Her Majesty the Queen - v. -, 2016 SKPC 19
Opinion
IN THE PROVINCIAL COURT OF SASKATCHEWAN Citation: 2016 SKPC 019 Date: February 24, 2016 Information: 39123041 Location: Prince Albert _____________________________________________________________________________ Between: Her Majesty the Queen - and - Aiden Pratchett Appearing: Michael Segu, Lana Morelli For the Crown Mark Brayford, Q.C., Brian Pfefferle For the Accused JUDGMENT M.M. BANIAK , J [ 1 ] The accused, Aiden Pratchett, stands charged as follows: 1) Between the 29 th day of September, A.D. 2014 and the 16 th day of October, A.D. 2014, at or near Fond-du-lac, Saskatchewan did have in his possession child pornography, contrary to s. 163.1(4) of the Criminal Code ;
2) Between the 29 th day of September, A.D. 2014 and the 16 th day of October, A.D. 2014, at or near Fond-du-lac, Saskatchewan did access child pornography contrary to s. 163.1(4.1) of the Criminal Code . [ 2 ] The trial commenced on October 5, 2015, in Prince Albert, Saskatchewan. [ 3 ] The Crown’s first witness was Constable Christopher Lair, a member of the Prince Albert Police Service for the last 9 1/2 years and for 10 years before that, Constable Lair served as a member of the RCMP.
Since October 2013, he has been a member of the Internet Child Exploitation Unit, commonly referred to as the ICE Unit. [ 4 ] He testified that investigations of child pornography are usually initiated by either complaints or by monitoring file sharing networks for subjects who are accessing, possessing, or sharing child pornography using file sharing software on the Internet. [ 5 ] The early portion of his examination-in-chief was primarily focused on the technical aspects of the investigation. [ 6 ] Constable Lair went to some length to differentiate the peer to peer file sharing network from the centralized server model: “in most cases when people are receiving information from the Internet they’re contacting a specific site and downloading information from that site that is stored on a server at that site. . .” (T9) [ 7 ] Constable Lair explained that persons accessing the centralized server model are accessing the same server, the same Internet address, and obtaining the same information from the same physical location. [ 8 ] In contrast, according to Constable Lair “peer to peer is a much different set up.
It would contact a network that would contact other peers, people that had files that they might want and they could share files . . . peer to peer systems are not centralized. Peer to peer network is information that is obtained from many different internet sites. Users can obtain files from many different sources on that network.” (T9 - 10) [ 9 ] When asked how one can be certain, keeping in mind the different sources of the information being obtained from, that one is getting what one asked for, Constable Lair answered as follows: Okay.
Because these files are being obtained from multiple sources and we’re getting just pieces of it called packets, the file sharing network, the file sharing software has to be able to identify packets of that file. And in order for that to happen, the system needs to know that it is, in fact, the exact same file. If it differs in any way, the software then takes these packets from multiple users, re- assembles them into one file, unless the source of each of those pieces is from the exact file, the software can’t put those pieces together. So this software uses what’s called a hashing algorithm.
A hashing algorithm is a mathematical formula that represent we call it a digital DNA signature of a particular file. So the software hashes that file and returns a string of alphanumeric characters that when the system sees the same string it knows that it’s the same file. (T-12) [ 10 ] A follow up question of: Okay. And if two files have the same hash value, what can you conclude from that?” Constable Lair answered as follows:
If two files have the same hash value, you can be certain that the file itself is the exact same file. You cannot be sure that someone has changed the file extension or the file name.
Those things could be changed, but the inside of the file that needs to be - that you need to be viewed or to be deconstructed and reconstructed, if it has the same hash value, you can be sure that that date is exactly the same. [ 11 ] He was next asked: “And why are hash values - you’ve explained why hash values are important to the functioning of the peer to peer network - but why are they important to you as an investigator?” [ 12 ] His response: Well, they’re important to me because when we monitor the file sharing networks we see that a particular IP address has a number of files that they’re currently sharing on a file sharing networks and those files are displayed by file name and they’re also displayed by hash value.
Now, law enforcement has a database of hash values that have been - that the files associate with those hash values have been entered into the database because another police officer in another jurisdiction at some point has categorized that image as being a child pornography image. So the software that we use to patrol the internet looks for file with those hash values in that database.
So when I see - when I use my law enforcement program to patrol the internet and look to see who is on file sharing networks trading child pornography I would see a user and I would be able to see the list of files that they have been flagged with. And when I see a hash value, I can’t see the file. So I don’t know by looking at the hash value that, in fact, is child pornography. However, once I have the file, once I’ve downloaded it and I know that the hash value is the same, I can say that the file reported by that person is child pornography whether or not I’ve got the file from them.
When I know that they have that hash value, a file with that hash value in their shared folder on their computer that was available to the network, I can get that file from any source and I can be sure that at that point they had child pornography on that system because the hash value is the same. (T14) [ 13 ] Constable Lair testified that the file sharing network that pertained to this case is the Gnutella Network, and that the program used to access the Gnutella network was Shareaza. [ 14 ] Constable Lair went on to state that once a person is on a file sharing network and downloads files, that folder by default goes into a directory created when the file sharing software was started: Now, if you have - whatever files you have in that shared folder while you are on the internet are potentially visible to any user on the internet when they have put in a search term that is in the file names that are in your shared folder. (T17) [ 15 ] He would use the Child Protection System (CPS) program to browse and see what was in someone’s shared folder: And so when I step into my virtual police car, that is what I see when I log onto the CPS system . . .IP address . . . the second column is the user name of the user that is reporting files on that IP address.
