HKSAR v. Kwok Po Lun
Read the full judgment text of DCCC 64/2012 on BabelCite. This District Court judgment was delivered on 19 March 2013.
1. The defendant pleads not guilty to one charge of possession of child pornography, contrary to section 3(3) of the Prevention of Child Pornography Ordinance, Chapter 579 (charge 1), and one charge of publishing child pornography, contrary to section 3(2) of the Prevention of Child Pornography Ordinance (charge 2).
Cites 4 cases
|
DCCC 64/2012 IN THE DISTRICT COURT OF THE HONG KONG SPECIAL ADMINISTRATIVE REGION CRIMINAL CASE NO. 64 OF 2012 ____________
____________
____________________________ REASONS FOR VERDICT ____________________________ 1.The defendant pleads not guilty to one charge of possession of child pornography, contrary to section 3(3) of the Prevention of Child Pornography Ordinance, Chapter 579 (charge 1), and one charge of publishing child pornography, contrary to section 3(2) of the Prevention of Child Pornography Ordinance (charge 2). Introduction 2.In summary on the 15 April 2010 the police executed a search warrant at Room 17086, 17/F, Block 3, Lotus Tower, Garden Estate, 297 Ngau Tau Kok Road in Kwun Tong where the defendant resided with his family. The police seized three computers, one from each of the two bedrooms and a notebook from the living room. 3.Initial examination at the home revealed no child pornography on the computers. Subsequent forensic examination by PC 3379 of the Technology Crime Division revealed 62,284 images and 639 films suspected to be child pornography were stored on one of the computers found in one of the bedrooms. The defendant was subsequently arrested on the 8 July 2010. 4.The prosecution case is that the computer on which the child pornography was stored was found by the police in the defendant’s bedroom and was used by the defendant. The prosecution submit on the evidence the only inference to draw is that the defendant knew of the existence of the child pornography on the computer and was therefore in possession of the child pornography. The defendant published some of the child pornography which was set to share via the internet. 5.The defence take issue with whose bedroom the computer was found; who the computer belonged to and whether the child pornography was in fact on the computer at the time the police seized the computer on the 15 April 2010. The defence called one expert witness Dr Kumar to give evidence as to the possibility someone other than the defendant could without the defendant’s knowledge have planted the child pornography in the computer. 6.The computer on which the child pornography was found had two hard discs installed referred to as HD1 and HD2. The suspected child pornography was found on HD2. In the admitted facts this computer is referred to as the relevant computer. In my verdict I will simply refer to this computer as “the computer”, which was marked exhibit P3. The law 7.The prosecution must prove that the images and films subject of the charges are child pornography within the definition of section 2 of the Prevention of Child Pornography Ordinance. The police viewed the suspected images and were of the opinion 46,281 images and 636 films were child pornography. The parties have however agreed that there is in fact only 40,954 images and 510 films which are child pornography (see paragraph 18 of the admitted facts, exhibit P1A). This agreement resulted in an amendment of the charges. 8.On a charge under section 3(3) the prosecution must prove beyond reasonable doubt the defendant was in possession of the child pornography. This involves the prosecution proving the defendant had control of and knowledge of the existence of the material but not that the defendant knew it was child pornography (see HKSAR v Justin Yves Herbonnet [2006] 1 HKLRD 862). On a charge under section 3(2) the prosecution must prove beyond reasonable doubt the defendant published the child pornography within the definition in section 2(2) and (3) of the Prevention of Child Pornography Ordinance. 9.Section 4 sets out various defences to charges brought under section 3 including that the accused had not seen the child pornography, and did not know nor suspect it to be child pornography; and that he had not asked for the child pornography and, within a reasonable time after coming in to his possession he endeavoured to destroy the child pornography. The standard of proof on the defendant is either an evidential burden or on a balance of probabilities depending on which defence is raised and under which section the defendant has been charged. Evidence 10.The prosecution called five witnesses: DPC 33596 (PW1), who went to the home of the defendant to execute the search warrant and seized the computers; PC 58917 (PW3), who conducted a preliminary examination of the computers at the home of the defendant; DSPC 48401 (PW2), who arrested the defendant on the 8th July 2010; WPC 4663 (PW5) who was responsible for handling the computers in the Technology Crime Division and PC 3379 (PW4) the computer expert. Four statements of PC 3379 (exhibits P8-P11) were read pursuant to section 65B of the Criminal Procedure Ordinance, Chapter 221 and adopted as part of his evidence-in-chief together with one further statement adduced whilst giving evidence (exhibit P15). 11.The defendant elected not to give evidence and called only Dr Ajay Kumar, whose report (exhibit D1) was also read pursuant to section 65B of the Criminal Procedure Ordinance and adopted as part of his evidence-in-chief. 12.Facts have also been admitted pursuant to section 65C of the Criminal Procedure Ordinance (exhibits P1, P1A and P1B), including the defendant lived together with his family at Room 17086, 17/F, Block 3, Lotus Tower, Garden Estate, 297 Ngau Tau Kok Road (paragraph 1); the seizure and preliminary examination of the three computers(paragraphs 4, 5 & 6); forensic examination of the computer, exhibit P3 (paragraphs 8 & 9); sketch and photographs (paragraph 7); and the arrest of the defendant (paragraph 14). I will refer to other admitted facts when dealing with the issues. 13.No adverse inference is drawn against the defendant for remaining silent. That is his right. This proves nothing one way or the other. The defendant electing not to give evidence however means there isno evidence from the defendant raising the issues subject of the statutory defences. Although the defendant told Dr Kumar that the material had been planted on the computer by someone without his knowledge this does not suffice to raise the issue that he had not seen the child pornography and did not know or suspect it to be child pornography. I am therefore satisfied Mr Wong has correctly conceded the defendant cannot rely on the defences in section 4. 14.Admitted in evidence is the defendant is a person of clear record. I direct myself in accordance with the decision in HKSAR v TANG Siu-man [1997-98] 1 HKCFAR 107. 15.I have carefully considered all the evidence and the submissions of Mr Ho and Mr Wong and fully familiarized myself with all the documentation. In reaching my verdict I remind myself of the burden and standard of proof and that the burden is on the prosecution throughout. The defendant has to prove nothing (save in the case where statutory defences apply). I direct myself that I must be sure of the defendant’s guilt. On the other hand if the court thinks that the defence evidence pointing to innocence is true or may be true, it would follow that the defence has raised sufficient doubt in the prosecution case and the defendant entitled to be acquitted. 