Searching over 5,500,000 cases.


searching
Buy This Entire Record For $7.95

Download the entire decision to receive the complete text, official citation,
docket number, dissents and concurrences, and footnotes for this case.

Learn more about what you receive with purchase of this case.

United States v. Hoeffener

United States District Court, E.D. Missouri, Eastern Division

August 25, 2017

UNITED STATES OF AMERICA, Plaintiff,
v.
ROLAND HOEFFENER, Defendant.

          MEMORANDUM AND ORDER

          PATRICIA L. COHEN, UNITED STATES MAGISTRATE JUDGE.

         This matter is before the Court on a motion to compel discovery filed by Defendant Roland Hoeffener [ECF No. 27]. The Government charged Defendant with violating 18 U.S.C. § 2252A(a) by: (1) receiving over the internet videos and images of child pornography and (2) possessing two storage devices containing images and videos of child pornography. Defendant seeks to compel the Government to disclose the source code, software and manuals related to the software program investigators used to identify Defendant's computer.[1] The Government opposes Defendant's motion [ECF No. 36] on the grounds: (1) Defendant has not sufficiently demonstrated that the requested information is material to Defendant's defense and (2) the requested information is protected from disclosure as a sensitive law enforcement investigation technique. The parties attached exhibits to their motion and response. The Court conducted an evidentiary hearing, and the parties filed post-hearing memoranda [ECF Nos. 53 and 55]. Defendant also attached several exhibits to his post-hearing brief. Having considered the parties' written materials and arguments, as well as the evidence adduced at the hearing, the Court denies Defendant's motion to compel discovery.

         I. Background

         A. The investigation

         On December 15, 2012, Detective Bobby Baine of the St. Louis Metropolitan Police Department engaged in “an authorized Internet undercover operation.”[2] Detective Baine used Torrential Downpour, a computer software program described (although not identified by name) in an April 29, 2013 affidavit that Detective Dustin Partney of the St. Louis County Police Department submitted in support of a search warrant. Detective Partney described Torrential Downpour as a “software program configured to search the BitTorrent network for [Internet Protocol (“IP”)] addresses . . . offering to share or possessing files known to law enforcement that contain images/videos of child pornography.”[3] During his on-line search, Detective Baine discovered an IP address later found to be associated with a Missouri computer.[4] According to Detective Partney's averments, Detective Baine “directly connected” with and downloaded several files from the computer.[5]

         In his affidavit, Detective Partney identified two files Detective Baine downloaded during his December 2012 on-line investigation.[6] The two identified files used “spread.em.chan” at the beginning of each file name and contained images depicting minor females exposing their genitalia. One of the depicted females was characterized as “prepubescent.”[7] Detective Partney viewed the files and “found them to contain” the described images.[8] Based on his training and experience, as well as Detective Baine's information, Detective Partney concluded that the computer “possess[ed] and distributed child pornography.”[9]

         Through information obtained from both the internet service provider for the IP address discovered by Detective Baine in December 2012 and a utility company, Detective Partney identified the computer as located at Defendant's residence in St. Louis County, Missouri.[10]Based on his training and experience, Detective Partney averred that “some people who collect child pornography tend to keep the images they obtain for extended periods of time and do not delete the images” or may “transfer the[] images to . . . digital media storage devices.”[11]

         Upon consideration of Detective Partney's affidavit and an application for a search warrant, a state court judge issued a warrant directing law enforcement officials to search Defendant's home for files and graphic images depicting pornography involving a person under the age of eighteen, as well as electronic data processing and storage devices, computers and computer systems, and other related items.[12] In the return and inventory for the search of Defendant's home, Detective Partney reported the seizure of multiple computers, hard drives, thumb-drives, Sim cards, CDs, digital cameras, and “tablet PC's” during execution of the search warrant at Defendant's home on April 30, 2013.[13] As revealed by the two-page portion of the report available of record and statements of counsel, Detective Steve Grimm conducted a forensic examination of the seized items and filed a forensic report.[14]

         B. The charges

         In August 2016, the Government charged Defendant with three offenses. In Count I, the Government charged Defendant with violating 18 U.S.C. § 2252A(a)(2) by “knowingly recei[ving]” over the internet videos and images of child pornography between December 1, 2012 and April 30, 2013.[15] In Counts II and III, the Government charged Defendant with violating 18 U.S.C. § 2252A(a)(5)(B) by “knowingly possess[ing]” through April 30, 2013, two storage devices containing images and videos of child pornography (Counts II and III).[16] Each count includes a list identifying four or more visual depictions of a minor allegedly engaging in sexually explicit conduct.[17]