That user name can be a couple of different ways. . . You can enter your own name when you are running your file sharing client. You can enter a user name. Or you can just allow it to go by default to what we call a G.U.I.D. Now, G.U.I.D. is an acronym for globally unique identifier. A G.U.I.D. is what the file sharing program, or client we call a program, the file sharing client, when it’s installed, this system assigns a G.U.I.D. And it could be easily perhaps understood as the serial number of that search warrant installation.
So when I download and install Shareaza 2.7.0.0. the system would assign me a G.U.I.D. and then that’s the serial number for that software installation on that computer.
If Shareaza then updates to 2.7.0.0. 1 and I update that, it assigns me a new G.U.I.D. because that’s how a serial number for that installation. . . . so every computer has that software installed has a different serial number that we call a G.U.I.D. (T19) [ 16 ] According to Constable Lair, if two people, in the same house downloaded Shareaza on their separate computers, they would have different G.U.I.D. numbers on their installation. [ 17 ] When asked if two people could have the same G.U.I.D. number at the same time, Constable Lair replied that it was mathematically possible but extremely unlikely. (T20) [ 18 ] During the course of his investigation, once Constable Lair logs onto the Child Protection System (CPS), he looks for locations that are in his area of responsibility to investigate and then proceeds to zero in on the IP address.
[ 19 ] The accused came to the attention of Constable Lair during such an investigation into file-sharing. Exhibit P-1 shows how the investigation commenced. The image obtained from the original download ( Exhibit P-2) was described by Constable Lair as follows: In my view that is a young female child approximately six to ten years old laying on a couch with her pants pulled to her knees and her legs up in the air showing her anus and vagina.
In my view, the size of the child, the lack of genital development and facial structure that I see, in my view, that was a child six to ten years old. [ 20 ] In order to obtain the physical address and the name of the subscriber, Constable Lair applied for a Production Order on September 30, 2014. The Production Order, (P-3), asked SaskTel for the name of the customer that was assigned that IP address on that time and date. Constable Lair explained why the request was so specific: As I said earlier, IP addresses can change depending on the needs of the internet service provided.
Therefore, it is important that I determine which internet account on the date that I was exchanging - the date and time that I was exchanging data that I received that download from. At that date and time, that’s when I need to know the physical address and name of that subscriber because two hours later that IP address could be subscribed to someone else. (T35) [ 21 ] Further investigation revealed that Aiden Pratchett was a member of the RCMP O.F.C., Fond-du-Lac, Saskatchewan. [ 22 ] Constable Lair next applied for a search warrant on October 15, 2014.
The search warrant was issued and it authorized the search of the duplex located within the RCMP campground at Fond-du-Lac between the hours of 10:00 a.m. and 6:00 p.m. on October 16, 2014. (Exhibit P-4) [ 23 ] The search warrant authorized a search of the entire duplex. [ 24 ] The search warrant was executed on October 16, 2014.
The search team consisted of Constable Lair; Corporal Jared Clarke, who is an ICE investigator in the RCMP; Constable Lindsey Wall who is a forensic technician with the Saskatoon Police Service ICE unit; Constable Shannon Parker, a Saskatoon Police Service technician with the ICE unit; Staff Sergeant Ron Weir of the Regina Police Service, who is the provincial co-ordinator for the Saskatchewan ICE Unit. [ 25 ] In addition to the ICE team, RCMP Inspector Shelly Dupont and Staff Sergeant Garfiel Elliott were involved. [ 26 ] One unit of the duplex was occupied by Mr.
Pratchett and his spouse, Sarah Colter, while Constable Bobby Michaud lived in the other unit. [ 27 ] After arriving at the campground, Bobby Michaud and Sarah Colter were detained. Mr. Pratchett, who was at the residence following a night shift, was summoned to the detachment by Inspector Dumont. He arrived within six minutes of being called and was promptly detained by Corporal Clarke. [ 28 ] Mr.
Pratchett’s residence was searched - three computers were seized: “one was a laptop computer; one was a desktop computer, and one was a larger tower, a red tower custom built computer.” (T50) [ 29 ] The red tower computer has the operating system encrypted, so that it could not be accessed without a password.
[ 30 ] The red tower computer had three hard drives inside it, and a fourth was found later. Three of the four hard drives were encrypted. [ 31 ] A search of the unit occupied by Constable Bobby Michaud revealed one computer which was non-password protected. Examination of his computer did not yield any child pornography. At that point Constable Michaud’s detention was terminated. [ 32 ] The first interview (Exhibit P-5) with Mr. Pratchett was conducted by Corporal Clarke, while Constable Lair monitored it. The second interview was conducted by Constable Lair, and it took place on the same day.
The first interview lasted about an hour and twenty minutes, while the second one was approximately one-half hour. (Exhibit P-6) [ 33 ] Prior to getting into any serious discussions with Corporal Clarke, Mr. Pratchett requested an opportunity to consult with counsel. This request was granted and Mr. Pratchett was eventually successful in speaking to counsel of his choice. He indicated to Corporal Clarke that he was satisfied with his call. [ 34 ] Every attempt by Corporal Clarke to obtain the password from Mr. Pratchett proved futile. During an interval when Mr.
Pratchett spoke with Sarah Colter, she had indicated to him that her computer was not locked, but that Mr. Pratchett’s was: “yours is locked like Fort Knox apparently which sounds like your computer.” (Exhibit P-5, pg 42) [ 35 ] During the interview with Constable Lair, Mr. Pratchett described himself as being computer savvy: “Ahm. . . I don’t know if you talked to my boss but I’m kind of the Detachment IT guy, right? . . . I’m not by any means an expert.
