Device Imaging vs. Device Search: Where the Warrant Runs Out.
Forensic imaging has a specific place in law enforcement investigations, and it is important to understand where it begins and ends. A device warrant generally authorizes the seizure of a device, the imaging of its data, and then the review of a specific portion of the imaged data.
Is Search Authority Limited?
Search authority is limited to the scope and particularity requirements of the Fourth Amendment. A full-device image does not broaden the authorized search; rather, it is a means to facilitate a targeted search for evidence that is explicitly authorized in the warrant. The same principle applies when a computer is taken to a lab. “A warrant to search one computer may not, however, authorize a search of all files on that computer, regardless of the type of information stored within each file.”
What Are the Three Distinct Investigative Acts?
These are (i) the seizure of a device, (ii) the imaging of that device, and (iii) the review of contents within the imaging.
Why Particular Descriptions are Required?
Particular descriptions of the evidence to be searched for prevent “mistaken searches of innocent people’s property.” This requires warrants to be specific to the particular crime or offense at hand.
The specificity required under a warrant depends on the type of crime being investigated, the type of item being searched for, the evidence being sought, and the time period involved.
Do Warrant Descriptions Need to be Perfect?
No. While warrant descriptions must be sufficiently particular, they are not required to be perfect in every instance.
What Did the Court Decide in Layne?
United States v. Layne, 43 F.3d 127 (5th Cir. 1995) that, while a warrant can authorize a search of “devices, computers, or other electronics,” it cannot authorize the “searches of [an individual’s] belongings for evidence of any possible crime.”
What Does a Device Warrant Authorize Agents to Search?
A device warrant allows agents to search for specific evidence of a federal crime that is located on a device that agents have probable cause to believe contains evidence. This is different from a warrant to search a device, a “device warrant” identifies the data that warrants imaging are being sought, not simply a phone or computer. For a warrant to be valid, the following elements must exist: (i) probable cause to believe a crime occurred; (ii) probable cause that the sought-after evidence of that crime is contained on a device; (iii) a sworn affidavit asserting probable cause; (iv) particularity in the description of the place to be searched and the items to be seized; and, (v) the approval of a judge.
What is Particularity in the Context of a Device Warrant?
In the context of a device warrant, “particularity” is the requirement that the warrant specifically identify the evidence to be seized. The purpose of particularity is to avoid allowing agents to “rummage through an individual’s belongings” during a search. Without particularity, “it is left to the officer’s discretion to decide whether a search is necessary for any reason or for no reason at all.”
How Specific Should a Device Warrant Be?
A device warrant needs to be as specific as possible, but the level of specificity depends on the circumstances of the case. For example, a warrant may be limited to a specific offense, or it may be limited in scope by a timeframe, a single account or user, or certain categories of data.
What Sets the Bounds of a Device Warrant’s Search?
While some device warrants identify the devices to be seized, the bounds of a device warrant’s search are set by its content-review clause. The content-review clause limits the categories of data that investigators can examine after taking a device image.
Where are Digital Photos Stored?
Digital photos may be stored on an individual’s smartphone, computer, video game console, DVR, smart device, or similar hardware.
Is forensic imaging different from searching copied data?
Yes. Forensic imaging is the process of making an exact copy of the original source media; searching is the process of reviewing the copied data. Imaging allows investigators to conduct subsequent reviews of the image without risking alteration of the original media.
How do forensic investigators ensure the integrity of the copied data?
To ensure the integrity of the copied data, forensic investigators employ a combination of the following:
- Calculating hash values. A hash value is a digital fingerprint created using a mathematical formula; comparing the hash value of the source media with that of the copy proves they are identical.
- Using write-blockers. Write-blockers are hardware or software tools that block any writes to the original source media.
- Preserving metadata. Forensic imaging avoids altering system logs and the source media’s metadata (such as modification dates).
- Maintaining chain-of-custody records. A chain-of-custody record provides a timeline and inventory of all individuals who had possession of the original source from the moment of seizure.