         C. Defendant's motion to compel discovery

         After Defendant requested and the Government refused to produce the manuals and software for the program used by Detective Baine in his on-line investigation, [18] Defendant filed his motion to compel discovery seeking disclosure of “all discovery requested relating to the computer program . . . utilized by investigators in this matter[, ] . . . includ[ing] user manuals, operation manuals, instruction manuals, documentation help or other technical manuals in possession of the investigators, and a copy of the program so that Defendant may conduct a forensic exam.”[19] More specifically, Defendant requests a copy of the version of the software that Detective Baine used to “perform his search of Defendant's computer.”[20]

         Defendant argues the requested information is material to his defense and discoverable under Federal Rule of Criminal Procedure 16(a)(1)(E)(i), as well as the United States Supreme Court decisions in Brady v. Maryland, 373 U.S. 83 (1963) and Giglio v. United States, 405 U.S. 150 (1972) because the use of Torrential Downpour forms at least part of the basis of the receipt-of-child-pornography charge in Count I.[21] Without the technical data regarding Torrential Downpour, Defendant asserts his attorney cannot adequately analyze whether the software functioned correctly and whether the preliminary search and subsequent downloads of “potential evidence” violated the Fourth Amendment, comported with information in the search warrant, or constituted a form of computer hacking.[22] Furthermore Defendant contends the Government's use of Torrential Downpour to access his computer is “directly at issue” because the Government “will presumably” present evidence in its case-in-chief regarding the investigation.[23] Finally, Defendant urges he needs the requested information to prepare for Detective Baine's cross-examination.[24] In support of his motion, Defendant cited United States v. Budziak, 697 F.3d 1105 (9th Cir. 2012) and provided a declaration of his expert, Michele Bush.

         1. Declaration of Michele Bush[25]

         Michele Bush, Defendant's computer forensics expert, stated she reviewed Detective Partney's affidavit in support of the search warrant, Detective Grimm's forensic report, the log “detailing the network activity between” Torrential Downpour and the IP address discovered during Detective Baine's on-line investigation, and the indictment.[26] Ms. Bush declared that the “log establishes that a connection was made between” Torrential Downpour software and Defendant's computer, but she needed to “validate the merits of the search warrant by identifying the information reported during the undercover investigation on the evidence seized from the suspect.”[27] Ms. Bush stated she “had not had the opportunity to examine the digital media seized from [Defendant]'s residence” and relied on the forensic report.[28]

         Ms. Bush described the BitTorrent network as allowing “users to download . . . parts of files from many different users which are then rebuilt into whole files.”[29] She defined a “torrent” as “a text file proprietary to the BitTorrent network that contains instructions for torrent software, such as uTorrent . . ., on how to download a file or sets of files on the BitTorrent network.”[30] As she explained, “[t]orrent files do not contain user data, such as images or videos, ” but rather an index of information about the files associated with the torrent.[31] Ms. Bush described “info hash” as a “unique[] identifie[r of a] ‘torrent' on the BitTorrent network.”[32] She noted the log identified Defendant's BitTorrent “software application utilized to connect to the BitTorrent network as uTorrent version 2.2.1.”[33]

         Additionally, Ms. Bush explained her understanding of Torrential Downpour as “a modified version of publicly available file sharing software used exclusively by law enforcement”[34] that differed from publicly available file sharing software “in at least three ways: 1) it downloads files from a single IP address, 2), it does not share files, and 3) it creates a detailed log of network activity between the software and the suspect['s computer].”[35] Finally, Ms. Bush opined:

there is no credible evidence that the files identified as suspect child pornography in Detective Partney's Affidavit for Search Warrant and included as part of Count One of the Indictment were publicly available on [Defendant's] computer identified at the IP address[ discovered during Detective Baine's on-line investigation]. In addition, it remains my opinion that law enforcement's proprietary software [Torrential Downpour] needs to be tested by a qualified third-party to determine its functionality and accuracy.[36]

(Footnote added.)

