Showing posts with label Law Enforcement. Show all posts
Showing posts with label Law Enforcement. Show all posts

Tuesday, November 28, 2017

Discussion: SCOTUS, Carpenter & Call Detail Records

November 28, 2017

Discussion: SCOTUS, Carpenter & Call Detail Records

On November 29, 2017, the Supreme Court of the United States (SCOTUS) will hear arguments in the case of Carpenter v. US.  At the heart of the arguments is whether or not the government (i.e., law enforcement) need a search warrant to obtain records from cellular providers for suspects in criminal incidents to help determine the location of those criminal suspects at or around the time of an incident.  Previously, as detailed in the USA Today article here, SCOTUS and lower courts have upheld that a search warrant is not required because the records are not subject to Fourth Amendment privacy restrictions due to the fact that the data (i.e., the records) are transmitted to a third party, being the cellular provider.  This is what is known as the “Third Party Doctrine”.  It has been cited in previous cases where a third party, such as a utility company, holds records that may be relevant in a criminal investigation and the burden of documentation on the government has heretofore been a subpoena for records, not a search warrant.  Because a search warrant requires probable cause to be stated, the standard would be higher to obtain the records.

Think of it this way:  Subpoena = “I want this”
                                     Search Warrant = “I want this, and here is why”


Call Detail Records… Sort of

Setting the Records Straight

I’ve read a lot online about this case.  A recent posting on PoliceOne.com erroneously leads the reader to believe that this case is about data contained on the cell phone, much like the often-argued Apple vs. FBI cases that keep popping up in the wake of active shooter/terrorist incidents (Read this blog’s take on that here:  https://prodigital4n6.com/clash-of-the-titans-apple-vs-the-u-s-government/ ).  Let me be clear: This case is not about cell phone data, forcing people to hand over their passcodes or allowing the government to pry into your device!  This case is about cellular location data subscribers virtually never see.  It is about records of cell site location data stored with your cellular provider, along with sending and receiving phone numbers for calls and texts, duration of calls and potentially locations of cell sites used for data transmissions when you check Facebook or your email.  You never see most of this data and if you call your cellular provider, they won’t give it to you without a subpoena. 

To Get A Warrant Or Not?  That is the Question!

Some brief background is in order before opining on this subject…
I’m a former law enforcement investigator with 15 years total experience.  I worked as the sole investigative member for my agency on the Internet Crimes Against Children Task Force for several years and have investigated hundreds of electronically-facilitated crimes, which meant that I had to author dozens of search warrants and subpoenas.  In Virginia, there is a law that allows police to obtain subscriber information only for users of internet service providers in child exploitation cases.  These “administrative subpoenas” need to be signed by a prosecutor and can simply be faxed to the provider to obtain name, address, phone number, email address and any other registrant information for the user of a screen name, email address, IP address, etc.  It is to be used in child exploitation cases only and no additional records are available through this process.

Each and every prosecuting attorney I’ve ever been trained by or worked with (and I’ve worked with some of the best at electronic crime prosecution) has a rule:  When in doubt, get a search warrant.  In fact, for cellular call detail records (CDRs), there is often a need to bypass a subpoena and get a search warrant, especially when requesting more than simple records – things like text message content.  You see, the law distinguishes between things like simple records and unique content of text messages, so the burden of the request is naturally higher when the police ask for content of email, text messages, etc. vs. simple records of who logged onto the service, when and from where.  It’s an important distinction and one that SCOTUS will no doubt delve into in great detail during arguments in this case.


 These things are everywhere!

Since leaving law enforcement and for nearly the past 4 years, I’ve been working mainly civil cases in the digital forensic field in a litigation support arena.  I’ve also been working cases involving analysis and mapping of cellular call detail records, so I’ve been involved in assisting attorneys on verbiage for the requests of these records, obtaining the records, analyzing the records and using them to prove or disprove location, link analysis and other items of interest in litigation.  A few of these cases have been retained by criminal defendants, so I have the benefit of experience at the prosecution end and the defense end to add credence to the next bit of information…

It’s very simple:  In most cases, getting a search warrant helps the prosecution and helps bolster the credibility of the evidence.  In most cases where a search warrant isn’t obtained and that fact is argued by the defense, the arguments help to bolster the defense and sometimes leads the evidence, such as cellular call detail records, to be thrown out. 