16.I remind myself that when drawing inferences from the evidence the inference must be a compelling one and the only one that no reasonable man could fail to draw from the direct facts proved. Expert evidence 17.I will first address the criticisms made of the experts called by the parties. There was no challenge to the expertise of PC 3379 (PW4). I was satisfied he was able to give expert evidence on computer forensic examination. Mr Wong however submits the evidence of the expert is not seen to be independent by reason of the fact he is a serving police officer and was part of the investigation team (see paragraph 16(c) of Mr Wong’s written submission). 18.I disagree the expert is to be regarded as part of the investigation team. PC 3379 was attached to the Technology Crime Division whereas the investigation was carried out by District Investigation Team 6 of Sau Mau Ping. PC 3379 was specifically requested to forensically examine the three computers seized. This in my view does not make him part of the investigation team. Nor does the fact that PC 58917 (PW3), who was also from the Technology Crime Division, conducted the preliminary examination of the three computers at the home of the defendant. 19.In my view PC 3379 was assisting the investigation team much in the same way that a fingerprint expert assists in analysing fingerprints lifted from the scene of crime or the Government Chemist analyses suspected dangerous drugs. Even if PC 3379 is regarded as part of the investigation team this is no bar to him being called as an expert witness, the extent of his independence going only to weight not admissibility (see R. v Gokal [1999] EWCA Crim 669). 20.Where criticism can be made however is that PC 3379 has not prepared what can properly be called an expert report setting out all his findings. What the officer did was prepare a series of statements each addressing the specific requests made of him by the officer in charge of District Investigation Team 6 of Sau Mau Ping. This is perhaps best illustrated with reference to hacking, one of the issues in the case being whether the computer was or may have been hacked. The evidence of PC 3379 is he did analyse the chance of the computer being hacked. As he was not requested specifically by the officer in charge of the case to consider whether the computer had been hacked PC 3379 did not include his findings in any of his statements or disclose this information until he was asked in court. 21.In my view a full report setting out all findings and not just limited to the specific requests should be prepared and this should also include the reply to any defence expert report. However it is right to say at no time was PC 3379 ever asked to prepare a full expert report whether by the officer in charge; the Department of Justice or anyone in the prosecution team. The failure to prepare a full report, however, does not cause me to doubt the evidence of PC 3379 and his expert opinion. I am satisfied PC 3379 acted professionally throughout and that his impartiality, objectivity and integrity have not been impugned. My attention has not been drawn to any feature of his evidence that could support a case of conscious bias or lack of objectivity. Further Dr Kumar in his report states the technical procedure adopted by PC 3379 for the forensic examination was quite professional and sufficiently detailed. Unless otherwise stated I accept the expert evidence of PC 3379. 22.Mr Ho questions the expertise of Dr Kumar, in particular that Dr Kumar does not appear to have much in depth knowledge of the operating system of a computer (see paragraph 22 of Mr Ho’s written submission). Whilst Dr Kumar’s main expertise is in the field of biometrics Dr Kumar explained that this requires a fundamental understanding of the hardware and software of a computer and how they work. This knowledge he gained from both his studies in electrical and electronic engineering (undergraduate, masters and Ph. D) together with his post doctoral research. 23.Dr Kumar has attended many courses worldwide on computer technology and has held teaching posts as a Post Doctoral Associate in the Department of Computer Science and Engineering at the Hong Kong University of Science and Technology and Post Doctoral Fellow in the Department of Computing at the Hong Kong Polytechnic, where he is now an Assistant Professor. 24.I was satisfied Dr Kumar did have an in depth knowledge of the operating systems of computers and could give expert evidence on computer technology and not that Dr Kumar was giving evidence outside his scope of expertise (see Fu Kor Kuen Patrick & another v HKSAR FACC 4/2011). However, the expert opinion of Dr Kumar as to whether it was possible the child pornography could have been found in the computer without the knowledge of the defendantis to be viewed in light of the fact that Dr Kumar did not make an actual examination of the computer. 25.I should add that in order that the court could fully understand all aspects of the expert evidence this necessitated repeated explanations by the experts and lengthy questioning by the court at the end of the evidence of each expert. I do not propose to set out a detailed summary of all the expert evidence and will refer to the relevant parts when addressing particular issues. Whose bedroom was the computer found and who was using the computer? 26.The prosecution case is that the computer was found in the defendant’s bedroom and that the defendant was the sole user of the computer. The defence submit the evidence that the computer was found in the defendant’s bedroom is unreliable (see paragraphs 6 & 7 of the written submission of Mr Wong) and that the court cannot rule out that the defendant’s parentsalso used the computer for their own purpose (see paragraph 8 of the written submission). 27.The police went to the defendant’s home at 06:35 hours on the 15 April 2010. DPC 33596 (PW1) testified he seized the computer from the bedroom on the left as one enters the flat (see sketch, exhibit P6). The prosecution rely on the evidence of oral statements attributed to the defendant that this bedroom was his and the computer was his; that when the defendant was arrested in July he was woken up in this bedroom; and the findings of the expert as to who was using the computer. Oral statements attributed to the defendant 28.In summary DPC 33596 testified that after the father had let the police in the flat the defendant was seen to walk out of the bedroom where the computer was found. DPC 33596 described the defendant as walking out of his bedroom. When asked by Mr Ho how he knew this was the defendant’s bedroom DPC 33596 replied that when the defendant walked out of the bedroom he saw a computer inside and therefore asked the father whose bedroom that was and who the computer belonged to. The defendant and not the father answered saying it was his bedroom and his computer. 29.DPC 33596 however made no written record of this at the time in his notebook or at the police station in the investigation report. The first record was made five months later in his witness statement. Cross-examination revealed that DPC 33596 made a record in his notebook that at 09:30 hours the father, on being told the computers would be seized, said that after the police have finished examining the three computers of his home the police need to return the computers to him if nothing is found. In answer to the court DPC 33596 said after the entry for arrival at 06:35 the next entry in his notebook was this entry at 09:30. 