.S.C. § 2703(b) be delayed for
ninety days; and (5) directing that three certified copies of this application and
Order be provided by the Clerk of this Court to the United States Attorney’s
Office.
Executed on ________
_________________________
Assistant United States Attorney
Appendix B
219
UNITED STATES DISTRICT COURT
FOR THE _______________
)
IN RE APPLICATION OF THE
)
UNITED STATES OF AMERICA FOR
)
MISC. NO.
AN ORDER PURSUANT TO
)
18 U.S.C. § 2703(d)
)
)
Filed Under Seal
ORDER
Tis matter having come before the Court pursuant to an application
under Title 18, United States Code, Section 2703, which application requests
the issuance of an order under Title 18, United States Code, Section 2703(d)
directing ISPCompany, an electronic communications service provider and/or
a remote computing service, located in City, State, to disclose certain records
and other information, as set forth in Attachment A to this Order, the Court
finds that the applicant has offered specific and articulable facts showing that
there are reasonable grounds to believe that the records or other information
and the contents of wire or electronic communications sought are relevant and
material to an ongoing criminal investigation.
IT APPEARING that the information sought is relevant and material
to an ongoing criminal investigation, and that prior notice to any person of this
investigation or this application and Order entered in connection therewith
would seriously jeopardize the investigation;
IT IS ORDERED pursuant to Title 18, United States Code, Section
2703(d) that ISPCompany will, within seven days of the date of this Order,
220
Searching and Seizing Computers
turn over to the United States the records and other information as set forth in
Attachment A to this Order.
IT IS FURTHER ORDERED that the Clerk of the Court shall
provide the United States Attorney’s Office with three (3) certified copies of
this application and Order.
IT IS FURTHER ORDERED that the application and this Order
are sealed until otherwise ordered by the Court, and that ISPCompany shall
not disclose the existence of the application or this Order of the Court, or the
existence of the investigation, to the listed subscriber or to any other person,
unless and until authorized to do so by the Court.
IT IS FURTHER ORDERED that the notification by the government
otherwise required under 18 U.S.C. § 2703(b)(1)(B) be delayed for a period
of ninety days.
__________________________
______________
United States Magistrate Judge
Date
Appendix B
221
ATTACHMENT A
You are to provide the following information, if available, as data files on CD-
ROM or other electronic media or by facsimile:
A.
Te following customer or subscriber account information for each
account registered to or associated with sample@sample.com for the
time period [date range]:
1. subscriber names, user names, screen names, or other identities;
2. mailing addresses, residential addresses, business addresses, email
addresses, and other contact information;
3. local and long distance telephone connection records, or records of
session times and durations;
4. length of service
(including start date) and types of service
utilized;
5. telephone or instrument number or other subscriber number or
identity, including any temporarily assigned network address; and
6. means and source of payment for such service (including any credit
card or bank account number) and billing records.
B.
All records and other information relating to the account(s) and time
period in Part A, including:
1. records of user activity for any connections made to or from the
account, including the date, time, length, and method of connec-
tions, data transfer volume, user name, and source and destination
Internet Protocol address(es);
2. telephone records, including caller identification records, cellular
site and sector information, GPS data, and cellular network identi-
fying information (such as the IMSI, MSISDN, IMEI, MEID, or
222
Searching and Seizing Computers
ESN);
3. non-content information associated with the contents of any com-
munication or file stored by or for the account(s), such as the source
and destination email addresses and IP addresses.
4. correspondence and notes of records related to the account(s).
C. [Before seeking to compel disclosure of content, give prior notice to the
customer or subscriber or comply with the delayed notice provisions of
18 U.S.C. § 2705(a).] Te contents of electronic communications (not
in electronic storage2) in ISPCompany’s systems in directories or files
owned or controlled by the accounts identified in Part A at any time
from [date range]; and the contents of electronic communications that
have been in electronic storage in ISPCompany’s electronic communi-
cations system for more than 180 days [and within date range].
2 “Electronic storage” is a term of art, specifically defined in 18 U.S.C. § 2510(17) as
“(A) any temporary, intermediate storage of a wire or electronic communication incidental
to the electronic transmission thereof; and (B) any storage of such communication by an
electronic communication service for purposes of backup protection of such communication.”
Te government does not seek access to any communications in “electronic storage” for less
than 181 days. [Te following sentence may not be included in the Ninth Circuit; see the
discussion of “electronic storage” in Chapter 3.C.3.] Communications not in “electronic
storage” include any email communications received by the specified accounts that the owner
or user of the account has already accessed, viewed, or downloaded.
Appendix B
223
224
Searching and Seizing Computers
Appendix C
Sample Language for Preservation
Requests under 18 U.S.C. § 2703(f )
ISPCompany
Address
Re: Request for Preservation of Records
Dear ISPCompany:
Pursuant to Title 18, United States Code Section 2703(f ), this letter is a
formal request for the preservation of all stored communications, records, and
other evidence in your possession regarding the following email address pending
further legal process: sample@sample.com (hereinafter, “the Account”).
I request that you not disclose the existence of this request to the subscriber
or any other person, other than as necessary to comply with this request. If
compliance with this request might result in a permanent or temporary
termination of service to the Account, or otherwise alert any user of the Account
as to your actions to preserve the information described below, please contact
me as soon as possible and before taking action.
I request that you preserve, for a period of 90 days, the information described
below currently in your possession in a form that includes the complete record.
Tis request applies only retrospectively. It does not in any way obligate you to
capture and preserve new information that arises after the date of this request.
Tis request applies to the following items, whether in electronic or other form,
including information stored on backup media, if available:
1. Te contents of any communication or file stored by or for the
Account and any associated accounts, and any information associated
with those communications or files, such as the source and destination
email addresses or IP addresses.
225
2.
All records and other information relating to the Account and any
associated accounts including the following:
a.
subscriber names, user names, screen names, or other identities;
b.
mailing addresses, residential addresses, business addresses, email
addresses, and other contact information;
c.
length of service
(including start date) and types of service
utilized;
d.
records of user activity for any connections made to or from
the Account, including the date, time, length, and method of
connections, data transfer volume, user name, and source and
destination Internet Protocol address(es);
e.
telephone records, including local and long distance telephone
connection records, caller identification records, cellular site and
sector information, GPS data, and cellular network identifying
information
(such as the IMSI, MSISDN, IMEI, MEID, or
ESN);
f.
telephone or instrument number or other subscriber number or
identity, including temporarily assigned network address;
g.
means and source of payment for the Account (including any credit
card or bank account numbers) and billing records;
h.
correspondence and other records of contact by any person or
entity about the Account, such as “Help Desk” notes; and
i.
any other records or evidence relating to the Account.