         In her declaration, Ms. Bush set forth several concerns about Torrential Downpour and the content of the forensic report.[37] Ms. Bush noted “[i]t is unknown how the BitTorrent [network] protocol affects Torrential Downpour's ability to successfully operate on the network and identify suspects” because, unlike other BitTorrent software, Torrential Downpour does not “share data” with other computers on the network.[38] Ms. Bush explained that the BitTorrent network protocol “can eventually restrict [a non-sharing computer] from receiving data, per a ‘tit-for-tat' policy requiring users to contribute data in order to obtain data.”[39]

         In addition, Ms. Bush stated “[i]t is unknown if Torrential Downpour can identify a [computer] containing only the torrent of suspect[ed] child pornography without possessing its content.”[40] This concern arose out of her view that a torrent does not consist of user data, i.e., images or videos a user can see but rather information about the torrent, which is used by the BitTorrent software to download information for a user's use.[41]

         Ms. Bush also questioned certain aspects of the forensic report in her effort to “validate the merits of the search warrant by identifying the information reported during the undercover investigation on the evidence seized from the suspect.”[42] In particular, Ms. Bush declared the forensic report “revealed an examination was conducted on approximately eight hard drives installed with operating systems [and o]nly two hard drives were found to contain file sharing software including Lime Wire and eMule.”[43] The report, Ms. Bush noted, was “silent with regard to locating [on any of the seized items] the uTorrent software version 2.2.1, the torrent identified [during the on-line investigation], or the files of suspected child pornography specifically downloaded” during the on-line investigation, i.e., those starting with “spread.em.chan.”[44]

         Additionally, Ms. Bush observed, the forensic report disclosed “the majority of the suspect child pornography was located within system locations on the hard drive, compressed backup files, external devices, and possibly encrypted containers, so it is unknown if any of those locations would have been publicly available.”[45] Based on her

experience . . . conduct[ing] forensic exams on computers seized during undercover investigations and f[inding] evidence contrary to the information reported by law enforcement's software such as file sharing [being] turned off prior to the undercover investigation or that files only existed in private folders that were not available for sharing and should not have been identified by law enforcement's automated software,

         Ms. Bush questioned whether Torrential Downpour may have accessed non-public information on Defendant's computer.[46]

         Ms. Bush also stated that her “forensic training” taught her she “cannot rely on” a software program that has not been tested or validated by her or available for testing by “industry peers.”[47] Ms. Bush opined that Torrential Downpour “needs to be tested by a qualified third- party to determine its functionality and accuracy.”[48]

         D. Government's response to motion

         The Government opposes Defendant's motion on the grounds the requested information “is law enforcement sensitive and not material to [Defendant's] defense.”[49] More specifically, the Government contends the requested information is protected by a law enforcement privilege that prohibits disclosure of a “sensitive law enforcement technique.”[50] With respect to materiality, the Government urges Defendant has not demonstrated a sufficient basis to support disclosure of the user manuals, source code or software for the program used by the investigator.[51] In support of its position, the Government cited, in relevant part, United States v. Pirosko, 787 F.3d 358 (6th Cir. 2015), and provided an affidavit of its computer forensics expert, Deteective Robert Erdely.

         1. Affidavit of Detective Robert Erdely[52]

         Detective Robert Erdely averred that he helped create and conducts training of law enforcement personnel for the Torrential Downpour software program used by “law enforcement organizations . . . to identify potential possessors and distributors of child pornography over the BitTorrent peer-to-peer (P2P) sharing network.”[53] Detective Erdely described Torrential Downpour as different from other available BitTorrent software in that law enforcement investigators do not need to look to outside websites to obtain .torrent files and infohashes because law enforcement maintains such information for use during investigations.[54]Additionally, Torrential Downpour downloads information from a “single source” or from a “solitary download candidate, ” rather than from “many sharing computers, ” which the BitTorrent network is designed to do because “it speeds up the download times.”[55] Torrential Downpour, unlike other BitTorrent software, “does not share any of the content downloaded during an investigation.”[56]

         Detective Erdely explained that a non-law enforcement user of the BitTorrent network must obtain a torrent file from an outside website and use it to “receive or distribute” information over the BitTorrent network.[57] To access information available through the network, a user loads the torrent (a file designated by “.torrent”)[58] into the computer's BitTorrent software on the user's computer and the BitTorrent software initiates contact with the BitTorrent network to locate “download candidates.”[59] A download candidate is a computer on the BitTorrent network “looking for or . . . actively sharing the same file(s) described by the .torrent file.”[60] The computer connecting with the BitTorrent network provides the network with certain information, including the “computer's IP address and the unique identifier of the .torrent” sought or available to share.[61] “Both the sharing computer and the downloading computer must have the same torrent file (identified through a unique identifier called an ‘infohash')” to download information available through the BitTorrent network.[62]