30.In the recent case of HKSAR v Chan Yuk Ling CACC 102/2012 the Court of Appeal said that judges will need to scrutinise very hard any reliance by the prosecution on alleged oral admissions which are not recorded in writing and shown to the suspect for his acknowledgement. Although DPC 33596 said in cross-examination there was a detailed statement made by the defendant at the police station no such statement has been adduced in evidence. I must therefore proceed on the basis this alleged admission was not reduced into writing and shown to the defendant for his acknowledgement. Heeding the caution of the Court of Appeal I am satisfied in the circumstances that it would be unsafe to rely on this evidence, in particular considering DPC 33596 made some record in his notebook of what was said at the defendant’s home but not of what the defendant said. 31.DSPC 48041 (PW2) testified that when he arrived to arrest the defendant on the 8 July 2010 the father led the police to the same bedroom, where the father woke up his son. DSPC 48041 made no written record of this in his note book, or witness statement. Nor was this recorded in the investigation report. I am satisfied in the circumstances, in particular DSPC 48041 was testifying over 2½ years after the event, that no weight should be attached to this evidence. 32.This however is not the only evidence to link the defendant with the bedroom and the computer. As noted already the defendant was seen to walk out of this bedroom by DPC 33596, a fact which was not challenged. More significant however is the evidence of what was found on the computer. In summary PC 3379, the prosecution expert, testified that two valid user accounts “Alan” and “Guest” were identified, however only “Alan” was activated to accept password logon whereas “Guest” was not activated (see paragraphs 10 & 11, exhibit P9). 33.Admitted in evidence is that the defendant was employed by Yung Shiang International (HK) Limited and his work email was [email protected] (see paragraph 17 of the admitted facts, exhibit P1). Clearly therefore the defendant uses the name Alan. 34.In addition PC 3379 found two Microsoft word files; four Microsoft excel files and 74 email files which related to male, Kwok Po Lun (the name of the defendant) and Alan (see paragraph 9, exhibit P10). Notwithstanding these files and emails were burnt on to CD-Rs (see paragraph 10, exhibit P10) the files have not been adduced in evidence. All that has been adduced is details of the files as shown in Annex A to exhibit P10. Claim forms of YS Group, where the defendant worked, can be seen on the full path of files 75, 76, 79 & 80 and the name “Alan” is seen on the full path of all files except 77-80. 35.When asked by the court how he knew the files related to Kwok Po Lun PC 3379 said he viewed the files and by way of example said the name Kwok Po Lun appeared in the file “My Resume.doc”, which is file 77 of Annex A. Notwithstanding the files have not been produced I accept the evidence of PC 3379 that these were found on the computer from which the names Kwok Po Lun, and Alan can be seen. I also accept the evidence of the expert that he recalls seeing the name Kwok Po Lun on the file “My Resume.doc”. 36.Having carefully considered this evidence I am satisfied so I am sure the only inference to draw is that the defendant is the Alan using the computer and that the defendant left his bedroom inside which was the computer. I also note that Dr Kumar in his report is of the opinion that the technical steps to establish the unique user account are of sufficient technical standard. 37.Accepting the fact there was only one user account in the name of Alan is a strong indication to show the defendant may well be one of the users of the computer Mr Wong submits this does not rule out the possibility that the computer was used by others as well. Alan being such a common name Mr Wong questions whether the defendant is the only Alan living in the flat (see paragraph 8 of the written submission of Mr Wong). 38.I have no hesitation in rejecting this submission. The admitted facts are the defendant lived in the flat with his family (see paragraph 1 of the admitted facts, exhibit P1). The evidence shows that in the flat was the defendant, his father and one lady, who DPC 33596 described as the father’s wife (which would be the mother or step-mother). Alan being a male name the only other person this could refer to is the father. Although there is no evidence as to whether the father had any English name I find inherently improbable that the father would put child pornography on the computer used by his son, let alone leave the child pornography on the computer. The fact that the father said to the police that the computers seized from his home were to be returned to him does not cause me to doubt this finding. Similarly I find inherently improbable the mother/step mother would put child pornography on the computer used by her son and leave that child pornography on the computer. When the police seized the computer was the child pornography on the computer? 39.Whilst there is no issue that child pornography was found on the computer the defence question whether the child pornography was on the computer when the police seized the computer on the 15 April 2010. The basis of this submission is twofold. First when PC 58917 (PW3) conducted the preliminary examination on the computer in the defendant’s home images were seen but no suspected child pornography was found. Second before forensic examination by the expert the storage of the computer was not secure. In these circumstances the defence submit that the court cannot rule out the possibility someone had put the child pornography on the computer after seizure and before forensic examination (see paragraphs 10-13 of the written submission of Mr Wong). Preliminary examination 40.The computer was seized on the 15 April 2010 and first examined by PC3379 (PW4), the expert, on the 23 April 2010 when he performed the process of ‘Forensic Image Acquisition’ by using computer forensics software “EnCase” (see paragraph 4, exhibit P8), 41.When PC 58917 examined the computer at the home of the defendant on the 15 April 2010 he used a programme called “SPADA” which had been designed specifically for forensic examination. Using the image search function of “SPADA” no child pornographic images were found. In cross-examination PC 58917 explained that as the “SPADA” programme was designed several years ago and no updates had been provided, “SPADA” may not be able to access everything on the computer. This was because the “SPADA” programme may not be completely compatible with the hardware of more recent computers resulting in “SPADA” not being able to read all the data on the computer. 42.PC 58917 told the court that although he was aware at the time of his examination of the shortcomings of “SPADA” he made no record of this in his witness statement or in the investigation report. PC 58917 said he thought this was not necessary and in answer to the court explained his witness statement was mainly to record what operation he carried out. 43.Mr Wong submits the failure to record “SPADA” has not been updated and therefore may be the reason why no child pornography was found on the computer during the preliminary examination invites grave suspicion that the child pornography may have found their way onto the computer after the examination by PC 58917 (see paragraph 11 of the written submission of Mr Wong). I have no hesitation in rejecting this submission. 