If you
have questions regarding this request, please call me at [phone
number].
Sincerely,
[NAME]
[GOVERNMENT ENTITY]
226
Searching and Seizing Computers
Appendix D
Sample Pen Register/Trap and Trace
Application and Order
Te sample pen/trap application and order below are designed (1) to collect
email addresses to which the account owner sends email and from which
the account owner receives email and (2) to collect IP addresses associated
with the transmission of email and the account owner’s access to the email
account. Investigators may edit the application in order to remove requests
for information that will not be needed in a particular case.
UNITED STATES DISTRICT COURT
FOR THE [DISTRICT]
)
IN RE APPLICATION OF THE
)
UNITED STATES OF AMERICA FOR
)
MISC. NO. ____
AN ORDER AUTHORIZING THE
)
INSTALLATION AND USE OF PEN
)
REGISTER AND TRAP AND
)
TRACE DEVICES
)
)
Filed Under Seal
APPLICATION
Te United States of America, moving by and through
[AUSA
name], its undersigned counsel, respectfully submits under seal this ex parte
application for an Order pursuant to 18 U.S.C §§ 3122 and 3123, authorizing
the installation and use of pen registers and trap and trace devices (“pen/trap
devices”) on the [service provider] email account [target email address] whose
227
listed subscriber is [subscriber name]. In support of this application, the United
States asserts:
1. Tis is an application, made under 18 U.S.C. § 3122(a)(1), for an
order under 18 U.S.C. § 3123 authorizing the installation and use of a pen
register and a trap and trace device.
2. Under 18 U.S.C. § 3122(b), such an application must include three
elements: (1) “the identity of the attorney for the Government or the State
law enforcement or investigative officer making the application”; (2) “the
identity of the law enforcement agency conducting the investigation”; and (3)
“a certification by the applicant that the information likely to be obtained is
relevant to an ongoing criminal investigation being conducted by that agency.”
18 U.S.C. § 3122(b).
3. Te attorney for the Government making the application is the
undersigned, [AUSA name], who is an “attorney for the government” as defined
in Rule 1(b)(1) of the Federal Rules of Criminal Procedure.
4. Te law enforcement agency conducting the investigation is the [law
enforcement agency].
5. Te applicant hereby certifies that the information likely to be
obtained by the requested pen/trap devices is relevant to an ongoing criminal
investigation being conducted by [law enforcement agency].
ADDITIONAL INFORMATION
6. Other than the three elements described above, federal law does not
require that an application for an order authorizing the installation and use
228
Searching and Seizing Computers
of pen/trap devices specify any facts. Te following additional information
is provided to demonstrate that the order requested falls within this Court’s
authority to authorize the installation and use of a pen register or trap and trace
device under 18 U.S.C. § 3123(a)(1).
7. A “pen register” is “a device or process which records or decodes
dialing, routing, addressing, or signaling information transmitted by an
instrument or facility from which a wire or electronic communication is
transmitted.” 18 U.S.C. § 3127(3). A “trap and trace device” is “a device
or process which captures the incoming electronic or other impulses which
identify the originating number or other dialing, routing, addressing, and
signaling information reasonably likely to identify the source of a wire or
electronic communication.” 18 U.S.C. § 3127(4).
8. In the traditional telephone context, pen registers captured the
destination phone numbers of outgoing calls, while trap and trace devices
captured the phone numbers of incoming calls. Similar principles apply to
other kinds of wire and electronic communications, as described below.
9. Te Internet is a global network of computers and other devices.
Every device on the Internet is identified by a unique number called an Internet
Protocol, or “IP” address. Tis number is used to route information between
devices. Two computers must know each other’s IP addresses to exchange even
the smallest amount of information. Accordingly, when one computer requests
information from a second computer, the requesting computer specifies its own
IP address so that the responding computer knows where to send its response.
Appendix D
229
An IP address is analogous to a telephone number and can be recorded by pen/
trap devices, and it indicates the online identity of the communicating device
without revealing the communication’s content.
10. On the Internet, data transferred between devices is not sent as
a continuous stream, but rather it is split into discreet packets. Generally, a
single communication is sent as a series of packets. When the packets reach
their destination, the receiving device reassembles them into the complete
communication. Each packet has two parts: a header with routing and control
information, and a payload, which generally contains user data. Te header
contains non-content information such as the packet’s source and destination
IP addresses and the packet’s size.
11. An email message has its own routing header, in addition to the
source and destination information associated with all Internet data. Te
message header of an email contains the message’s source and destination(s),
expressed as email addresses in “From,” “To,” “CC” (carbon copy), or “BCC”
(blind carbon copy) fields. Multiple destination addresses may be specified in
the “To,” “CC,” and “BCC” fields. Te email addresses in an email’s message
header are like the telephone numbers of both incoming and outgoing calls,
because they indicate both origin and destination(s). Tey can be recorded
by pen/trap devices and can be used to identify parties to a communication
without revealing the communication’s contents.
230
Searching and Seizing Computers
THE RELEVANT FACTS
12. Te United States government, including the [law enforcement
agency], is investigating
[crime facts]. Te investigation concerns possible
violations by unknown individuals of, inter alia, [statutes].
13.
[***OPTIONALLY INSERT FACTUAL PARAGRAPH(S)
HERE. Please note that additional facts are not required by statute, but some
districts include them in applications anyway. For example, some districts will
include a fact paragraph like this one: “Te investigation relates to the purchase
and sale of stolen credit cards and other unauthorized access devices, which
are then used to perpetrate mail and wire fraud. Investigators believe that
matters relevant to the offenses under investigation have been and continue
to be discussed using jjones007992@isp.com. Investigators believe that the
listed subscriber for this email address number is John Jones, a target of the
investigation, …”]
14. Te conduct being investigated involves use of the email account
[target email address]. To further the investigation, investigators need to obtain
the dialing, routing, addressing, and signaling information associated with
communications sent to or from that email account.
15. Te pen/trap devices sought by this application will be installed
at location(s) to be determined, and will collect dialing, routing, addressing,
and signaling information associated with each communication to or from the
[service provider] email account [target email address], including the date, time,
Appendix D
231
and duration of the communication, and the following, without geographic
limit:
• IP addresses, including IP addresses associated with access to the
account;
• Headers of email messages, including the source and destination
network addresses, as well as the routes of transmission and size of
the messages, but not content located in headers, such as subject
lines;
• the number and size of any attachments.
GOVERNMENT REQUESTS
16. For the reasons stated above, the United States requests that the
Court enter an Order authorizing installation and use of pen/trap devices to
record, decode, and/or capture the dialing, routing, addressing, and signaling
information described above for each communication to or from the [service
provider] email account [target email address], along with the date, time, and
duration of the communication, without geographic limit. Te United States
does not request and does not seek to obtain the contents of any communications,
as defined in 18 U.S.C. § 2510(8), pursuant to the proposed Order.