         Once a match is located, the BitTorrent software “can then connect to 1 or many download candidates and request to download the pieces of the files needed.”[63] The BitTorrent network shares files “by downloading ‘pieces, '” which, as Detective Erdely explained, “are not typically the whole file but instead a piece of one file or several files.”[64] The BitTorrent software finds the download of a piece “successful” by comparing its SHA-1 hash value to the value in the torrent file and concluding those values match or are the same.[65] “[B]y default, [the BitTorrent software, other than Torrential Downpour, ] shares downloaded data back to other BitTorrent [network] users from whatever location the data was saved to, which would include an external hard drive.”[66]

         Detective Erdely averred that uTorrent software does not have a “‘default download' folder” but, instead, a user may save downloaded torrent files to a folder the user configured or “another location, even external hard drives, encrypted drives or network attached storage devices.”[67] Additionally, based on his “hundreds of investigations, ” Detective Erdely stated “it is common for users downloading child pornography to copy and/or move files from location to location, often deleting the file from the original location.”[68] In response to Ms. Bush's concern that the forensic report failed to mention that uTorrent was discovered on any of the items seized[69] from Defendant's home, Detective Erdely pointed to a reference in the portion of the forensic report available of record stating that uTorrent was installed on a seized item.[70]

         Torrential Downpour, Detective Erdely averred, “never obtains any unshared information from any computer running” BitTorrent software.[71] Rather, the law enforcement software “‘searches' for download candidates in [the] same that any public user of the” BitTorrent network searches and “only searches for information that a user has already made public by the very use of the uTorrent” software.[72] As Detective Erdely described, “[e]ach and every location where a user downloads file(s) . . . becomes ‘publicly shared.'”[73] Detective Erdely explained Id. that, due to the BitTorrent software's matching of SHA-1 hash values of downloaded pieces, “it would be ‘absolutely impossible' to randomly download files from a suspect's computer which are from ‘unshared folders'” (emphasis in original).[74]

         Detective Erdely further asserted that, “at the FBI's direction, ” an independent company performed validation testing of Torrential Downpour.[75] Specifically, the company tested Torrential Downpour's software and its source code to verify: (1) that it “contacts and downloads from the [IP] address and port specified, ” (2) that it “properly conducts . . . a ‘single source download' or . . . will only ever download from the one IP address specified, ” (3) that it is “incapable of sharing the downloaded content out to other [B]it[T]orrent [network] users, ” and (4) that it “accurately places the downloaded content into the evidence folder created for each and every investigation.”[76] The testing company concluded Torrential Downpour “passed all operational/validation tests.”[77] Detective Erdely also noted that the company found Torrential Downpour contained “a minor bug:” “if a file path became too long, the program would stop performing investigations.”[78] The discovered program bug, Detective Erdely averred, was fixed.[79]

         With regard to the importance of protecting Torrential Downpour's software and source code from discovery, Detective Erdely averred:

If the source code or certain other details about [Torrential Downpour] became public, child pornography distributors could find a way to avoid detection from [Torrential Downpour] and could render that tool of law enforcement ineffective. Additionally, the .torrent[s] and the hash values of the files being investigated could hinder future investigations once th[e] identifier to the illegal files became public. The infohash becoming public would also allow others to quickly find and download these child pornography files.[80]

(Footnote added.)

         E. The hearing

         At the evidentiary hearing, Defendant, through counsel, stated that the written motion and Ms. Bush's attached declaration demonstrated the requested information was material, and he would not present additional evidence during the hearing.[81] The Government introduced four exhibits[82] and the testimony of Detective Erdely.[83] During his testimony, Detective Erdely described in more detail: (1) the manner in which the BitTorrent network, uTorrent software, and Torrential Downpour software work; (2) the results of the validation testing of the Torrential Downpour software; and (3) the sensitive and confidential nature of the Torrential Downpour software, source code, and manuals.

