DIRECT EXAMINATION BY MS. JOHNSON:
MS. JOHNSON: Good afternoon, Special Agent Croft.
JOSHUA CROFT: Good afternoon.
MS. JOHNSON: Where do you work?
JOSHUA CROFT: Homeland Security Investigations.
MS. JOHNSON: Is Homeland Security Investigations sometimes called HSI?
JOSHUA CROFT: Yes, it is.
MS. JOHNSON: What is your title at Homeland Security Investigations?
JOSHUA CROFT: I'm a special agent and computer forensic agent.
MS. JOHNSON: What difference, if any, is there between a special agent and a computer forensic agent?
JOSHUA CROFT: So the special agent does investigative duties investigating cases, arresting criminals. Computer forensic agent, I received extra training in how to extract data from computers.
MS. JOHNSON: How long have you worked as a special agent or computer forensics agent with HSI?
JOSHUA CROFT: So I've been a special agent since December of 2016 and a computer forensics agent since June of 2023.
MS. JOHNSON: When you were a special agent, were there any particular areas of investigation that you focused on?
JOSHUA CROFT: Yes. I was assigned to the child exploitation investigations unit.
MS. JOHNSON: As a computer forensics agent do you have any areas of focus or is your scope more broad?
JOSHUA CROFT: It's more broad. We support any investigation that our entire agency investigates.
MS. JOHNSON: Have you received training in the analysis of electronic evidence?
JOSHUA CROFT: Yes, I have.
MS. JOHNSON: Have you received training in forensic examinations of electronic devices?
JOSHUA CROFT: Yes, I have.
MS. JOHNSON: And does that include training in the analysis and extraction of laptop computers?
JOSHUA CROFT: Yes, that's correct.
MS. JOHNSON: Can you at a very high level describe some of that training.
JOSHUA CROFT: Sure, yes.
So my earliest certification was a CompTIA A plus certification, which is an entry information technology certification process. I've also attended the basic computer evidence recovery training that my agency, HSI, puts on, as well as the basic mobile evidence recovery training, which handles phones and tablets and those types of devices, and I've also received a certification from the SANS Institute.
MS. JOHNSON: What does that stand for?
JOSHUA CROFT: Actually, I don't know. They are very opaque in that fashion, but it's an information technology and digital forensics organization that provides professional certification, and I have received a certified forensic examiner certification from them.
MS. JOHNSON: As a computer forensic agent at HSI, have you performed extractions on electronic devices?
JOSHUA CROFT: Yes, I have.
MS. JOHNSON: And approximately how many laptops or computers have you extracted during your tenure?
JOSHUA CROFT: Approximately 80.
MS. JOHNSON: I want to talk about a few definitions so we are all on the same page.
At a high level what does it mean to forensically examine an electronic device?
JOSHUA CROFT: So that's for me to extract data without altering it and then reproduce it in reports in a fashion that a layman could understand or examine.
MS. JOHNSON: Can you define the term forensic image.
JOSHUA CROFT: Yes. So when I extract data from a device, we save it in a file generically called a forensic image, which is a package of all the data that's self-verifying so that we know the data is all there and hasn't been altered.
MS. JOHNSON: How do you know that the forensic image of the data that you have extracted correctly copied from the electronic device that you took it from?
JOSHUA CROFT: We do that by checking the hash value of the file when it's copied out.
MS. JOHNSON: Can you explain what a hash value is.
JOSHUA CROFT: Yes. So a hash value is a unique identifier that a mathematical algorithm assigns to a set of data, and that number or the hash value will change if anything in that data is altered. So, for instance, if you had the hash value of a photograph and somebody took that photo and altered even one pixel in it, when it runs back through that computation you'll have an entirely different hash value and know that it's not the same file.
MS. JOHNSON: After you take the forensic image by extracting data from a particular electronic device, what steps, if any, do you take to ensure that the data isn't altered?
