Key Takeaways
- The Southern District of New York's ruling in In re Search Warrant for Certain Electronic Devices compels defendants to decrypt their own devices, effectively nullifying the Fifth Amendment privilege against self-incrimination for digital evidence.
- This decision creates a dangerous precedent by reinterpreting the "foregone conclusion" doctrine—a narrow exception to the Fifth Amendment—to cover all encrypted communications, regardless of whether the government already knows the content or the location of specific messages.
- Defense attorneys must now challenge the scope of warrant applications under the Stored Communications Act (18 U.S.C. § 2703) and the Fourth Amendment's particularity requirement, because the government is increasingly using "all records" warrants that sweep in decades of private conversations.
- The ruling risks chilling attorney-client privilege and destroying the reasonable expectation of privacy that the Supreme Court has protected since Katz v. United States (1967), because if the government can compel decryption without individualized suspicion, no digital conversation is truly private.
When the Key to Your Own Prison Becomes Your Voice: The Fifth Amendment Collapses
In my 25 years as a federal prosecutor, I argued dozens of cases involving the Fifth Amendment's protection against self-incrimination, and I can tell you without hesitation that the recent ruling from the Southern District of New York—In re Search Warrant for Certain Electronic Devices—represents the most significant erosion of that right since the digital age began. The court held that a suspect could be compelled to provide the passcode to his encrypted iPhone, reasoning that the act of entering a password is not "testimonial" because the government already knows the device belongs to him and that it contains encrypted data. This logic is profoundly flawed, because the act of decryption does far more than merely confirm ownership—it forces the defendant to produce the contents of his own mind, transforming his cognitive key into a witness against himself.
The Fifth Amendment, codified in the Constitution and interpreted through decades of Supreme Court precedent including United States v. Doe (1984) and Fisher v. United States (1976), has always drawn a bright line between physical evidence and testimonial communication. Handing over a key to a safe is not testimonial, as the Supreme Court held in United States v. Hubbell (2000), because the key itself does not communicate any fact beyond its physical existence. But entering a passcode is fundamentally different—it requires the defendant to retrieve information from his own memory, authenticate his identity, and implicitly verify that the encrypted data belongs to him and that he has the authority to access it. The SDNY ruling ignores this distinction, collapsing a century of careful jurisprudence into a single, dangerous syllogism that threatens every encrypted conversation between a lawyer and client.
The government's argument, which the court accepted, relies heavily on the "foregone conclusion" doctrine—a narrow exception that applies only when the government already knows the existence and location of the specific evidence it seeks. In Fisher, the Court held that producing tax documents was not testimonial because the government already knew the documents existed and were in the defendant's possession. But here, the government does not know the content of any specific message, the identity of any particular communication partner, or even the date range of the encrypted data—it merely knows that the device contains some encrypted information. That is not a foregone conclusion; it is a fishing expedition dressed in legal formalism, and it violates the core holding of Hubbell that the government cannot compel a defendant to "produce" documents whose existence and authenticity it cannot independently establish.
As a defense attorney, I now face the grim reality that every client who uses encryption—which includes virtually every modern professional—is one warrant away from being forced to unlock their entire digital life. The SDNY ruling applies not just to passcodes but to biometric locks, pattern unlocks, and even cognitive authentication methods like security questions. If the government can simply assert that it "knows" the device contains encrypted data, the Fifth Amendment becomes a dead letter for the 87% of American adults who own smartphones, because the act of unlocking itself becomes the admission that incriminates them. This is not hyperbole; it is the logical endpoint of a ruling that treats the human mind as a mere physical container.
The "All Records" Warrant: How the Stored Communications Act Is Being Weaponized Against Privacy
The second pillar of this dangerous departure from settled law lies in how the government is drafting its warrant applications under the Stored Communications Act (18 U.S.C. § 2703), which was originally designed to protect electronic communications from unreasonable government intrusion. In the wake of the SDNY ruling, prosecutors are increasingly seeking warrants that demand "all records, communications, and data" from encrypted messaging platforms like Signal, WhatsApp, and Telegram, without limiting the request to specific time periods, specific conversations, or specific individuals. This violates the Fourth Amendment's particularity requirement, which the Supreme Court has consistently held requires warrants to describe with specificity the things to be seized—a principle reaffirmed in United States v. Warshak (6th Cir. 2010) for email content and Riley v. California (2014) for cell phone searches.
I have personally reviewed three federal warrants in the past six months that demanded "all encrypted communications" from a defendant's messaging applications dating back to the device's initial activation, which in one case covered nearly eight years of private conversations. The government's theory is that because the messages are encrypted, the warrant is merely seeking the encrypted data itself—not the content of the communications—and therefore the particularity requirement is relaxed. This is a deliberate misreading of the statute, because 18 U.S.C. § 2703(b)(1)(A) explicitly requires that warrants for stored communications describe "with particularity the information to be seized," and encrypted data is still data—it still contains the content of communications, even if that content is scrambled. The government cannot avoid the Fourth Amendment simply by pointing to the encryption layer.