44.I accept the evidence of PC 3379 that “SPADA” permitted only a preliminary examination, whereas the software “EnCase” has more powerful functions and permits a more detailed examination. I am satisfied so I am sure the only inference to draw is that the child pornography was on the computer at the time of seizure on the 15 April 2010. Whilst surprising the police used an old software programme with known shortcomings to conduct the preliminary examination the fact that PC 58917 did not find any child pornography during the preliminary examination and did not record in his witness statement the shortcomings of “SPADA” as the possible reason for this do not cause me to doubt this is the only inference to draw. Handling of the computer 45.After PC 58917 completed the preliminary examination of the computer DPC 33596 (PW1) attached ‘anti tamper’ labels to the switches of the computer. In cross-examination DPC 33596 said these were sufficient to prevent anyone switching on the computer later because markings would be left on the labels if someone tried to tamper with the computer. In court DPC 33596 gave the number of the two labels he attached. Part of one of the labels AD 014391 was not covering a switch but found on the side of the computer. DPC 33596 thought that because the computer was handed over to the Technology Crime Division they will have peeled off the label when conducting their examination. 46.The other label AD 014392 is seen on the back of the computer just below a switch. Due to the lapse of time DPC 33596 could not be sure if he placed this label in a different position. DPC 33596 agreed this label appeared intact and when asked by Mr Wong that it would appear the label could easily be lifted and reapplied again DPC 33596 said he was not very clear about this as this was the first time he had used such labels. DPC 33596 then agreed that he could not really say how effective the labels were to prevent people tampering with the computer. 47.The computers were then taken to the police station and kept under a desk in DPC 33596’s office without being locked away. On the 21 April 2010 DPC 33596 delivered the computers to WPC 4663 (PW5) of the Technology Crime Division for forensic examination. WPC 4663 testified that when the computers were handed to her they were sealed with labels. WPC 4663 conducted a preliminary examination of the computers, which included cutting open the labels to see if there was any damage to the hard discs. After checking WPC 4663 applied new labels. 48.In cross-examination WPC 4663 identified in court the two labels put on by DPC 33596 and said these were the only two labels on the computer when she received the computer. WPC 4663 pointed out the part of AD 014391 which had been cut and moved to the side of the computer underneath label AE004581 (the same position as pointed out by DPC 33596). The other part was on the back of the computer in the right upper corner just below label AE 004982. WPC 4663 confirmed that the second label AD 014392 was still intact and had not been moved from the back of the computer. 49.After preliminary examination WPC 4663 put the computers in a locker in the forensic room prior to sending them to the exhibits room of the Technology Crime Division in the late afternoon of the same day. In cross-examination WPC 4663 said the computers were kept under lock to prevent tampering with the exhibits. 50.As noted earlier PC 3379 (PW4) first examined the computer on the 23 April 2010. In cross-examination PC 3379 said he checked the labels when he took the computer out of the exhibits room at which time the labels were intact. To conduct his examination PC 3379 needed to take off some of the labels and would then reapply new labels after the examination was completed. 51.Placing exhibits under a desk is most unsatisfactory. All exhibits should be properly kept. Notwithstanding the computer was kept under the desk I have no hesitation in rejecting the submission that whilst under the desk the computer was interfered with, whether by a police officer or someone else, whereby 62,284 images and 639 films suspected to be child pornography were downloaded, copied or by other means planted on the computer. I accept the evidence that the labels put on the computer by DPC 33596 were intact when the computers were handed over to WPC 4663 after which they were kept locked in the exhibits room pending examination by PC 3379. I find inherently improbable that someone could have downloaded, copied or by other means planted such a large quantity of suspected child pornography on the computer without anyone noticing what was happening. 52.In addition the expert evidence as to physical access to the computer without the password (which I discuss in detail in the next section of the verdict) again makes inherently improbable that someone accessed the computer and downloaded, copied or by other means planted the child pornography on the computer whilst the computer was kept in the police station. 53.The keeping of the computer under the desk of DPC 33596, whilst most unsatisfactory, does not cause me to doubt the only inference to draw is that the child pornography was on the computer at the time of seizure by the police on the 15 April 2010. Physical and remote access to a computer 54.The fact the child pornography is on the computer is not sufficient to prove the defendant was in possession of that child pornography. The prosecution must prove the defendant knew of the existence of the child pornography on the computer. There being no admission by the defendant he knew of the existence of the child pornography on the computer the court is asked from all the circumstances to draw the inference that the defendant must have known. This question largely depends on how the computer was accessed. Access can be either physical access or remote access. Physical access 55.As seen earlier only one valid user account was activated in the name of “Alan”, who I am satisfied so I am sure is the defendant (see paragraphs 32-36). PC 3379 explained when accessing the computer “Alan” would have to log on with his password as shown in Figure 3.2, exhibit P9. There being no evidence before the court that the defendant gave his password to anyone, including his family, I am satisfied so I am sure the only inference to draw from the evidence is that the defendant was the only one who used the password to log on the computer. 56.Dr Kumar in his report states that somebody can have physical access to the computer with or without account details and password and transfer the child pornography by copying from another location for example a portable hard disc, DVD drive or network access. PC 3379 gave evidence as to three ways in which a person can physically gain access to a computer without the password. The first two involve the removal of the hard disc. When this occurs either the child pornography is copied on to the hard disc or the hard disc is replaced with another hard disc (this example was given in cross-examination). The third way is as stated by Dr Kumar namely copying by the use of a portable device, which contains the windows operating system. 57.In evidence Dr Kumar said that because Microsoft operating systems are very widely used Microsoft has come up with software to help the legitimate user who forgets his password. This software can be saved in a CD Rom or USB and because Microsoft has the largest share of the market this is easily available as compared to obtaining bypass software for less popular operating systems. Further Dr Kumar said that certain bypass software can also be downloaded freely from the internet. 