Inspector General: FBI Lost Six Months Of Important Text Messages Because Its Retention System Sucks
from the all-the-smart-people-at-the-agency-etc dept
It's great to know the FBI wants encryption broken so it can forensically molest any devices in its possession to find the mother lode of culpatory evidence these devices always contain. ("Always," you ask? The FBI irritatedly taps the word "always" repeatedly in response.)
The reason this is such good news is that the FBI can't even manage to reliably extract content from phones it issues to agents and other personnel. If you can't expertly handle data migration/storage from phones in your control at all times, how badly are you going to bungle forensic evidence extraction at scale if the government ever green lights encryption backdoors?
The DOJ Inspector General has just released a report [PDF] detailing its investigation of missing text messages sent by two agents at the center of a Congressional hearing about supposed biased behavior during the FBI investigation of Hillary Clinton and Mueller's investigation of Donald Trump. Agents Peter Strzok and Lisa Page exchanged text messages expressing their dislike of Trump and made some comments suggesting they would do something to harm his presidential chances. Critics believed this showed these agents -- if not the agency itself -- were guided by political bias when investigating Trump's ties with Russia.
Maybe there was more to this than there first appeared to be. Thousands of text messages from the agents' devices went missing -- a gap that stretched from December 2016 to May 2017. The Inspector General's office used forensic tools to recover roughly 19,000 text messages from the two phones. The culprit appears to be standard operating procedure rather than a deliberate attempt to destroy evidence.
Strzok and Page had each returned their DOJ-issued iPhones six months earlier when their assignments to the SCO (Special Counsel's Office) had ended. The OIG was told that the DOJ issued iPhone previously assigned to Strzok had been re-issued to another FBI agent… CYBER obtained a forensic extraction of the iPhone previously assigned to Strzok; however, this iPhone had been reset to factory settings and was reconfigured for the new user...
The same thing happened to Page's phone. It was reset in July 2017 by personnel at the DOJ's Justice Management Decision. It hadn't been issued to another agent but it had been restored in preparation for reassignment.
Resetting phones just makes sense. Nothing about the FBI's handling of records its supposed to be retaining does. Text messages are official communications. They're subject to public records requests and they're often responsive to subpoenas in criminal cases. Wiping a phone without ensuring existing communications have been backed up is monumentally stupid and possibly illegal.
To the agency's credit, it does try to retain these communications before resetting issued devices. The problem is its tool works poorly. As does its management:
FBI Assistant General Counsel [redacted for some fucking reason] informed OIG that there does not appear to be a directive for preservation of texts by ESOC [Enterprise Security Operations Center], but that ESOC retains text messages as a matter of practice.
Define "retain" and "matter of practice" in the context of a six-month gap of non-retention of Strzok/Page text messages. I guess it's the thought that counts?
[E]SOC could not provide a specific explanation for the failure in the FBI's text message collection relating to Strzok's and Page's S5 phones…
ESOC did offer up a set of possible explanations for the failure, none of which are reassuring. First, it could have been a bug reported by the vendor in 2016 but not fixed until March 2017. The application itself could have been misconfigured. The application may not have been compatible with device software updates.
Efforts were made to mitigate the issue. But those failed as well. The FBI phased out Samsung S5s and replaced them with S7s. Nothing changed but the phone model.
[A]ccording to FBI's Information and Technology Branch, as of November 15, 2018, the data collection tool utilized by FBI was still not reliably collecting text messages from approximately 10 percent of FBI issued mobile devices…
That the OIG was able to recover thousands of messages from forensic extraction and scouring the FBI's enterprise database isn't really good news. It's unlikely the FBI will make the same effort when hit with discovery demands and it already won't thoroughly search databases it has full access to when responding to FOIA requests. So, records are going to go missing and it won't be until the OIG steps in that any effort will be made to find the missing records, much less take a good look at the broken processes that caused them to go missing in the first place.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: data retention, fbi, inspector general, lisa page, peter strzok, public records, text messages
Reader Comments
Subscribe: RSS
View by: Time | Thread
Amazing what goes missing
[ link to this | view in chronology ]
Re: Amazing what goes missing
Isn't that what people were saying over and over, year after year, administration after administration? Thinking of that classic Ian Fleming quote, it's hard to believe that there was ever any serious attempt to fix the government's chronic "lost email" problem -- nor will there likely ever be.
[ link to this | view in chronology ]
Re: Re: Amazing what goes missing
[ link to this | view in chronology ]
Re: Amazing what goes missing
Perhaps they're thinking they want to be above accountability whenever they're in power, so aren't too interested in holding the other party accountable when they're not.
[ link to this | view in chronology ]
This is normal.
The FBI needs to, every once in a while, demonstrate that despite its hyperconservative MIBby appearance, it is as bumbling and incompetent as the rest of law enforcement.
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Not a problem
No worries, I'm sure that if they manage to cripple encryption and get a leprechaun golden key they'll be much more careful with that, and would never lose it inside a few months.
[ link to this | view in chronology ]
Found the problem
[ link to this | view in chronology ]
Just send them on a trip!
[ link to this | view in chronology ]
What kind?
Not that it really matters, but were they Samsung or Apple phones?
[ link to this | view in chronology ]
[ link to this | view in chronology ]
B. SC resets his iPhone destroying the texts
C. The texts were evidence destroyed by the SC.
How is this not obstruction of justice?
[ link to this | view in chronology ]