Feds use malware to ensnare child porn users

WASHINGTON — The user’s online handle was Pewter, and while logged onto a website called Playpen, he allegedly downloaded images of young girls being sexually molested.

Pewter had carefully covered his tracks. To reach the site, he first had to install free software called Tor, the world’s most widely-used tool for giving users anonymity online.

In order to uncover Pewter’s true identity and location, the FBI quietly turned to a technique more typically used by hackers. The agency, with a warrant, surreptitiously placed computer code, or malware, on all computers that logged into the Playpen site. When Pewter connected, the malware exploited a flaw in his browser, forcing his computer to reveal its true Internet protocol address. From there, a subpoena to Comcast yielded his real name and address.

Pewter was unmasked last year as Jay Michaud, a 62-year-old administrator in the Vancouver, Wash., public schools. With a second warrant, agents searched the suspect’s home and found a thumb drive that allegedly contained multiple images of children engaged in sex acts. Last July, Michaud was arrested and charged with possession of child pornography.

Michaud’s is the lead case in a sweeping national investigation into child porn on the so-called dark Web, the universe of sites that are off Google’s radar and where users can operate with anonymity.

As criminals become savvier about using technology such as Tor to hide their tracks, investigators are turning to hacking tools to thwart them. In some cases, law enforcement is placing malware on sites that might have thousands of users. Some privacy advocates and analysts worry that in doing so, investigators may also wind up hacking and identifying the computers of law-abiding people who are seeking to remain anonymous, people who can also include political dissidents and journalists.

“As the hacking techniques become more ambitious, failure in execution can lead to large-scale privacy and civil liberties abuses at home and abroad,” said Ahmed Ghappour, a professor at the University of California Hastings College of Law. “It’s imperative that Congress step in to regulate exactly who and how law enforcement may hack.”

But Justice Department officials said that the government investigates crime based on evidence of illegal activities. “When we obtain a warrant, it’s because we have convinced a judge that there is probable cause that we’ll be able to find evidence in a particular location,” said a senior department official, who spoke on condition of anonymity under ground rules set by the department.

In the Playpen case, the government activated malware on a site with 215,000 members as of last February and obtained Internet protocol addresses of 1,300 computers. Out of that group, the government said it has charged 137 people.

“It’s a lot of people,” said Colin Fieman, a public defender in Tacoma representing Michaud. “There never has been any warrant I’ve seen that allows searches on that scale. It is unprecedented.”

Michaud is arguing that his charges be dismissed on grounds that the government’s use of the tool violated the Fourth Amendment. Fieman argues that some people might have gone to the site seeking to express fantasies, which while repugnant, are legal. The site, he said, doesn’t clearly advertise itself as devoted to child pornogaphy.

He likened the government’s warrant to a “general warrant,” referring to the British practice during the colonial era of allowing government searches without any individualized suspicion.

A judge in the case is scheduled on Friday to hear a defense motion to throw out the charges against Michaud.

“This is a gray area in the law,” said Thomas Brown, a former federal prosecutor in the Southern District of New York who handled cases involving the use of hacking techniques. “It’s another instance where you’ve got technology outstripping the law.”

Fieman also said that rules established by the federal courts, grounded in constitutional principles, require that a warrant be deployed in the district in which it is issued – in this case, the Eastern District of Virginia. Michaud’s computer was in Vancouver.

But prosecutors argue that the technique is lawful and that in general a warrant may be issued even when the location to be searched is unknown, as long as there is probable cause that the search will turn up evidence of a crime.

“The Supreme Court has made clear that the Fourth Amendment … does not preclude use of warrants where the purpose of the search is to discover the location of the place to be searched,” said David Bitkower, then a deputy assistant attorney general, in a Dec. 2014 letter to a federal courts committee weighing changes to the rule that governs how search warrants are issued.

In the Playpen case, the government argued that it had probable cause to search the computers of anyone who navigated to the site – whether one person or 10,000 people – on the grounds that the site was devoted to child porn and anybody who knew how to get to it likely did so with the intent to view the content. The site can’t be found through a Google search and can only be reached by users who know its exact, algorithm-generated Web address and are using special software that connects to the Tor network.

In such a case, “we have an obligation to investigate all 10,000 1/8people3/8, not just one,” prosecutor Keith Becker told Judge Robert J. Bryan of the U.S. District Court at a hearing in the Western District of Washington at Tacoma in December.

The FBI seized Playpen last year, and after operating it for two weeks, shut it down. During those two weeks, according to court documents, it deployed what it obliquely calls a “network investigative technique,” or NIT, to capture the IP address of anyone who logged into the website.

“In general, the constitution doesn’t say that we have to stop investigating just because we need to use a computer technique to identify suspects rather than opening a letter or entering a private house,” said the senior department official. “The law doesn’t give online pedophiles immunity from court-authorized search warrants just because they’re using modern software.”

Fieman also argued that the government itself violated the law when it seized Playpen last year and then rather than shut it down immediately or find ways to reroute visitors, continued to operate the child porn site.

“What the government did is comparable to flooding a neighborhood with heroin in the hope of snaring an assortment of low-level drug users,” Fieman said in a motion to dismiss filed in November.

Justice Department spokesman Peter Carr said that “at no time in an operation like this does the FBI post any images, videos or links to images of child pornography.” Any such postings are done by website users, not the FBI, he said. Also, he said, immediately shutting down a website would prevent law enforcement from identifying the offenders and frustrate efforts to identify and rescue child victims from abuse.

Without using the hacking technique, officials say, it would be very difficult to locate pedophiles who go to great lengths to hide their tracks.

