UNITED STATES NEWS

‘Cold’: FBI, Secret Service failed to crack Josh Powell’s encryption

Jan 31, 2019, 11:00 AM

This still frame image from one of Steve Powell's home videos shows his oldest son, Josh Powell, si...

This still frame image from one of Steve Powell's home videos shows his oldest son, Josh Powell, sitting at his computer in 2003. Josh Powell's use of encryption on his personal files continues to frustrate police investigating the Dec. 7, 2009, disappearance of Josh Powell's wife, Susan Powell. (Caption: West Valley Police Department)

(Caption: West Valley Police Department)

Editor’s note: This is the 12th of a weekly series featuring highlights from a KSL investigative podcast series titled “Cold” that reports new information about the case of missing Utah woman Susan Powell.

WEST VALLEY CITY — An off-the-shelf computer hard drive seized from the basement office of Josh and Susan Powell’s home the day after her disappearance continues to frustrate police more than nine years later.

Warrants filed in the case as far back as Dec. 8, 2009, show police believe the drive could hold evidence related to Susan Powell’s disappearance the day before.

The Western Digital-brand “My Book World Edition” external drive, 1 terabyte in capacity, is locked with encryption. All efforts to crack that encryption have so far failed.

West Valley police suspect this Western Digital external hard drive seized from Josh and Susan Powell’s home on Dec. 8, 2009, might hold evidence related to Susan Powell’s unsolved disappearance. The drive was encrypted and has resisted all efforts to circumvent that encryption. (Photo: West Valley City, Utah police)

The first stop for that hard drive after police took it from the Powell home with a search warrant was the Intermountain West Regional Computer Forensics Laboratory in Salt Lake City.

FBI supervisory special agent Cheney Eng-Tow said the laboratory’s digital forensic experts worked with West Valley police detectives. They produced an exact copy of the drive, called a mirror. Then they attempted to extract information from the mirror using specialized software called a forensic tool kit.

That failed because the drive had been encrypted. Agents tried several methods of circumventing the encryption, from guessing potential passwords to attempting a “brute force” attack.

“You’re just trying combinations from the dictionary, combinations of letters, alpha-numeric characters, and so the longer that password is, the longer it’s going to be before you can break it,” Eng-Tow said.

While serving a search warrant at the South Hill, Wash., home of Steve Powell on Aug. 25, 2011, police looked for any writings that appeared to hold possible passwords. Those potential passwords were entered into Josh Powell’s encrypted digital media, in the hopes of getting past encryption. (Photo: West Valley City, Utah police)

Laboratory analysts also attempted more human approaches, such as using children’s names or birthdates.

“We do break encryption here on cases. Sometimes we’re successful doing it, other times we’re not,” Eng-Tow said. “FBI headquarters has a unit basically that can try and do that as well.”

FBI

On June 22, 2010, 3rd District Judge Robert Hilder signed a warrant allowing the forensics laboratory to send three encrypted devices, including the mirror of that Western Digital hard drive, to FBI headquarters in Quantico, Virginia.

West Valley police asked for court permission in 2010 to provide Josh Powell’s encrypted digital media to FBI headquarters in Quantico, Va. After more than a year, the FBI reported that it was unable to access the devices. (Photo: West Valley City, Utah police)

After more than a year, FBI headquarters returned the drives to Utah. The bureau had been unable to access them.

Case records show West Valley police also requested help from AccessData, the Utah-based software vendor that produced the forensic tool kit program used by the FBI, as well as the U.S. Secret Service.

The city submitted a mirror to the federal agency but in May 2011, the Secret Service reported that it was also unable to crack the encryption.

Decipher forensics

A secrecy order prevented police from discussing the case or their evidence until May 2013, when the Susan Powell case officially became “cold.” By that point, Josh Powell and his brother Michael Powell, who police suspected had knowledge of Susan Powell’s death, had both committed suicide.

In October of 2013, after a judge had lifted that secrecy order, Susan Powell’s father Chuck Cox suggested that police submit a mirror to a Utah company called Decipher Forensics. The lead detective on the Powell case, Ellis Maxwell, spoke with Trent Leavitt from Decipher the following month.

“I explained to Trent that Josh Powell admitted he used a 24 character password … when we seized further digital media,” Maxwell wrote in a later report. “At that time in 2011, Josh admitted and provided one password that was potentially 56 characters long.”

This still frame image from one of Steve Powell’s home videos shows his oldest son, Josh Powell, sitting at his computer in 2003. Josh Powell’s use of encryption on his personal files continues to frustrate police investigating the Dec. 7, 2009, disappearance of Josh Powell’s wife, Susan Powell. (Caption: West Valley Police Department)

Maxwell provided a mirror to Decipher Forensics in December of 2013. Four years later, Decipher had still not succeeded in cracking the drive. Police records revealed Decipher requested and received access to mirrors of all the other computer drives seized from the Powell home in 2009, along with the FBI’s analysis and other case documents.

At that time in 2017, investigators reminded Decipher staff they were prohibited from discussing their efforts under a non-disclosure agreement.

Case files also indicate that on Jan. 4, 2018, police provided yet another mirror of the encrypted drive to a computer systems security expert with Intermountain Healthcare. An IHC spokesman said that employee volunteered his expertise as a private individual and the device in question never entered an Intermountain facility.

Complex password

The most simple solution would have been for Josh Powell to voluntarily provide his password to police. They requested he do so multiple times, but he frequently claimed to have forgotten it.

Because the entire volume is encrypted, there’s no way to know how much data it actually holds or if any of its contents are relevant to the case. Many of Susan Powell’s friends and family members suspect the drive might be the last, best chance of learning what happened to her.

“It’s good maybe to be optimistic like that, but in the end there could be nothing on it of value,” Eng-Tow said. “Is there something on there that is incriminating or not? You’ll never know until you actually get into it and see it.”

United States News

FILE - President Joe Biden speaks in the East Room of the White House, Oct. 30, 2023, in Washington...

Associated Press

Biden heads to Las Vegas to showcase $8.2B for 10 major rail projects around the country

WASHINGTON (AP) — President Joe Biden is heading to Las Vegas to showcase $8.2 billion in funding for 10 major passenger rail projects across the country, including to spur work on high-speed, electric train routes that could one day link Nevada and California, as well as Los Angeles and San Francisco. The administration says the […]

3 hours ago

Associated Press

Palestinians crowd into ever-shrinking areas in Gaza as Israel’s war against Hamas enters 3rd month

RAFAH, Gaza Strip (AP) — Desperate Palestinians fleeing Israel’s expanding ground offensive crowded into an ever-shrinking area of the Gaza Strip as the Israel-Hamas war entered its third month Friday. The United Nations warned that its aid operation is “in tatters” because no place in the besieged enclave is safe. Israel’s ferocious military assault on […]

4 hours ago

Associated Press

UNLV gunman was unemployed professor who had 150 rounds of ammunition and a target list, police say

LAS VEGAS (AP) — A 67-year-old college professor who was denied jobs at various Nevada colleges and universities stuffed loaded handgun magazines into his waistband before walking into a University of Nevada, Las Vegas campus building and killing three faculty members, police said. After police killed him in a shootout, Anthony Polito was found to […]

7 hours ago

FILE - This undated photo provided by the Hennepin County Sheriff's Office in Minnesota on June 3, ...

Associated Press

High-profile attacks on Derek Chauvin and Larry Nassar put spotlight on violence in federal prisons

Derek Chauvin was stabbed nearly two dozen times in the law library at a federal prison in Arizona. Larry Nassar was knifed repeatedly in his cell at a federal penitentiary in Florida. The assaults of two notorious, high-profile federal prisoners by fellow inmates in recent months have renewed concerns about whether the chronically understaffed, crisis-plagued […]

8 hours ago

FILE - Maureen Reid, left, and her guide dog, Gaston, cross the intersection of Wood Street and Roo...

Associated Press

Census Bureau wants to change how it asks about disabilities. Some advocates don’t like it

The U.S. Census Bureau wants to change how it asks people about disabilities, and some advocates are complaining that they were not consulted enough on what amounts to a major overhaul in how disabilities would be defined by the federal government. Disability advocates say the change would artificially reduce their numbers by almost half. At […]

8 hours ago

This cover image released by Money/Republic Records shows “Pink Friday 2” by Nicki Minaj, relea...

Associated Press

Attention all Barbz: Nicki Minaj has released ‘Pink Friday 2,’ 13 years after the original

LOS ANGELES (AP) — Nicki Minaj ‘s highly anticipated fifth studio album, “Pink Friday 2,” is finally here. Out Friday, the 10-time Grammy nominee’s 41st birthday, “Pink Friday 2” is Minaj’s first full-length release since 2018’s “Queen.” The 22-track release is stacked with features, including contributions from Drake, Lil Wayne, J. Cole, Lil Uzi Vert […]

8 hours ago

Sponsored Articles

Follow @iamdamonallred...

Avoid a potential emergency and get your home’s heating and furnace safety checked

With the weather getting colder throughout the Valley, the best time to make sure your heating is all up to date is now. 

...

Dierdre Woodruff

Interest rates may have peaked. Should you buy a CD, high-yield savings account, or a fixed annuity?

Interest rates are the highest they’ve been in decades, and it looks like the Fed has paused hikes. This may be the best time to lock in rates for long-term, low-risk financial products like fixed annuities.

Follow @KTAR923...

West Hunsaker at Morris Hall supports Make-A-Wish Foundation in Arizona

KTAR's Community Spotlight this month focuses on Morris Hall and its commitment to supporting the Make-A-Wish Foundation in Arizona.

‘Cold’: FBI, Secret Service failed to crack Josh Powell’s encryption