That being the case, my question to government investigators everywhere is, why not just get a search warrant anyway?

Yes, there are exceptions to every “search warrant rule”, exigency being the most obvious.  But absent exigency, a search warrant should probably be sought. 

Investigative Lead vs. Evidence

Part of what’s the heart of this argument is whether or not CDRs constitute an investigative lead or evidence.  When police request a “tower dump” of all devices connected to a particular cell site in a given time frame around a crime to help generate a potential suspect list or prove/disprove a suspect was in the area at the time of the crime, that serves as an investigative lead, but it can also quickly turn into evidence.  I would submit that investigative leads alone do not require a search warrant.  By their very nature, they are lacking in specific evidence in support of them, so a search warrant likely isn’t feasible.  However, I would further submit that a “tower dump” and the data derived therefrom also doesn’t fall under the category of a specific subscriber’s (i.e., target’s) call detail records.  They are records maintained by the cellular provider, but not specific to any one subscriber.

Only after a suspect list has been developed and substantial information gathered to develop actionable intelligence can we start to cross the bridge into evidence.  It also cannot be overlooked that sometimes, cellular location evidence serves to exonerate a suspect, by proving he (or his device) was not in the area at the time of the incident.  Either way, the importance of evidentiary data in, contrast to investigative leads, dictates that obtaining a search warrant is likely the prudent move.

Wrapping it Up


Back when the Third Party Doctrine was originally held, wireless cell phones were just an idea.  In 2017, we use them to stay connected in our everyday lives.  They help us keep in contact with friends and loved-ones, facilitate banking transactions, arrange transportation and much more.  The devices themselves store a very large amount of data, but they cannot do it without internet connectivity, which is what the cellular providers do for us.  The weight of cellular location evidence in both criminal and civil cases has grown exponentially in the modern era and will only keep growing as time goes on and cellular networks transition from 4G to 5G technology.

My prediction: SCOTUS will hold that the government needs a search warrant to obtain cellular records of a specific subscriber or target of an investigation.  However, they need to understand and explicitly distinguish between records for a specific subscriber needing a search warrant vs. tools police use to generate investigative leads, for which the burden of the request should be much lower.  Such is the case when requesting tower dumps.  Only by making that distinction clear will they serve to help answer additional questions in subsequent cases and put the matter entirely to rest… until next time!

Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others). He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Twitter: @ProDigital4n6

Monday, October 24, 2016

Electronically Stored Information (ESI) in High-Profile Cases



October 24, 2016

Electronically Stored Information (ESI) in High-Profile Cases

If it seems like the frequency of high-profile and attention-grabbing cases involving Electronically Stored Information (ESI) and digital evidence in the media are on the increase, you’re 100% correct!  ESI is ubiquitous – on our computers, on our phones, on our tablets and even in our watches and cars.  ESI can range from standard email to text messages to any other type of messaging service and from pictures to audio files to video and even the GPS data on your car’s navigation system.  It is, quite literally, everywhere!  So when an incident involving email or text messages arises, we naturally gravitate to the salacious nature of the ESI and the information stored on digital devices.  After all, we all use them!  In this article, we’ll explore some of the higher profile cases involving ESI and digital evidence and what considerations examiners should take in cases like these.  First up, a "no-brainer"…

The FBI Investigation of Secretary Hillary Clinton

Unless you’ve been living under a rock, you’ve heard in painful repetition about the alleged malfeasance of former Secretary of State Hillary Clinton and her once-private email server.  Indeed, I wrote about this case in abstract terms when discussing Ethical Sensitive Data Handling. But when we boil down the politics of the case, it involves ESI and digital evidence in their purest form.  Digital evidence examiners and investigators were required to sift through gigabytes (if not more) of data to determine what, if any, illegal acts took place.  And because it is generally humanly impossible to read each and every email amongst the thousands presented individually, the normal methodology would be to use e-discovery methods and key words to search for emails to and from individuals of interest and the content of emails which may contain certain key words.