58.In cross-examination PC 3379 said that the operating system on the portable device must be compatible with the computer in question. Dr Kumar agreed with PC 3379 that the bypassing software needs to be matched with the hardware of the computer but explained that there is a large family or class of hardware for which a single bypass software will suffice. Dr Kumar said where the operating system was Microsoft Windows XP it therefore becomes relatively easier to succeed in gaining access to the computer by trying one or two bypass software, or at the most three. In cross-examination Dr Kumar agreed that if the person did not know what the hardware was he would have to prepare up to three different bypass software to seek successful access to the computer. Further Dr Kumar said in normal circumstances if someone uses bypass software there will be some traces left in the computer. 59.I find inherently improbable that someone, without the defendant knowing what was happening, went into his home and either removed the hard disc or was carrying a portable device containing three different types of bypass software so as to copy the child pornography on to the computer. Further I am satisfied this reasoning equally applies to physical access to the computer whilst under the desk of DPC 33596. 60.Having carefully considered the evidence relating to physical access to a computer without the password I am satisfied so I am sure the only inference to draw is that no one other than the defendant had physically accessed the computer to put the child pornography on the computer. I now turn to consider whether the child pornography could have been put on the computer remotely. Remote Access 61.PC 3379 said a computer may be accessed remotely by use of the function “Remote Desktop’ or by the installation of similar programmes permitting remote access. Dr Kumar in his report states remote access to the computer can also be with or without the account details and password. Remote Desktop 62.If the function ‘Remote Desktop’ is activated the computer can be used remotely through the internet by other specified users. The evidence of PC 3379 is that access by “Remote Desktop” was not activated; ‘Select Remote Users’ showed no user was added connecting to the computer remotely; and there were no trace of any records of remote user login found in the ‘Security of Event Viewer’ (see paragraphs 6-8, & 10, exhibit P11). 63.Dr Kumar in his report states the methodology adopted by PC 3379 is quite scientific and sufficiently detailed in making reasonable arguments to negate such possibility of access by “Remote Desktop”. Further Dr Kumar concludes that in view of the “remote desktop users’ settings, the contents in Windows Registry and the time/date stamp of last modifications can sufficiently confirm that it is highly unlikely that the defendant’s computer was remotely accessed using the Remote Desktop method. 64.PC 3379 said he was aware of two similar programmes but on examination did not find any similar programmes installed permitting remote access. In cross-examination PC 3379 acknowledged this finding was not in any of his statements. Although PC 3379 could not in court remember the names of other similar programmes he said he was aware of the names at the time of his examination. Furthermore when PC 3379 looked through the names of the files he would check if there were any files of which he did not know the names or were suspicious to see if they were remote control programmes. In addition PC 3379 used anti-virus software to check all files on the computer to see if any contained a virus which could control the computer. No virus was found (see paragraph 8, exhibit P10). Dr Kumar in his report states this check was satisfactory. 65.PC 3379 said this part of the examination took him 1-2 hours. PC 3379 did not record how many files were on the computer but guessed he looked at more than 100 and less than 1000. PC 3379 disagreed with Mr Wong that he did not do go through the programmes. At paragraph 16(b) of his written submission Mr Wong submits that it is doubtful such a test was adequate for the purpose and relies on Dr Kumar’s opinion such a check should take substantially longer, up to weeks, at least a week. 66.With respect Dr Kumar was asked about the time taken to find evidence of hacking and not checking to see whether there were any other programmes found on the computer which permitted remote access. Even then Dr Kumar explained much depended on how efficient the tools were used in the examination and when asked by Mr Wong if this could be done in 2-3 hours Dr Kumar replied, “Possibly not”. 67.I accept the evidence of PC 3379, who examined the actual hard discs of the computer, that Remote Desktop was not activated and that there were no other programmes installed on the computer permitting remote access. Hacking 68.In answer to the court PC 3379 gave three possible reasons for someone to hack into a computer namely; to take control of the computer, to destroy the computer or to obtain documents from the computer. Dr Kumar agreed saying that a hacker must have some reason, motivation or attraction to attack another computer. 69.Dr Kumar said one of the most common reasons is to make the computer a slave so as to control the computer to launch certain activities which may be difficult or illegal or where the hacker wishes to hide his true identity. In answer to the court Dr Kumar said one reason a hacker may download child pornography on another’s computer would be to protect his own identity. Both Dr Kumar and PC 3379 said that by hacking into someone else’s computer the hacker can distribute or view the material remotely. 70.Dr Kumar in his report says that under some circumstances it is possible for someone to hack a computer resulting in material being found on the computer without the knowledge of the user of the computer. In the appendix to his report Dr Kumar provides examples as to how a computer is hacked, which require tracing of the IP address and ascertaining of the password either by guessing or using a Brute Force tool. 71.Dr Kumar concludes that in the light of available technical evidence and the known vulnerabilities of Windows XP there is a reasonable possibility that somebody, other than the defendant, could have planted the child pornography in the computer. Dr Kumar however never examined the hard discs of the computerand therefore cannot say whether the computer was or may have been hacked other than by reference to the possibility of how a computer can be hacked. 72.By reason of there being a firewall and anti-virus programme installed on the computer; that the user password consisted of 16 letters and numbers and no software which can control the computer was found installed on the computer PC 3379 was of the opinion the chances of the computer being hacked were very low. 73.In deciding whether the child pornography may have been planted on the computer as a result of hacking I have carefully considered the expert evidence, including the following specific areas; the vulnerability of Windows XP; whether any traces of hacking were found on the computer and the location where the child pornography was found. Vulnerability of Windows XP 74.In evidence Dr Kumar said that the operating systems of Windows XP Service Pack 2 (SP2) and Service Pack 3 (SP3) are well known for their vulnerability to external attacks. Dr Kumar said that it is reported in the literature that SP2 is generally believed to be highly vulnerable with the most attacks reported. As a result Microsoft introduced an enhanced version SP3 to try fix up the previous version and subsequently Windows 7.0 has also been introduced. Dr Kumar mistakenly stated in his evidence that the operating system on the computer was Windows XP Service Pack 2. When pointed out by the court that the Windows XP version was in fact SP3 and not SP2 Dr Kumar said SP3 remains vulnerable. 