Is accessing data different from copying data?
Yes. Accessing a file updates its metadata and system logs. While accessing files may be necessary during some immediate searches, it can compromise the integrity of digital evidence. Forensic imaging stores data in a manner that allows investigators to conduct a search without altering the original media.
Can forensic imaging be limited by a warrant?
Yes. Under Rule 41(e)(2)(B), a warrant authorizing forensic imaging also authorizes a later review of the imaged data consistent with the warrant, unless the warrant specifies otherwise. Seizing a device, forensic copying, and reviewing the imaged data are three separate, and legally distinct, investigative acts. A warrant could authorize one, two, or all three of these acts.
How do warrants typically authorize forensic imaging?
Warrants that authorize forensic imaging generally do so through specific provisions authorizing “seizure, imaging, and review,” or through general provisions authorizing “forensic examination.”
What are the four primary methods of acquiring data for analysis?
The four primary methods of acquiring data for forensic examination are:
- Physical imaging is a bit-by-bit copy of the original source.
- Logical extraction creates a copy of the original source’s
Does Rule 41 let agents review images months later?
Yes. Rule 41(e)(2)(B) allows agents to perform later reviews of copied electronically stored information. This Rule applies to warrant executions that are too large in scope to allow a real-time review. It reads, “A warrant under Rule 41(e)(2)(A) may authorize the seizure of electronic storage media or the seizure or copying of electronically stored information. Unless otherwise specified, the warrant authorizes a later review of the media or information consistent with the warrant.” A time limit of 14 days applies to warrant executions. If the original warrant was not executed within 14 days, Rule 41(e)(2)(B) will not apply. Rule 41(e)(2)(B) does apply to reviews performed after the 14-day execution period has run. The Rule provides that the time for executing the warrant refers to the seizure or on-site copying of the media or information, and not to any later off-site copying or review, so the 14-day period limits only the initial seizure or on-site copying and not the later forensic review.
The fact that a review can take place later does not remove any other constitutional or statutory limit on the review. The review remains limited by (i) the particularity requirements of the warrant, (ii) the warrant’s probable cause, (iii) the reasonableness requirement of the Fourth Amendment, and, (iv) Rule 41(e)(2)(A)’s 14-day limit on the initial seizure or on-site copying.
What happens to nonresponsive data contained in forensic images?
Nonresponsive data, data that does not fit within the warrant’s scope, may be subject to segregation, sealing, deletion, or return. Nonresponsive data may be retained if retained mirror images are necessary for ongoing or subsequent investigations, and if retention is authorized in a warrant. Once the evidentiary needs have ended, there are grounds for challenging the retention of mirror images under Rule 41(g).
What does Rule 41(g) say about the return of seized property?
Rule 41(g) provides a mechanism for the return of seized property, for property seized in violation of the rule or property in the unlawful possession of the government. It reads: “A person aggrieved by an unlawful search and seizure of property or by the deprivation of property may move for the property’s return. The motion must be filed in the district where the property was seized.”
What can courts do about nonresponsive copied data?
Courts can order sealing or destruction of nonresponsive copied data.”
How long does a forensic lab need to return a device image?
The time it takes a forensic lab to return a device image can be highly variable.
It will depend on:
- The type of agency (private vs. government)
- The device’s storage capacity
- Encryption status and key availability
- The urgency of the investigation
- The case’s priority within the forensic lab’s existing workload
Todd Spodek and the attorneys at Spodek Law Group handle federal cases of this kind from New York, Brooklyn, Queens and Los Angeles.
When do agents need to seek a second device search warrant?
When agents use search terms and filters to review images, should those search terms and filters be limited to evidence identified in the warrant?
Yes. When agents use search terms and filters to review images, they must limit those search terms and filters to evidence identified in the warrant. Reviewing files in search results does not mean the files are responsive, and investigators must only examine evidence the warrant’s content-review clause allows. Reviewing files outside the warrant’s scope risks triggering the “plain view” doctrine and may result in suppression of any newly discovered (but nonresponsive) evidence.