I don’t know how you guys do what you do, but I am very familiar with computer hardware on the user end.” (Exhibit P-6, pg 3) [ 36 ] During the interview with Constable Lair, Mr. Pratchett again reiterated his position that he was not going to be providing passwords. He also expressed the view that no one he could think of could have been involved: “I can’t in all conscience say that there’s anyone I can think of who would have done this.” (Exhibit P-6, pg 53) [ 37 ] Mr.
Pratchett also stated that he has never had anyone service his computer as he was quite capable of doing it himself. [ 38 ] Exhibit P-8 was a two page document which comprised the Fond-du-Lac RCMP detachment work
schedule from August 21, 2014 to October 15, 2014. Constable Lair testified that he reviewed Mr. Pratchett’s work logs for that time frame: Well, I went through and did an analysis and comparison of his shift
schedule and his work logs. And I compared it to the activity that was flagged by CPS and I found that every time there was activity on the CPS log with respect to his IP address, was a time when he was not on duty. [ 39 ] He was asked: “Between the offence dates that we are talking about on Information 041, so September 29, 2014, to October 16, 2014, what CPS activity did you find that occurred while Mr.
Pratchett was on shift?” Answer: “None”. [ 40 ] Constable Lair testified that CPS has the ability to browse the contents of the shared folder and that he was able to obtain copies of all those files being shared during the entire offence date. [ 41 ] These files were contained on three DVDs labelled Volume 1, Volume 2 and Volume 3 (Exhibit P-9).
[ 42 ] A representative sample from each disc showed these images as described by Constable Lair: Volume 1: It is a female child nude from the waist down on a bed, approximately six to eight years old. She is now - and now we have an adult’s hand fondling her buttocks and anus. And now there’s a still image of an adult penis attempting anal penetration.
The title says, “honey shit lover sex”. (T82) Volume 2: We see a female child lying on top of an adult male, both are nude, and the adult male is attempting vaginal penetration. (T83) Volume 3: We’re seeing a female child approximately five to seven years old performing oral sex on an adult male. (T85) [ 43 ] The last file being flagged by CPS was at 11:32 a.m. on October 16, 2014, the day the search warrant was being executed. This was a minute before Mr. Pratchett was called to attend the RCMP detachment. [ 44 ] On December 22, 2014, Mr.
Pratchett was arrested. [ 45 ] Constable Lair again decided to interview Mr. Pratchett and this time he asked Sergeant Parisien to take part. According to Constable Lair, “. . . I wanted Sergeant Parisien here to be able to answer any technical questions that Mr. Pratchett had that were done above my level of expertise”. (T93) [ 46 ] As the interview progressed, it became apparent that Sergeant Parisien played a much more active role than simply being around to answer Mr. Pratchett’s technical questions.
However, when all was said and done, the investigation was not advanced appreciably by this interview. [ 47 ] Constable Lair presented Mr. Pratchett with a spreadsheet (Exhibit P-11) downloaded from CPS which chronologically set out all of the activity related to his IP address during the time in question, namely September 29, 2014, to October 16, 2014. [ 48 ] The entry on October 16, 2014, was at 11:32 a.m., one minute before Inspector Dupont called Mr. Pratchett and requested that he come to the detachment. Mr.
Pratchett arrived at the detachment at approximately 11:40 a.m., and the ICE team entered the Pratchett residence at 12:13 p.m. They used a key to gain entry and the house was unoccupied. The computer was shut off. [ 49 ] Mr. Pratchett offered the opinion that Constable Lair did not have a “very good understanding of how computers work”. (Exhibit P-10, p 7) [ 50 ] When Sergeant Parisien suggested to Mr.
Pratchett that he and only he could have logged into the “encrypted computer, connected to the internet, searched for and found vile child abuse videos, downloaded them on to your computer and then shared them with the world, just a minute before you were called by the Superintendent. . .”, Mr. Pratchett responded by asking “is your experience with computers, Sergeant, that they only do things that people who are sitting physically at them tell them to do?” [ 51 ] When Sergeant Parisien answered “yes”, Mr. Pratchett stated: “Okay.
Then I don’t think we have anything more to say to each other today. . .” (Exhibit P-10, p 25) [ 52 ] Constable Lair was not cross-examined.
[ 53 ] The Crown’s next witness was Constable Shannon Parker, a forensic computer technician, employed by the Saskatoon Police Service. She became a member of the provincial ICE Unit some 18 months earlier. [ 54 ] Prior to travelling to Fond-du-Lac to take
part in executing the search warrant of Mr. Pratchett’s residence she was briefed as follows: During the briefing Investigator Lair stated that between September 29 and I believe it was October 15 he had received some partial downloads. He had indicated that it was a peer to peer file sharing investigation and that the Shareaza version 2.7.7.0 was responsible. He also provided file name and the hash associated with that and a G.U.I.D. (T110) [ 55 ] Her role was that of an exhibit officer. As the exhibit report (Exhibit P-13) shows, thirty exhibits were seized from the Pratchett residence.
She took 104 photos, 44 of which were assembled and comprise Exhibit P-14. [ 56 ] She testified that the red tower was seized and three hard drives were found in that tower. Later, while looking for a serial number of the tower, she discovered a fourth hard drive. She described this fourth hard drive as exceptional with great storage capability. [ 57 ] She testified that all of the hard drives from the red tower were completely encrypted and, therefore, not accessible to police. (T122) [ 58 ] Another item seized was a router. Constable Parker explained its function as follows: . . .