17. Te United States further requests that the Court authorize the
foregoing installation and use for a period of sixty days, pursuant to 18 U.S.C.
§ 3123(c)(1).
18. Te United States further requests, pursuant to 18 U.S.C. §§
3123(b)(2) and 3124(a)-(b), that the Court order [service provider] and any
232
Searching and Seizing Computers
other person or entity providing wire or electronic communication service
in the United States whose assistance may facilitate execution of this Order
to furnish, upon service of the Order, information, facilities, and technical
assistance necessary to install the pen/trap devices, including installation and
operation of the pen/trap devices unobtrusively and with minimum disruption
of normal service. Any entity providing such assistance shall be reasonably
compensated by [law enforcement agency], pursuant to 18 U.S.C. § 3124(c),
for reasonable expenses incurred in providing facilities and assistance in
furtherance of this Order.
19. Te United States further requests that the Court order [service
provider] and any other person or entity whose assistance may facilitate
execution of this Order to notify [law enforcement agency] of any changes
relating to the email account [target email address], including changes to
subscriber information, and to provide prior notice to the [law enforcement
agency] before terminating service to the email account.
20. Te United States further requests that the Court order that the
[law enforcement agency] and the applicant have access to the information
collected by the pen/trap devices as soon as practicable, twenty-four hours per
day, or at such other times as may be acceptable to them, for the duration of
the Order.
21. Te United States further requests, pursuant to 18 U.S.C. §
3123(d)(2), that the Court order [law enforcement agency] and any other
person or entity whose assistance facilitates execution of this Order, and their
Appendix D
233
agents and employees, not to disclose in any manner, directly or indirectly, by
any action or inaction, the existence of this application and Order, the resulting
pen/trap devices, or this investigation, except as necessary to effectuate the
Order, unless and until authorized by this Court.
22. Te United States further requests that this application and any
resulting Order be sealed until otherwise ordered by the Court, pursuant to 18
U.S.C. § 3123(d)(1).
23. Te United States further requests that the Clerk of the Court
provide the United States Attorney’s Office with three certified copies of this
application and Order, and provide copies of this Order to [law enforcement
agency] and [service provider] upon request.
24. Te foregoing is based on information provided to me in my official
capacity by agents of [law enforcement agency].
I declare under penalty of perjury that the foregoing is true and
correct.
Executed on _________________.
___________________________
[AUSA name]
[AUSA title]
[address]
234
Searching and Seizing Computers
UNITED STATES DISTRICT COURT
FOR THE _______________
)
IN RE APPLICATION OF THE
)
UNITED STATES OF AMERICA FOR
)
MISC. NO.
AN ORDER AUTHORIZING THE
)
INSTALLATION AND USE OF PEN
)
REGISTER AND TRAP AND
)
TRACE DEVICES
)
)
Filed Under Seal
ORDER
[AUSA name], on behalf of the United States, has submitted an
application pursuant to 18 U.S.C. §§ 3122 and 3123, requesting that the Court
issue an Order pursuant to 18 U.S.C. § 3123, authorizing the installation and
use of pen registers and trap and trace devices (“pen/trap devices”) on the
[service provider] email account [target email address], whose listed subscriber
is [subscriber name].
Te Court finds that the applicant is an attorney for the government
and has certified that the information likely to be obtained by such installation
and use is relevant to an ongoing criminal investigation being conducted by
[law enforcement agency] of unknown individuals in connection with possible
violations of [statutes].
IT IS THEREFORE ORDERED, pursuant to 18 U.S.C. § 3123, that
pen/trap devices may be installed and used to record, decode, and/or capture
dialing, routing, addressing, and signaling information associated with each
Appendix D
235
communication to or from the [service provider] email account [target email
address], including the date, time, and duration of the communication, and
the following, without geographic limit:
• IP addresses, including IP addresses associated with access to the
account;
• Headers of email messages, including the source and destination
network addresses, as well as the routes of transmission and size of
the messages, but not content located in headers, such as subject
lines;
• the number and size of any attachments.
IT IS FURTHER ORDERED, pursuant to 18 U.S.C. § 3123(c)(1),
that the use and installation of the foregoing is authorized for sixty days from
the date of this Order;
IT IS FURTHER ORDERED, pursuant to 18 U.S.C. §§ 3123(b)(2)
and 3124(a)-(b), that [service provider] and any other person or entity providing
wire or electronic communication service in the United States whose assistance
may, pursuant to 18 U.S.C. § 3123(a), facilitate the execution of this Order
shall, upon service of this Order, furnish information, facilities, and technical
assistance necessary to install the pen/trap devices, including installation and
operation of the pen/trap devices unobtrusively and with minimum disruption
of normal service;
IT IS FURTHER ORDERED that [law enforcement agency]
reasonably compensate [service provider] and any other person or entity whose
236
Searching and Seizing Computers
assistance facilitates execution of this Order for reasonable expenses incurred
in complying with this Order;
IT IS FURTHER ORDERED that [service provider] and any other
person or entity whose assistance may facilitate execution of this Order notify
[law enforcement agency] of any changes relating to the email account [target
email account], including changes to subscriber information, and to provide
prior notice to [law enforcement agency] before terminating service to the
email account;
IT IS FURTHER ORDERED that [law enforcement agency] and the
applicant have access to the information collected by the pen/trap devices as
soon as practicable, twenty-four hours per day, or at such other times as may be
acceptable to [law enforcement agency], for the duration of the Order;
IT IS FURTHER ORDERED, pursuant to 18 U.S.C. § 3123(d)(2),
that [service provider] and any other person or entity whose assistance facilitates
execution of this Order, and their agents and employees, shall not disclose in
any manner, directly or indirectly, by any action or inaction, the existence of
the application and this Order, the pen/trap devices, or the investigation to any
person, except as necessary to effectuate this Order, unless and until otherwise
ordered by the Court;
IT IS FURTHER ORDERED that the Clerk of the Court shall provide
the United States Attorney’s Office with three certified copies of this application
and Order, and shall provide copies of this Order to [law enforcement agency]
Appendix D
237
and [service provider] upon request;
IT IS FURTHER ORDERED that the application and this Order
are sealed until otherwise ordered by the Court, pursuant to 18 U.S.C. §
3123(d)(1).
__________________
_______________________
Date
United States Magistrate Judge
238
Searching and Seizing Computers
Appendix E
Sample Subpoena Language
Te SCA permits the government to compel disclosure of the basic subscriber
and session information listed in 18 U.S.C. § 2703(c)(2) using a subpoena.