75.Dr Kumar wished to underline that whilst it was nice to say it is difficult to by-pass firewalls and anti-virus programmes nevertheless it is not impossible or uncommon to see firewalls by passed by external hackers. Dr Kumar said anti-virus programmes and firewalls have their limitations as they can only focus on a range of vulnerabilities, and not all vulnerabilities. When a new vulnerability is discovered a solution to fix the problem will be found therefore requiring the programmes to be regularly updated by either automatic update or a new version. IP address and Password 76.In cross-examination Dr Kumar said that depending on the level of sophistication of the hacker, a hacker could disguise himself as the account user whereby he could then install programmes on the computer as though he was the real account user. To do so the hacker would require the credentials of that computer, namely the Internet Protocol (IP) address and password. Without the password Dr Kumar said that it was going to be difficult to hack a computer however having ascertained the IP address it would be rather easy for a hacker to obtain the password by methods such as phishing. 77.In answer to the court Dr Kumar explained that to gain complete access to another computer the hacker would look to exploit the vulnerabilities of not only the operating system but also the vulnerabilities of the browser and the applications and software already installed on the computer. To exploit these vulnerabilities the hacker would definitely need the IP address as this was the point of contact with the computer. 78.In the appendix to his report Dr Kumar explained how to hack a computer using the IP address. In the report Dr Kumar said finding a friend’s IP address is a little tough job. In answer to the court Dr Kumar said finding a complete stranger’s IP address could be very difficult, however various sources such as playing games where passwords are shared or clicking on spam e-mail may provide the opportunity. Traces of hacking 79.Dr Kumar said a very common method of making the computer a slave is by use of a tool called a botnet, which is known to be commercially available from underground sources. In cross-examination Dr Kumar said that in normal circumstances where a botnet has been used there will be some traces left as anti-virus programmes are designed to detect botnets. However this depends on the level of sophistication of the anti-virus programme and the botnet. 80.PC 3379 said in court that generally speaking some traces of hacking would be left in the windows registry or there will be another user account or some unusual programmes installed. PC 3379 did not find any such traces of hacking. Nor did PC 3379 find any traces of hacking by using the IP address. PC 3379 acknowledged in cross-examination it is possible a very sophisticated hacker may leave no trail. 81.PC 3379 agreed he was never asked to look for signs of hacking and therefore made no reference to hacking in any of his statements. PC 3379 said that after receiving Dr Kumar’s report he did not examine the computer again as he had already analysed the chance of the computer being hacked. The details were on his computer but had not been disclosed because no one requested them. 82.The next day PC 3379 provided print outs relating to the firewall and anti-virus installed on the computer but no list of what checks he had made when looking for signs of hacking. These print outs showed that the anti-virus software was set at basic protection and network emails at ordinary protection with sensitivity of the start up technology set at medium. Accepting there could be higher settings PC 3379 explained that the firewall and anti-virus software showed the security level of the computer was very high. The setting of the firewall was enabled with the highest security which means the firewall can filter all kinds of viruses or threats of virus. PC 3379 again mentioned that he did an anti-virus scan and found no virus (see paragraph 8, exhibit P10), which as noted earlier Dr Kumar stated in his report was satisfactory (see paragraph 64). 83.Reference was also made in cross-examination by Mr Wong to the fact that the anti-virus may not be up to date. This arose from the fact the print outs showed the anti-virus was not updated. PC 3379 explained that the anti-virus was up to date at the time of seizure but in carrying out his examination he did not update the anti-virus. I accept this explanation. 84.When asked by Mr Wong if something would pop up on the computer telling the user of the computer that someone else was using the computer at the same time Dr Kumar replied that hacking programmes were designed to run anonymously as possible therefore if a hacker would like to give an indication this would very much defeat the purpose of hacking. Location of the child pornography 85.The child pornography was found in four different locations within D drive, namely ‘eMule’ Downloads\Incoming; My Pictures; Download; and TDDOWNLOAD (see paragraph 16, exhibit P9). PC 3379 explained that ‘eMule’ is a peer-to-peer file sharing programme which enables the user to search for files the user wants which he can download for his own use and upload for sharing with others. 86.In answer to the court Dr Kumar explained that a hacker would use a location which would be rather difficult to be viewed by the owner of the computer so he can successfully hide the material. In other words the hacker would choose a location not frequently accessed by the user of the computer. This however would depend on the availability of space on that computer. Dr Kumar said it would be very difficult to use well known or established sites as the hacker is then likely to be caught more easily. On the other hand by using ‘eMule’ this has the attractions of fast speed and can be used anonymously therefore Dr Kumar concluded that it was likely ‘eMule’ would be used by a hacker. 87.In cross-examination when asked if from the literature he had read about hackers installing ‘eMule’ Dr Kumar replied that he had no knowledge of ‘eMule’ being installed by hackers but explained that where a hacker gains control of the Windows XP he gains control of the ‘eMule’ programme on the computer. In answer to the court Dr Kumar said to his knowledge he was not aware of botnets being used to distribute pornographic material. Dr Kumar explained this maybe because research was usually into information security protection, which has a commercial or other forensic value. 88.Dr Kumar agreed in cross-examination that a hacker will disguise a programme so as not to be easily detected. Dr Kumar however explained that this did not necessarily mean changing the name. Where a hacker installed ‘eMule’ so long as this was placed in a separate directory or different folder the unique identity could be kept. Whilst natural to think the hacker will change the file name Dr Kumar explained, in answer to the court, that because the names convey a lot of information by not changing the name this allows ease of identifying the files for viewing or distribution, especially where there are voluminous files. 89.In cross-examination Dr Kumar said that if the user of the computer clicks on ‘My Programmes’ the user will become aware of the installation of programmes installed by a hacker. Dr Kumar agreed that installation by a hacker of ‘eMule’ would be low level sophistication and easily discovered. In re-examination Dr Kumar said that a normal average user would not click on ‘My Programmes’. This answer was based on the fact Dr Kumar had not done so for years. 