United States v. Perez, 2015 WL 3498734 (2015) (unreported)

Facts

  • A Federal Bureau of Investigation (FBI) agent downloaded files containing child pornography that were being shared by a computer logged into a peer-to-peer network.

  • The IP address sharing the files was assigned to the home of Javier Perez.

  • Investigators obtained a warrant authorizing a search of Perez’s home for “all visual depictions” of child pornography “on whatever medium,” along with other materials related to child-pornography offenses.

  • Agents executed the warrant and seized a desktop computer and three thumb drives.

  • Using forensic-analysis software, the government catalogued and segregated files by type and extracted graphic-image and video files, including files concealed by extensions not typically associated with images or videos.

  • To review the extracted material, agents:

    • viewed thumbnails of graphic images and opened images they believed contained child pornography,
    • played short portions of video files to determine their content,
    • opened emails without attachments if the subject line or sender suggested child-pornography content, and
    • opened and cursorily examined other extracted file types, including internet-history information.
  • The agents found 10 files containing child pornography and a list of child-pornography-related search terms used to search the peer-to-peer network.

  • Perez was charged with distributing and possessing child pornography.

  • Perez moved to preclude the government from introducing evidence obtained from his computer and storage devices, arguing that the forensic software use exceeded the warrant’s scope and that opening files amounted to an unlawful rummage for evidence.

Issues

  1. Whether the government’s use of forensic-analysis software to catalogue, segregate, and extract image and video files (including those hidden by misleading extensions) exceeded the scope of the search warrant and violated the Fourth Amendment.
  2. Whether agents’ review methods—viewing thumbnails, opening selected images, sampling portions of videos, and reviewing certain emails and internet-history data—were unreasonable and converted the search into a general rummage.

Decision

  • The court denied Perez’s motion to preclude the government from introducing the computer-search evidence.
  • The court concluded that using forensic tools to sort and extract potentially responsive files did not exceed the warrant’s scope.
  • The court found the agents’ limited review of the extracted files was a reasonable way to determine whether the materials fell within the warrant’s authorization.
  • When a warrant authorizes a search for child-pornography images and related records on digital media, investigators may use forensic software to identify and sort files by type, including identifying image and video files that are disguised by misleading file extensions.
  • Agents executing a digital search may view thumbnails and open selected images, and may play short segments of videos, as a means to confirm whether content is within the warrant’s scope.
  • Agents may examine other extracted artifacts (such as certain emails and internet-history data) when the file indicators reviewed (for example, sender or subject line) suggest a connection to the offenses described in the warrant.
  • The Fourth Amendment analysis focuses on whether the execution methods were reasonable and remained connected to the evidence described in the warrant, not on whether the search avoided all exposure to nonresponsive data.

Conclusion

United States v. Perez held that the government’s forensic cataloguing and extraction of files from seized devices, followed by agents’ limited viewing of thumbnails, selected images, short video segments, and certain related communications and browsing artifacts, stayed within the warrant for child-pornography evidence and was reasonable under the Fourth Amendment, so the court declined to exclude the resulting digital evidence.