What did the Fourth Circuit conclude in United States v. Kim, 677 F. Supp. 2d 930 (S.D. Tex. 2009)?
The district court held that, in Kim, agents exceeded the scope of the warrant when they decrypted files after a magistrate judge had refused to issue a warrant for them, and it suppressed the images recovered from those files. The agent encountered an encrypted file that appeared to contain the encrypted evidence he was authorized to search for under the warrant. The agent then sought a key for the decryption. According to the Fourth Circuit: “ a warrant authorizing the search for evidence of computer-related criminal activity does not grant agents the right to decrypt files found on the computer, when their decryption might provide evidence of additional crimes that agents were not authorized to look for.”
What should officers do when they encounter evidence outside their warrant’s scope?
When officers encounter evidence that is out of scope for their current warrant, they should avoid altering the evidence. If the evidence was encrypted and the officer found evidence to decrypt it, the officer should either request the key, request the decryption, or seek the decryption from a provider, as appropriate. The discovery of encrypted evidence for which agents already have probable cause to search would support seeking a second warrant.
How can investigators execute an image review while staying within the scope of the warrant?
If investigators encounter evidence of a crime that is out of the warrant’s scope for which they believe they have probable cause, the investigators can seek a second warrant. However, if an investigator conducts searches of categories of data not listed in the warrant, the investigator is conducting a warrantless search in violation of the Fourth Amendment.
Do agents’ concerns about “hidden” files justify searches that are outside the scope of a device warrant?
No. Even if agents are concerned about “hidden” files, they cannot avoid warrant particularity, minimization, or nonresponsive data constraints. While this may lead to additional investigative work, this work cannot be conducted unless authorized by a court.
When is another warrant required for the examination of newly discovered evidence?
When investigators encounter new evidence that is of a different type or quality than the evidence they sought, a further examination of that newly discovered evidence is limited to the plain-view doctrine and the good-faith exception. If agents have probable cause, they need to obtain a second warrant.
Can police use unrelated evidence found in plain view?
The plain-view doctrine is much narrower in the context of computer searches than in the context of physical searches. In United States v. Nixon, 418 U.S. 683 (1974), 418 U.S. 683 (1974), the Supreme Court has explained that in a search for relevant evidence, law enforcement personnel may encounter irrelevant information: “We recognize that, in the course of searching for relevant evidence, law enforcement personnel will inevitably encounter non-relevant information. However, an officer’s review of non-relevant information should be limited to what is necessary to determine its relevance.” A warrant authorizing the search of a computer is not a general warrant, and “it is limited in scope by the Fourth Amendment’s requirements of particularity and probable cause.” With respect to computer searches, different jurisdictions apply different plain-view rules and have different requirements regarding the development of a prior ex ante examination protocol.
Does plain-view evidence of a second crime violate digital plain-view rules?
If evidence of a second crime is uncovered in a warrant-authorized search for evidence of a first crime, the evidence of the second crime may still be admissible under the plain-view doctrine. There is no per se exclusionary rule that the discovery of out-of-scope evidence violates the rules for the digital plain view. Admissibility depends on whether agents lawfully reached the file and whether they were able to determine the evidence’s incriminating character in plain view.
How apparent must the incriminating character of plain-view evidence be?
The evidence’s incriminating character must be “immediately apparent.” For images, it may suffice that the image itself be incriminating. If decryption is needed to view the evidence, then the character of the evidence may not be immediately apparent.
Are broad device warrants generally upheld?
Broad device warrants have generally been upheld. In United States v. Williams, the Fourth Circuit found that agents’ affidavits tied the computers to the specific offenses under investigation. This showed “that the warrant was not a general warrant and that there was a substantial connection between the evidence the government sought and the location of the search.”
Broad searches are generally more likely to be upheld when the warrants are limited by (i) offenses, (ii) time periods, (iii) categories of evidence sought, and, (iv) account, user, or device identifier.
What private or privileged data should not reach case agents?
