Thumbnails, Cache Files, and Whether They Prove Possession.
# Thumbnails, Cache Files, and Whether They Prove Possession Browsers can create cache files even when a user does not explicitly save data to the computer. As a result, simply showing that a cache file exists on a device is generally not enough to prove possession. To support a charge based on the evidence of a cache file, the prosecution typically needs to present additional evidence proving that the user was aware and accessed the material. The finding of a thumbnail is slightly different. A thumbnail is typically created when a file is viewed or when a user opens a folder containing images. Thus, the evidence of a thumbnail is more indicative that the user may have accessed the imagery. Nevertheless, even the finding of a thumbnail is generally not enough to sustain a federal charge unless the government can also prove that the user had knowledge, access, and control of the data and that the material was attributed to that specific user. The significance of the evidence of a cache file also depends on the specific type of offense that is charged. While the government may charge possessing illicit imagery in some cases, it may charge different offenses involving an intentional transfer of illicit imagery, or other related charges, depending on the circumstances. The evidentiary significance of the cache file differs depending on the government’s theory. This applies in particular to cases involving modern Windows operating systems. In Windows 10 and Windows 11, images of thumbnails are generally not stored in individual folder-level Thumbs.db files. Instead, they are stored in a centralized thumbcache database located in a hidden system directory. This affects attribution and the significance of the evidence. Attribution depends on the nature of the image, and the thumbnail itself proves nothing beyond the computer’s ability to generate a thumbnail. ## What Kind of Cache or Thumbnail Artifact Was Found? There are several types of caches, and each has its own characteristics. Examples include: - Web browser caches: A web browser caches temporary copies of content from websites in order to display that content more efficiently in the future. A cache can contain image files, web page data, and other information. - Windows thumbnail files: The Windows operating system creates thumbnail image files for use in folders. These files are called Thumbs.db files. They are created automatically and not at the user’s explicit command. Because this is automated, simply finding a Thumbs.db file does not necessarily prove that the user viewed or accessed the images. However, thumbnails can remain in Thumbs.db files even after the user has deleted the corresponding image files. This can have implications for charges involving possession. - App media caches: Mobile and computer apps may have their own separate media cache, which is stored in their own unique way. A media cache created by an app may function differently from a browser cache or an OS thumbnail store. - Other file or media formats: Cloud photo previews, video-streaming buffers, and other cached artifacts will each store and present data in their own unique way. For example, a cloud-photo preview may store a low-resolution version of a photo on a user’s device, without storing the full-resolution version of the photo. In some cases, streaming video services will cache brief segments of video temporarily for playback while storing the remainder of the video on their remote servers. The difference between possessing full-resolution images and possessing low-resolution previews can be significant. It can be important for the defense to determine exactly how the data was stored, accessed, and whether it was permanently or temporarily stored locally on the computer. ## Does the Law Treat Automatic Cache as Knowing Possession? The federal statute under 18 U.S.C. §2252 (which is the most often charged federal statute in child exploitation cases) requires proof of knowing possession of the illicit image material. Thus, a finding of a cache file showing that the material existed on the computer may not be sufficient on its own to prove possession with the required knowledge. This makes it essential to consider the circumstances as well as additional artifacts that can be extracted from the computer. In California, the criminal statute prohibiting child sexual abuse material (CSAM) is found in California Penal Code §311.11. Similar to 18 U.S.C. §2252, California Penal Code §311.11 prohibits the knowing possession or control of CSAM, while the sharing of such material is prohibited by other provisions of Penal Code §311. In other words, California’s law mirrors the relevant portions of the federal statute in its imposing of criminal penalties for possession. Virginia has numerous child exploitation statutes as well. For example, Virginia Code §18.2-374.1 prohibits a wide range of conduct. Notably, this statute includes a prohibition against electronic transmission and a prohibition against possessing CSAM with the intent to sell or distribute it for profit. For some of these types of conduct, the presence of a cache file alone may be more than enough for a conviction. For others, the presence of a cache file alone will not be enough. One relevant case is United States v. Kuchinski. In this case, the government’s evidence of knowing possession was limited to the presence of a cache file. According to the appellate court:
“If the only evidence of possessing child sexual abuse material (CSAM) is a cache file in which a computer automatically stores images of child abuse, then, ‘finding a cache file alone is not enough to establish knowledge under [21 U.S.C. § 844(a)].’ This was the case in Kuchinski. Therefore, without additional evidence of ‘knowledge of the files, knowledge of how the files were created, or control of the files,’ the federal government does not establish a violation of the statute. The Ninth Circuit rejected the theory that a cache file alone established knowledge.” Tecklenburg’s case explains that California law and federal law can lead to different results. In Tecklenburg v. Appellate Division of the Superior Court, 169 Cal.App.4th 1402 (2009), the appellate court noted that California Penal Code §311.11 imposes criminal liability based on possessing or controlling CSAM, whereas the federal statute focuses on knowing possession. This means that while possessing a cache file might be enough to satisfy California’s broader criminal statute, it may not meet the federal criminal law requirement of knowing possession. ## What Evidence Shows the User Knew and Controlled the Illicit Content? The search terms that were used to find the contraband imagery can be indicative of whether this was done intentionally, or whether the computer’s owner may have accidentally accessed the imagery through legitimate search term queries. Other artifacts like file-open artifacts can show whether the user viewed the material, which is critical to proving knowing possession. The file location can also be useful to federal prosecutors in demonstrating whether the imagery was placed where the user could have viewed it. For example, imagery placed on a computer’s desktop would be considered accessible, whereas imagery that requires a search of the folder system would not necessarily be as accessible. The date and time that material was deleted from the device is another critical piece of evidence that can be used to support arguments regarding the user’s knowledge of and control over the illicit material. On Windows systems, Jump Lists are an additional type of artifact used to establish attribution of the illicit imagery to a specific user, as Jump Lists can show the files that were recently opened on a system, or even what programs have been run. Similarly, Shellbags are another useful artifact on Windows systems, as they reveal the history of accessed folders. These folders can include both system and user-created folders, and they are an invaluable resource in criminal cases that involve the possession of contraband imagery. Even if evidence of a cache file exists, browser history can either corroborate or contradict a conclusion that the imagery was intentional. This means that both evidence from the browser and evidence from the file system needs to be carefully reviewed and contrasted. Similarly, the timestamps on cache files must be correlated with browser history, and with operating-system activity artifacts. If that correlation shows that the computer user accessed the content, then this, along with other artifacts, can be used to argue for criminal guilt. The evidence that federal prosecutors use can include other artifacts as well, such as those used to store cloud data or files created when the operating system has generated thumbnails. These artifacts also need to be looked at carefully to determine the significance of their presence on a computer. ## When Are Thumbnails or Cache Files Weak Evidence? Generally, an ordinary user’s day-to-day activity on a computer system should be seen as providing an opening. Thus, as a general rule, most users do not have access to tools that allow for the retrieval of deleted thumbnails or the images in unallocated space, which is the data residue in a computer’s file system that has not been formally rewritten. As a result, in many cases, images and video material recovered from unallocated space is effectively unusable because it would not be considered “possessable” by the user. An example of this occurred in United States v. Flyer, where a conviction based solely on evidence recovered from the defendant’s computer system was overturned upon appeal. The appellate court’s reasoning was that the imagery in question resided in the unallocated space and therefore, it was not considered possessable without the use of forensic recovery tools. In United States v. Ganzer, the appellate court noted that it is imperative to link contraband items on a computer to specific users. The court rejected the idea that merely having contraband items in a user’s device is enough to prove attribution. If you are facing federal criminal charges, an important aspect of your defense will be determining how to prevent the government from being able to definitively attribute any incriminating images and other digital evidence to you. Attribution also has implications with wireless networks. Having the same IP address doesn’t identify who specifically used the device in the image.The case turned on which person had accessed the illicit content, as that is what separates an unlawful possessing from a lawfully owning computer. This is another example of an important defense strategy in cases where the government bases its case solely on the presence of illicit imagery on a computer system or network. ## Are Hash Matches and Timestamps Enough by Themselves? In United States v. Broy, the court recognized the evidentiary limits of cryptographic hash matches. Cryptographic hash matches identify the image, but they don’t show when a user accessed it or their intent. While, as described in some academic literature, a cryptographic hash match usually indicates a byte-for-byte match between files, it doesn’t necessarily mean that a human user viewed the illicit imagery. The same is true when it comes to a perceptual-hash match. A perceptual-hash match means that a content-matching algorithm has indicated that the content is visually similar to a file from a law enforcement database, rather than byte-for-byte. An image found in a thumbnail database does not equal a cryptographic hash match. As a result, the defense and the prosecution cannot assume that these are the same things.
With timestamps, there are numerous pitfalls. First, an investigator needs to verify the time-zone settings for computer usage timestamps so that the events are not recorded incorrectly. An event that occurs at 1:00 PM in UTC may be 5:00 AM in California. Additionally, a user manually changing the computer’s clock setting can also be problematic.