JOSHUA CROFT: So the biggest thing we do is, once we have made that original extraction, we call that the gold copy, and that gets saved separately from all the other evidence and stays on its own, and we never use it. What we will do is, we will copy, we will make a working copy of that gold copy so that at any point if that hash value changes through whatever process we examine the file with, we know we have to go back to the original one.
MS. JOHNSON: After you extract data from the electronic device and create the forensic image, do you ever go back to the actual electronic device?
JOSHUA CROFT: Rarely, but there can be instances where you would have to re-examine a device. But we try to limit that -- limit any interaction with the device so we are not altering anything.
MS. JOHNSON: Why do you try to limit interaction with the device?
JOSHUA CROFT: So any time a user interacts with the device, it's leaving some kind of artifact or breadcrumb trail of your presence there, like powering it on, what folders did you open, did you create files on there, and things of that nature. So we want to do everything possible to not alter the data we have.
MS. JOHNSON: I want to focus just on laptops today. What kind of tools do you use to extract the data that is stored in laptops and create the forensic image?
JOSHUA CROFT: In this particular case there is two tools I used. The TX1, which is a hardware device that has a write-blocking capability. And what that means is that when we plug a device into it, we can't write any data to it. It cuts off our interaction to it, so we know that we are only copying out data and not altering what's on there. And another function that device has is, it creates the hash of the extraction we make so we can verify it in the future.
MS. JOHNSON: Is there another tool you used in this case?
JOSHUA CROFT: Yes. There is another tool I used called the digital collector, which is a hardware device that plugs in through a USB into a computer, and it has software on it that helps us extract the data, similar to the TX1, and it also has that same function of creating a hash value for the data you retrieve from a device.
MS. JOHNSON: When you use tools like TX1 and digital collector, how do you know that these tools were successful in extracting the data that's stored on the electronic device?
JOSHUA CROFT: While the device is doing its thing, it creates a log file that shows you the work that's done. That includes the hash verification at the end.
MS. JOHNSON: If there are any errors in the extraction, would that be reflected in the log file?
JOSHUA CROFT: Yes, it would show there.
MS. JOHNSON: And once you have the forensic image created from the electronic device, what do you do with that data to make it user friendly?
JOSHUA CROFT: So like I said earlier, we create that gold copy that stays unaltered, and then we take the working copies that you spawn off of that one, and we feed it into various software programs. In this case I used a program by a company called Magnet. It's called axiom examiner. And you take your extracted data, your forensic image, and you feed it into that, and it will create a report where it shows the data in a more user-friendly manner.
MS. JOHNSON: If I refer to that report that shows data in a more user-friendly manner as the axiom report, will you know what I'm talking about?
JOSHUA CROFT: Yes.
MS. JOHNSON: In the axiom report, how is that data displayed in a more user-friendly manner for an individual to review?
JOSHUA CROFT: So it has a graphic user interface, kind of like any other software program you'd be familiar with where there is different info panes that have categories of data, and then you can take a look at those categories in different windows that show you what content, what data was captured by the program.
MS. JOHNSON: Are the categories of data things like chat messages, documents, images, things like that?
JOSHUA CROFT: Yes. Also operating system artifacts, file system. It uses various different categories and breaks it down so it's much more user friendly.
MS. JOHNSON: And typically is the axiom report searchable?
JOSHUA CROFT: Yes, it is.
MS. JOHNSON: I want to talk about your process now for examining laptops. At a high level can you walk us through the general steps you take when you extract data from a laptop.
JOSHUA CROFT: Sure.
The very first thing I do is, I'll take the chain-of-custody form and sign it to prove that I have accepted it from another person so we can maintain the integrity of the property that way to know who it switched hands from, where and when.
Then the next thing I will do is, I photograph all the devices that come into the lab so I can show what condition it was in, so that say someone can't accuse us of damaging their property later when we return it.
At that point I'll test the function of the devices. In the case of laptops, see if they are charge, the battery charges, does it power on. Typically, we will want to see if there is any user partitions with a password or encrypted hard drives that might make recovering the data difficult. So that's why we power it on, to see if those kind of things are present. Then after assessing the device and its function that way, I'll determine what tool works best to actually create the forensic extraction of that data.