Information that is privileged or otherwise protected from government access is data that should not reach case agents. The common solution to ensuring that no privileged data reach case agents is to have a privilege filter team review the imaging for privileged or otherwise protected content. Any information found that is privileged or otherwise protected is set aside, and only relevant, non-privileged material is sent to the case agents. A “privilege leak” can support motion to suppress all tainted evidence, and the suppression of any subsequent leads derived from those tainted leads.
What should investigators do when an individual consents to unlock their device?
Consent to unlock a device is not necessarily consent to search the contents of that device. The consent to unlock the device allows for imaging of the device, which is then reviewed by the case agents in accordance with the terms of the warrant. Compelled passcodes, when the individual is not consenting to use his or her own password or biometric data to unlock the device, present more complex constitutional questions. When individuals are compelled to provide their passcode or have their fingerprints used or their faces imaged by law enforcement agents, they should either not give consent or should object under penalty of perjury.
When can individuals object to data imaging under Fifth Amendment grounds?
Individuals should object to the imaging of digital evidence on Fifth Amendment grounds when they are compelled to produce an encrypted key, a passcode, or another form of evidence that reveals the contents of their mind.
What are the consequences of privilege leaks for case agents?
When digital material that contains privilege or is otherwise protected is exposed to case agents, a taint-remedy dispute may arise. Generally, privilege-shielded digital information requires filter protocols before it is reviewed by case agents.
What is a privilege filter team, and how is it viewed by courts?
A privilege filter team is a group of individuals whose purpose is to review imaged data for privilege and otherwise exempt digital information before it goes to the case agents. Government filter teams, that are composed of individuals within the prosecutor’s office, receive heightened scrutiny because the prosecutor’s office is reviewing and removing all exempt digital data, while the case agent will only see the material that is not exempt.
What is a geofence warrant?
A geofence warrant identifies the devices and account information of devices that are believed to be within a certain geographic area (the “geofence”) during a certain time period.
What defense challenges test where the warrant ran out?
Defense attorneys test the boundaries of search warrants through various types of challenges. These challenges address the different stages of a computer search, and when the warrant expires.
When can defendants pursue a Franks challenge?
Under Franks v. United States, defendants have grounds to pursue a Franks challenge when there is a false statement in a material affidavit, knowing or reckless of the statement’s falsity.
A search inventory lists the items that are taken from the subject of the warrant. It is required for each search warrant.
A search warrant is generally supported by a sworn affidavit from a government agent. The affidavit describes the evidence acquired by law enforcement.
How can the defense seek information about how the review is being conducted?
In a criminal case, the defense can seek information about how the review is being conducted through discovery. This includes information and data such as (i) search logs and forensic logs showing what devices, accounts, and data have been accessed; (ii) search terms and filters that have been used; (iii) a list of all files that have been exported from the image for review; (iv) a list of the files that have been reviewed; and, (v) a log of the time and duration of the imaging, transfer, and review of the imaged data.
What constitutes overbreadth in the context of computer searches?
Search warrants that are overbroad, that is, too broad in scope for probable cause, are ones that are missing (i) limitations by the crime or offense, (ii) limitations by the timeframe, (iii) limitations by a specific account or user, and, (iv) limitations by category of data.
Do hash values validate forensic images or investigations?
While a matching hash value may be enough to validate that a forensic image matches the original device source, a matching hash value is not evidence that: (i) the reviewing agents stayed within the scope of the warrant; and, (ii) that there is any validity to the agents’ interpretations of the recovered artifacts.
When does seizing a phone before searching warrant authorization become unlawful?
If agents seize a phone, computer, or any other device before seeking a search warrant, then the continued possession and retention of the device can become unlawful in violation of the Fourth Amendment.
Talk to Spodek Law Group
Every case turns on its own facts, and general information is no substitute for advice about yours. Todd Spodek, managing partner of Spodek Law Group, and the firm's attorneys defend federal criminal and white collar matters nationwide. Reach the firm at 212-300-5196.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196