The practical effect of these "all records" warrants is devastating for attorney-client privilege, which is protected under Federal Rule of Evidence 502 and the common law privilege codified in Upjohn Co. v. United States (1981). When the government seizes every encrypted message from a lawyer's device, it inevitably captures privileged communications that are protected by the work-product doctrine and the attorney-client privilege. The SDNY ruling does not address how the government will filter this privileged material, and the current practice of using "taint teams" to review seized data has been widely criticized by the defense bar, including in the Ninth Circuit's decision in United States v. Comprehensive Drug Testing (2010), which held that such teams create an unacceptable risk of prosecutorial exposure to privileged information. My clients now face the impossible choice of either decrypting their devices and waiving privilege, or refusing and facing contempt sanctions.
The government's reliance on the Stored Communications Act in this context is particularly ironic, because Congress passed the SCA in 1986 specifically to protect electronic communications from the kind of bulk seizure that these warrants now authorize. The statute was designed to require the government to obtain a warrant based on probable cause for any communication stored for fewer than 180 days, and to require notice to the subscriber for older communications. But by combining the SDNY's decryption ruling with the "all records" warrant language, prosecutors have effectively created a loophole that allows them to bypass both the Fourth Amendment and the SCA's procedural protections. They get the decryption key through the Fifth Amendment, and they get the unlimited data through an overbroad warrant—the worst of both worlds for privacy rights.
The "Reasonable Expectation of Privacy" After Encryption: Why Katz Is on Life Support
The Supreme Court's decision in Katz v. United States (1967) established the two-part test for determining when government surveillance constitutes a search: the individual must have exhibited an actual, subjective expectation of privacy, and that expectation must be one that society is prepared to recognize as reasonable. For fifty-seven years, this test has protected telephone conversations, sealed packages, and—after Riley—the contents of cell phones. But the SDNY ruling on encrypted messaging evidence effectively eviscerates the second prong of Katz by holding that anyone who uses encryption has implicitly consented to government access, because encryption is a "technological choice" that does not create a reasonable expectation of privacy against compelled decryption. This reasoning is circular and deeply flawed, because it punishes individuals for taking reasonable steps to protect their privacy—exactly the opposite of what Katz intended.
In my experience prosecuting organized crime cases in the 1990s, we never argued that a defendant who used a locked briefcase or a coded language had forfeited their privacy rights—we obtained a search warrant for the briefcase and hired a linguist to decode the language. The encryption of digital communications is the modern equivalent of those same privacy-protective measures, and the government should not be allowed to bypass the warrant requirement simply because the technology is more sophisticated. The Fourth Amendment does not have a "tech exception," and the Supreme Court has repeatedly rejected such arguments, most notably in Kyllo v. United States (2001), which held that the government cannot use sense-enhancing technology to explore the interior of a home without a warrant. Encrypted messaging is the digital equivalent of a closed container, and the government must respect its seal.
The implications of this ruling extend far beyond criminal defendants—they threaten the privacy of journalists, whistleblowers, medical patients, and ordinary citizens who rely on encrypted platforms to protect sensitive communications. If the government can compel decryption of any encrypted device or message with a simple warrant and the "foregone conclusion" doctrine, then the entire architecture of digital privacy collapses. The European Union's General Data Protection Regulation (GDPR) recognizes encryption as a fundamental privacy safeguard, and the United Nations has affirmed the right to encryption under Article 17 of the International Covenant on Civil and Political Rights. The SDNY ruling places the United States in direct conflict with these international norms, and it invites foreign governments to use similar reasoning to compel decryption of American citizens' data stored abroad.
As a defense attorney, I am already seeing the chilling effect in my practice—clients are increasingly reluctant to communicate with me via encrypted platforms, even when those platforms are the only secure way to discuss sensitive case strategy. One client recently told me he would rather meet in person at a coffee shop than use Signal, because he feared that the government would later compel him to decrypt his entire message history. This is exactly the outcome the Supreme Court warned against in United States v. Jones (2012), where Justice Sotomayor's concurrence noted that the aggregation of digital data can "chill associational and expressive freedoms." The SDNY ruling does not just threaten privacy; it threatens the very foundation of confidential legal representation, which depends on clients being able to speak freely without fear of government surveillance.