MS. JOHNSON: During this process how, if at all, do you confirm that the data extracted and processed correctly?
JOSHUA CROFT: Like I mentioned earlier, the tools have log functions that tell you what data has been extracted, and they provide you with the hash value of that package of data at the end of that extraction.
MS. JOHNSON: So Special Agent Croft, I want to speak now about your role in this case. Were you asked to extract certain electronic devices in this case?
JOSHUA CROFT: Yes.
MS. JOHNSON: I am going to talk about just three of the electronic devices you extracted today.
Do you have an understanding of whose laptops you extracted that are sitting next to you?
JOSHUA CROFT: Yes. They belong to Cassie Ventura.
MS. JOHNSON: For each of those laptops was a similar process of extraction of the data followed by you?
JOSHUA CROFT: Roughly similar, but each had their own unique kind of challenges to extract the data.
MS. JOHNSON: I want to direct your attention to what's been marked for identification only as Government Exhibit B-100. Do you see that in front of you?
JOSHUA CROFT: Yes, I do.
MS. JOHNSON: Did you perform an extraction on this electronic device?
JOSHUA CROFT: I did.
MS. JOHNSON: How do you know that?
JOSHUA CROFT: So I spoke earlier about the chain-of-custody forms which I have here. Here it shows that I accepted the property from Special Agent Quinn on December 28 in our lab.
MS. JOHNSON: What kind of laptop is the item marked for identification as Government Exhibit B-100?
JOSHUA CROFT: This is a MacBook Pro.
MS. JOHNSON: What's the relative age, give or take, of that MacBook Pro?
JOSHUA CROFT: It's relatively old. It's probably 2010, 2011, roughly.
MS. JOHNSON: What color is the case?
JOSHUA CROFT: It's a white case.
MS. JOHNSON: Can you explain at a high level the process of extracting the data from this particular laptop?
JOSHUA CROFT: Yes. When this one came into the lab, I did the procedure I talked about earlier, took photographs, then plugged it in, indicated it was charging, and I was able to power it up. And it did finish booting up to the MacBook user setup screen.
MS. JOHNSON: What are some reasons why you would see the MacBook user setup screen?
JOSHUA CROFT: So either it would be because it's a brand-new computer out of the box, or a user at some point had wanted to maybe sell it or exchange it, turn it in, and remove their personal data from it. So there is a function inside the MacBook settings where you can reset it to factory defaults.
MS. JOHNSON: Despite being confronted by the factory default screen, what, if any, data were you able to extract from this device?
JOSHUA CROFT: I was able to remove the hard drive and use the TX1 device to extract the data from that, and it did indeed contain data that had not been wiped or overwritten by that factory reset setting.
MS. JOHNSON: Once you extracted the data from using TX1, did you process it into an axiom report?
JOSHUA CROFT: Yes, I did.
MS. JOHNSON: Moving on to the next laptop, which is marked for identification as Government Exhibit B-200, do you see that device in front of you?
JOSHUA CROFT: Yes, I do.
MS. JOHNSON: Did you perform an extraction of data on this electronic device?
JOSHUA CROFT: Yes, I did.
MS. JOHNSON: How do you know that?
JOSHUA CROFT: Again, I have the property custody receipt with me signing for it on December 28.
MS. JOHNSON: What kind of electronic device is Government Exhibit B-200?
JOSHUA CROFT: That is a MacBook Air laptop.
MS. JOHNSON: Can you explain at a high level the process of extracting the data from Government Exhibit B-200?
JOSHUA CROFT: Yes. This one did function, battery charged, and it was able to power on, and it came to a login screen for a user Frank Black, and there was a second login screen for a guest user.
MS. JOHNSON: Focusing on the guest user account, were you able to determine if there was any data stored in the guest user account?