And so what a router basically does is it directs traffic from the outside world, so the world wide web, the wide area network, and it acts as a bridge from that wide area network to your inside world, to your home network or to your land, your local area network. So it’s a bridge between two networks, first and foremost. And then second of all, it’s going to direct traffic. And we can get into that later. But traffic is going to come into your router, and the router is going to say, I’m going to direct this traffic to the desktop right beside me here. I’m going to direct the traffic to Ms. Colter’s computer.
I’m going to direct this traffic to the laptop or to whatever devices he’s got in the residence. So that’s the gist of what a router is. (T124) [ 59 ] In her opinion, “because the router assigns each device in your home its own internal IP” (T 152), it is not possible that the data packets would end up at some other device. [ 60 ] In this particular case, Cosntable Parker was certain that the Shareaza traffic was destined only for the red computer tower: “Because the internal IP is tied to that VIN number, that MAC address.
And that physical MAC address has been found on the red computer tower.” (T 152) [ 61 ] Constable Parker described a MAC (Media Access Control) as being similar to a VIN (vehicle identification number). Any physical device that has the ability to have network capabilities is assigned a MAC address. So each device, or piece of hardware, has a different MAC address: . . . just like the vehicle example.
It’s a completely distinct, unique address physically assigned to a physical device. (T 140) [ 62 ] Constable Parker was not cross-examined. [ 63 ] The next witness was Sergeant Darren Parisien, who was qualified as an expert in the peer-to-peer file sharing investigation and techniques.
[ 64 ] He describes his duties as follows: I develop and update training as it relates to peer-to-peer file sharing investigation techniques and software. And I coordinate training nationally and internationally regarding peer to peer investigative techniques.
And I’m the lead instructor for that case and have been since 2008. (T 159) [ 65 ] He testified that there are a multitude of file sharing programs, including the Shareaza peer-to-peer file sharing, which “I’ve used . . . a number of times and I’m quite familiar with the software”. (T 167) [ 66 ] Sergeant Parisien testified as to how he became involved in this particular investigation: Well, I learned from the investigators that there was some encryption that was encountered during the search warrant, specifically at least one entire computer was encrypted with a program called True Crypt.
And the investigators were unable to link some of the suspected criminal activity to - concretely to that computer. So I reviewed some of the information in relation to the child protection system logs which are basically created when law enforcement servers and crawlers send out messages to peer networks looking for people who are sources of known illegal files.
So in reviewing that child protection system information I made some observations regarding a port number and program that was used in relation to that computer and I further assisted Constable Parker of the Tech Unit with her examination of a router which was seized from the residence during the search warrant. (T 196) [ 67 ] With respect to the observations he made regarding the port number, he testified as follows: . . . in the port number in relation to the peer-to-peer file sharing application is the conduit for which the activity between the client running on the suspect’s computer and the peer-to-peer network interact by way of sending messages back and forth.
The default port number that is involved with the file sharing application Shareaza is port number 6346. But when you install Shareza on your computer, it needs to assign a port number. So basically a conduit is a port number. If you do nothing when you install the program, it assigns 6346 to your computer, sorry, to that application. But the user has the ability to change that port number. There are about 64,000 ports associated to a router and any one of those, for the most part, any one of those ports are available to transfer information back and forth through your computer to the router.
And in this case the 32888, which was the port number identified through the child protection system all the activity associated to Constable Lair’s investigation, that 32888 is not the standard port number. And I wouldn’t be surprised if I saw 6346, 6347, 6348 because those - sometimes your computer picks a different one, if one is available.
But to see port number 32888, that would be consistent with a user manually changing the port number and entering that port number to be used by the Shareaza file sharing program. (T 197) [ 68 ] Sergeant Parisien also testified about G.U.I.D. numbers, and his review of the G.U.I.D. numbers associated with Mr. Pratchett’s installation of Shareaza. He testified that there were multiple G.U.I.D. numbers and he explained how these could be generated.
So in Shareaza, specifically this version, but a number of Shareaza versions, the user, when they’re running a program, they can simply click on a button and change their G.U.I.D. number. So there’s a button that says, generate new G.U.I.D. So just click on this area under security, you click on certificates and this is a well-known kind of aspect of Shareaza that is not really present in a lot of other peer-to- peer programs.
But in Shareaza you can click on, in the security tab there’s an area that says generate new G.U.I.D. (T 207) [ 69 ] In response to a question of whether another person online on Gnutella, using Shareaza, could change your G.U.I.D. number, Sergeant Parisien’s answer was no: . . . so you can’t change my G.U.I.D. You couldn’t say, add more folders. You couldn’t say show me what else is on your computer. You can’t say auto update this application. None of that.
You can send me a message . . . but other things such as update, change a port, update G.U.I.D., update version, those are all things that an outside user who is interacting with your computer with Gnutella Network has no ability to control or send messages in regards to. (T 208) [ 70 ] Sergeant Parisien prepared a report regarding his investigation of Mr. Pratchett (Exhibit P-17). The report covered the period
from September 15 to October 16, 2014. [ 71 ] In reference to that report, Sergeant Parisien was asked the following: “. . . you indicated in your report that files were downloaded over multiple days during multiple peer-to-peer sessions all linked to the same client and identical port. Is that stating based on what you’ve been telling us here this afternoon?” He answered: Yes. So the internal - or sorry, the public IP address which basically points us to say, house, is the same. So we’re arriving at the same house. And the port umber is the same through all of this.
If you look under column B of the whole entire report, every single instance in here is 32888. And the reason it’s 32888 is because the user, when they set up Shareaza, said, all my Shareaza activity is going to come to the house on port 32888. That’s what I want it to come and go from. So that allows me to determine that it’s likely the same computer. In this case the G.U.I.D. changes and there’s some other factors that are in the lay here. But this progression of files, even with the G.U.I.D. number changing here, this progression of files indicates to me that this is the same user and the same computer.