A last-access timestamp on an image or cache file doesn’t always necessarily mean that the file was viewed. Operating systems can update that timestamp as part of an automated background process, so it is not conclusive proof of human viewing without corroborating evidence.
The investigator’s forensic parser might also be interpreting the time-stamp on an incorrect page or have other issues. The date and time recorded on a cached thumbnail’s activity file are not the same as the dates and times on raw database records that need manual verification in order to determine the actual time of the event. Therefore, in federal criminal defense cases involving the use of computers, it is critical to double check every artifact for errors and inconsistencies.
A criminal trial is the final step in the process. Evidence presented to a jury will be much more convincing than arguments made during a pretrial hearing, so it is the responsibility of a defense lawyer and a digital forensics expert to address those issues as soon as possible and to the fullest extent possible. ## What Happens After a CyberTip or Device Seizure? Electronic service providers are required by federal law to refer suspected cases of CSAM to law enforcement authorities. Under 18 U.S.C. §2258A, a service provider must report any discovered material to the National Center for Missing & Exploited Children (NCMEC). NCMEC then sends a CyberTip to the appropriate law enforcement authorities. CyberTips commonly include information such as the IP address of the originating device, any identifying information pertaining to the account, relevant timestamps, filenames, and even cryptographic hash values for the images and other files in question.
Although highly useful for law enforcement, these reports provide only enough information to treat the reporting device as an investigative lead. In many cases, it will take extensive effort before investigators determine if anyone should be held criminally liable. This includes evidence obtained from search warrants and other investigative means.
For example, law enforcement may serve a search warrant for the device used. If the device is not immediately available or is not readily identifiable, law enforcement officers may seize any devices in the house. While a federal target letter may be sent in lieu of a search warrant, this happens much later in the process. At this point, you will need to get a qualified criminal defense attorney on your side.
Once the prosecution determines that it will be seeking an indictment, it must comply with a number of procedural requirements. This includes requirements set forth in the Adam Walsh Act. Section 504 of the Adam Walsh Act provides that any individual facing prosecution shall have access to the images and videos from which a hash match was extracted. It also requires that this evidence be reasonably accessible to your defense lawyer’s expert so that he or she can plan the review of other non-contraband digital evidence in the files. With this in mind, it is important to discuss your case with an experienced lawyer. At Spodek Law Group, we work on cases involving the use of computers in child exploitation offenses, including cases where the defense team successfully overturned convictions based on the improper interpretation of digital artifacts. ## What if I Accidentally Found and Deleted the Illicit Content? The affirmative defense established in 18 U.S.C. §2252(c) allows users to defend themselves against criminal prosecution if they promptly deleted the material in question. The statute states in relevant part: “It shall be an affirmative defense to the application of this subsection that the material in question consisted of fewer than three matters, that the person promptly took action to remove the person’s possession and control of such matter after discovery of the matter, and that the person either did not or was unable to report the matter in good faith to law enforcement authorities, or did report the matter in good faith to law enforcement authorities; and it shall be further necessary that the person did not retain possession or control of the material as a result of such prompt action nor did he show it to any person except in good faith and for purposes within the knowledge and control of such person.” The statute’s application allows the use of this affirmative defense in cases that meet all of the following requirements: - Fewer than three matters were possessable;
- The material was promptly deleted upon discovery;
- The material was not retained after discovery;
- The material was not shared or distributed to a non-law-enforcement recipient after discovery; and
- The material was either reported in good faith to law enforcement, or there was a justifiable reason the material was not reported to law enforcement. While the federal statute addresses these specific conditions, the defense of “prompt deletion” exists in various forms across different jurisdictions. As with all other defenses, a defense lawyer’s ability to successfully advance a prompt-deletion defense will depend on the facts and circumstances involved. However, the fact that the defendant has already attempted to eliminate the illicit material by deleting the file (or files) can serve as powerful evidence on the side of the defendant in a criminal prosecution. The defense expert will want to establish when the material was discovered and what actions were taken after this discovery. A computer’s forensic records will often help to establish these facts, and this can facilitate an affirmative defense for prompt deletion, whether or not the material was promptly reported to law enforcement authorities.
Speak With a Federal Defense Lawyer
If you are dealing with any part of what this article describes, the next step is a conversation with a lawyer who handles these cases. Spodek Law Group is a second generation criminal defense firm practicing since 1976, representing clients nationwide from offices in New York, Brooklyn, Queens and Los Angeles. Call 212-300-5196 to speak with our team.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196