JOSHUA CROFT: There wasn't, but that would be fairly typical because with this version of the Mac operating system a guest-user account, by default, is set to remove any user data that's left there when the computer is powered down.
MS. JOHNSON: Were you able to extract data from this electronic device?
JOSHUA CROFT: Yes. This one I was able to boot up into target disk mode, which is a setting MacBooks have which turn a laptop into a hard drive, in essence, that's recognized by another laptop or another MacBook that you plug it into.
MS. JOHNSON: Since the guest-user profile didn't have any data, is the data that's extracted from the other profile the Frank Black profile?
JOSHUA CROFT: Yes, correct.
MS. JOHNSON: And did you process the extracted data into an axiom report?
JOSHUA CROFT: I did.
MS. JOHNSON: Turning to the last electronic device, which is marked for identification as Government Exhibit B-300, did you perform an extraction on this laptop?
JOSHUA CROFT: Yes, I did.
MS. JOHNSON: How do you know that?
JOSHUA CROFT: Again, I have my signature here on the chain of custody.
MS. JOHNSON: Can you explain at a high level the process of extracting the data from the laptop marked Government Exhibit P-300.
JOSHUA CROFT: Sure. So this particular laptop, when I was assessing it, it was able to power on, but there was a clicking noise that I believe was coming from the hard drive, and it didn't finish the boot process, only a blank screen on the laptop display, so I powered it down and removed the hard drive and the laptop and used the TX1 again to image that.
MS. JOHNSON: I'm sorry. I forgot to ask you. What kind of laptop is Government Exhibit B-300?
JOSHUA CROFT: Sorry. This is a -- looks like the chain of custody got switched here. This -- this is a MacBook Pro.
MS. JOHNSON: And you mentioned that you had to remove the hard drive to extract the data from Government Exhibit B-300. Were you able to recover all the data on that hard drive?
JOSHUA CROFT: No. So there were some bad sectors on that hard drive where there was some damage that wasn't allowing us to recover the data that was on there, but it did recover a majority of the contents of the drive.
MS. JOHNSON: What, if any, signs of physical damage were there to the actual laptop?
JOSHUA CROFT: So you could see some dents and kind of bending around the CD drive on this one, which indicated it had been bumped or dropped possibly at some point.
MS. JOHNSON: Were you able to determine that not all of the data was extracted because of the log files from the TX1 program?
JOSHUA CROFT: Yes, correct. As I spoke about earlier, that TX1 has a function where it will detect bad sectors and then attempt to keep scanning until it finds good sectors, and it will tell you in the log that there were in fact bad sectors where no data was retrieved, but then it shows you where the rest of the data continued.
MS. JOHNSON: After you had extracted the data you were able to extract from the hard drive, did you process that date into an axiom report?
JOSHUA CROFT: Yes, I did.
MS. JOHNSON: I have just a few questions for you about what data looks like once it's processed into an axiom report.
Can you explain for the jury the concept of unallocated space?
JOSHUA CROFT: Yes. Unallocated space is space on the -- on a file system or on a hard drive where something that's not viewable to the user exists, i.e., something that was deleted at some point.
MS. JOHNSON: And can forensic extraction of a device recover data from unallocated space?
JOSHUA CROFT: Yes, it can.
MS. JOHNSON: Can you explain sort of how computers store data and what gets overwritten?
JOSHUA CROFT: Sure. If you imagine a hard drive in the file system as a book, you have the table of contents, which is -- say you're looking at the files on your computer, and you see the list of what files exist there. That's your table of contents. And the files themselves would be the chapters in your book.
And what a computer does for efficiency sake is, when an item is deleted it will remove the entry from the table of contents, but it doesn't waste the time in wiping all of the bits and bytes off the hard drive itself, so the file itself still exists in unallocated space on the hard drive.
MS. JOHNSON: So is that why a forensic extraction can recover some files that a user might not necessarily be able to see on a laptop?