You can see in this instance there’s five, sorry, six different G.U.I.D.s. Every single - sorry five. Two of them are the same, which is on the same date, both on September 27 th . But the presence of identical files, identical file names, identical port, identical IP address over a standard period of time indicates to me that this is the same computer, the same installation of the program, the same user, the same pool of shared files that are being shared from this computer during this time frame.
And that’s consistent with multiple files across this report. (T 221) [ 72 ] Defence declined to cross-examine Sergeant Parisien. [ 73 ] The next witness was Sergeant Joel Bautista, a member of the Saskatoon City Police force for thirteen years - and with the ICE unit since 2009. He is a forensic technician. His involvement in the investigation started November 19, 2014, when he was asked to analyze the My Cloud storage device - which was one of the 30 exhibits seized during the search of Mr.
Pratchett’s residence. [ 74 ] He described My Cloud as follows: Basically, Your Honour, a My cloud device is a device that can be accessed in your own network. So with a My Cloud the advantage of a My Cloud is the fact that it can hold a large amount of data and since it’s connected within your network, it can be accessed via a laptop, a stand alone desk top computer, anything connected within your network. This device consisted of four hard drives. Each hard drive was 2 terabytes in size for a total data storage size of 8 terabytes.
Basically a My Cloud is a personal, I want to say, cloud storage device for the home use. (T 231) [ 75 ] He testified that each hard drive was re-attached into the My Cloud, and, once operational, hooked up to a forensic laptop. This meant that Sergeant Bautista could view on the laptop what the user would be viewing if he were to go into the My Cloud. (T233) [ 76 ] Sergeant Bautista testified that he went through every folder on this device. The database where the passwords are kept was encrypted. [ 77 ] He was asked: “So were you able to get into that database?” His answer: No.
So what I did was for a period of roughly five days, I attempted a quick brute force attack. Brute force attack basically takes all possible character combinations and tries to force that into the program in order to get it open. It’s not 100% full proof, but I wanted to see the complexity, possible complexity of this suspect’s password. And this was my first, if you want to say, introduction into it. Usually if a password is simple, may be less than eight characters, may be all upper case, all lower case, depending on the brute force attack, it would be in a matter of minutes or seconds.
This was a little test to see just the password strength of the actual key pass. And in this case from November 25, 2014 to December 2, 2014, it was unsuccessful. (T 235) [ 78 ] During that time, if the program used was averaging some 20,000 passwords per second, billions of attempts would have been made to get into this key pass.
[ 79 ] Sergeant Bautista was not cross-examined. [ 80 ] The next Crown witness was Constable Lindsey Wall, a member of the Saskatoon Police Service, and since October of 2013 assigned to the provincial ICE Unit. He described himself as a forensic technician. [ 81 ] He prepared a forensic report (Exhibit P-21), and much of his testimony related to that report. [ 82 ] He was a member of the team that entered Mr. Pratchett’s residence. His objective was to gather as much evidence as possible in a short period of time. To this end, he would attempt to access Mr.
Pratchett’s computer. [ 83 ] He was asked: “And how successful were you in doing that when it came to Mr. Pratchett’s computer?” Answer: Not very successful. . . when I first walked over to Mr. Pratchett’s computer, the monitor was off. I moved the mouse. When I moved the mouse, the monitor activated, and this is the screen that came up when I moved that mouse. That’s again taken with my small camera. It’s not very clear. But True Crypt Boot Loader 7.1A, and it requires a password. (T 250) [ 84 ] He described True Crypt: . . . as an encryption program.
So True Crypt - it’s freely available on the internet for download and it basically locks your computer. It’s different than a Windows password that in this instance, with the boot loader, you can’t even access the operating system. You need to provide a password before the operating system will load. (T 250) [ 85 ] He described the difference between a Windows password and a True Crypt as follows: If we were to think of a Windows password say just a door to a room, with a Windows password with the forensic tools that we have, the forensic tools that we have don’t recognize that Windows password.
So we’re able to view the system. The system is up and running. I can view the system. I can triage. I can do - I can use any of my other tools on that system. So if that’s a room, Windows password, you can get in through the window and I can see everything in that room as it should be. If we’re still thinking of the computer as a room with the encryption software True Crypt, I need the keys to get into that room. If I don’t have the keys, number 1, I can’t get in. I can’t get in through the window.
Even if I could get in through a window, everything in that room would be so disorganized you wouldn’t even recognize what you’re looking at in that room. So even if I manage to use my forensic tools to access this drive, all the information on that drive is completely useless to me unless I have the proper keys to put everything back together. (T 251) [ 86 ] Constable Wall testified that he was allowed full access to Sarah Colter’s computer. It was running and he did not need a password to view it. He did not find anything relevant to the investigation on Ms.
Colter’s computer. [ 87 ] Constable Wall also examined Constable Michaud’s computer and did not find anything relevant on it. Constable Michaud’s computer had a different IP address and a different wi-fi address than Mr. Pratchett’s. [ 88 ] Constable Wall testified that Mr. Pratchett’s red computer had four hard drives - PE 17, PE 18, PE 19 and PE 30. [ 89 ] He examined PE 17 at the Pratchett residence:
At the scene I did a quick triage. So I basically looked for items that I believed would provide us evidence for our investigation. I looked through file folders, I ran some key word searches. I looked specifically for Shareaza, the downloading program that we believed was used.
