Shield Public Safety Training · Police Technology Case Law Center

United States v. Kienast

907 F.3d 522 (7th Cir. 2018)

A Seventh Circuit decision applying the good-faith exception to the FBI’s use of a Network Investigative Technique warrant to identify anonymous users of a dark-web website.

CourtU.S. Court of Appeals, Seventh Circuit
DecisionOctober 23, 2018
Consolidated AppealsFour Playpen defendants
OpinionJudge Amy Coney Barrett
TechnologyNetwork Investigative Technique
NetworkTor anonymizing network
Warrant CourtEastern District of Virginia
Territorial IssueFormer Rule 41(b)
Decision GroundGood-faith exception
DispositionSuppression denied

Executive Summary

The Case in One Paragraph

The FBI seized control of Playpen, a child-pornography website operating through the Tor network, and temporarily ran it from a government server in Virginia. Because Tor concealed users’ actual IP addresses and locations, agents obtained a warrant from a magistrate judge in the Eastern District of Virginia authorizing a Network Investigative Technique. When a user logged in, code sent from the government-controlled website caused the user’s computer to transmit identifying information to the FBI. The technique identified users located outside Virginia, after which local agents obtained conventional warrants for their homes and devices. Defendants argued that the magistrate judge lacked territorial authority under the version of Federal Rule of Criminal Procedure 41 then in effect. The Seventh Circuit assumed without deciding that the warrant was invalid but refused suppression because agents fully disclosed the technique, obtained judicial approval, and acted in objectively reasonable reliance on the warrant.

Core RuleWhen agents fully disclose a novel remote-search technique and reasonably rely on a magistrate judge’s warrant amid unsettled territorial law, the good-faith exception may defeat suppression even if the judge lacked authority to issue the warrant.

Key Holdings at a Glance

Underlying Validity ReservedThe court assumed a Rule 41 or constitutional defect without definitively deciding it.
Full Technical Disclosure MatteredThe affidavit explained how the NIT would reach users whose locations were concealed.
Judicial Error Is DifferentThe exclusionary rule principally deters culpable police misconduct, not a magistrate’s legal mistake.
Novel Law Supported RelianceConflicting judicial decisions showed that the territorial question was genuinely unsettled.
Derivative Warrants SurvivedEvidence obtained through later local warrants was not suppressed.
Suppression Is a Last ResortExclusion was disproportionate where agents followed a detailed judicial process in good faith.

The Playpen Investigation

Playpen was a global online forum accessible only through Tor, software designed to conceal a user’s true IP address and location. The FBI obtained control of the website and operated it for a limited period from a server in Newington, Virginia.

Ordinary server logs would reveal only Tor-related routing information rather than a user’s actual address. Agents therefore sought judicial authority to deploy code that could cause a logging-in user’s computer to provide identifying information directly.

How the Network Investigative Technique Worked

The NIT was delivered when an authenticated Playpen user accessed the government-controlled site. It caused the activating computer to transmit limited identifying data, including its true IP address, operating-system information, host name, and other identifiers, to an FBI-controlled computer.

The technique did not depend on knowing where the activating computer was located. Concealment of location was the investigative problem the code was designed to solve.

Technology DisclosureDescribe the triggering event, code delivery, data returned, destination server, duration, target class, minimization, security controls, and whether the technique accesses information stored inside a protected computer.

The Eastern District of Virginia Warrant

The supporting affidavit told the magistrate judge that the website’s users could be located anywhere and that the NIT would collect identifying information from activating computers. The warrant authorized deployment against users who logged in with valid credentials during the operational period.

After an IP address identified a user outside Virginia, agents in that user’s district sought a separate warrant to search the person’s residence and electronic devices. Those later searches produced the evidence challenged on appeal.

The Former Rule 41 Territorial Problem

At the time, Rule 41(b) generally limited a federal magistrate judge’s warrant authority to persons or property within the issuing district, subject to specified exceptions. The NIT reached activating computers whose locations were unknown and often outside the Eastern District of Virginia.

The defendants argued that the magistrate judge had no authority to authorize those remote searches. Rule 41 was later amended to address remote access when technological means conceal the location of electronic storage media or information.

Issue AvoidedKienast did not conclusively decide whether the warrant violated Rule 41 or the Fourth Amendment. It resolved the cases through the good-faith exception.

Why the Good-Faith Exception Applied

Agents did not conduct a secret warrantless hack and ask for forgiveness later. They prepared a detailed affidavit, disclosed the mechanics and extraterritorial implications, presented the request to a neutral magistrate judge, and executed the resulting authorization as written.

The court found no evidence that agents misled the judge, withheld material facts, relied on a bare-bones affidavit, or exceeded the warrant. Because reasonable judges disagreed about the legal issue, the agents’ reliance could not be characterized as obviously unlawful.

Good-Faith PrincipleSuppression is generally inappropriate when officers act within the scope of a warrant and reasonably rely on the issuing judge’s resolution of a novel legal question.