         Detective Erdely testified that peer-to-peer file sharing networks, such as the BitTorrent network, “look to multiple computers [to download material] for redundancy (in case one of the sharing computers goes offline during a download) and speed (usually a computer has greater download than upload speed).”[84] When the pieces making up the files in a torrent are downloaded from the BitTorrent network, the BitTorrent software puts the pieces in the correct order to provide data for the user to view.[85]

         During installation of the uTorrent software on the user's computer, uTorrent notifies and requires consent of the user that downloaded files are made available to others.[86] Additionally, the user must allow the uTorrent software to be an exception to any firewall on the user's computer.[87] Once installed, the user must allow the uTorrent software to start each time the computer's operating system starts.[88] Each time the uTorrent software starts, it offers to computers seeking information through the BitTorrent network the files on the user's computer that are available for sharing, even if the user's computer is not actively downloading material from the BitTorrent network.[89] The user may use a “stop button” in the uTorrent program to stop sharing information with the BitTorrent network during a session, but may not set uTorrent software to prevent it from uploading information available for sharing.[90]

         The first version of Torrential Downpour was available in October 2012.[91] Detective Erdely explained that, through use of Torrential Downpour, an investigator sees the IP addresses of those computers seeking to obtain the torrent the investigator is investigating.[92] The investigator then chooses a computer's IP address and port for Torrential Downpour to connect to, then Torrential Downpour ascertains whether the computer has the investigated torrent, and, if so, directly connects to the computer.[93]

         Torrential Downpour provides a record or log of the date, time, and infohash of the investigation, the activity occurring during the investigation, the path and file name investigated, and the investigated computer's IP address, port identifier, and BitTorrent software[94] As Detective Erdely described, the log for Detective Baine's December 2012 on-line investigation reports that the investigated computer had all pieces of the torrent investigated, “did not need anything from the investigating computer, ” and provided the data during one connection.[95] After a download, law enforcement personnel assess whether the downloaded files meet the requirements for “child pornography” as defined by the charging jurisdiction.[96]

         Torrential Downpour participates in the BitTorrent network without sharing information it obtains through the network because the BitTorrent network protocol allows that participation.[97] More specifically, the BitTorrent network has a “choked” state preventing a computer from obtaining information available through the network when the computer is not sharing information, and an “optimistically unchok[ed]” state when the network unchokes the computer to give it data.[98] Detective Erdely noted that without this feature the network would not work because the first time a computer accesses the network it has no data to share.[99]

         The BitTorrent network also supports single source downloads.[100] A non-law enforcement user of the BitTorrent network may obtain such downloads by using an IP filter to filter activity into the user's computer so that only one IP address can communicate with the user's computer.[101] Torrential Downpour ensures single source downloads.[102]

         Torrential Downpour does not access encrypted material on a computer, but while uTorrent is “downloading to an encrypted volume” the data “is in a decrypted state” and shared.[103] When the user “unmounts [the downloaded data] so it is no longer accessible, ” the sharing stops because the data is now encrypted and BitTorrent software “cannot see” the encrypted data.[104] Encrypted data “cannot be accessed unless it is decrypted and connected to [or] in” a computer.[105] Additionally, if a user accesses data through a Virtual Private Network, Torrential Downpour “still sees” the computer's IP address, but at a different location, and law enforcement is able to locate the computer after further investigation of the log information.[106]

         With regard to the validation testing of Torrential Downpour, the testing company found “no errors in . . . single source downloads, how logs are written, how [the] infohash is documented, [or the] dates and times” recorded.[107] An error would exist, Detective Erdely stated, if Torrential Downpour allowed reaching out to a different IP address than the investigated IP address, and no such error was found during the validation testing.[108]

         According to Detective Erdely, Torrential Downpour cannot go into unshared portions of an investigated computer and cannot override settings on that computer.[109] Additionally, Detective Erdely has not found a report that Torrential Downpour has accessed unshared parts of a computer or overridden a computer's settings.[110]

         With respect to the need to protect the Torrential Downpour program from public disclosure, Detective Erdely explained that:

[t]he torrents we investigate would be exposed, the hashes of the files we investigate that we found that relate to child exploitation [would be available if the program is disclosed]. The version of software, we appear like as we're conducting these investigations [would be available if the program is disclosed]. People could change one little bit of the torrent, not really changing the downloads but now it's a different infohash [if they had the requested information about Torrential Downpour, then] we have to start from scratch. [Additionally, those having the requested information] could develop ways to avoid trading with our software based on characteristics of the software. And certainly we don't want to get the hash values [of the child pornography] that we investigate out to the general public.[111]

         (Footnote added.) Detective Erdely described as “extremely confidential and law enforcement sensitive” “[t]he source code and the program and the infohashes we investigate, the hashes of the files we investigate, [and] the version of software we appear as on the network.”[112] If that information is shared with the public, Detective Erdely testified, “you've just taken the ability of law enforcement away to conduct these investigations, leaving pedophiles and child predators out there to do what they want.”[113] In summary, Detective Erdely described the sensitive nature of the Torrential Downpour software as follows:

It's designed to download child pornography. It interacts with a law enforcement system that I'm the administrator of. The software will download infohashes relating to child exploitation. It would reveal the hash values of the files we're investigating. It would identify to the people that have it how we appear on the network. Any of these actions or any of these things I described could be altered to subvert our efforts and avoid detection, whether that be change the torrents, change the hashes of the files, [or] not allow communication with our software.[114]

(Footnote added.)