JOSHUA CROFT: Correct. So it would be as if you're looking at the table of contents, but you don't see an entry for chapter 5. But then you skip past the contents of the book and scan through, and you see chapter 5 is there and it will always be there until the file system assigns another file to reside on the spot where chapter 5 was.
MS. JOHNSON: With respect to the three laptops that we are discussing in your testimony today, are you generally familiar with the source of chat messages that were extracted from those laptops?
JOSHUA CROFT: Yes.
MS. JOHNSON: What is the source of the messages?
JOSHUA CROFT: On these devices we found numerous iTunes phone backups. So in the era before the iCloud was popular you could use the iTunes software to plug your phone into your laptop or desktop and create a backup of your phone's contents that would reside on that computer.
(Continued on next page)
BY MS. JOHNSON:
MS. JOHNSON: Were you asked to review some messages from these laptops and assess the way the messages appeared?
JOSHUA CROFT: Yes, I did.
MS. JOHNSON: At a high level, how does the way Axiom is programmed affect the way some chat messages appear once the data is processed into the Axiom report?
JOSHUA CROFT: So sometimes you'll see -- if you think about all the different chat apps that exist from WhatsApp, Signal, Snapchat, or iMessage, each of them uses a different database to store their data, and Axiom itself, as a forensic program, has a limited number of ways to display those different formats of databases back to the user. So sometimes you'll see data that looks kind of funky on what Axiom is showing you, but as a forensic agent, I take a look at the raw data behind what Axiom is showing you to confirm or to verify that data is proper and correct.
MS. JOHNSON: When you see data that, as you said, looks kind of funky, is the way to check the source of that data to go to the actual raw data as you just described?
JOSHUA CROFT: Yes, so one of the features Axiom has, not only does it have an interface that allows the lay person to view the reports, it also will show you the behind the scenes. It has the software in it that allows you to view all these different types of databases or the raw bits and bytes straight off the forensic image.
MS. JOHNSON: I want to talk about some of the ways in which data can appear funky in Axiom due to the programming that you just described. Is one of those ways the way usernames appear in chat threads?
JOSHUA CROFT: Yes, that can happen.
MS. JOHNSON: What about duplicate messages in one thread?
JOSHUA CROFT: That's another potential issue we encounter.
MS. JOHNSON: Is there any other technical explanation for having duplicate messages in some chat threads?
JOSHUA CROFT: Yes, especially some of the ones I reviewed on this one, in these laptops is that there were several phone backups from the same device that existed on there. So you can imagine, you know, over the years you backed up your phone one, two, or three times, all three of those three different phone backups are on there. In those instances, there were overlap and the same exact message appearing three times.
MS. JOHNSON: What about blank messages appearing in chat threads, is that another one of the issues you described?
JOSHUA CROFT: Yes. That can happen commonly when you're dealing with the carved data, which we recovered from unallocated space. So you can never guarantee that all of that chapter 5 in the example wasn't at least partially overwritten by another file, you may be able to recover the majority of it, but there might be little bits that the program can't find and can't recover.
MS. JOHNSON: What about message threads that appear to be either missing participants or missing other indicia like timestamps?
JOSHUA CROFT: So those can be manifested by sometimes different versions of an app having different naming conventions in the tables in their databases. So if you imagine a version 1 of a messaging app having a column in its data saying, message send date, and then eight years down the road — this is just a hypothetical example — they change the format of it, they shift the column over one and call it date message sent, Axiom is going to have a problem in some instances representing that data, but that's why we check and verify that the data is there.
MS. JOHNSON: Thank you, Special Agent Croft. I have no further questions at () this time.
THE COURT: Cross-examination.
MS. GERAGOS: Thank you.
CROSS-EXAMINATION BY MS. GERAGOS:
MS. GERAGOS: Good afternoon, Special Agent Croft. My name is Teny Geragos. I want to personally thank you for explaining this all to us.
JOSHUA CROFT: You're welcome.
MS. GERAGOS: I just have a few questions for you and then we can be on with our day.