Tis information is specified in Part A below, and the government is not
required to provide notice to the subscriber or customer when using a
subpoena to compel disclosure of this information.
When the government either gives prior notice to the customer or subscriber
or complies with the delayed notice provisions of 18 U.S.C. § 2705(a),
it may use a subpoena to compel disclosure of “the contents of a wire or
electronic communication that has been in electronic storage in an electronic
communications system for more than one hundred and eighty days” and
“the contents of any wire or electronic communication” held by a provider
of remote computing service “on behalf of . . . a subscriber or customer of
such remote computing service.” 18 U.S.C. §§ 2703(a), 2703(b)(1)(B)(i),
2703(b)(2). Tis information is specified in Part B below. As discussed in
Chapter 3.C.3, there is disagreement among courts on whether previously
retrieved communications fall within the scope of communications in
“electronic storage.”
Te information requested below can be obtained with the use of an
administrative subpoena authorized by Federal or State statute or a Federal
or State grand jury or trial subpoena or a § 2703(d) order or a search warrant.
See 18 U.S.C. §§ 2703(b)(1)(B)(i), 2703(c)(2).
Attachment To Subpoena
All customer or subscriber account information for the [choose one: email
account, domain name, IP address, subscriber, username]
[specify email
account, domain name, IP address, subscriber, username], or for any related
accounts, that falls within any of the following categories:
1. Name,
2. Address,
239
3.
Local and long distance telephone toll billing records,
4.
Records of session times and durations,
5.
Length of service (including start date) and types of service utilized,
6.
Telephone or instrument number or other subscriber number or
identity, including any temporarily assigned network address such as
an Internet Protocol address, and
7.
Means and source of payment for such service (including any credit
card or bank account number).
8.
[Before seeking to compel disclosure of content, give prior notice to the
customer or subscriber or comply with the delayed notice provisions of
18 U.S.C. § 2705(a).] For each such account, the information shall also
include the contents of electronic communications (not in electronic
storage) held or maintained by your company for the use of the account
at any time, up through and including the date of this subpoena; and
the contents of electronic communications that have been in electronic
storage in your company’s electronic communications system for more
than 180 days.
“Electronic storage” is defined in 18 U.S.C. § 2510(17) as “(A) any
temporary, intermediate storage of a wire or electronic communication
incidental to the electronic transmission thereof; and (B) any storage
of such communication by an electronic communication service
for purposes of backup protection of such communication.” Te
government does not seek access to any such materials unless they have
been in “electronic storage” for more than 180 days.
You are to provide this information, if available, as data files on CD-ROM or
other electronic media or by facsimile to [fax number].
240
Searching and Seizing Computers
Appendix F
Sample Premises Computer
Search Warrant Affidavit
Tis form may be used when a warrant is sought to allow agents to enter a
premises and remove computers or electronic media from the premises. In
this document, “[[” marks indicate places that must be customized for each
affidavit. Fill out your district’s AO 93 Search Warrant form without any
reference to computers; your agents are simply searching a premises for items
particularly described in the affidavit’s attachment. Consider incorporating
the affidavit by reference. See Chapter 2 for a detailed discussion of issues
involved in drafting computer search warrants.
UNITED STATES DISTRICT COURT
FOR THE [DISTRICT]
)
In the Matter of the Search of
)
Case No.
[[Premises Address]]
)
)
AFFIDAVIT IN SUPPORT OF AN APPLICATION
UNDER RULE 41 FOR A WARRANT TO SEARCH AND SEIZE
I, [[AGENT NAME]], being first duly sworn, hereby depose and state as
follows:
INTRODUCTION AND AGENT BACKGROUND
1. I make this affidavit in support of an application under Rule 41 of
the Federal Rules of Criminal Procedure for a warrant to search the premises
known as [[PREMISES ADDRESS]], hereinafter “PREMISES,” for certain
things particularly described in Attachment A.
241
2. I am a
[[TITLE]] with the
[[AGENCY]], and have been since
[[DATE]]. [[DESCRIBE TRAINING AND EXPERIENCE INCLUDING
EXPERTISE WITH COMPUTERS]].
3. Tis affidavit is intended to show only that there is sufficient probable
cause for the requested warrant and does not set forth all of my knowledge
about this matter.
PROBABLE CAUSE
4.
[[Give facts that establish probable cause to believe that evidence,
fruits, or contraband can be found on each computer that will be searched
and/or seized, or to believe that the computers may be seized as contraband or
instrumentalities.]]
TECHNICAL TERMS
5.
[[THIS SECTION MIGHT BE UNNECESSARY; DEFINE ONLY
TECHNICAL TERMS AS NECESSARY TO SUPPORT PROBABLE
CAUSE.]] Based on my training and experience, I use the following technical
terms to convey the following meanings:
a. IP Address: Te Internet Protocol address (or simply “IP address”)
is a unique numeric address used by computers on the Internet. An IP address
looks like a series of four numbers, each in the range 0-255, separated by periods
(e.g., 121.56.97.178). Every computer attached to the Internet computer must
be assigned an IP address so that Internet traffic sent from and directed to that
computer may be directed properly from its source to its destination. Most
Internet service providers control a range of IP addresses. Some computers
have static—that is, long-term—IP addresses, while other computers have
dynamic—that is, frequently changed—IP addresses.
b. Internet: Te Internet is a global network of computers and other
electronic devices that communicate with each other. Due to the structure of
the Internet, connections between devices on the Internet often cross state and
international borders, even when the devices communicating with each other
are in the same state.
COMPUTERS AND ELECTRONIC STORAGE
6. As described above and in Attachment A, this application seeks
permission to search and seize records that might be found on the PREMISES,
in whatever form they are found. I submit that if a computer or electronic
242
Searching and Seizing Computers
medium is found on the premises, there is probable cause to believe those
records will be stored in that computer or electronic medium, for at least the
following reasons:
a. Based on my knowledge, training, and experience, I know that
computer files or remnants of such files can be recovered months or even years
after they have been downloaded onto a hard drive, deleted or viewed via the
Internet. Electronic files downloaded to a hard drive can be stored for years
at little or no cost. Even when files have been deleted, they can be recovered
months or years later using readily available forensics tools. Tis is so because
when a person “deletes” a file on a home computer, the data contained in the
file does not actually disappear; rather, that data remains on the hard drive
until it is overwritten by new data.
b. Terefore, deleted files, or remnants of deleted files, may reside
in free space or slack space—that is, in space on the hard drive that is not
currently being used by an active file—for long periods of time before they are
overwritten. In addition, a computer’s operating system may also keep a record
of deleted data in a “swap” or “recovery” file.