I did find the Shareaza version 2.7.7.0 executable file on PE 17. (T 258) [ 90 ] He described an “executable file” as being “the file that you would click on to launch the program, or to start the program”. (T 258) In other words, the executable file is only the springboard to start the program, but the program still needs the configuration files in order to actually function.” (T 259) [ 91 ] None of the configuration files were found on PE 17.
According to Constable Wall’s testimony, the executable file for Shareaza version 2.7.7.0 was created on September 15, 2014. [ 92 ] Constable Wall was not able to access the other three hard drives (PE 18, PE 19 and PE 30) as all of those drives were encrypted. [ 93 ] By further analyzing the hard drive (PE 17), Constable Wall concluded that the files that he was able to locate on Mr. Pratchett’s computer were a match for the files he was provided by Constable Lair: With the CPS list I was given by Constable Lair, those files contained hash values as well. So the DNA to those files.
What I did was I ran these files that I found through a hashing program. So I hashed these files as well and found that they were an exact match for the files on Constable Lair’s CPS list. (T 265) [ 94 ] Constable Wall was asked: “So if I understand your overall forensic analysis correctly, you found the Shareaza version that Constable Lair was investigating on the one unencrypted drive on the red tower computer?” Answer: “Yes.” (T 294) [ 95 ] Defence did not cross-examine Constable Wall. Crown did not call further evidence. [ 96 ] Mr. Pratchett testified.
His examination-in-chief was brief and succinct - so much in fact, that I reproduce it here in its entirety: Q Mr. Pratchett, you’re the accused in these proceedings obviously. A Yes. Q I want to take you back to the day that the officers came to Fond-du-Lac, October 16 th of last year, just not quite a year ago. And we’ve heard you were residing there, correct? A That’s correct. Q Who was your employer then? A The RCMP. Q And the October 16 th meeting with the police, as we’ve seen, you were interviewed twice, at the Fond-du-Lac detachment that
day that was video taped, correct? A Yes. Q And you had a chance to watch those subsequently, here in court for instance, correct? A That’s correct. Q And were you attempting to tell the truth when you were answering those questions? A Yes, I was. Q Subsequent to that, just over two months later on December 22 nd , during that interval you hadn’t been charged, correct, during that interval? A That’s correct. Q And you hadn’t been provided with disclosure during that interval. A No, I had not. Q And on December 22 nd when charges were proceeded with you were interviewed again. A Yes. Q Okay.
At that time you’ve seen the video here in court. A Yes. Q Were you attempting to tell the truth in that interview? A Yes, I was. Q Now, I want to ask you specifically, have you ever downloaded child pornography? A No, I have not. Q Have you ever possessed child pornography?
A No, I have not. Q Do you have any interest in children in a sexual way? A No, I do not. Q Did you commit the offences that are alleged against you? A No, I do not. Cross-examination of Mr. Pratchett [ 97 ] Mr. Pratchett acknowledged that he had an interest in computers; that he was enrolled in the Bachelor of Science in Computer Technology program through Athabasca University; and that his understanding of computers exceeded that of most average persons.
He, in fact, built the red tower computer. [ 98 ] He agreed that others at the RCMP detachment in Fond-du-Lac would look to him for advice and assistance if they encountered any problems with their computers. [ 99 ] He agreed that he was concerned with security as it pertained to his computer, but expressed no specific concerns about it being stolen from or tampered with, at the RCMP detachment. [ 100 ] Mr. Pratchett acknowledged that the laptop computer and Ms.
Colter’s computer had single Windows passwords but were not encrypted with True Crypt. [ 101 ] He was questioned as to why he was prepared to provide some passwords, including his work drives, but not the password to his red computer. He responded that he was simply following legal advice to not provide personal passwords. [ 102 ] However, he also agreed that even after receiving legal advice he was prepared to give up some passwords, but not the one to the red computer. [ 103 ] Mr. Pratchett explained why he used encryption: I was not using the encryption in that fashion.
I was not concerned that someone would come into my house and access my computer while I was away. My concern was that the computer would be stolen in which case it would be turned off or powered off at which point the password would assert itself. But in the ordinary use, the computer is on and it’s logged in. The password isn’t necessary. (T 317) [ 104 ] That answer led to this exchange: Lines 1 - 32, page T318: Q Okay. And how do you activate your encryption, Mr. Pratchett?
A Sorry. What do you mean by activate? Q Well, if I’m using your red tower computer, how do we get to the black screen that we saw during Constable Wall’s presentation this morning. A You turn - Q What has to happen? A You turn on the computer. Q Okay. But if I’m already using it and I am surfing the web on Firefox and I walk away from the computer, does it automatically go to that black screen? A No. Q So what has to happen? A It would have to be turned off or re-started.
Q So when the police entered your home, it’s fair to say that before they entered your home, the computer had either been turned off or re-started. A Yes. Q Okay. And for anything to work on that computer and to get past the True Crypt encryption, logically then it has to be turned on, right? The computer has to be on. A Yes. Q And you and I can agree that in the minutes before Inspector Dupont called you to come to the detachment you were inside your residence. A Yes. Q And other than I’m guessing your cat, you were alone? A Yes. [ 105 ] Mr.
Pratchett was next asked if someone “is smart enough to know the user name and the password for your router, you would
agree with me that it would be virtually impossible to randomly guess your password for your True Crypt encryption”. His answer: “ I agree, yes.” [ 106 ] Further: Q “Yes, in fact, we’ve heard the evidence that the police have tried over 3 trillion combinations and have not gained access, right?” Answer: “Yes”. (T 321) [ 107 ] Mr. Pratchett also conceded that he monitored his computer fairly closely and “. . . kept a close eye on the band width being used” (T 322), and that band width would be affected by files being uploaded or downloaded. [ 108 ] In the same vein, Mr.