         Furthermore, as Detective Erdely explained, law enforcement personnel must be licensed to use Torrential Downpour, and the program's source code is “compiled” to prevent changes to it.[115] Law enforcement personnel using the program receive “the executable” file of the software for free “for the purpose of conducting investigations, not to redistribute” it.[116] Moreover, the licensed law enforcement personnel using Torrential Downpour do not have access to and are not given the program's source code.[117]

         With regard to the user manual for Torrential Downpour, Detective Erdely stated it contains information that requires protection.[118] In particular, Detective Erdely explained the manual contains information about the law enforcement server, its location, and how law enforcement accesses it.[119]

         F. Post-hearing briefs

         Defendant filed a post-hearing brief with several attachments. None of the attachments contained additional declarations or other evidentiary material from Defendant's expert or any other individual responding to the testimony and exhibits presented during the hearing. In his post-hearing brief, Defendant asked the Court either: (1) to order the Government to provide validation testing information related to Torrential Downpour or (2) to strike and deem inadmissible at trial Detective Erdely's affidavit and testimony regarding that testing.[120]Additionally, Defendant requested the Court consider his motion to compel as a motion for a subpoena under Federal Rule of Criminal Procedure 17(c), if the Court denies the motion to compel.[121]

         The Government filed a response to Defendant's post-hearing brief.[122] The Government opposed Defendant's request that the Court consider the motion to compel as a request for a subpoena under Rule 17 on two grounds. First, the Government argued the requirements supporting disclosure of information under Rule 17(c) are different than the requirements for disclosure of information under Rule 16(a)(1)(E)(i) and Defendant did not address the requirements of Rule 17(c).[123] Second, the Government contended that Rule 17(c) was not intended to serve as a discovery tool.[124]

         II. Standard

         District courts have broad discretion to resolve motions to compel discovery in criminal cases. United States v. Hintzman, 806 F.2d 840, 846 (8th Cir. 1986). A district court's decision regarding a motion to compel discovery is proper if, considering the circumstances, the decision is not “a gross abuse of discretion resulting in fundamental unfairness at trial.” Id. (internal quotation marks omitted) (quoting Voegeli v. Lewis, 568 F.2d 89, 96 (8th Cir. 1977)).

         III. Discussion

         Defendant argues the requested information is material to his defense and, therefore, discoverable under Federal Rule of Criminal Procedure 16(a)(1)(E)(i)[125] based on four grounds.[126] First, Defendant asserts the use of Torrential Downpour forms at least part of the basis for the receipt-of-child-pornography charge in Count I and Defendant needs the requested Torrential Downpour information to assess whether Count I is “accurate, legitimate and proper.”[127] Second, Defendant contends the use of Torrential Downpour to access Defendant's computer is “directly at issue, ” because the Government will “presumably present” in its case-in-chief evidence of the investigation.[128] Third, Defendant argues the requested information is needed to prepare for the cross-examination of Detective Baine.[129] Finally, Defendant urges the use of Torrential Downpour is the sole basis of the search warrant and, without the requested information, his attorney cannot adequately analyze whether the software was functioning correctly or whether the preliminary on-line search and subsequent downloads of “potential evidence” violated the Fourth Amendment, comported with information in the search warrant, or constituted a form of computer hacking.[130] In support of his position that the requested information is material, Defendant relies on his expert's declaration and the Ninth Circuit's decision in Budziak, supra.

         The Government opposes the motion on the ground Defendant has not demonstrated the requested information is material to a defense for purposes of Rule 16. In particular, the Government argues the defense expert provides only a general description of the information sought and conclusory allegations of materiality.[131] The Government relies on the Sixth Circuit's decision in Pirosko, supra, as support for its position that Defendant has not demonstrated Rule 16 materiality. Additionally, the Government contends the requested information constitutes a sensitive law enforcement investigative technique protected from disclosure by a law enforcement privilege.