c. Similarly, files that have been viewed via the Internet are typically
automatically downloaded into a temporary Internet directory or “cache.” Te
browser often maintains a fixed amount of hard drive space devoted to these
files, and the files are only overwritten as they are replaced with more recently
viewed Internet pages or if a user takes steps to delete them.
d. [[FOR CHILD PORNOGRAPHY CASES]] I know from training
and experience that child pornographers generally prefer to store images of
child pornography in electronic form as computer files. Te computer’s ability
to store images in digital form makes a computer an ideal repository for
pornography. A small portable disk or computer hard drive can contain many
child pornography images. Te images can be easily sent to or received from
other computer users over the Internet. Further, both individual files of child
pornography and the disks that contain the files can be mislabeled or hidden
to evade detection. In my training and experience, individuals who view child
pornography typically maintain their collections for many years and keep and
collect items containing child pornography over long periods of time; in fact,
they rarely, if ever, dispose of their sexually explicit materials.
e. [[FOR BUSINESS SEARCH CASES]] Based on actual inspection
of
[[spreadsheets, financial records, invoices]], I am aware that computer
Appendix F
243
equipment was used to generate, store, and print documents used in the [[tax
evasion, money laundering, drug trafficking, etc.]] scheme. Tere is reason to
believe that there is a computer system currently located on the PREMISES.
7.
[[FOR CHILD PORNOGRAPHY OR OTHER CONTRABAND
CASES]] In this case, the warrant application requests permission to search
and seize [[images of child pornography, including those that may be stored on
a computer]]. Tese things constitute both evidence of crime and contraband.
Tis affidavit also requests permission to seize the computer hardware and
electronic media that may contain those things if it becomes necessary for
reasons of practicality to remove the hardware and conduct a search off-site.
[[In this case, computer hardware that was used to store child pornography
is a container for evidence, a container for contraband, and also itself an
instrumentality of the crime under investigation.]]
8.
[[FOR CHILD PORNOGRAPHY PRODUCTION CASES]] I know
from training and experience that it is common for child pornographers to use
personal computers to produce both still and moving images. For example,
a computer can have a camera built in, or can be connected to a camera
and turn the video output into a form that is usable by computer programs.
Alternatively, the pornographer can use a digital camera to take photographs
or videos and load them directly onto the computer. Te output of the camera
can be stored, transferred or printed out directly from the computer. Te
producers of child pornography can also use a scanner to transfer photographs
into a computer-readable format. All of these devices, as well as the computer,
constitute instrumentalities of the crime.
9.
[[FOR HACKING OR OTHER INSTRUMENTALITY CASES]]
I know that when an individual uses a computer to [[obtain unauthorized
access to a victim computer over the Internet]], the individual’s computer will
generally serve both as an instrumentality for committing the crime, and also as
a storage device for evidence of the crime. Te computer is an instrumentality
of the crime because it is used as a means of committing the criminal offense.
Te computer is also likely to be a storage device for evidence of crime. From
my training and experience, I believe that a computer used to commit a crime
of this type may contain: data that is evidence of how the computer was used;
data that was sent or received; notes as to how the criminal conduct was
achieved; records of Internet discussions about the crime; and other records
that indicate the nature of the offense.
244
Searching and Seizing Computers
10. [[FOR CASES WHERE A RESIDENCE SHARED WITH OTHERS
IS SEARCHED]] Because several people share the PREMISES as a residence, it
is possible that the PREMISES will contain computers that are predominantly
used, and perhaps owned, by persons who are not suspected of a crime. If agents
conducting the search nonetheless determine that it is possible that the things
described in this warrant could be found on those computers, this application
seeks permission to search and if necessary to seize those computers as well. It
may be impossible to determine, on scene, which computers contain the things
described in this warrant.
11. Based upon my knowledge, training and experience, I know that
searching for information stored in computers often requires agents to seize
most or all electronic storage devices to be searched later by a qualified
computer expert in a laboratory or other controlled environment. Tis is
often necessary to ensure the accuracy and completeness of such data, and to
prevent the loss of the data either from accidental or intentional destruction.
Additionally, to properly examine those storage devices in a laboratory setting,
it is often necessary that some computer equipment, peripherals, instructions,
and software be seized and examined in the laboratory setting. Tis is true
because of the following:
a. Te volume of evidence. Computer storage devices (like hard disks
or CD-ROMs) can store the equivalent of millions of pages of information.
Additionally, a suspect may try to conceal criminal evidence; he or she might
store it in random order with deceptive file names. Tis may require searching
authorities to peruse all the stored data to determine which particular files are
evidence or instrumentalities of crime. Tis sorting process can take weeks or
months, depending on the volume of data stored, and it would be impractical
and invasive to attempt this kind of data search on-site.
b. Technical requirements. Searching computer systems for criminal
evidence sometimes requires highly technical processes requiring expert skill
and properly controlled environment. Te vast array of computer hardware
and software available requires even computer experts to specialize in some
systems and applications, so it is difficult to know before a search which expert
is qualified to analyze the system and its data. In any event, however, data search
processes are exacting scientific procedures designed to protect the integrity
of the evidence and to recover even “hidden,” erased, compressed, password-
protected, or encrypted files. Because computer evidence is vulnerable to
inadvertent or intentional modification or destruction (both from external
Appendix F
245
sources or from destructive code imbedded in the system as a “booby trap”), a
controlled environment may be necessary to complete an accurate analysis.
12. In light of these concerns, I hereby request the Court’s permission to
seize the computer hardware (and associated peripherals) that are believed to
contain some or all of the evidence described in the warrant, and to conduct an
off-site search of the hardware for the evidence described, if, upon arriving at
the scene, the agents executing the search conclude that it would be impractical
to search the computer hardware on-site for this evidence.
13. Searching computer systems for the evidence described in Attachment
A may require a range of data analysis techniques. In some cases, it is possible
for agents and analysts to conduct carefully targeted searches that can locate
evidence without requiring a time-consuming manual search through unrelated
materials that may be commingled with criminal evidence. In other cases,
however, such techniques may not yield the evidence described in the warrant.
Criminals can mislabel or hide files and directories, encode communications
to avoid using key words, attempt to delete files to evade detection, or take
other steps designed to frustrate law enforcement searches for information.
Tese steps may require agents and law enforcement or other analysts with
appropriate expertise to conduct more extensive searches, such as scanning
areas of the disk not allocated to listed files, or peruse every file briefly to
determine whether it falls within the scope of the warrant. In light of these
difficulties, the [[AGENCY]] intends to use whatever data analysis techniques
appear necessary to locate and retrieve the evidence described in Attachment
A.