90.In answer to the court when asked what he would say about a hacker putting child pornography into ‘My Pictures’ Dr Kumar said it was very difficult to answer which directory would be chosen as this depended on the situation at that point of time and the thinking of the hacker. Dr Kumar went on to say that if the hacker liked to hide the material he would not place them in ‘My Pictures’ which was a commonly used place for pictures but would rather go to a place where pictures were not commonly stored. Dr Kumar said he would not expect a hacker to put child pornography in ‘My Pictures’ but likely in ‘eMule’. However if the user of the computer was using ‘eMule’ then Dr Kumar said it was reasonable to expect the user will discover the material. Was the child pornography planted on the computer as a result of hacking? 91.In determining whether the child pornography was planted or may have been planted on the computer as a result of hacking I take into account PC 3379 had actually examined the computer. In cross-examination PC 3379 said he had been specifically trained for detecting hacking. Dr Kumar on the other hand did not examine the computer and when cross-examined on his expertise said he had not studied any courses on hacking. Dr Kumar only had what he described as a kind of general experience of observing the load patterns of the computer processor to ascertain the likelihood of the computer being used remotely for some unintended task. Dr Kumar said this was part of the operating system course he teaches and that he has some case studies of where a computer has been hacked showing how the load patterns differ from when the computer has not been hacked. 92.Having carefully considered all the evidence including the vulnerability of computers using Windows XP operating system I find I am satisfied so I am sure I can accept the opinion of PC 3379 that the chances of hacking were low. Taking into account that PC 3379 found no virus or traces of hacking and that the child pornography was stored in well known or established sites which were commonly used, in particular ‘My Pictures’, I am satisfied so I am sure the only inference to draw is that the child pornography found on the computer was not as a result of hacking. Nothing said by Dr Kumar or Mr Wong causes me to doubt this is the only inference to draw. Nor does the fact that PC 3379 did not include his findings on hacking in any of his statements. 93.I have also considered the evidence relating to exhibit P15B, which is a copy of Annex A (referred to in paragraph 9, exhibit P15), which details the files shared automatically through the internet (which is discussed further at paragraph 107). Mr Wong drew Dr Kumar’s attention to 34 files which were accessed at the same time namely 23:58 on 14 April 2010 (see file no. 7 for the first file with that access time). 94.Dr Kumar said the likelihood access to these files was by some automated programme was much higher than someone accessing these files manually. When asked by Mr Wong if a home user would have such automated programme Dr Kumar explained that some automated operation is a possibility for example where files are copied from the hard disc to a USB or CD Rom allowing a block of files to be simultaneously copied. Other than this Dr Kumar said it was rather difficult to think of someone using such a programme for a useful purpose to simultaneously access the files in such a short time period. 95.Mr Wong then asked Dr Kumar whether such access was more or less likely to be as a result of hacking. Dr Kumar replied that access could be for some malicious intention or for some useful application such as an anti-virus check where there would be simultaneous checking of a block of files. Dr Kumar however explained that such anti-virus check would not change the access times and therefore the 34 files accessed at the same time were unlikely to be as a result of an anti-virus check. 96.When the court asked Dr Kumar whether his evidence suggested or implied this automated action of access to over 30 files at the same time was as a result of a hacker Dr Kumar replied not necessarily. Dr Kumar explained it could also be part of the logic of the computer that the times may not be accurate and were recorded as the first time access was started. 97.In answer to the court Dr Kumar said that access to the files at the same time was not necessarily as a result of automated action. Dr Kumar did not rule out the possibility of manually clicking files but said this was less likely as it was difficult to think of some motivation to access files at such short intervals. In questions arising Dr Kumar agreed with Mr Ho that one possible way was to manually highlight all the files and drag them to another location for copying whereby all the files would have the same access time unless the logic of the computer was set for the actual time copying takes place. 98.Having carefully considered the evidence relating to P15B, in particular the various reasons why a number of files may have the same access time, I find this evidence does not cause me to doubt the only inference to draw is that the child pornography found on the computer was not as a result of hacking. 99.I remind myself that the rejection of the defence evidence relating to possible ways the child pornography could have been put on the computer without the knowledge of the defendant is not determinative of the issues in the case. The prosecution must prove beyond reasonable doubt the defendant had control of and knowledge of the existence of the child pornography. Did the defendant access the child pornography? 100.As noted earlier the child pornography was found in four different locations within D drive, the vast majority in ‘eMule’ and ‘My Pictures’ (see paragraph 85). ‘eMule’ 101.30,580 images and 624 films of suspected child pornography were found in ‘eMule’. ‘eMule’ was installed at 14:51 on the 19 December 2009 by using the account “Alan”, and the programme files of ‘eMule’ belonged to the account “Alan” (see paragraphs 12-13, exhibit P9). The account “Alan” was last used to execute the programme ‘eMule’ on the 14 April 2010, the day before arrest (see paragraphs 6-8, exhibit P15). My Pictures 102.My Pictures is a commonly used site for storing pictures (see paragraph 90). A total of 31,704 suspected child pornographic pictures were found in ‘My Pictures’ Link Files 103.One of the tasks requested of PC 3379 was to check whether the child pornographic materials were accessed (see paragraphs 3(iii), 10 and 11, exhibit P15). PC 3379 found 15 ‘link files’ containing suspected child pornography. Link files represent the record of a user opening a file. When a document is opened a link file is created in the Recent folder, in the root of the folder with the user’s logon name. In cross-examination PC 3379 explained that a link file is only created when the user directly opens a file. If on the other hand the user opens the file with other programmes for example media player for films then a link file will not be created. A full description of a link file is to be found in footnote 3 to paragraph 10, exhibit P15. 