So you testified that Ms. Ventura gave Homeland Security these three devices that we just looked at, right?
JOSHUA CROFT: Yes.
MS. GERAGOS: And she gave Homeland Security essentially what's called a consent to search those devices, right?
JOSHUA CROFT: That's correct.
MS. GERAGOS: And can you explain to the jury what a consent to search means versus a warrant?
JOSHUA CROFT: Sure. So in the course of an investigation, we can ask a witness, or even a suspect for that matter, if they would consent to have us search a device, and if they agree to it, that's one way we would examine a device without having obtained a warrant.
MS. GERAGOS: And we just went through B-100, B-200, and B-300. So for B-100, that device was operable when you turned it on, right?
JOSHUA CROFT: Correct.
MS. GERAGOS: And it was not damaged?
JOSHUA CROFT: No.
MS. GERAGOS: And it was not broken?
JOSHUA CROFT: Correct.
MS. GERAGOS: And then for B-200, I think you said that was the MacBook Air, right?
JOSHUA CROFT: Let me doublecheck for you.
MS. GERAGOS: Thank you.
JOSHUA CROFT: That's correct, MacBook Air.
MS. GERAGOS: And that was operable when you opened it and had it charged?
JOSHUA CROFT: Correct.
MS. GERAGOS: It was not broken or damaged?
JOSHUA CROFT: Correct.
MS. GERAGOS: And B-200 was the device that, when you opened it, there were two user profiles?
JOSHUA CROFT: Correct.
MS. GERAGOS: There was the Frank Black user profile and the guest user profile?
JOSHUA CROFT: That's correct.
MS. GERAGOS: And you determined that there was no material in the guest setting, right?
JOSHUA CROFT: Yes.
MS. GERAGOS: But Ms. Ventura had given you consent to search this device, right?
JOSHUA CROFT: That's correct.
MS. GERAGOS: Were you able to collect or process every single file from this device, from what you could tell, you had no issues extracting the data from this device?
JOSHUA CROFT: From what I could tell, the log indicated we collected the data successfully without errors like in the instance of the third laptop I talked about.
MS. GERAGOS: We'll get to the third one so I can understand that a little bit more.
For this, what we'll call the Frank Black and guest user laptop, B-200, you did not encounter any problems when you opened it, powered it on, and then extracted the data, right?
JOSHUA CROFT: Correct.
MS. GERAGOS: And we get to the third one, which is B-300, and I didn't catch what type of MacBook model that was.
JOSHUA CROFT: Let me get that for you. So this was a MacBook Pro.
MS. GERAGOS: Were you able to determine the approximate year from that model?
JOSHUA CROFT: The model number is A1278 -- I don't know the exact year that would have been released.
MS. GERAGOS: Was this a laptop that had a CD slot in it?
JOSHUA CROFT: Yes.
MS. GERAGOS: And so what would that indicate to you as to the age of the laptop?
JOSHUA CROFT: It would be a fairly old model if it still had a CD drive in it.
MS. GERAGOS: Do you know an approximate year, give or take one or two years, or no?
JOSHUA CROFT: Best guess would be before 2012.
MS. GERAGOS: And so you charged that, you powered it on, but that one just did not finish booting. Can you just explain how that one worked when you turned it on?
JOSHUA CROFT: Correct. So there was -- when I turned it on, the screen was black and it never showed a login screen, and you could hear a faint clicking, which sometimes indicates there's some type of damage on a hard drive.
MS. GERAGOS: And I think you said it had appeared slightly damaged, like it was bumped or it was dropped, right?
JOSHUA CROFT: Correct.
MS. GERAGOS: And you had attributed that to perhaps the reason why it was clicking when you turned it on?
JOSHUA CROFT: Yes.
MS. GERAGOS: And you were still able to extract a lot of data from that laptop; is that right?
JOSHUA CROFT: That's correct.
MS. GERAGOS: And then going back to, well, I guess all of them. You described the reason for duplicate messages, and I think you described the reason, as you go back before we had iCloud backups, we could back up our phones to our iTunes, right, you could just plug in your phone to a cord to a laptop, right?