Exclusion and Police Deterrence

The exclusionary rule is designed to deter deliberate, reckless, grossly negligent, or recurring police misconduct. It is not an automatic personal remedy for every warrant defect.

Suppressing the evidence in Kienast would primarily punish agents for submitting a candid application and deferring to a judge. The Seventh Circuit saw little deterrent benefit in encouraging officers to avoid judicial review when confronting new technology.

Critical QualificationGood faith weakens when agents obscure the technology, misstate its scope, omit known jurisdictional problems, use the technique beyond authorization, or rely on a warrant so facially deficient that no reasonable officer could accept it.

What Kienast Does—and Does Not—Establish

  • It does not definitively validate the original NIT warrant.
  • It does not hold that government hacking is never a Fourth Amendment search.
  • It does not authorize undisclosed remote access or collection beyond a warrant.
  • It does not excuse a knowingly false, reckless, or materially incomplete affidavit.
  • It applies suppression doctrine, not a universal operational rule for remote searches.
  • Current applications must use the amended Rule 41 and controlling statutes and precedent.

Kienast and Related Remote-Search Decisions

CaseIssueCentral Rule
United States v. KienastOriginal Playpen NIT warrantGood-faith reliance defeated suppression despite assumed territorial invalidity.
United States v. GrisantiRenewed challenge to the same warrantKienast controlled; disagreement over warrant authority did not defeat good faith.
United States v. DorosheffDOJ knowledge and Rule 41 amendmentEfforts to clarify Rule 41 did not establish bad faith by the applying agents.
United States v. BrewerVehicle tracker beyond state boundaryTerritorial state-law noncompliance did not itself require federal suppression.

Agency Operations Checklist

  1. Identify the triggering conduct and target class with objective specificity.
  2. Explain why ordinary investigative tools cannot reveal the concealed location or identity.
  3. Describe the remote-access code and every category of information it will return.
  4. Identify the issuing court’s territorial and statutory authority under current law.
  5. Set deployment, duration, access, minimization, retention, deletion, and termination limits.
  6. Separate identification data from communications content and stored files.
  7. Use local follow-up warrants before searching identified residences or devices.
  8. Preserve source code versions, affidavits, warrants, deployment logs, server logs, returns, security records, and chain of custody.

Litigation and Review Checklist

  • Determine which version of Rule 41 applied when the warrant issued.
  • Identify the precise technical operation performed on the target computer.
  • Compare the affidavit’s description with actual deployment and data collection.
  • Analyze territorial authority separately from probable cause and particularity.
  • Determine whether agents disclosed that target locations were unknown.
  • Test for misleading statements, material omissions, facial deficiency, or scope violations.
  • Trace derivative evidence through each later local warrant.
  • Evaluate whether existing law was settled enough to make reliance objectively unreasonable.

Frequently Asked Questions

Did Kienast hold that the NIT warrant was valid?

No. The court assumed a defect for purposes of analysis and resolved the appeal under the good-faith exception.

Why did agents need the NIT?

Tor concealed the true IP addresses and physical locations of Playpen users. The NIT caused an activating computer to transmit identifying data.

Why might the magistrate have lacked authority?

The former Rule 41 generally limited warrant authority to persons or property within the issuing district, while the activating computers were located elsewhere.

Why was evidence not suppressed?

Agents candidly disclosed the technology, obtained a warrant, acted within its scope, and relied on a judge’s resolution of unsettled law.

Does amended Rule 41 now address concealed locations?

Yes. Rule 41(b)(6) authorizes specified remote-access warrants when technological means conceal the location of electronic storage media or information.

Primary Authorities and Related Law

United States v. Kienast, 907 F.3d 522 (7th Cir. 2018)
Published appellate opinion applying good faith to the Playpen NIT warrant.
Read the complete opinion
United States v. Leon, 468 U.S. 897 (1984)
Supreme Court decision establishing the warrant-reliance good-faith exception.
Read United States v. Leon
Federal Rule of Criminal Procedure 41
Current federal warrant rule, including remote-access authority for concealed locations.
Read Rule 41
United States v. Grisanti, 943 F.3d 1044 (7th Cir. 2019)
Later Seventh Circuit application of Kienast to the same NIT warrant.
Read United States v. Grisanti

Final Assessment

United States v. Kienast is a leading example of suppression doctrine adapting to novel investigative technology. The court did not give remote hacking a constitutional blank check. It instead focused on agent conduct: detailed disclosure, judicial authorization, compliance with the warrant, and reasonable reliance amid unsettled law.

Shield Practice RuleWhen seeking authority for a novel remote-search technique, disclose exactly what the code will do, confront territorial uncertainty directly, minimize collection, preserve technical records, and obtain judicial approval before deployment; good faith is built through candor and disciplined execution.

Shield Public Safety Training · Police Technology Case Law Center

This monograph is provided for training and general informational purposes. It is not legal advice and does not replace review of complete opinions, current statutes, court rules, controlling federal and state authority, provider requirements, agency policy, technical documentation, or consultation with prosecutors and agency counsel.

© 2026 Shield Public Safety Training. All rights reserved. Reviewed August 30, 2026.