Pratchett agreed that he had his computer locked up to keep people out: I wanted to be there when they did the search warrant, just so I could, you know - I don’t like the idea of people in my house when I am not there. You know, the cat’s in her blanket. I know they’re worried that we might somehow delete something, but cuff me. I don’t care. I just t[sic] be there when they’re in my house. I’m private about that kind of shit. Same reason I had my computer locked up. (T 331) Position of the Parties Defence [ 109 ] Defence submits that although Mr.
Pratchett is probably the most logical suspect, that does not establish guilt.
He took the stand in his own defence and categorically denied downloading or possessing child pornography. [ 110 ] He was not able to explain how the child pornography ended up on his computer, but the accused does not bear this burden. [ 111 ] Defence argued that the accused did not try to blame anyone else at the detachment, or his spouse, for accessing or tampering with his computer; a fact that should bolster his credibility. [ 112 ] Further, defence argued that no negative inference should be made against the accused for not giving up or surrendering his password as he was simply following legal advice and exercising his right to remain silent. [ 113 ] Defence counsel concluded his remarks with these words: And in this case I suggest that his evidence is that he is innocent and that he has met the burden that is upon him to raise that reasonable doubt.
And the fact that we can’t prove who did it, that’s not our burden. (T 337) Crown [ 114 ] The Crown submits that all elements of the offences have been established. That the material in question is child pornography within the definition of the Criminal Code , and that the accused had knowledge and control of the illegal material. [ 115 ] The Crown further argues that the massive body of evidence presented at trial by all of the Crown witnesses went completely unchallenged.
Therefore, taking the totality of the evidence into account, and the inferences that can be drawn from that evidence, the Crown contends that it has proven the accused’s guilt beyond a reasonable doubt.
Analysis [ 116 ]
Section 163.1(1) reads as follows: 163.1(1) In this section, “child pornography” means (
a) a photographic, film, video or other visual representation, whether or not it was made by electronic or mechanical means, (
i) that shows a person who is or is depicted as being under the age of eighteen years and is engaged in or is depicted as engaged in explicit sexual activity, or (ii) the dominant characteristic of which is the depiction, for a sexual purpose, of a sexual organ or the anal region of a person under the age of eighteen years; (
b) any written material, visual representation or audio recording that advocates or counsel sexual activity with a person under the age of eighteen years that would be an offence under this Act; (
c) any written material whose dominant characteristic is the description, for a sexual purpose, of sexual activity with a person under the age of eighteen years that would be an offence under this Act; or (
d) any audio recording that has as its dominant characteristic the description, presentation or representation, for a sexual purpose, of sexual activity with a person under the age of eighteen years that would be an offence under this Act. [ 117 ]
Section 163.1(4) of the Criminal Code states:
(4.2) For the purposes of subsection (4.1), a person accesses child pornography who knowingly causes child pornography to be viewed by, or transmitted to, himself or herself. [ 118 ] At the outset, it is my finding that the material viewed (Exhibits P-2, P-7, and P-9) , meets the definition of child pornography as defined in the Criminal Code .
These were very young children in sexually explicit situations. [ 119 ] With respect to possession, the Supreme Court addressed comprehensively the various requirements which the Crown has to prove in R v Morelli [1] : Firstly, the accused has to have knowledge of the material; secondly, the accused knowingly keeps or shares the material in a specific or particular place; and, thirdly, the accused intends to have the material for his own use or benefit. In order to establish the above, the Crown has to prove that the accused had sufficient control over the material in question.
By proving that the accused knowingly stored and retained the material throughout the time in question, the Crown would satisfy the mens rea requirement.
[ 120 ] The accused is charged with possession of child pornography and, secondly, of accessing child pornography. [ 121 ] The evidence adduced by the Crown was not challenged as none of the Crown witnesses were cross-examined. [ 122 ] It is worth mentioning that all of the witnesses, including the accused, have a great deal of technological expertise and sophistication.
So even though only one of the witnesses was qualified as an expert, it could easily be said that all of the witnesses were experts in their own right when it comes to Internet and computer technology. [ 123 ] The first witness, Constable Lair, testified that he commences his investigation if the child protection system flags an IP address as being in possession of child pornography. [ 124 ] In this case, Constable Lair obtained a Production Order which pointed to Mr.
Pratchett of Fond-du-Lac, SK as being the person behind the IP address sharing the child pornography. [ 125 ] Following the execution of the Search Warrant, police seized a number of devices including Mr. Pratchett’s red computer. [ 126 ] As already outlined previously when examining the various witnesses’ testimony, all evidence pointed towards the accused’s computer network and the Gnutella network. Only the accused had access to his computer and only he knew what the password was. No one at the RCMP detachment in Fond-du-Lac, or in the Pratchett residence had access to the red computer.
Sarah Colter did not know the password to the red computer and there is no evidence that she ever used it. There was no child pornography on her computer. In my view, there is absolutely no evidence to suggest that she may have been involved in any way. [ 127 ] The evidence, primarily through Constable Parker, establishes that all the material, all the Sharaeza traffic, came into the accused’s residence through a router that directed everything to the red computer only. [ 128 ] The notion that someone could, either through luck or skill, access Mr. Pratchett’s red computer seems extremely unlikely.
The best forensic technicians from the ICE Unit - after attempting some three trillion possible configurations or combinations - were unable to figure out or get past the True Crypt Boot Loader. [ 129 ] Mr. Pratchett himself was not surprised that the encryption system was so formidable. [ 130 ] This fact, combined with Mr. Pratchett’s diligence in regularly checking his band width usage, makes it highly unlikely that he would not have been aware if a hacker had been using his computer. He was a sophisticated and frequent user of the system. He was on his computer on a daily basis.
