How File-Sharing Software Turns Possession Into a Distribution Charge.
In many cases, P2P software will upload files while the user is downloading. For example, the software may use “automatic seeding” to make files that have been downloaded available to other network users, or it may upload segments of the file as the user downloads them. This opens up the possibility of federal prosecutors treating the case as a child pornography distribution offense, even though the defendant’s intent was only to possess.
Child pornography distribution is a very different offense from possession, carrying significantly greater sentencing exposure under federal law. A child pornography distribution offense carries a mandatory minimum of five years of imprisonment, and a first-time child pornography possession offense carries up to 10 years of imprisonment.
Under the federal child pornography statutes, distribution offenses are prosecuted under 18 U.S.C. §§ 2252 and 2252A, and possession offenses are prosecuted under 18 U.S.C. § 2252A(a)(5). Distribution is also broadly defined, and it can include transmission by computer, file transfer, uploading, sending an image through email, or even sending an image through a messaging app like WhatsApp or Snapchat.
In California, child pornography possession is prosecuted under Penal Code § 311.11(a), and distribution offenses are prosecuted under Penal Code § 311.1(a).
Does Use of File-Sharing Software Automatically Make it a Distribution Case?
While it is possible for the use of file-sharing software to lead to a distribution charge, the use of file-sharing software is not enough to convict a defendant of a distribution charge. The government must still prove that a defendant had the legally required knowledge in order to meet the standard for a distribution offense.
How does BitTorrent turn downloads into alleged uploads?
How does BitTorrent work?
Traditional file downloading involves downloading a file from a central server. But with a P2P protocol like BitTorrent, BitTorrent clients (which are the users on the P2P network) share pieces of files among themselves. Trackers and distributed hash tables help peers locate one another, and “leechers” (which are users who have not yet completed their file download) can upload parts of files that they have acquired from other peers as they receive and request more pieces. Even if the user has not yet downloaded the entire file, their partial download can potentially be shared as small pieces with other users.
How does BitTorrent lead to child pornography distribution charges?
While this can be difficult to prosecute, federal law enforcement agencies like the FBI and DHS have developed efficient methods for building their cases, and they use hash values to make illegal material identification fast and accurate. A hash value is a cryptographic value that uniquely identifies a digital file. Law enforcement agencies have built hash value databases for millions of known child pornography files. When an IP address is associated with a specific file hash value, investigators can request a block of the suspected file to be sent to them, and if the hash value of the block they received matches the file they were expecting, then the transmission has been documented. Federal prosecutors will often refer to these transfers as “uploads,” because that is how they choose to conceptualize the file transfer process. In reality, these transfers are caused by the BitTorrent protocol’s automatic sharing of file pieces.
How do other P2P protocols turn possession into distribution?
Peer-to-peer protocols like Gnutella, eDonkey, and Soulseek use “searches” to make illegal files available, but these protocols also expose files downloaded through the P2P protocols themselves. With most default P2P settings, users that download any type of file will have their downloaded files located in “shared folders” that others can browse and search. As a result, downloading an illegal file on one of these networks is likely to make that same file available to other network users, and this can have the consequence of turning possession into a distribution charge.
What must prosecutors prove when file sharing happens automatically?
What knowledge must the government prove under 18 U.S.C. §§ 2252 and 2252A?
Under both 18 U.S.C. § 2252 and 18 U.S.C. § 2252A, the government must prove that the defendant knowingly engaged in the conduct charged. Specifically, under 18 U.S.C. § 2252(a)(2), the government must prove the defendant knowingly received or distributed the visual depiction. Under 18 U.S.C. § 2252A(a)(2) and (a)(5), the government must prove the defendant acted “knowingly” with respect to the CSAM in question.
How do prosecutions involving “sharing” or making CSAM “available” for download differ from traditional distribution cases?
While traditional distribution cases focus on the act of sending CSAM, sharing or making illegal content “available” for others can be treated as an attempt to distribute or as child pornography distribution. The federal child pornography statutes prohibit “distributing” child pornography, and different federal courts have varying views on whether making child pornography available (and thus potentially including “sharing” on a P2P network) constitutes the act of “distribution” under the statutes’ terms. Even in cases where federal prosecutors attempt to prove distribution, they may also allege a “distribution charge” without evidence of a completed transfer. Whether availability constitutes completed distribution depends on the statutory text and controlling precedent in each jurisdiction.
When has a transfer been completed?
When an investigator with the FBI or DHS downloads an illegal file or block of files, this is generally considered to be a completed transfer. The same logic applies if a user or someone else has used an illegal file or block of files.
Does the government have to prove a defendant knew that the transfer was completed?