104.PC 3379 found 15 link files under a folder of the account “Alan”: the folder name being “\DocumentsandSettings\Alan\Recent”. The account “Alan” had been used to access the files to which the link files pointed as listed in Table 2, exhibit P15 at the times listed in Table 3. These times show the 15 files were opened between 12 January 2010 and 15 April 2010, the day of arrest. File no. 4 named 001.jpg (5).Ink was accessed at 00:53 hours on the 15 April 2010. The defendant less than three hours earlier at 22:02:24 had last logged on to the computer using the account “Alan” (see paragraph 5, exhibit P15). PC 3379 however did not check to see when the defendant logged off. 105.Also significant is 9 files came from ‘eMule’, 5 files from ‘My Pictures’ and 1 file from D:\Download showing “Alan” accessed files for viewing from three of the locations where the child pornography was found. In re-examination when asked about the access time in Annex A, exhibit P15, PC 3379 explained that it was more appropriate to look at the link files for which access time means only viewing the file unlike the metadata in Annex A, for which the access times does not necessarily equate with viewing (this is also discussed in paragraphs 116-119). 106.I have carefully considered the evidence as to the locations of the child pornography in the computer together with the evidence relating to link files. I accept the evidence of PC 3379 that the account “Alan” had been used to access the child pornography to which 15 link files pointed. I note Dr Kumar was not asked any questions about link files. I am satisfied so I am sure the only inference to draw from the evidence is that the defendant did access the child pornography. Verdict Possession (Charge 1) 107.Taking into account the following matters:
I am satisfied so I am sure the only inference to draw is that the defendant controlled and knew of the existence of the child pornography on the computer. Further I am satisfied so I am sure the only inference to draw is that the defendant also knew the exact nature of the material was child pornography. Distribution (Charge 2) 108.The prosecution allege that of the 40,954 images and 510 films the defendant published 9 images and 497 films containing child pornography, all of which were found in the programme ‘eMule’ (see paragraphs 17-18, exhibit P9). . 109.‘eMule’ was capable of automatically sharing its files being uploaded and downloaded (see paragraph 9, exhibit P15). The incoming file path where ‘eMule’ was used to store downloaded and uploaded files is D:\eMuleDownloads\Incoming where almost half of the suspected child pornography was stored(see paragraphs 15-16, exhibit P9). All files in this path were set to share via the internet thus permitting access by the public (see paragraph 18, exhibit P9 and paragraph 6, exhibit P10). 110.PC 3379 inspected the file sharing status of ‘eMule’ and confirmed a total of 9 images and 501 films containing suspected child pornography had been shared possibly via the internet (see paragraph 18, exhibit P9 and P9A). PC 3379 explained by possibly he meant that if internet connection was successful then it was possible the file can be distributed. 111.PC 3379 specifically checked to see whether one of the films, the title of which is translated as “ChildAmerica.avi” had been distributed via the internet. PC 3379 explained with reference to Figure 6.3, exhibit P9 that there had been 996 requests of which 30 had been accepted for uploading resulting in a total of 2.92 MB data from the file being uploaded and shared onto the internet (see paragraph 17, exhibit P9). PC 3379 explained in simple terms that 30 people used the programme ‘eMule’ to download the file “ChildAmerica.avi” from the computer, however he did not know whether those downloads were in fact successful although 2.92 MB had been transmitted out. 112.I accept the evidence of PC 3379 that files containing child pornography were shared via the ‘eMule’ programme. In this regard I note Dr Kumar in his report is of the opinion that the technical steps to establish installation and sharing of the images and video files via ‘eMule’ are of sufficient technical standard. 113.The definition of publishing including distributes, which is defined as including making any message or data available through any means of electronic transmission, I find I am satisfied so I am sure the defendant published the 9 images and 497 films containing child pornography by making them available through the peer-to-peer sharing programme ‘eMule’ via the internet. 114.In reaching my findings I have carefully considered everything said by Mr Wong both individually and collectively. Nothing said by Mr Wong or Dr Kumar causes me to doubt the findings I have made. I am satisfied so I am sure there are no material and significant discrepancies, improbabilities or omissions in the evidence, which cause me to doubt the findings I have made. I am satisfied so I am sure the prosecution have proved all the elements of the charges beyond reasonable doubt, each charge considered separately. The defendant is convicted as charged. 115.I would add even if I am wrong to exclude the possibility the computer may have been hacked then by reason of what Dr Kumar said in cross-examination that by using ‘eMule’ this was hacking of a low level sophistication and in answer to the court that he would not expect a hacker to put child pornography in ‘My Pictures’, the defendant would have discovered the child pornography (see paragraphs 89 & 90). The onus would then be on the defendant to establish that he did not ask for any child pornography and, within a reasonable time endeavoured to destroy the child pornography. Nothing in the evidence is sufficient to raise this issue or any of the statutory defences. 116.Finally whilst in reaching my verdict I have not relied on what is termed the metadata of the files for example Annex A, exhibit P15 as much time was spent on this area in evidence some explanation I feel is required. The metadata comprising of the creation, modification and access times of the files clearly can be important in showing when the files were in fact created, modified and accessed, in particular the access time being the last access time may show when the user of the computer last accessed the child pornography. 117.Mr Ho in paragraphs 40, 42(5), 46 and 47 of his written submission seeks to rely on the metadata relating to access time. Mr Wong in his oral submission says the use of this data by the prosecution is unfair where the prosecution in their opening did not specify they were relying on such data. I note the metadata was available to the defence prior to trial having been saved into two Excel files and burnt into two CD-Rs (see paragraph 12, exhibit P8). The Excel Files and CD-Rs were also produced in court as exhibits P14A-P14D. 118.PC 3379 however did not rely on this metadata in giving his opinion. PC 3379 said the times were for reference only. This was because access did not mean only viewing. The access time may also be affected by copying a file; an anti-virus scan or using a programme to modify a file. Whilst one may be able to analyse the data to see which of these possibilities may apply, as Mr Ho has done in his written submission, PC 3379 did not do so. 119.In reaching his opinion that the defendant accessed the child pornography PC 3379 relied on the link files (see paragraphs 103-105) explaining that it was more appropriate to look at the link files for which access time means only viewing the file. 120.Although the metadata was available to the defence prior to trial taking into account PC 3379 did not rely on this metadata and that Mr Ho’s analysis was not the subject of specific questioning, I also have not relied on this metadata in reaching my verdict, in particular whether the defendant did access the child pornography.
Please refer to CACC164/2013 for the relevant appeal(s) to the Court of Appeal. |
Cases cited in this judgment
Further hearings and rulings under DCCC 64/2012