Facts
- Investigators reviewing law-enforcement P2P monitoring data saw repeated “query hit” activity for known child-pornography files associated with a particular IP address on the Gnutella network.
- The IP address was traced to a Comfort Inn wireless network; investigators believed a user was accessing Gnutella using Shareaza, a Gnutella-based client.
- The government obtained a court order under the federal pen register/trap-and-trace statute to collect dialing, routing, addressing, and signaling information for wireless communications in the vicinity of the hotel.
- Investigators configured a monitoring device to detect protocol/network identifiers such as “Gnutella” and “Shareaza,” and not to capture or search for explicit file names or descriptive search terms.
- When Gnutella traffic was detected, the system generated emails containing the captured technical data the detective characterized as routing and signaling information.
- A second device identified MAC addresses tied to the Gnutella-related wireless activity near the hotel.
- Investigators located a van parked near the hotel and observed a laptop running inside it, consistent with the detected wireless activity.
- Investigators obtained and executed a search warrant for the van, seizing two computers and four external storage drives.
- A forensic examination found multiple child-pornography files; the defendant was charged with receiving child pornography.
- The defendant moved to suppress, claiming the pen/trap monitoring captured “content” and thus constituted a warrantless Fourth Amendment search that tainted the later warrant.
Issues
- Whether pen register/trap-and-trace monitoring that detected identifiers like “Gnutella” and “Shareaza” captured “content” of electronic communications, triggering a warrant requirement under the Fourth Amendment.
- Whether the monitoring exceeded the pen/trap statute by collecting protected “content,” rather than permissible dialing, routing, addressing, and signaling information.
Decision
- The district court adopted the magistrate judge’s recommendations and denied the motion to suppress.
- The court found the monitoring collected non-content signaling/routing information within the pen/trap statute’s authorization.
- Because the initial collection was lawful, the subsequent search warrant for the van was not tainted, and the seized evidence was admissible.
Legal Principles
- The pen register/trap-and-trace statute authorizes collection of dialing, routing, addressing, and signaling information, but not the “content” of communications.
- “Content” refers to information concerning the substance, purport, or meaning of a communication.
- In classifying captured data as content or non-content, courts may focus on the function of the data in establishing or routing communications, not solely on packet structure labels such as “header” versus “payload.”
- When initial pen/trap collection is lawful and limited to non-content data, evidence obtained under a later probable-cause warrant is not subject to suppression as fruit of an unlawful search.
Conclusion
The court denied suppression because the government’s court-authorized pen/trap monitoring was limited to non-content technical information used to identify a device on a P2P network, supporting a later, valid warrant to search the defendant’s van and seize digital evidence.