No, the government only has to prove the defendant knew that the transfer of a file or block of files occurred. The government will generally rely on a variety of forms of circumstantial evidence to show the defendant’s knowledge of the transfer, including:
- The installation prompts the defendant agreed to upon installing the P2P software
- The warnings the client provides when downloading a file or block of files
- Evidence that the defendant has seeded files before
- Evidence that the defendant deliberately named the shared folder that became available to other users on the network
- The defendant’s general technical skill level, such as whether the defendant is comfortable using computers and what types of websites or software the defendant frequently uses online.
Are technical skills always evidence of sharing knowledge?
While technical skill can be circumstantial evidence of knowledge, technical skill is not, in and of itself, proof of sharing knowledge.
Does an IP address prove who shared the files?
How do police know who the suspect is?
In a typical case, law enforcement will record the IP address of anyone who advertises a target file on a BitTorrent swarm. Law enforcement will then subpoena the ISP associated with the IP address, and the ISP will then identify the subscriber to the account associated with that IP address.
Is the IP address the only piece of evidence?
For a lot of suspects, this is the only evidence law enforcement has. But in some cases, they can also use IP addresses to target specific devices or persons. For example, police can track an individual suspect if the suspect is using a dedicated network adapter that has a fixed IP address.
What if the IP address is dynamic?
In most cases, a suspect’s computer will be using a dynamic IP address, which changes periodically. If the suspect claims to have no involvement with a BitTorrent file, the exact timestamps of the download or upload can be very important. With a dynamic IP address, it is more difficult for investigators to reliably associate a specific individual with a specific IP address.
What if the suspect has shared Wi-Fi?
If the suspect has shared Wi-Fi, this can significantly weaken the government’s attribution case as well. Investigators must be able to prove the suspect’s computer is the computer that accessed or shared the illegal material. This involves proving the suspect’s computer was the only device on the suspect’s Wi-Fi network with an active internet connection at the time of the incident, but this may not be possible if multiple devices were connected. Even with access to the suspect’s router logs, proving that a specific device was connected to a specific IP address may be difficult, especially if the suspect has an active guest network.
How do ISP records work?
ISP records can only identify the account subscriber, not the specific device or person who used the internet connection. A public IP address is assigned to the subscriber’s internet connection, and network address translation puts all devices that connect to the internet through the router behind this public IP address.
How can malware lead to a child pornography distribution charge?
A device infected with malware may appear to advertise or share the target file even if the subscriber did not do so. These types of software-generated uploads can lead to an innocent person facing serious criminal charges based on deceptive or misleading data.
If you are facing this situation, Spodek Law Group handles federal criminal defense matters nationwide, from offices in New York and Los Angeles.
What evidence can challenge a claimed file transfer?
Why doesn’t deleting a file prove there is no file?
When you delete a file, your computer’s operating system does not immediately erase it. Instead, the computer marks the file as “available space” and overwrites it when necessary. This means a file can still be recovered after being deleted. Torrent clients can keep logs of completed and in-progress downloads as well. Many torrent clients can resume files that were downloaded prior to a known date as well.
What evidence are forensic analysts looking for when searching a suspected computer?
When searching a suspected computer, forensic analysts look for:
- Browser cache/temp files
- Thumbnails
- Windows registry files and other artifacts
- Torrent logs
- Evidence of use or installation of torrent clients
- Evidence of use or installation of other P2P clients
- Evidence of attempts to obfuscate or delete files, or conceal the computer’s activity online
Why can a computer’s sleep records be useful?
In a distribution case, the computer’s sleep records (if available) can be extremely useful. If a suspect claims to have been away from the computer at the time the transfer occurred, the suspect may be able to prove that the computer was asleep, off, or in use by another person.
If investigators captured a block of a file, it will be important to determine whether the block truly represents content that is prohibited under the child pornography statutes, whether the defendant had the requisite knowledge and control, and whether the captured block could have been retrieved from a peer other than the defendant.
A single, un-verified fragment will not constitute proof of a child pornography offense. However, a single verified fragment can potentially support an overall theory of distribution.
Do automatically generated thumbnails or cache artifacts establish knowing possession or distribution?
Not in and of themselves, these items can support an argument for knowing possession or distribution. However, these artifacts do not independently establish a defendant’s possession, knowledge, or intent.
Why is it important to carefully examine both the warrant affidavit and the law enforcement capture record?
A defense review should involve carefully comparing the information in a warrant affidavit with a law enforcement capture record of a suspected P2P client (i.e., the suspected client’s advertising behavior and/or network activity). This comparison may reveal inconsistencies that a experienced defense team can then use to defend the accused.
What if the files were downloaded accidentally?
Accidental downloading is not an affirmative defense. In fact, it can support a distribution charge. However, accidental downloading can undermine knowledge, and it may complicate the federal government’s prosecution of a child pornography possession charge, depending on the circumstances.
What if I deleted the files before the police intervened?
Deleting the files in an attempt to avoid criminal prosecution after learning of an investigation can be construed as tampering with evidence, which can result in additional criminal charges. However, if a user deletes files in response to recognizing the files’ content, this can be seen as evidence of both knowing possession and acknowledgment of the files’ illegal content. This may defeat the possibility of using the “accidental download” argument.