14. [[INCLUDE THE FOLLOWING IF THERE IS A CONCERN
ABOUT THE SEARCH UNREASONABLY IMPAIRING AN
OPERATIONAL, OTHERWISE LEGAL BUSINESS]] I recognize that the
Company is a functioning company with many employees, and that a seizure
of the Company’s computers may have the unintended effect of limiting the
Company’s ability to provide service to its legitimate customers. In response
to these concerns, the agents who execute the search anticipate taking an
incremental approach to minimize the inconvenience to the Company’s
legitimate customers and to minimize the need to seize equipment and data.
It is anticipated that, barring unexpected circumstances, this incremental
approach will proceed as follows:
246
Searching and Seizing Computers
a. Upon arriving at the PREMISES, the agents will attempt to identify
a system administrator of the network (or other knowledgeable employee) who
will be willing to assist law enforcement by identifying, copying, and printing
out paper and electronic copies of the things described in the warrant. Te
assistance of such an employee might allow agents to place less of a burden on
the Company than would otherwise be necessary.
b. If the employees choose not to assist the agents, the agents decide that
none are trustworthy, or for some other reason the agents cannot execute the
warrant successfully without themselves examining the Company’s computers,
the agents will attempt to locate the things described in the warrant, and will
attempt to make electronic copies of those things. Tis analysis will focus on
things that may contain the evidence and information of the violations under
investigation. In doing this, the agents might be able to copy only those things
that are evidence of the offenses described herein, and provide only those things
to the case agent. Circumstances might also require the agents to attempt to
create an electronic “image” of those parts of the computer that are likely to store
the things described in the warrant. Generally speaking, imaging is the taking
of a complete electronic picture of the computer’s data, including all hidden
sectors and deleted files. Imaging a computer permits the agents to obtain an
exact copy of the computer’s stored data without actually seizing the computer
hardware. Te agents or qualified computer experts will then conduct an off-
site search for the things described in the warrant from the “mirror image”
copy at a later date. If the agents successfully image the Company’s computers,
the agents will not conduct any additional search or seizure of the Company’s
computers.
c. If imaging proves impractical, or even impossible for technical reasons,
then the agents will seize those components of the Company’s computer system
that the agents believe must be seized to permit the agents to locate the things
described in the warrant at an off-site location. Te seized components will be
removed from the PREMISES. If employees of the Company so request, the
agents will, to the extent practicable, attempt to provide the employees with
copies of data that may be necessary or important to the continuing function
of the Company’s legitimate business. If, after inspecting the computers, the
analyst determines that some or all of this equipment is no longer necessary
to retrieve and preserve the evidence, the government will return it within a
reasonable time.
Appendix F
247
CONCLUSION
15. I submit that this affidavit supports probable cause for a warrant to
search the PREMISES and seize the items described in Attachment A.
REQUEST FOR SEALING
[[IF APPROPRIATE: It is respectfully requested that this Court issue an
order sealing, until further order of the Court, all papers submitted in support
of this application, including the application and search warrant. I believe that
sealing this document is necessary because the items and information to be
seized are relevant to an ongoing investigation into the criminal organizations
as not all of the targets of this investigation will be searched at this time.
Based upon my training and experience, I have learned that, online criminals
actively search for criminal affidavits and search warrants via the Internet and
disseminate them to other online criminals as they deem appropriate, i.e., post
them publicly online through the carding forums. Premature disclosure of the
contents of this affidavit and related documents may have a significant and
negative impact on the continuing investigation and may severely jeopardize
its effectiveness.]]
Respectfully submitted,
[[AGENT NAME]]
Special Agent
[[AGENCY]]
Subscribed and sworn to before me on ___________:
_________________________________________
UNITED STATES MAGISTRATE JUDGE
248
Searching and Seizing Computers
ATTACHMENT A
1. All records relating to violations of the statutes listed on the warrant and
involving [[SUSPECT]] since [[DATE]], including:
a.
[[IDENTIFY RECORDS SOUGHT WITH PARTICULARITY;
EXAMPLES FOR A DRUG CASE FOLLOW]];
b. lists of customers and related identifying information; types, amounts,
and prices of drugs trafficked as well as dates, places, and amounts of
specific transactions;
c. any information related to sources of narcotic drugs (including names,
addresses, phone numbers, or any other identifying information);
d. any information recording [[SUSPECT]]’s schedule or travel from
2008 to the present;
e. all bank records, checks, credit card bills, account information, and
other financial records.
2.
[[IF OFFENSE INVOLVED A COMPUTER AS AN
INSTRUMENTALITY OR CONTAINER FOR CONTRABAND]] Any
computers or electronic media that were or may have been used as a means to
commit the offenses described on the warrant, including [[receiving images of
child pornography over the Internet in violation of 18 U.S.C. § 2252A.]]
3. For any computer hard drive or other electronic media (hereinafter,
“MEDIA”) that is called for by this warrant, or that might contain things
otherwise called for by this warrant:
a. evidence of user attribution showing who used or owned the MEDIA
at the time the things described in this warrant were created, edited, or
deleted, such as logs, registry entries, saved usernames and passwords,
documents, and browsing history;
b. passwords, encryption keys, and other access devices that may be
necessary to access the MEDIA;
c. documentation and manuals that may be necessary to access the
MEDIA or to conduct a forensic examination of the MEDIA.
4.
[[IF CASE INVOLVED THE INTERNET]] Records and things
evidencing the use of the Internet Protocol address
[[e.g.
10.19.74.69]]
Appendix F
249
to communicate with [[e.g. Yahoo! mail servers or university mathematics
department computers]], including:
a. routers, modems, and network equipment used to connect computers
to the Internet;
b. records of Internet Protocol addresses used;
c. records of Internet activity, including firewall logs, caches, browser
history and cookies, “bookmarked” or “favorite” web pages, search
terms that the user entered into any Internet search engine, and records
of user-typed web addresses.
As used above, the terms “records” and “information” include all of the
foregoing items of evidence in whatever form and by whatever means they
may have been created or stored, including any form of computer or electronic
storage (such as hard disks or other media that can store data); any handmade
form (such as writing, drawing, painting); any mechanical form (such as
printing or typing); and any photographic form (such as microfilm, microfiche,
prints, slides, negatives, videotapes, motion pictures, photocopies).
250
Searching and Seizing Computers
Appendix G
Sample Letter for
Provider Monitoring
As discussed in Chapter 4.D.3.c of this manual, agents and prosecutors
should adopt a cautious approach to accepting the fruits of future monitoring
conducted by providers under the provider exception. Furthermore, law
enforcement may be able to avoid this issue by relying on the computer
trespasser exception. However, in cases in which law enforcement chooses to
accept the fruits of future monitoring by providers, this letter may reduce the
risk that any provider monitoring and disclosure will exceed the acceptable
limits of § 2511(2)(a)(i).