JOSHUA CROFT: That's correct.
MS. GERAGOS: And you could select on iTunes and say, back up your phone, right?
JOSHUA CROFT: That's correct.
MS. GERAGOS: And so, for example, B-200 had several phone backups onto that computer, right?
JOSHUA CROFT: That's correct, yes.
MS. GERAGOS: And that's why there are sometimes duplicate messages for many of the chats on that device, right?
JOSHUA CROFT: Yes. I can't speak to every single time there was a duplication, but from the checking and verification I did, that did appear to be the cause.
MS. GERAGOS: Understood. Thank you.
Did you review, I know that you processed B-100, B-200, B-300, meaning that you extracted, and I know you reviewed some of the chats because we asked you to, which is very helpful, so thank you, but did you review any of the data on either of the devices after you extracted it, did you then go through the review step once you had extracted the data?
JOSHUA CROFT: No. So I didn't do the full review. What I'll do is I'll do spot-checking to see, you know, you're expecting to see certain types of files, do those show up in the report, and at that point it was passed on to other agents to do the full review.
MS. GERAGOS: So other agents in HSI are then assigned to review the extraction and see basically what's relevant from the laptop; is that right?
JOSHUA CROFT: That's correct.
MS. GERAGOS: Thank you, agent Croft. We really appreciate it. Have a wonderful weekend.
THE COURT: Redirect?
MS. JOHNSON: Just one redirect question, Special Agent Croft.
REDIRECT EXAMINATION BY MS. JOHNSON:
MS. JOHNSON: On Government Exhibit B-200, when you came across the user profile Frank Black, did you continue to process the data under the consent that Ms. Ventura had given?
JOSHUA CROFT: No. So what I did was, to preserve the data, I did a forensic image, then I contacted the agent and let him know that there was a user partition on there that indicated that it possibly belonged to somebody else, so we didn't actually process any data or search it until later.
MS. JOHNSON: And was a warrant obtained before it was processed or searched?
JOSHUA CROFT: Yes, it was.
MS. JOHNSON: No further questions.
THE COURT: Thank you very much, agent Croft.
JOSHUA CROFT: Thank you.
(Witness excused)
THE COURT: The government have any further witnesses for today?
MS. COMEY: Not for today, your Honor. If it's all right with your Honor and defense counsel, we propose to end the week early.
THE COURT: Any objections from the jury?
I'm going to give you some instructions for our long weekend, you've earned it, four days off, but this is when it is very important for you to follow those instructions. Do not talk to anyone about the case. If anyone tries to talk to you about the case, walk away or tell them that you cannot talk about it because I am ordering you not to talk about the case. You can tell them that. Do not watch, look up, browse, read, or use your phone or computer to access anything about the case. So if you see something come up on the TV screen, change the channel, turn the TV off, go for a walk. These are some things you can do. If something appears on your phone, you can swipe away, turn off your phone, go on a bike ride, watch the Nicks avenge their game one loss. Don't try to research anything. Do not look up the attorneys, the places, the people, or things in this case. And do not try to talk to the lawyers or reach out to them or anyone involved in this case. Don't reach out to them in any way, shape, or form, electronically or otherwise. Don't try to talk to anyone in the courthouse about the case. And no one in the courthouse is to talk to you. If anyone breaks these rules, let me know. If you see or hear another juror violate these rules, it is your job to let me know. It's not tattling -- it is tattling, but the law requires you to tattle under these circumstances.
So look, including jury selection, you all have been here for basically four weeks, and this is an immense public service, we are making great progress, we are right on schedule. So thank you very much for your hard work. Enjoy the long weekend. You all really deserve it. And if there's anything that would make your jury service more pleasant, please let our courtroom deputy know and we will get on it. I think it's a little warmer here today. So we'll keep working on everything to make your service as pleasant as possible. Thank you very much.
All rise.
(Continued on next page)
(Jury not present)
THE COURT: Anything further to address before you all go to sleep?
MS. COMEY: Not from the government, your Honor.
THE COURT: Anything from the defense?
I guess I would ask who the next witnesses are if you have that information here. I know you're going to furnish a list to the defense, but if you have it.
MS. COMEY: Let me just confer and make sure I don't misspeak, your Honor.
Your Honor, on Tuesday, our first witness will be Capricorn Clark. After that we will have a witness from the LAPD and a witness from the LAFD, and I think that will take us through the end of the day Tuesday. And if it's all right with your Honor, we're working through travel through the rest of the week, so we will email the Court and defense after we get out of court today, so later today with the rest.
THE COURT: That's fine. Are you still thinking six weeks for the case in chief?
MS. COMEY: Yes, your Honor. I think we're right on time. I say that hesitating not knowing how long cross examinations for certain witnesses will be, but I do think our case will end up being just about six weeks.
THE COURT: Are we still looking, I did tell the jurors we were going to try to get this done on July 4th, and it's too early to really be able to predict with any certainty going through trial, but is there any reason not to think that we're going to able to meet that deadline, from the government's perspective?
MS. COMEY: Not from the government's perspective, your Honor, assuming that the defense case is no more than about a week and then we do summations and charge the jury. I would think that we should be able to wrap this up before the 4th of July.
THE COURT: So I'll just ask everybody, when you get that first inkling that there's an issue or there's going to be an extension, let me know so I can let the jurors know there might be a delay. I think if you do things in advance, it comes off much better. Thank you.
Mr. Agnifilo.
MR. AGNIFILO: We'll do that, Judge. I'm sorry to ask the Court. The VTC, anything from the -- and I'm not expecting, I know that your Honor was involved, we'll keep pushing things on our end, too, but we just haven't had a great deal of success.
THE COURT: Yeah, me neither.
MR. AGNIFILO: I know.
THE COURT: So we did reach out to the BOP to see if they'll be able to accommodate nighttime access to the VTC, which they said they could absolutely not do, but never say never. If there's something that you can think of.
And let me ask, Ms. Comey, are you aware of anything that can be done along these lines? I mean, in terms of the hours, I think there are some limitations, there are some issues just with general staffing that prevent them from being able to do this, but in your experience, is there any alternative or anything you can think of that we could do?
MS. COMEY: In terms of the timing of the VTC, your Honor?
THE COURT: I think it's more about the amount of access, if there's a way to work --
MS. COMEY: I've had a case before where accommodations were made, and I'm thinking, I can remember a couple where accommodations were made where defendants were given additional VTC time on weekends and holidays when we were able to say the Judge would really like this to happen. We can try to call and convey that the judge in this case would really like this to happen.
THE COURT: I would appreciate that, if you could do that. And we have a four-day weekend. At least for this next four-day period, it may be possible for you to get that additional time since we won't be here in the courtroom during the day.
MR. AGNIFILO: The other request, and I'm sorry to keep coming back to this, is if we don't get more VTC time, maybe get more phone time? I think we're out of minutes. And so if we can't speak on --
THE COURT: I saw that in your letter. Let me work on that.
MR. AGNIFILO: Thank you, Judge. I know this is a little unorthodox, we really appreciate it.
THE COURT: That's fine. Let's try to get you more time.
Anything else?
MS. SHAPIRO: Your Honor, with respect to the Court's deadlines for Sunday nights, can we move those to Monday night just for this week because Monday is a holiday?
THE COURT: Sure. Hopefully I don't have to put in something in writing.
Anything else?
MR. AGNIFILO: I think that's all we have for you this week, Judge.
THE COURT: Everyone has done a fantastic job. Thank you. If there's anything else we can do on a procedural level to help things move along more smoothly, let us know. Otherwise, a well deserved break for everyone. So have a great holiday and we'll see you back here on Tuesday.
(Adjourned to May 27, 2025 at 8:30 a.m.)