The destruction defense is available in both federal and state cases involving child pornography, but the circumstances under which it can be asserted can be very limited.
What is the “destruction defense” for a federal child pornography case?
Under Section 2252(c), the destruction defense is available to persons prosecuted for child pornography possession offenses under Section 2252(a)(4), but only if:
- the defendant possessed fewer than three matters containing prohibited visual depictions,
- the defendant destroyed the materials before law enforcement agents intervened,
- the defendant acted promptly and in good faith, without retaining the materials or allowing anyone other than a law enforcement agency to access them, and
- the defendant possessed fewer than three matters containing prohibited visual depictions.
If the charges are based on child pornography possession under Section 2252A(a)(5), the same logic applies. Under Section 2252A(d), the destruction defense allows individuals who possessed the illegal material to avoid prosecution by destroying all copies of the illegal material as soon as they realized its illegal nature and as long as they only possessed fewer than three prohibited images at the time that they were arrested. The same applies to those who possessed a single prohibited video file and destroyed a copy of the file within 30 days.
How can the destruction defense support a challenge to a distribution charge?
A key component of the destruction defense is to destroy all copies of the materials in question, and to not retain any copies, upload copies, allow other people to access copies, and share or distribute the copies in any way. With that said, even if a person did not fulfill the destruction defense requirements, they may still be able to fight off a distribution charge if they can prove that any alleged distribution occurred as a result of using the file-sharing software’s default settings.
Does the same destruction defense apply to a child pornography charge under California Penal Code 311.11(a)?
The destruction defense applies to child pornography possession cases under California Penal Code 311.11(a). However, the defense requires destroying the material within 14 days (not 30 days), and it is only available for those who possessed the material for an “impermissible, non-commercial purpose” and who did not “permit anyone else access to it,” or “retain, share, distribute, or multiply any other copying or image.”
Can Distribution Penalties Apply Without a Distribution Conviction?
Do the same legal standards apply to a child pornography offense’s statutory elements, prosecutorial charging theories, and sentencing enhancements?
The terminology used by federal prosecutors in an indictment or at trial is often loosely derived from the terms used in the applicable federal statute, but the statutory elements themselves present the legal standard that the government must prove in a criminal trial. Each statutory element presents a separatelegal standard with the same level of proof required in a criminal conviction. A prosecutorial charging theory cannot expand or replace these distinct legal standards; and, while a sentencing judge can apply a sentencing enhancement based on relevant conduct, the sentencing judge still has to find the relevant conduct beyond a reasonable doubt.
How do the Guidelines’ provisions for Sentencing Enhancements Differ from those for Charging Theories?
Unlike a prosecutorial charging theory, a sentencing judge can apply any applicable sentencing enhancement based on relevant conduct that it finds has occurred. Relevant conduct can include circumstances related to the offense that do not lead to a separate criminal charge, and the term for relevant conduct includes any activity related to the defendant’s alleged crime and a broad range of circumstances as well.
For example, USSG § 2G2.2(b)(3) provides for a sentencing enhancement if a defendant, or a person on behalf of whom the defendant intentionally acted “received or provided” materials with child sexual abuse image or videos. Under this specific Guideline, the provision only requires a finding of the defendant’s receipt or provision of illegal materials, not his or her distribution of these materials, to trigger the sentencing enhancement. With this in mind, you can face sentencing enhancements based on “distribution” allegations, without actually being convicted of the criminal offenses of receipt or distribution.
Does a Criminal Conviction for Possession Establish a Prior Criminal Offense for the Purposes of Sentencing Enhancements?
No. A criminal conviction for possession will not establish a prior criminal offense for the purpose of sentencing enhancements if the offense committed is receipt or distribution. Even if federal prosecutors use a distribution theory, a criminal conviction for possession alone does not automatically establish a separate offense. A defendant convicted of possession can still face up to 15 or 40 years of federal imprisonment if a qualifying prior conviction is on his or her criminal record.
Can a Defendant face Charges for Receipt if he or she Only Downloaded the Material?
In federal child pornography cases involving P2P downloads, receiving or receiving through electronic means can be prosecuted under 18 U.S.C. § 2252A(b) and 18 U.S.C. § 2252A(e) as separate criminal offenses. The charge of receipt or receiving requires proof of the defendant’s transfer of material (through either upload or download) with his or her knowledge and control over the file in question. In many cases involving P2P downloads, this will include a successful download from another peer. As a result, those who downloaded illegal materials (or suspected illegal materials) may face child pornography charges even without evidence that they distributed, shared, or uploaded any files on the internet.
Get Advice on Your Situation
If you want someone to look at the specifics of your case, Spodek Law Group handles federal criminal defense nationwide from New York and Los Angeles. The firm has been practicing since 1976 and its motto is simple: we owe loyalty to only you. Call 212-300-5196.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196