Tis letter is intended to inform [law enforcement agency] of [Provider’s]
decision to conduct monitoring of unauthorized activity within its computer
network pursuant to 18 U.S.C. § 2511(2)(a)(i), and to disclose some or all of
the fruits of this monitoring to law enforcement if [Provider] deems disclosure
will assist in protecting its rights or property. On or about [date], [Provider]
became aware that it was the victim of unauthorized intrusions into its computer
network. [Provider] understands that 18 U.S.C. § 2511(2)(a)(i) authorizes
an officer, employee, or agent of a provider of wire or
electronic communication service, whose facilities are used
in the transmission of a wire or electronic communication, to
intercept, disclose, or use that communication in the normal
course of his employment while engaged in any activity which
is a necessary incident to the rendition of his service or to the
protection of the rights or property of the provider of that
service[.]
Tis statutory authority permits
[Provider] to engage in reasonable
monitoring of unauthorized use of its network to protect its rights or property
and also to disclose intercepted communications to [law enforcement] to
further the protection of [Provider]’s rights or property. Under 18 U.S.C. §§
251
2702(b)(5) and 2702(c)(3), [Provider] is also permitted to disclose customer
communications, records, or other information related to such monitoring if
such disclosure protects the [Provider]’s rights and property.
To protect its rights and property, [Provider] plans to [continue to] conduct
reasonable monitoring of the unauthorized use in an effort to evaluate the
scope of the unauthorized activity and attempt to discover the identity of the
person or persons responsible. [Provider] may then wish to disclose some or
all of the fruits of its interception, records, or other information related to
such interception, to law enforcement to help support a criminal investigation
concerning the unauthorized use and criminal prosecution for the unauthorized
activity of the person(s) responsible.
[Provider] understands that it is under absolutely no obligation to conduct
any monitoring whatsoever, or to disclose the fruits of any monitoring, records,
or other information related to such monitoring, and that [law enforcement]
has not directed, requested, encouraged, or solicited [Provider] to intercept,
disclose, or use monitored communications, associated records, or other
information for law enforcement purposes.
Accordingly, [Provider] will not engage in monitoring solely or primarily
to assist law enforcement absent an appropriate court order or a relevant
exception to the Wiretap Act (e.g., 18 U.S.C. § 2511(2)(i)). Any monitoring
and/or disclosure will be at [Provider’s] initiative. [Provider] also recognizes
that the interception of wire and electronic communications beyond the
permissible scope of 18 U.S.C. § 2511(2)(a)(i) may potentially subject it to
civil and criminal penalties.
Sincerely,
General Counsel
252
Searching and Seizing Computers
Appendix H
Sample Authorization for Monitoring
of Computer Trespasser Activity
I am [Name of Owner/Operator or person acting on behalf of Owner/
Operator, Title] of [Name and Address of Organization]. I am the [Owner]
[Operator] [person acting on behalf of the Owner or Operator], and own or
have the authority to supervise, manage, or control operation of the [relevant
part of the] [Organization’s] computer system or the data and communications
on and through the network. An unauthorized user(s), who I understand has
no contractual basis for any access to this computer system, has accessed this
computer and is a trespasser(s). I hereby authorize [law enforcement agency] to
intercept communications to, through, or from a trespasser(s) transmitted to,
through, or from [Organization’s] computer system. Te general nature of the
communications to be monitored are [general description of the identifying
characteristics of the communications to be monitored.] [Organization will
assist law enforcement agency to conduct such interception under the direction
of law enforcement agency.] Such interception may occur at any location on the
computer system or network, including at multiple or changed locations, which
may facilitate the interception of communications to or from the trespasser.
Tis authorization does not extend to the interception of communications
other than those to, through, or from a trespasser(s). Tis authorization does
not restrict monitoring under any other appropriate exception to the Wiretap
Act, 18 U.S.C. § 2510 et seq.
Tis authorization is valid [for a specified time period] [indefinitely, until
withdrawn in writing by me or a person acting for me]. I understand I may
withdraw authorization for monitoring at any time, but I agree to do so in
writing.
_______________________________
___________________
Signature of Owner/Operator
Date
253
254
Searching and Seizing Computers
Appendix I
Sample Email Account
Search Warrant Affidavit
Te sample 2703 search warrant affidavit and attachments below are designed
(1) to obtain email messages associated with the target email account that
relate to the investigation, and (2) to obtain records relating to who created,
used, or communicated with the account. Investigators may edit the affidavit
and attachments to remove requests for information that will not be needed
in a particular case. In addition, please note that while the facts described in
the “backg2round” section of the affidavit are true for most email providers,
the affiant should be certain that they are true for the particular email provider
that is the subject of the affidavit.
Notes: When filling out the search warrant form, write “See Attachment A”
in the section that asks for the location of the search and “See Attachment
B” in the section that asks for a description of the items to be seized. Fax the
warrant, along with both attachments and the “certificate of authenticity,” to
the service provider. Te service provider should then give the requested data
to the agent, who should cull through the data returned by the provider and
isolate material that is not called for by the warrant.
UNITED STATES DISTRICT COURT
FOR THE [DISTRICT]
IN THE MATTER OF THE SEARCH OF
INFORMATION ASSOCIATED WITH
[[EMAIL ADDRESSES]] THAT IS STORED
Case No. ______
AT PREMISES CONTROLLED BY [[EMAIL
PROVIDER]]
affidavit IN SUPPORT OF
AN APPLICATION FOR A SEARCH WARRANT
255
I, [AGENT NAME], being first duly sworn, hereby depose and state as
follows:
INTRODUCTION AND AGENT BACKGROUND
1. I make this affidavit in support of an application for a search war-
rant for information associated with certain accounts that is stored at prem-
ises owned, maintained, controlled, or operated by [EMAIL PROVIDER], an
email provider headquartered at [PROVIDER ADDRESS]. Te information
to be searched is described in the following paragraphs and in Attachment A.
Tis affidavit is made in support of an application for a search warrant un-
der 18 U.S.C. §§ 2703(a), 2703(b)(1)(A) and 2703(c)(1)(A) to require [EMAIL
PROVIDER] to disclose to the government records and other information in
its possession pertaining to the subscriber or customer associated with the ac-
counts, including the contents of communications.
2. I am a Special Agent with the [AGENCY], and have been since
[DATE]. [DESCRIBE TRAINING AND EXPERIENCE TO THE EX-
TENT IT SHOWS QUALIFICATION TO SPEAK ABOUT THE INTER-
NET AND OTHER TECHNICAL MATTERS].
3. Te facts in this affidavit come from my personal observations, my
training and experience, and information obtained from other agents and wit-
nesses. Tis affidavit is intended to show merely that there is sufficient probable
cause for the requested warrant and does not set forth all of my knowledge
about this matter.