Regardless of all of the expertise at the digital evidence section of the FBI and other investigating agencies, a reported 30,000 emails could not be recovered.  This, perhaps more than any other factor involved in this case, has garnered the most high-profile attention.  Think about the irony of that for a minute – the data we don’t know about and can’t recover has garnered the most attention.  Undoubtedly, the value of appropriate, effective recovery methods for ESI cannot be ignored.

Former Congressman & Mayoral Candidate, Anthony Weiner

Are selfies considered ESI?  You bet!  Unfortunately for the legal profession in general, ESI generally gets pigeon-holed into two categories – email and text messages.  But Electronically Stored Information (ESI) can come in various means as this example and the following will show.  When former New York Congressman Anthony Weiner was exposed (pun intended) in 2011 sending nude pictures of his genitals to women he met online, it opened up a can of worms about ESI that perhaps hasn’t been fully explored.  While those pictures may not have been used as evidence in any court case yet, with the subsequent revelations of similar behavior (2013 & 2016), it’s almost certain they will be used in some sort of domestic case involving divorce and/or custody.



As I constantly tell investigators in both the private and public arenas, affairs are conducted via mobile devices, plain and simple.  Toward the end of discovering the evidence of those affairs, examiners should consider all areas where the evidence may be stored.  In this simple example, it can be stored on the primary (sending) device, the secondary (receiving) device and stored on the servers of the provider used to send the photos, such as iMessage (Apple), Skype, Twitter and so on.  The data is somewhere, it’s just a matter of articulating where it may be found and why you need access to it.

Law Enforcement Use of Body-Mounted Cameras

As touched-upon in the article linked here, the advent of police use of body-mounted cameras to help create an unedited view of encounters with the public has created a swell of a particular type of ESI and digital evidence, digital video.  Along with the ability to record virtually every encounter an officer has with the public comes the responsibility for safe, accurate storage and public access to the ESI, where appropriate.  These videos have already been used in a number of civil and criminal proceedings and their ubiquitous nature will only continue.



Fortunately, along with the explosion of this type of evidence, the market has adjusted and there are already at least one or two reputable digital evidence storage services for this ESI.  However, the volume of storage space needed to store millions of hours of digital video cannot be overlooked.  This evidence must be handled very carefully to ensure the purest form of the evidence is provided in legal proceedings and to belay any claim that the custodial agency manipulated or edited the video, beyond protection of innocent victims. 

Wrapping it up

ESI is everywhere… In case you missed it the first time.  This article merely points out a few cases and instances where ESI either was used or could be used in future proceedings.  The goal here is to spawn those in the legal profession to start broadening their view of where ESI can originate and what is available in any case they may work.  However, once certain types of ESI are identified, only trained professionals should be charged with the acquisition and secure storage of this digital evidence.  Only then is the integrity of the evidence and the digital forensic process truly adhered to. 


Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Globally


We Find the Truth for a Living!
Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others). He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.
Twitter: @ProDigital4n6

Saturday, January 23, 2016

Customer Service in Digital Forensics



January 23, 2016

Customer Service in Digital Forensics

My first jobs as a teenager were in customer service.  The brief first foray into the world of customer service was at an amusement park, which ironically, was anything but amusing.  After 3 months there, I transitioned to a retail environment where I worked for several years and into college.  You might be surprised to learn that the transition from retail customer service to public service in law enforcement was not all that much of a leap.  The biggest overall difference is the personal danger aspect.



After leaving law enforcement to start my own digital forensic consulting company, I find that many of the lessons, skills and techniques I learned working in a retail environment serve me quite well in dealing with attorneys, clients and the general public.  This is an intangible that I propose often gets lost among both governmental and private sector digital forensic practitioners.  We all have customers -- from the crimes against person detective to the special agent accountant to the corporation who feels they’ve been the victim of intellectual property theft.  The natural tendency is for us to treat our customers like they need us.  They need our skills, our knowledge and our expertise to help analyze, interpret and explain what may have been going on in their cases.  But the truth is, we need them at least as much!


Customer Service in the Public Sector

For my friends & colleagues in the government sector, this can sometimes be a far leap.  You see, the reality is that many in public service don’t really have a sense of service at all.  Yes, that comment will undoubtedly bristle some of my public sector friends, but deep down, they all know it’s true.  There are folks working for the government that are there to pick up a steady paycheck, get decent benefits, not really caring to be pushed or challenged and doing (almost) as little as possible.  This article is not for them.

