United States v. Kienast
A Seventh Circuit decision applying the good-faith exception to the FBI’s use of a Network Investigative Technique warrant to identify anonymous users of a dark-web website.
Executive Summary
The FBI seized control of Playpen, a child-pornography website operating through the Tor network, and temporarily ran it from a government server in Virginia. Because Tor concealed users’ actual IP addresses and locations, agents obtained a warrant from a magistrate judge in the Eastern District of Virginia authorizing a Network Investigative Technique. When a user logged in, code sent from the government-controlled website caused the user’s computer to transmit identifying information to the FBI. The technique identified users located outside Virginia, after which local agents obtained conventional warrants for their homes and devices. Defendants argued that the magistrate judge lacked territorial authority under the version of Federal Rule of Criminal Procedure 41 then in effect. The Seventh Circuit assumed without deciding that the warrant was invalid but refused suppression because agents fully disclosed the technique, obtained judicial approval, and acted in objectively reasonable reliance on the warrant.
Key Holdings at a Glance
The Playpen Investigation
Playpen was a global online forum accessible only through Tor, software designed to conceal a user’s true IP address and location. The FBI obtained control of the website and operated it for a limited period from a server in Newington, Virginia.
Ordinary server logs would reveal only Tor-related routing information rather than a user’s actual address. Agents therefore sought judicial authority to deploy code that could cause a logging-in user’s computer to provide identifying information directly.
How the Network Investigative Technique Worked
The NIT was delivered when an authenticated Playpen user accessed the government-controlled site. It caused the activating computer to transmit limited identifying data, including its true IP address, operating-system information, host name, and other identifiers, to an FBI-controlled computer.
The technique did not depend on knowing where the activating computer was located. Concealment of location was the investigative problem the code was designed to solve.
The Eastern District of Virginia Warrant
The supporting affidavit told the magistrate judge that the website’s users could be located anywhere and that the NIT would collect identifying information from activating computers. The warrant authorized deployment against users who logged in with valid credentials during the operational period.
After an IP address identified a user outside Virginia, agents in that user’s district sought a separate warrant to search the person’s residence and electronic devices. Those later searches produced the evidence challenged on appeal.
The Former Rule 41 Territorial Problem
At the time, Rule 41(b) generally limited a federal magistrate judge’s warrant authority to persons or property within the issuing district, subject to specified exceptions. The NIT reached activating computers whose locations were unknown and often outside the Eastern District of Virginia.
The defendants argued that the magistrate judge had no authority to authorize those remote searches. Rule 41 was later amended to address remote access when technological means conceal the location of electronic storage media or information.
Why the Good-Faith Exception Applied
Agents did not conduct a secret warrantless hack and ask for forgiveness later. They prepared a detailed affidavit, disclosed the mechanics and extraterritorial implications, presented the request to a neutral magistrate judge, and executed the resulting authorization as written.
The court found no evidence that agents misled the judge, withheld material facts, relied on a bare-bones affidavit, or exceeded the warrant. Because reasonable judges disagreed about the legal issue, the agents’ reliance could not be characterized as obviously unlawful.
Exclusion and Police Deterrence
The exclusionary rule is designed to deter deliberate, reckless, grossly negligent, or recurring police misconduct. It is not an automatic personal remedy for every warrant defect.
Suppressing the evidence in Kienast would primarily punish agents for submitting a candid application and deferring to a judge. The Seventh Circuit saw little deterrent benefit in encouraging officers to avoid judicial review when confronting new technology.
What Kienast Does—and Does Not—Establish
- It does not definitively validate the original NIT warrant.
- It does not hold that government hacking is never a Fourth Amendment search.
- It does not authorize undisclosed remote access or collection beyond a warrant.
- It does not excuse a knowingly false, reckless, or materially incomplete affidavit.
- It applies suppression doctrine, not a universal operational rule for remote searches.
- Current applications must use the amended Rule 41 and controlling statutes and precedent.
Kienast and Related Remote-Search Decisions
| Case | Issue | Central Rule |
|---|---|---|
| United States v. Kienast | Original Playpen NIT warrant | Good-faith reliance defeated suppression despite assumed territorial invalidity. |
| United States v. Grisanti | Renewed challenge to the same warrant | Kienast controlled; disagreement over warrant authority did not defeat good faith. |
| United States v. Dorosheff | DOJ knowledge and Rule 41 amendment | Efforts to clarify Rule 41 did not establish bad faith by the applying agents. |
| United States v. Brewer | Vehicle tracker beyond state boundary | Territorial state-law noncompliance did not itself require federal suppression. |
Agency Operations Checklist
- Identify the triggering conduct and target class with objective specificity.
- Explain why ordinary investigative tools cannot reveal the concealed location or identity.
- Describe the remote-access code and every category of information it will return.
- Identify the issuing court’s territorial and statutory authority under current law.
- Set deployment, duration, access, minimization, retention, deletion, and termination limits.
- Separate identification data from communications content and stored files.
- Use local follow-up warrants before searching identified residences or devices.
- Preserve source code versions, affidavits, warrants, deployment logs, server logs, returns, security records, and chain of custody.
Litigation and Review Checklist
- Determine which version of Rule 41 applied when the warrant issued.
- Identify the precise technical operation performed on the target computer.
- Compare the affidavit’s description with actual deployment and data collection.
- Analyze territorial authority separately from probable cause and particularity.
- Determine whether agents disclosed that target locations were unknown.
- Test for misleading statements, material omissions, facial deficiency, or scope violations.
- Trace derivative evidence through each later local warrant.
- Evaluate whether existing law was settled enough to make reliance objectively unreasonable.
Frequently Asked Questions
Did Kienast hold that the NIT warrant was valid?
No. The court assumed a defect for purposes of analysis and resolved the appeal under the good-faith exception.
Why did agents need the NIT?
Tor concealed the true IP addresses and physical locations of Playpen users. The NIT caused an activating computer to transmit identifying data.
Why might the magistrate have lacked authority?
The former Rule 41 generally limited warrant authority to persons or property within the issuing district, while the activating computers were located elsewhere.
Why was evidence not suppressed?
Agents candidly disclosed the technology, obtained a warrant, acted within its scope, and relied on a judge’s resolution of unsettled law.
Does amended Rule 41 now address concealed locations?
Yes. Rule 41(b)(6) authorizes specified remote-access warrants when technological means conceal the location of electronic storage media or information.
Primary Authorities and Related Law
Published appellate opinion applying good faith to the Playpen NIT warrant.
Read the complete opinion
Supreme Court decision establishing the warrant-reliance good-faith exception.
Read United States v. Leon
Current federal warrant rule, including remote-access authority for concealed locations.
Read Rule 41
Later Seventh Circuit application of Kienast to the same NIT warrant.
Read United States v. Grisanti
Final Assessment
United States v. Kienast is a leading example of suppression doctrine adapting to novel investigative technology. The court did not give remote hacking a constitutional blank check. It instead focused on agent conduct: detailed disclosure, judicial authorization, compliance with the warrant, and reasonable reliance amid unsettled law.