It is unlikely that he would be unaware of someone downloading material onto his computer. Moreover, Mr. Pratchett had other material, like car manuals that he said were his and which he referred to, in the shared folder. Undoubtedly, when accessing such a shared folder, it would have been virtually impossible not to notice the explicit and eye-catching pornographic files. [ 131 ] Further, the evidence (Exhibit P-11) shows that the only time the CPS is flagging files and noting activity is when Mr.
Pratchett is off duty and at home. [ 132 ] On the day of the search warrant execution, October 16, 2014, at 11:32 a.m., the computer was running. The accused was summoned to the detachment a few minutes later and when the police entered the locked residence a short time later, it was turned off. No one was at home. The inescapable conclusion is that it was Mr. Pratchett who turned it off.
[ 133 ] According to Constable Wall’s testimony, the operating system on Mr. Pratchett’s computer could not be accessed remotely. [ 134 ] All of the Crown witnesses, from Constable Lair to Constable Wall, were convinced that it was Mr. Pratchett who controlled the flow of traffic to the red computer and that only he had access.
That testimony was not challenged. [ 135 ] Accessing child pornography is defined in subsection (4.2): For the purposes of subsection (4.1), a person accesses child pornography who knowingly causes child pornography to be viewed by, or transmitted to, himself or herself. [ 136 ] The accused took the stand and denied possessing or accessing child pornography. He had no explanation or knowledge as to how the child pornography ended up in his folders. In fairness, the accused is not required to explain anything or disprove anything.
The burden falls on the Crown to prove its case beyond a reasonable doubt. [ 137 ] While there is conflict, or contradictory evidence, particularly between an accused who gives exculpatory evidence, and one or more witnesses who contradict and call into question the accused’s credibility, the direction given by the Supreme Court in R v W(D) [2] is instructive. The test is as follows: Firstly, if you believe the evidence of the accused, obviously you must acquit. Second, if you do not believe the testimony of the accused but you are left in reasonable doubt by it, you must acquit.
Third, even if you are not left in doubt by the evidence of the accused, you must ask yourself whether, on the basis of the evidence which you do accept, you are convinced beyond a reasonable doubt by that evidence of the guilt of the accused. [ 138 ] A denial does not create a reasonable doubt any more than a complaint or charge establishes proof of an offence having been committed. The testimony of the accused should not be analyzed separately. Rather, it should be weighed and evaluated in light of all the evidence. [ 139 ] Having regard to all of the Crown’s evidence, I reject the accused’s evidence.
I found all of the Crown witnesses to be forthright and credible. In contrast, Mr. Pratchett was less forthcoming. Segments of what he said to the investigating officers during the interviews, and later his testimony at trial, were contradictory and at odds to the evidence provided by other witnesses whom I found credible. [ 140 ] He testified that usually his computer was on and logged in, so that a password would not be necessary to use it (T 317). However, Sarah Colter, when speaking to Mr.
Pratchett during one of his interviews, stated that he had the computer locked up like Fort Knox. [ 141 ] He told the interviewer that he took a casual approach to the “pc hygiene” (Exhibit P-6, p 28) and that as a result he was some “80 Windows updates behind because I don’t usually turn my computer off”. ( Ibid) [ 142 ] Yet he acknowledged that he was very security conscious and didn’t like “people in my shit”. (Exhibit P-5, p 63)
[143] Mr. Pratchett stated during the interview that he used the Shareaza program previously, but not for the last couple of years. Theexpert testimony of Sergeant Parisien, which I accept, suggests that the version used by Mr. Pratchett only came out on September 13,2014, mere days before the alleged offence dates. [144] Having rejected the testimony of the accused, before I can convict, I have to be convinced beyond a reasonable doubt of hisguilt based on the whole of the evidence. [145] The reasonable doubt standard is an exacting standard of proof.
It is not proof to an absolute certainty, or beyond any doubt[3],but it requires a great deal of certainty. It relies to a certain degree on reason and common sense. [146] Relying on this definitive standard, the Crown must prove guilt beyond a reasonable doubt. This burden carries with it the dutyof excluding all rational conclusions alternative to guilt. [147] In this case the Crown has met this burden. I found the Crown witnesses, without exception, to be knowledgeable and crediblewitnesses.
Their testimony was not challenged. [148] Examining the totality of the evidence, there is no evidentiary foundation for the presence of the child pornography in theaccused’s computer other than that the accused was responsible for it being there. [149] The presence of the pornography on the accused’s computer, a computer he guarded assiduously, is a powerful piece ofevidence linking the accused to the offence. [150] There is no evidence that anyone other than the accused ever used the red computer.
In light of this, the notion that someoneother than the accused was responsible is without merit. [151] The accused was a sophisticated and frequent user of the system. He was on his computer on a daily basis. To suggest that hewould be unaware of someone, perhaps a hacker, let’s say, of downloading material onto his computer is fanciful and defies logic. Inshort, I find that Mr.
Pratchett had knowledge of the material stored in his computer; that he had control over it; and that he knowinglystored and retained the material throughout the time in question. [152] In short, all evidence points towards the accused as being guilty of the offences he is being charged with. Accordingly, I findhim guilty as charged. ________________________ M.M. Baniak, J [1] R v Morelli, 2010 SCC 8 , [2010] 1 SCR 253. [2] R v W(D), (SCC), [1991] 1 SCR 742.
[3] R v Lifchus (1997), (SCC), 5 CR (5th) 1 SCC (para 36).
Loading document…