“It’s encrypted, so I guess we’re just out of luck.” I hear some version of that from attorneys and other clients more often than you’d think, usually said with a kind of resigned finality, as though the phone in evidence had sealed itself inside a block of concrete. Sometimes it’s true (well, not the part about the concrete). More often, it isn’t — and treating encryption as the end of the inquiry leaves evidence on the table that the other side may be perfectly happy to collect.
Here’s the thing worth understanding: encryption locks the front door. It rarely locks the windows, the copies, and the spare key under the mat.
Modern devices encrypt data at rest. When an iPhone or a current Android phone or a laptop running FileVault or BitLocker is powered off or locked, the data on it is scrambled and, without the key, is effectively unreadable. That part is real, and it’s strong – it’s real strong. But “the data on that specific device, while it is locked” is a much narrower thing than “the information you’re after,” and the gap between those two is where most access actually happens.
The passcode is the whole ballgame — and people are careless with it. Full-disk encryption is only as strong as the credential protecting it. People reuse passwords, write them on sticky notes, store them in a notes app, share them with a spouse or an assistant, or pick something guessable. When access to a
device is lawfully available — through consent, a cooperating party, or a court order — the encryption stops being an obstacle the moment the passcode is in hand.
And by the way, the data usually lives in more than one place. This is the point often missed. A message exists on the sender’s phone and the recipient’s. When the message’ sender deleted it from their phone, it doesn’t do anything to the recipient’s copy of the message. Photos sync to iCloud or Google Photos. Documents sync to cloud storage. Phones back up to a computer or to the cloud, sometimes automatically, sometimes in a form far easier to access than the locked handset itself. The encrypted device in the evidence bag may be the hardest copy of the data to reach — and the least necessary, once you map where else that same information lives.
Cloud accounts are their own doorway. When the data has synced to a provider, the relevant credential may be an account password rather than a device passcode, and the legal path may be a subpoena or
warrant to the provider rather than an attempt on the hardware. Different lock, different key, often a more productive one.
The law here is genuinely unsettled, and that’s your department, not mine. Whether a person can be compelled to disclose or enter a passcode touches the Fifth Amendment, and courts around the country have landed in different places on it — some applying a “foregone conclusion” rationale, others declining to. Compelled use of a fingerprint or face has its own tangled line of cases. I’m a forensic examiner, not a lawyer, and I won’t pretend the doctrine is settled when it plainly isn’t. But knowing that these avenues exist — and that they’re contested — is the difference between assuming a device is unreachable and asking the right questions about how it might lawfully be reached.
So what should you actually do? Stop treating “it’s encrypted” as the end of the road, as a verdict. Treat it as one locked door in a building with several entrances. Ask where else the data lives — the other party’s device, the cloud, a backup, a synced computer. Preserve all of it early, before someone decides to tidy up. And bring in a forensic examiner before you conclude anything is impossible, because what’s feasible depends heavily on the specific device, the operating system version, and how the data was stored — details that change constantly and that a competent examiner tracks for a living.
Encryption is a strong lock. It is not a force field. The attorneys who understand the difference get to the evidence; the ones who don’t talk themselves out of it.
Have you ever had a case when a locked or encrypted device in your case was or was not actually a dead end? I’d love to hear about it.
Don’t miss a single issue of our informative newsletter … Subscribe now