         A. Materiality

         1. Standard

         Federal Rule of Criminal Procedure 16(a)(1)(E)(i) requires the Government to permit a defendant, upon the defendant's request, “to inspect and to copy or photograph . . . books, papers, documents, [and] data, [among other items] . . . or copies or portions of any of these items” that are in the Government's possession, custody, or control and are “material to preparing the defense.” A defendant may examine specified information in the Government's possession that is “material to the preparation of [the defendant's] defense against the Government's case-in-chief” or the defendant's defense on the merits. United States v. Armstrong, 517 U.S. 456, 463 (1996) (concluding that Rule 16(a)(1)(C), a predecessor to Rule 16(a)(1)(E), does not apply to a defendant's request to examine Government information for a selective prosecution claim, because that claim is not a defense on the merits).

         The Eighth Circuit defines “material” information for purposes of Rule 16 as information that is “helpful to the defense.” United States v. Vue, 13 F.3d 1206, 1208 (8th Cir. 1994) (discussing Rule 16(a)(1)(C), the predecessor to Rule 16(a)(1)(E)(i)).[132] However, importantly, a showing of materiality requires more than “a mere conclusory allegation” of the requested information's materiality. United States v. Krauth, 769 F.2d 473, 476 (8th Cir. 1985) (discussing predecessor Rule 16(a)(1)(C)).

         To demonstrate materiality, a defendant must show “more than that [the requested information] bears some logical relationship to the issues in the case.” United States v. Ross, 511 F.2d 757, 762 (5th Cir. 1975) (discussing predecessor Rule 16(b));[133] accord United States v. Jordan, 316 F.3d 1215, 1250 (11th Cir. 2003) (discussing predecessor Rule 16(a)(1)(C)). In particular, a defendant must show the pretrial disclosure of the requested information would “enable the defendant significantly to alter the quantum of proof in his favor.” Ross, 511 F.2d at 763; accord Jordan, 316 F.3d at 1250. More specifically, a defendant must show “case-specific facts which would demonstrate the materiality of the information sought.” United States v. Santiago, 46 F.3d 885, 895 (9th Cir. 1995) (discussing predecessor Rule 16(a)(1)(C)); accord Krauth (finding a discovery motion properly denied where the defendant failed to produce evidence that the requested information would be helpful to the defense).

         With regard to child pornography cases addressing requests for the disclosure of information related to law enforcement software programs under the materiality requirement of Rule 16, the success of a defendant's motion to compel depends on the specificity of the defendant's evidentiary support for the motion in demonstrating the need for the requested information to defend the charges. In Budziak, the United States Court of Appeals for the Ninth Circuit concluded that the defendant made a sufficient showing “that discovery of the EP2P software[, an enhanced version of LimeWire file-sharing software used by investigators, ] was material to preparing his defense.” Budziak, 697 F.3d at 1112-13. In particular, the defendant, who was charged in relevant part with distribution of child pornography due to two investigators' downloads of child pornography from the defendant's computer, sought disclosure of “the EP2P program and its technical specifications.” Id. at 1107, 1109, 1112. The defendant had, the Ninth Circuit found, “identified specific defenses to his distribution charge that discovery on the EP2P program could potentially help him develop.” Id. at 1112. In particular, the Ninth Circuit stated the defendant

presented evidence suggesting that [(1)] the FBI may have only downloaded fragments of child pornography files from [the defendant's] “incomplete” folder, making it “more likely” that he did not knowingly distribute any complete child pornography files [to the investigators] and [(2)] the [investigators] could have used the EP2P software to override his sharing settings.

Id. Importantly, the Ninth Circuit found it was “logical to conclude that the functions of the program were relevant to his defense” because “the distribution charge against [the defendant] was premised on the FBI's use of the EP2P program to download files from him.” Id. The Ninth Circuit held the district court abused its discretion in denying the defendant “discovery on the EP2P program.” Id. at 1113.

         In Pirosko, the United States Court of Appeals for the Sixth Circuit concluded the defendant's requested disclosure of “the law enforcement tools and records used . . . to search [the defendant]'s computer equipment” did not satisfy Rule 16's materiality requirement. Pirosko, 787 F.3d at 368. The Sixth Circuit found the “purpose of [the defendant]'s motion to compel [was] not to aid in the preparation of his defense, but to contradict the district court's finding of distribution [of child pornography] at sentencing.” Id. When addressing the Government's argument that a law enforcement privilege protected the requested information from disclosure, the Court distinguished Budziak on the ground the defendant in that case provided evidence of government error. Id. at 366. The defendant's evidentiary support for his motion to compel was a letter with one sentence summarily questioning the government's affidavit as not showing “which tools, which records, or the means by which those records were created” and “leaving otherwise answerable questions unanswered.” Id. The Sixth Circuit concluded the “lone allegation [in the letter was] simply not enough to overcome the numerous facts supporting the government's position that it legitimately obtained child pornography from [the defendant]'s shared folders.” Id.

         The United States Court of Appeals for the First Circuit also provides useful guidance in United States v. Chiaradio, 684 F.3d 265, 271-72, 276-78 (1st Cir. 2012). There the First Circuit affirmed the denial of a defendant's motion to compel production of the source code for law enforcement software used by investigators to identify the defendant's computer as sharing child pornography through the file-sharing software on the defendant's computer. The defendant argued he needed the source code to determine whether he “could credibly challenge the reliability of the technology and . . . block the [Government's] expert testimony . . . about the [law enforcement software] program and how it implicated the defendant.” Id. at 277. The First Circuit did not resolve the issue of the source code's materiality under Rule 16, because it found the defendant was not prejudiced due to other information the defendant had received relating to the on-line investigation. Id. at 277-78.

         2. Showing of materiality

         (a) Materiality based on Count I

         Defendant asserts the use of Torrential Downpour forms at least part of the basis of the receipt-of-child-pornography charge in Count I of the indictment and Defendant needs the requested information to assess whether Count I is “accurate, legitimate and proper.”[134] Defendant urges that “[w]ithout access to the technical data behind Torrential Downpour the defense would be relying on blind faith regarding the programming of the software, the methodology respecting its use, it[s] error rate, whether it is subject to peer review, and every other aspect.”[135] Defendant contends that the absence of downloaded images on the seized items, as mentioned in Ms. Bush's declaration, supports reasonable doubt with regard to the charge in Count I. The Government urges there are plausible explanations for the absence of downloaded files on the seized items. Specifically, the Government states Defendant could have moved the downloaded files into inaccessible encrypted areas or deleted the downloaded files.

         While the absence of downloaded images and videos on the seized items may arguably help to demonstrate reasonable doubt with regard to Count I of the original indictment, the absence of the downloaded images and videos on seized items does not assist with the development of reasonable doubt regarding Count I of the superseding indictment. Count I of the original indictment explicitly mentioned as material constituting child pornography two files that the log of Detective Baine's December 2012 on-line investigation reported as downloaded during that investigation. The downloaded files are identified in the log and in Count I of the original indictment as beginning with the phrase “spread.em.chan.” Count I of the superseding indictment also specifically identifies certain images and videos of child pornography, but none of the references begin with the phrase “spread.em.chan.” Therefore, nothing in the pending receipt-of-child-pornography charge reveals that the charge is based, to any extent, on materials downloaded from Defendant's computer while Detective Baine used Torrential Downpour in December 2012. Additionally, no other material in the available record supports a conclusion that any file downloaded by Detective Baine during his December 2012 on-line investigation forms any basis for the receipt-of-child-pornography charge in Count I of the superseding indictment.

         To the extent Defendant relies on Budziak as support for this ground, that decision is distinguishable. In Budziak, the defendant there was charged with distribution of child pornography based only on the investigators' download of alleged child pornography material during their on-line investigations. Here, Defendant is not charged with distribution of child pornography and, as noted above, the charges pending against Defendant are not based on downloaded material obtained during Detective Baine's December 2012 on-line investigation. Without more, Defendant has not shown how the software, source code, manuals, and validation testing information requested by Defendant would be helpful in raising reasonable doubt.

         (b) Materiality based on the Government's case-in-chief

         Defendant contends the use of Torrential Downpour to access Defendant's computer is “directly at issue” because the Government “will presumably” present evidence in its case-in-chief of the investigation of the charges.[136] The Government does not expressly respond to this argument.

         While it is reasonable to predict that the Government will present testimony regarding Detective Baine's use of Torrential Downpour during the December 2012 on-line investigation, Ms. Bush's declaration does not elucidate how the requested information would assist Defendant's response to the Government's case-in-chief. Without more, Defendant has not demonstrated the materiality of the requested information based on the Government's presentation of evidence regarding the on-line investigation during its case-in-chief.[137]

         (c) Materiality for cross-examination of Detective Baine

         Defendant asserts the requested information is needed to “adequately prepare for the cross-examination of Detective Baine.”[138] The ...


Buy This Entire Record For $7.95

Download the entire decision to receive the complete text, official citation,
docket number, dissents and concurrences, and footnotes for this case.

Learn more about what you receive with purchase of this case.