PROBABLE CAUSE
4. [Give facts establishing probable cause. At a minimum, establish a
connection between the email account and a suspected crime. Also mention
whether a preservation request was sent (or other facts suggesting the email is
still at the provider)]
TECHNICAL BACKGROUND
5. In my training and experience, I have learned that [EMAIL PRO-
VIDER] provides a variety of on-line services, including electronic mail
(“email”) access, to the general public. Subscribers obtain an account by regis-
tering with [EMAIL PROVIDER]. During the registration process, [EMAIL
PROVIDER] asks subscribers to provide basic personal information. Terefore,
the computers of [EMAIL PROVIDER] are likely to contain stored electron-
256
Searching and Seizing Computers
ic communications (including retrieved and unretrieved email for [EMAIL
PROVIDER] subscribers) and information concerning subscribers and their
use of [EMAIL PROVIDER] services, such as account access information,
email transaction information, and account application information.
6. In general, an email that is sent to a [EMAIL PROVIDER] subscriber
is stored in the subscriber’s “mail box” on [EMAIL PROVIDER] servers until
the subscriber deletes the email. If the subscriber does not delete the message,
the message can remain on [EMAIL PROVIDER] servers indefinitely.
7. When the subscriber sends an email, it is initiated at the user’s com-
puter, transferred via the Internet to [EMAIL PROVIDER]’s servers, and then
transmitted to its end destination. [EMAIL PROVIDER] often saves a copy
of the email sent. Unless the sender of the email specifically deletes the email
from the [EMAIL PROVIDER] server, the email can remain on the system
indefinitely.
8. An [EMAIL PROVIDER] subscriber can also store files, including
emails, address books, contact or buddy lists, pictures, and other files, on serv-
ers maintained and/or owned by [EMAIL PROVIDER]. [NOTE: Consider
consulting the provider’s law enforcement guide or contacting the provider to
identify other types of stored records or files that may be relevant to the case
and available from the provider. If there are such records, specifically describe
them in the affidavit and list them in Section I of Attachment B.]
9. Subscribers to [EMAIL PROVIDER] might not store on their home
computers copies of the emails stored in their [EMAIL PROVIDER] account.
Tis is particularly true when they access their [EMAIL PROVIDER] account
through the web, or if they do not wish to maintain particular emails or files
in their residence.
10. In general, email providers like [EMAIL PROVIDER] ask each
of their subscribers to provide certain personal identifying information when
registering for an email account. Tis information can include the subscriber’s
full name, physical address, telephone numbers and other identifiers, alterna-
tive email addresses, and, for paying subscribers, means and source of payment
(including any credit or bank account number).
11. Email providers typically retain certain transactional information
about the creation and use of each account on their systems. Tis information
can include the date on which the account was created, the length of service,
records of log-in (i.e., session) times and durations, the types of service utilized,
Appendix I
257
the status of the account (including whether the account is inactive or closed),
the methods used to connect to the account (such as logging into the account
via [EMAIL PROVIDER]’s website), and other log files that reflect usage of
the account. In addition, email providers often have records of the Internet
Protocol address (“IP address”) used to register the account and the IP ad-
dresses associated with particular logins to the account. Because every device
that connects to the Internet must use an IP address, IP address information
can help to identify which computers or other devices were used to access the
email account.
12. In some cases, email account users will communicate directly with
an email service provider about issues relating to the account, such as techni-
cal problems, billing inquiries, or complaints from other users. Email provid-
ers typically retain records about such communications, including records of
contacts between the user and the provider’s support services, as well records of
any actions taken by the provider or user as a result of the communications.
INFORMATION TO BE SEARCHED
AND THINGS TO BE SEIZED
13. I anticipate executing this warrant under the Stored Communica-
tions Act, in particular 18 U.S.C. §§ 2703(a), 2703(b)(1)(A) and 2703(c)(1)(A),
by using the warrant to require [EMAIL PROVIDER] to disclose to the gov-
ernment copies of the records and other information (including the content of
communications) particularly described in Section I of Attachment B. Upon
receipt of the information described in Section I of Attachment B, government-
authorized persons will review that information to locate the items described in
Section II of Attachment B.
CONCLUSION
14. Based on my training and experience, and the facts as set forth in
this affidavit, there is probable cause to believe that on the computer systems
in the control of [EMAIL PROVIDER] there exists evidence of a crime [and
contraband or fruits of a crime]. Accordingly, a search warrant is requested.
15. Tis Court has jurisdiction to issue the requested warrant because
it is “a court with jurisdiction over the offense under investigation.” 18 U.S.C.
§ 2703(a).
16. Pursuant to 18 U.S.C. § 2703(g), the presence of a law enforcement
officer is not required for the service or execution of this warrant.
258
Searching and Seizing Computers
REQUEST FOR NONDISCLOSURE AND SEALING
17. [IF APPROPRIATE: Te United States requests that pursuant to
the preclusion of notice provisions of 18 U.S.C. § 2705(b), [EMAIL PROVID-
ER] be ordered not to notify any person (including the subscriber or customer
to which the materials relate) of the existence of this warrant for such period
as the Court deems appropriate. Te United States submits that such an order
is justified because notification of the existence of this Order would seriously
jeopardize the ongoing investigation. Such a disclosure would give the sub-
scriber an opportunity to destroy evidence, change patterns of behavior, notify
confederates, or flee or continue his flight from prosecution. [Note: if using
this paragraph, include a nondisclosure order with warrant.]]
18. [IF APPROPRIATE: It is respectfully requested that this Court
issue an order sealing, until further order of the Court, all papers submitted
in support of this application, including the application and search warrant.
I believe that sealing this document is necessary because the items and infor-
mation to be seized are relevant to an ongoing investigation into the criminal
organizations as not all of the targets of this investigation will be searched at
this time. Based upon my training and experience, I have learned that online
criminals actively search for criminal affidavits and search warrants via the
internet, and disseminate them to other online criminals as they deem ap-
propriate, e.g., by posting them publicly online through the carding forums.
Premature disclosure of the contents of this affidavit and related documents
may have a significant and negative impact on the continuing investigation
and may severely jeopardize its effectiveness.]
Respectfully submitted,
[AGENT NAME]
Special Agent
[AGENCY]
Subscribed and sworn to before me on [date]:
_________________________________________
UNITED STATES MAGISTRATE JUDGE
ATTACHMENT A
Appendix I
259
Place to Be Searched
Tis warrant applies to information associated with [EMAIL AC-
COUNT] that is stored at premises owned, maintained, controlled, or oper-
ated by [EMAIL PROVIDER ], a company headquartered at [ADDRESS].
260
Searching and Seizing Computers

 

 

 

 

 

 

 

Content      ..     33      34      35      36     ..