The issue, said Ghappour, the law professor, is not the use of the malware per se, but “whether hacking warrants are written narrowly enough to guarantee that only those culpable set the trigger 1/8to launch the NIT3/8, and consequently get hacked,” he said. “Given the scale of these operations, the smallest mistake could result in hundreds, if not thousands, of privacy violations.”

Privacy advocates concerned about the government doing mass hacks point to the case of TorMail, an anonymous email service, now shuttered. TorMail, which despite the name is not affiliated with the group behind Tor, was used by a range of people, from criminals to dissidents and journalists.

In the summer of 2013, reports surfaced of people trying to log in to TorMail and finding a Down for Maintenance message instead, and finding suspicious-looking code included in the TorMail Web page. Security researchers who analyzed the code concluded that it was likely placed there by the FBI.

At the time, the government would not confirm that the bureau was behind the hack. This week, people familiar with the investigation confirmed the FBI had used an NIT on TorMail. But, they said, the bureau obtained a warrant that listed specific email accounts within TorMail for which there was probable cause to believe the true user was engaged in illicit child pornography activities. In that way, the sources said, only suspects whose accounts had in some way been linked to involvement in child porn would have their computers infected.

An FBI official said the bureau recognizes that the use of the NIT is “intrusive” and should only be used “in the most serious cases.” He said the FBI uses the tool only against offenders who are “the worst of the worst.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Traffic idles while waiting for the lights to change along 33rd Avenue West on Tuesday, April 2, 2024 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood seeks solutions to Costco traffic boondoggle

Let’s take a look at the troublesome intersection of 33rd Avenue W and 30th Place W, as Lynnwood weighs options for better traffic flow.

A memorial with small gifts surrounded a utility pole with a photograph of Ariel Garcia at the corner of Alpine Drive and Vesper Drive ion Wednesday, April 10, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Death of Everett boy, 4, spurs questions over lack of Amber Alert

Local police and court authorities were reluctant to address some key questions, when asked by a Daily Herald reporter this week.

The new Amazon fulfillment center under construction along 172nd Street NE in Arlington, just south of Arlington Municipal Airport. (Chuck Taylor / The Herald) 20210708
Frito-Lay leases massive building at Marysville business park

The company will move next door to Tesla and occupy a 300,0000-square-foot building at the Marysville business park.

Cars drive onto the ferry at the Mukilteo terminal on Monday, Nov. 1, 2021 in Mukilteo, Washington. (Olivia Vanni / The Herald)
Everett woman disrupts ferry, threatens to drive motorhome into water

Police arrested the woman at the Mukilteo ferry terminal Tuesday morning after using pepper-ball rounds to get her out.

Bothell
Man gets 75 years for terrorizing exes in Bothell, Mukilteo

In 2021, Joseph Sims broke into his ex-girlfriend’s home in Bothell and assaulted her. He went on a crime spree from there.

Allan and Frances Peterson, a woodworker and artist respectively, stand in the door of the old horse stable they turned into Milkwood on Sunday, March 31, 2024, in Index, Washington. (Ryan Berry / The Herald)
Old horse stall in Index is mini art gallery in the boonies

Frances and Allan Peterson showcase their art. And where else you can buy a souvenir Index pillow or dish towel?

Providence Hospital in Everett at sunset Monday night on December 11, 2017. Officials Providence St. Joseph Health Ascension Health reportedly are discussing a merger that would create a chain of hospitals, including Providence Regional Medical Center Everett, plus clinics and medical care centers in 26 states spanning both coasts. (Kevin Clark / The Daily Herald)
Providence to pay $200M for illegal timekeeping and break practices

One of the lead plaintiffs in the “enormous” class-action lawsuit was Naomi Bennett, of Providence Regional Medical Center Everett.

Dorothy Crossman rides up on her bike to turn in her ballot  on Tuesday, Aug. 1, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Voters to decide on levies for Arlington fire, Lakewood schools

On Tuesday, a fire district tries for the fourth time to pass a levy and a school district makes a change two months after failing.

Everett
Red Robin to pay $600K for harassment at Everett location

A consent decree approved Friday settles sexual harassment and retaliation claims by four victims against the restaurant chain.

A Tesla electric vehicle is seen at a Tesla electric vehicle charging station at Willow Festival shopping plaza parking lot in Northbrook, Ill., Saturday, Dec. 3, 2022. A Tesla driver who had set his car on Autopilot was “distracted” by his phone before reportedly hitting and killing a motorcyclist Friday on Highway 522, according to a new police report. (AP Photo/Nam Y. Huh)
Tesla driver on Autopilot caused fatal Highway 522 crash, police say

The driver was reportedly on his phone with his Tesla on Autopilot on Friday when he crashed into Jeffrey Nissen, killing him.

Janet Garcia walks into the courtroom for her arraignment at the Snohomish County Courthouse on Monday, April 22, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Everett mother pleads not guilty in stabbing death of Ariel Garcia, 4

Janet Garcia, 27, appeared in court Monday unrestrained, in civilian clothes. A judge reduced her bail to $3 million.

magniX employees and staff have moved into the company's new 40,000 square foot office on Seaway Boulevard on Monday, Jan. 18, 2020 in Everett, Washington. magniX consolidated all of its Australia and Redmond operations under one roof to be home to the global headquarters, engineering, manufacturing and testing of its electric propulsion systems.  (Andy Bronson / The Herald)
Harbour Air plans to buy 50 electric motors from Everett company magniX

One of the largest seaplane airlines in the world plans to retrofit its fleet with the Everett-built electric propulsion system.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.