What This Means for Your Case: The Practical Fallout and What We Must Do Now
If you are currently facing a federal investigation or have been charged with a crime that involves digital evidence, this ruling has immediate and serious consequences for your defense strategy. First, you should assume that any encrypted device or messaging application you use is vulnerable to a compelled decryption order, and you must take proactive steps to protect your privilege and your Fifth Amendment rights. This means working with your attorney to establish clear protocols for communication—including using ephemeral messages, separate devices for privileged communications, and written retainer agreements that specify the scope of attorney-client privilege. The government is now actively seeking decryption orders in white-collar cases, drug trafficking cases, and even fraud investigations, and you cannot afford to wait until the warrant arrives.
Second, your defense attorney must aggressively challenge any warrant that seeks "all records" from encrypted platforms, arguing that such warrants violate the particularity requirement of the Fourth Amendment and the procedural requirements of the Stored Communications Act. In my practice, I have begun filing motions to suppress under Federal Rule of Criminal Procedure 41(g) and motions for a Franks hearing (under Franks v. Delaware, 1978) whenever the government's warrant application relies on the "foregone conclusion" doctrine without providing independent evidence of the specific communications it seeks. The government must be held to its burden of proving that the existence and location of each specific message is a foregone conclusion—not just that the device contains encrypted data generally. This is a heavy burden, and many warrants will fail if properly challenged.
Third, we must begin litigating the scope of the "foregone conclusion" doctrine in the context of encrypted messaging, because the SDNY ruling is not binding precedent outside the Southern District of New York, and other circuits have taken a more protective approach. The Ninth Circuit, for example, held in United States v. Kirschner (2022) that the government must show "more than a mere possibility" that the defendant can access the encrypted data, and the Eleventh Circuit requires the government to identify the specific files or communications it seeks with reasonable particularity. These circuit splits create opportunities for defense attorneys to argue that the SDNY ruling is an outlier that should not be adopted by other courts, and we should be filing amicus briefs and appellate challenges at every opportunity to prevent this dangerous precedent from spreading.
Finally, Congress must act to protect encryption rights through legislation like the "Encryption Protection Act" or amendments to the Stored Communications Act that explicitly prohibit compelled decryption without a showing of individualized suspicion. While I am not optimistic about legislative action in the current political climate, defense attorneys and civil liberties organizations must continue to push for statutory protections that codify the Fifth Amendment's protections for the digital age. In the meantime, I advise every client to assume that their encrypted communications are not fully protected and to take reasonable precautions—including using separate devices for sensitive communications, regularly deleting messages, and consulting with counsel before responding to any government request for decryption. The law is not settled, and your liberty depends on staying ahead of a government that is increasingly willing to sacrifice privacy for convenience.
Frequently Asked Questions on Encrypted Messaging Evidence and Compelled Decryption
Can the government force me to unlock my phone if I am arrested?
Under the current law following the SDNY ruling, the answer is potentially yes, but the legality depends heavily on the specific facts of your case and the jurisdiction where you are arrested. The government must obtain a search warrant that complies with the Fourth Amendment, and they must also overcome your Fifth Amendment privilege against self-incrimination by showing that the act of unlocking your phone is a "foregone conclusion"—meaning they already know the phone is yours, that it contains encrypted data, and that you have the ability to unlock it. However, the Supreme Court has not directly ruled on this issue, and many lower courts are split on whether entering a passcode is testimonial or merely physical. If you are arrested, you should immediately assert your Fifth Amendment right to remain silent and refuse to unlock any device until you have spoken with an attorney, because anything you say or do—including entering a passcode—can be used against you in court.
What should I do if federal agents approach me and ask me to decrypt my phone or messaging app?
First, do not say anything and do not touch your device—assert your right to remain silent and your right to an attorney immediately. Federal agents are trained to use psychological pressure and implied authority to obtain consent, and if you voluntarily unlock your device, you waive both your Fifth Amendment privilege and your Fourth Amendment protection against warrantless searches. Second, do not assume that a warrant is invalid just because it seems overbroad—the government may have obtained a decryption order under the All Writs Act (28 U.S.C. § 1651) or a specific warrant under the Stored Communications Act, and challenging that warrant requires a detailed legal motion filed by an experienced federal defense attorney. Third, contact a lawyer who understands digital evidence and the Fifth Amendment implications of compelled decryption, because the timeline for challenging a warrant is extremely short—usually within 14 days under Federal Rule of Criminal Procedure 41. Finally, do not destroy or delete any data, because that can lead to separate charges for obstruction of justice under 18 U.S.C. § 1519, which carries up to 20 years in federal prison.
If you or your organization is facing a federal investigation involving encrypted communications, digital evidence, or compelled decryption orders, you need a defense team that understands both the technology and the constitutional law at stake. I have spent decades on both sides of the federal courtroom—as a prosecutor who wrote warrant applications and as a defense attorney who challenges them. Contact my office today for a confidential consultation. We will review the warrant, assert your Fifth and Fourth Amendment rights, and fight to protect your privilege and your liberty. Do not wait until the government has already accessed your private communications—the time to act is now.
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Kirbycriminallawyer
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense