Hacker News new | ask | show | jobs
by jasonfarnon 1 day ago
"the only possible evidence they had was the wrong username."

Out of curiosity and definitely not defending this prosecution, but if the chain "unique Kik username -> unique gmail address -> unique ISP user -> guy living alone, happens to have Kik on his device" weren't screwed up by the investigators submitting the wrong username, would you say that's enough for a jury to convict ? I don't know about Canada but in the US at least no judge would step in and say that's not enough for a jury to convict on. Convictions happen based on he said/she said. In fact that's probably what this boiled down to. The defense isn't hiring a computer expert to dispute the chain "validated" by Kik/google/etc. unless the guy is rich. They probably accepted that as fact and just argued it wasn't him using the account. And everyone charged with this type of crime says "It must have been someone else on my computer."

3 comments

No, there are open wifi routers, there are WPA attacks, friends that were given wifi passwords, and a lot of other things. Convicting on IP address match should disqualify the trial judge.
Judges generally do not evaluate the quality of evidence. Unless the defense challenges, it's assumed that the prosecutions claims are founded in fact. It doesn't matter if the prosecution alleges you did six impossible things before breakfast unless the defense disputes these allegations.
A judge that has no reasonable doubt with this sort of evidence has no business being a judge.

We don't know what defense did in this trial but not picking up on the username mismatch and the assumed non-challenge of the evidence is telling as well.

In an adversarial system (which the US and Canada and UK are), the judge is not supposed to challenge evidence unless it's glaringly, obviously adrift from reality. That's the job of the defense lawyer. In civil law systems the roles of the judge and prosecutor are combined and responsility for bad decisions is distributed differently.
a simple law could mandate that attribution chains presented as evidence (by either party) MUST recursively include a header reminding everyone about this law (so that ALL defendant, plaintif, their lawyers and the judge & jury if applicable), the law being for example:

1) the username must be introduced as " the <N>-character user name <username> at the <M>-character online platform <platform> ..." along with a cryptographic hash of the concatenation, of user name, service name, ... so that any alteration is easily noticed.

2) a histogram of usernames binned by Damerau-Levenstein edit distance, along with a tabular cumulative count so that everyone can comfortably read off how many other but similar user names this platform has less than 1 edit away, less than 2 edits away, less than 3 edits away etc...

3) the law should introduce a bet between law enforcement and corporations: upon being requested for the other half of a forensic link (say an IP address, or an email address, ...), it must demand the exact number of characters, it must provide a list or at least a cumulative count of user names less than N edits away. if they are ever caught violating user privacy they owe money to the state, the individual, ... even if law enforcement demanded out of band cooperation. The corporation should financially feel the risk of prosecution / police making invalid requests, so they have an incentive to technologically think ahead of the police and their sloppy work.

> In an adversarial system (which the US and Canada and UK are), the judge is not supposed to challenge evidence unless it's glaringly, obviously adrift from reality.

So regardless of common law vs civil law systems, one could devise laws such that this type of errors could be made glaringly clear to anyone involved, by law.

It's not like the first time humanity is confronted with misattribution. If a phenomenon has a word, its typically been happening for a long time. If the laws haven't been adjusted to learn from mistakes, it's not because they don't want to learn, but because they want to not learn.

The prosecution must still present evidence that proves guilt beyond reasonable doubt.

"Something something IP address" sort of evidence that the article describes doesn't seem to cut it.

Indeed, but it's up to the defense to articulate what the basis of that doubt is. If you read jury instructions, they typically tell the jurors to only base their decision on the information presented in the courtroom and to set aside their own intuitions, prior life experience etc.

Now this isn't universal; I've seen judges that encourage the jury to ask questions in open court (by submitting as notes to the judge who reads them out), for example. But that's very unusual. Judges who make a habit of questioning submitted evidence are likely to have their rulings challenged far more often and be accused of bias, even if they are superb jurists. And high status in the legal world goes to appellate judges whose rulings set legal precedent. Trial judges do get cool points for calling out bad lawyering and writing spicy opinions but this can also be a career anchor.

We are encouraged by civics classes and media to believe in courts as truth-finding institutions, but the reality is that most of the time they are engaged in argument-scoring. Even to the extent that they do pursue truth via the appellate process, it doesn't happen in a timely fashion. There's saying that the wheels of justice grind slowly, but they grind exceeding fine, which goes back to the Roman empire: so you're looking at an institution that is historically so confident in its process that it has become divorced from any sense of urgency in its application.

Is that the standard for evidence in Canada?
I am curious if you’ve ever met a judge. Every single one I’ve known was a giant, arrogant, jackass. They aren’t actually (generally) interested in being good at their job, they just like the idea.
Happens all the time. You have to then say ”the ip address does not prove it because X”. If prosecutor have a photo of you committing the murder it is enough evidence. But then maybe you will say ”that isn’t me. That’s photoshopped” and then court needs to evaluate if that can be the case or not. But if you don’t give any plausible explanation to the photo it will be used against you.
> happens to have Kik on his device

That would have been (highly likely) true by construction, after all the single underscore username did exist. The only case it wouldn't have been true is if they deleted the app but not their account I guess.

"That would have been (highly likely) true by construction"

You're assuming people knew what evidence to question. That is having the kik app on his device isn't evidence against the claim that "kik didn't return the wrong guys username". Of course it's evidence in support of what he was accused of.

_Exactly_.

Both the article and the parent comment treat "happens to have Kik account" as an independent discovery that affects our Bayesian inference.

No. The innocent was identified exactly _because_ they have a Kik account, so the conditional probability they have a Kik account is 1.

No. If the target of your "Bayesian inference" is whether the chain kik->gmail->ISP is reliable, then it isn't independent evidence. But that isn't the same as the target of inference in court, which is guilt or innocence, and obviously having kik is additional evidence for that. As I mentioned, the chain kik->gmail->ISP would not even be disputed in a run-of-the-mill accusation in the US, any more than DNA evidence gets scrutinized for lab mix-ups. You would need expensive attorneys and experts for that.
If it wouldn't happen today, it's only because the US has a long history of doing this, mainly to black people.

Youre more confident that it doesn't still happen than I am though.