My purpose in this article is to refresh the sense of service of those in the government who enjoy their job and enjoy the rewards that come with doing a good job, even if it’s not always (or ever) recognized.  The homicide detective who brings you a cell phone or computer of a suspect is your first-line customer.  Without him, your job doesn’t exist and trust me, if no one is bringing you work, your superiors will eventually recognize that and start to re-evaluate your job.  Sometimes, even the most dedicated public servant sighs and gnashes his teeth when the detective (who sometimes fits the category in the previous paragraph) brings you evidence and wants you to solve his case for him.  But think about why you got interested in this field in the first place.  Think about what drives you and challenges you.  No two cases are the same.  Maybe this case will be the one in which you’ll be able to write a case-study or learn a new technique.  Maybe you’ll discover evidence that will lead to the rescue of a child or the arrest of a sexual assault suspect.  And while it’s true that the investigators are the first-line customers of the public-sector digital forensic examiner, the real customer is the innocent public and victims of crime.  They’re the ones you are there to help.  Never forget that.

Customer Service in the Private Sector

Being in private practice, you’d think having good customer service would be a “no-brainer”.  Well, in the past 18+ months since we launched Pro Digital full-time, I’ve been schooled in the fact that not every private practitioner really practices good customer service (or even knows what it is).  I’ve been pleasantly shocked to receive no less than a half-dozen referrals because of other practitioner’s lack of responsiveness and service.  I’m happy to serve their clients.  It gives Pro Digital a better reputation, expands our client-base and assures our place in the digital forensic market. 

Our customers (clients) range from spouses embroiled in divorce matters to plaintiffs or defendants in civil actions.  They all require different levels of communication, attention, education and technical expertise to help them through their cases.  Going a bit further, we help out indigent clients and accept court-appointed cases at reduced rates because our history of public service was not abandoned when we launched a private practice.  We know our clients need us to perform services they may have neither the skills nor the equipment to perform, but just because that fact is present and undeniable doesn’t mean we take our clients for granted.

Perhaps the best notion on which to hang the proverbial hat of customer service upon in private practice of digital forensics is trust.  Our clients trust us with their data, which is oftentimes very sensitive.  They trust us to be able to help them in their cases.  And they trust that we won’t over-bill or exploit their naiveté about digital forensics and investigation.  That measure of trust is one we do not take lightly, nor do we ever intend to forget.

One More Thought

I’d like to close by touching briefly on the public-private sector “rivalry”, or whatever term is appropriate to define the alleged philosophical difference in approaches between public and private sector practitioners.  Both as a digital forensic consultant and as a trainer, I’ve run into a segment of workers and “leaders” in public service with the overall mindset that what they do is of a higher calling and, because they don’t get paid as much as private sector practitioners, they are sacrificing some of themselves for the public good.  I’ve even experienced this as a contract trainer who teaches to law enforcement. 

To be honest, it makes no sense to me.  It may make some sense if I had never worked in law enforcement, but being that I also dedicated 15 years of my career to public service, I really don’t accept the notion that my counterparts in public service are sacrificing themselves for the public good.  The bottom line is, we all get paid to do a job.  (And please trust me when I say that many of you get paid much more than me!)  Government workers are paid by tax-payers to do a job, just like private practitioners are paid by clients to do a similar job.  We all have “customers” and we’re all answerable to them.  We’re all part of the system and the system needs us all to try to maintain fair and impartiality in investigations and court proceedings. 

We all have a role to fill.  Let’s make a common pledge to work together to serve everyone to the best of our ability by putting ego aside and working for the benefit of the digital forensic field, never forgetting the value of the customers we serve.  We’ll all gain from that mindset!

Author:
Patrick J. Siewert, SCERS, BCERT, LCE
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Globally

We Find the Truth for a Living!

About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation cases in Virginia court history.  A graduate of both SCERS, BCERT, the Reid School of Interview & Interrogation and various online investigation schools (among others), Siewert continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations.
Twitter: @ProDigital4n6