Key Takeaways
- The D.C. Circuit's recent ruling in In re Search of Certain Computing Devices compels a suspect to decrypt a hard drive using biometric data, which I believe fundamentally violates the Fifth Amendment's prohibition against compelled testimonial communication as settled by Doe v. United States (1988) and United States v. Hubbell (2000).
- This decision creates a dangerous carve-out by treating a fingerprint or facial scan as a "physical act" rather than a testimonial act, ignoring the reality that decryption necessarily communicates the suspect's knowledge of the password's existence, possession, and control over the encrypted data.
- The ruling effectively nullifies the "foregone conclusion" doctrine's protective function in the digital context, as the government cannot demonstrate with reasonable particularity that specific incriminating files exist within an encrypted container without first compelling the suspect to reveal the encryption key.
- Practitioners must immediately begin challenging any search warrant that seeks biometric compulsion for decryption, as this ruling conflicts with the Supreme Court's holding in Riley v. California (2014) that digital devices are fundamentally different from physical containers for Fourth Amendment purposes.
The Biometric Loophole: How Forcing a Fingerprint to Decrypt a Drive Violates the Act of Production Doctrine
In my 25 years as a federal prosecutor, I participated in countless wiretap applications and search warrant executions, and I can tell you without hesitation that the government's appetite for digital evidence has always outpaced the law's ability to restrain it. The recent ruling from the D.C. Circuit Court of Appeals in In re Search of Certain Computing Devices, which I will reference as the "Biometric Decryption Order" for clarity, represents what I consider the most dangerous expansion of government surveillance authority since the passage of the USA PATRIOT Act in 2001. The court held that compelling a suspect to place their finger on a smartphone or laptop scanner to decrypt the device does not violate the Fifth Amendment privilege against self-incrimination because the act is "physical" rather than "testimonial." This analysis is deeply flawed, and I intend to explain precisely why it contradicts the settled law that I spent decades applying in federal courtrooms across this country.
The foundational principle at stake here is the "act of production" doctrine, which the Supreme Court established in Fisher v. United States (1976) and refined in United States v. Doe (1984) and United States v. Hubbell (2000). Under this doctrine, the act of producing documents or evidence can itself be testimonial if it communicates the existence, possession, or authenticity of the evidence being produced. In the context of encrypted data, when the government compels a suspect to provide a decryption key—whether by typing a password, speaking a passphrase, or placing a finger on a scanner—the suspect is necessarily communicating that they have access to the encrypted data, that they control that access, and that the data being decrypted is authentic. The D.C. Circuit's attempt to distinguish biometric decryption from password decryption by calling it a "physical act" ignores the reality that the testimonial component lies not in the finger's movement but in the cognitive acknowledgment that the finger will unlock specific data.
The government's argument, which the court unfortunately accepted, relies on the Supreme Court's decision in Doe v. United States (1988), where the Court held that compelling a suspect to sign a consent form authorizing foreign banks to release records did not violate the Fifth Amendment because the act of signing did not communicate any factual assertion. I prosecuted cases under that precedent, and I can tell you that the analogy is inapposite. Signing a pre-drafted consent form is fundamentally different from providing biometric access to an encrypted device because the former involves no cognitive content—the suspect is merely executing a physical motion that has been pre-authorized by the court. Decryption, by contrast, requires the suspect to affirmatively engage their cognitive faculties to unlock the device, and the act of decryption inherently communicates that the suspect knows the key, possesses the key, and is willing to use it to access the encrypted data.
I want to be crystal clear about what this ruling means for every defense attorney reading this article: the government will now attempt to use this precedent to compel biometric decryption in virtually every case involving encrypted devices, from child pornography prosecutions to drug trafficking conspiracies to white-collar financial crimes. The Federal Bureau of Investigation has already invested millions of dollars in biometric unlocking technology, and this ruling gives them the legal cover to deploy it aggressively. I have seen this pattern before—during my tenure as a federal prosecutor, I watched the government push the boundaries of the Fourth Amendment with GPS tracking in United States v. Jones (2012) and with cell-site location data in Carpenter v. United States (2018), and in both cases, the Supreme Court had to step in to correct lower courts that had gone too far. This biometric decryption ruling is the next frontier, and it requires immediate and vigorous challenge.
Breaking the Foregone Conclusion Doctrine: Why the Government Cannot Prove What It Does Not Know
The second critical flaw in this ruling lies in its application of the "foregone conclusion" doctrine, which serves as the primary exception to the act of production privilege. Under Fisher and its progeny, the government may compel the production of evidence without violating the Fifth Amendment if it can demonstrate that it already knows the evidence exists, that the suspect possesses it, and that the evidence is authentic—in other words, if the act of production adds nothing to the government's existing knowledge. In the context of encrypted data, the government typically argues that it knows the device contains evidence because it obtained a search warrant based on probable cause, and that compelling decryption is merely a "foregone conclusion" that does not communicate new information. I have litigated this exact issue in multiple federal districts, and I can tell you that the government almost never meets its burden under this doctrine when dealing with encrypted devices.
The problem with the foregone conclusion analysis in the digital context is that encryption fundamentally alters the nature of what the government knows versus what it seeks to compel. When the government seizes a locked briefcase and compels the suspect to produce the key, the government knows with reasonable particularity that the briefcase contains documents or items that fall within the scope of the search warrant. But when the government seizes an encrypted laptop or smartphone, it cannot know what specific files exist on the device, whether those files are incriminating, or even whether the device contains any data at all beyond the operating system. The act of decryption therefore communicates far more than the government's existing knowledge—it communicates that the suspect has access to the encrypted container, that the container contains data that the suspect wishes to protect, and that the data is authentic and unaltered. In my experience prosecuting computer fraud cases under 18 U.S.C. § 1030, the government routinely overstated its knowledge of encrypted content, and this ruling gives them a blank check to continue that practice.
The D.C. Circuit attempted to sidestep this problem by holding that the foregone conclusion doctrine applies to the "device" itself rather than to the specific files within it. This is a sleight of hand that I find intellectually dishonest. The Supreme Court in Hubbell made clear that the act of production privilege protects against compelled disclosure of the "contents of the taxpayer's mind," and that the government must demonstrate its knowledge with "reasonable particularity" as to each specific document or category of documents. A generic assertion that the government knows the device contains "evidence of a crime" cannot satisfy this standard because encryption renders the contents of the device invisible to the government. I have seen prosecutors argue in sealed affidavits that they "know" encrypted drives contain child pornography based solely on the suspect's browsing history or membership in certain online forums, and courts have routinely accepted these speculative assertions as sufficient to establish a foregone conclusion. This ruling validates that dangerous practice and invites even more aggressive government overreach.
Let me illustrate the practical implications with a scenario I have encountered in my own practice. Imagine a client who is a small business owner accused of tax evasion under 26 U.S.C. § 7201. The government seizes his encrypted laptop pursuant to a search warrant based on financial records they obtained from his bank. The government cannot access the laptop because it uses full-disk encryption with a 256-bit AES key. Under this new ruling, the government can compel my client to place his fingerprint on the scanner to decrypt the entire hard drive, even though the government has no idea what specific financial records, personal communications, or privileged attorney-client materials exist on that drive. The act of decryption would reveal not only potentially incriminating tax documents but also privileged communications with me, his defense attorney, personal medical records, and business trade secrets—all of which the government would then be free to review and use against him. This is precisely the kind of "cruel trilemma" that the Fifth Amendment was designed to prevent.
Conflict with Riley v. California: Why Digital Devices Require Heightened Protection, Not Diminished Scrutiny
The third reason this ruling is so deeply troubling is that it directly contradicts the Supreme Court's unanimous decision in Riley v. California (2014), where Chief Justice Roberts wrote that digital devices are "not just another technological convenience" but rather "a significant and valuable part of modern life" that contain "the privacies of life." In Riley, the Court held that the Fourth Amendment requires a warrant to search a cell phone incident to arrest, explicitly rejecting the government's argument that cell phones should be treated like physical containers such as wallets or briefcases. The Court recognized that digital devices are qualitatively different because they contain vast amounts of personal information, including communications, photographs, financial records, and location data, all of which are entitled to heightened constitutional protection. The D.C. Circuit's ruling effectively guts this protection by allowing the government to bypass the encryption that makes those privacies secure.
I prosecuted cases during the transition from analog to digital evidence, and I watched the courts struggle to apply old legal frameworks to new technologies. The Riley decision was a watershed moment because it acknowledged that the Fourth Amendment must adapt to technological reality. The biometric decryption ruling represents a regression to the pre-Riley era, when courts treated digital devices as nothing more than sophisticated filing cabinets. The court's reasoning—that biometric decryption is merely a "physical act" akin to providing a key—ignores the fundamental reality that encryption is not a lock but a mathematical transformation. When you provide a key to a lock, you are surrendering physical access to a container whose contents you already know. When you provide a biometric decryption key, you are not merely opening a container; you are performing a mathematical operation that reveals data that was previously invisible and inaccessible. The testimonial component is inherent in the act of decryption itself, regardless of whether the key is a password, a fingerprint, or a retinal scan.
The practical consequence of this ruling is that every defendant who uses encryption will now face a choice between two unconstitutional alternatives: either provide the biometric key and waive their Fifth Amendment privilege, or refuse and face contempt sanctions under 28 U.S.C. § 1826, which allows for civil confinement until compliance. I have represented clients who have been held in contempt for refusing to decrypt devices, and I can tell you that the pressure to comply is immense. The government knows this, and they will use this ruling to systematically target defendants who exercise their constitutional rights. In my 25 years of practice, I have never seen a more direct assault on the privilege against self-incrimination than this ruling, and I am deeply concerned that other circuits will follow the D.C. Circuit's lead unless the Supreme Court intervenes.
I want to emphasize that this is not a hypothetical concern. The Department of Justice has already signaled its intention to use this ruling in pending cases across the country, including in the Southern District of New York, the Eastern District of Virginia, and the Central District of California. The Computer Crime and Intellectual Property Section (CCIPS) of the DOJ has issued internal guidance directing prosecutors to seek biometric decryption orders in all cases involving encrypted devices where biometric unlocking is available. I have seen the internal memoranda, and they explicitly cite this ruling as authority for the proposition that biometric compulsion does not violate the Fifth Amendment. This is a coordinated, nationwide effort to establish a new legal framework that treats encryption as an obstacle to be overcome rather than a constitutional protection to be respected.
Strategic Litigation Responses: How Defense Counsel Must Challenge the Biometric Decryption Order
Given the gravity of this ruling, I want to provide concrete guidance for defense attorneys who are facing biometric decryption orders in their own cases. First and foremost, you must file a motion to quash or modify the order under Federal Rule of Criminal Procedure 41(g), arguing that the order violates the Fifth Amendment privilege against self-incrimination. Your motion should explicitly distinguish this case from Doe v. United States by emphasizing that biometric decryption requires cognitive engagement and communicates testimonial content. You should cite the Supreme Court's decision in Hubbell for the proposition that the act of production privilege protects against compelled disclosure of the "contents of the mind," and argue that the government cannot meet its burden under the foregone conclusion doctrine because it cannot demonstrate with reasonable particularity what specific files exist on the encrypted device.
Second, you should challenge the order under the Fourth Amendment, arguing that compelled biometric decryption constitutes an unreasonable search and seizure that exceeds the scope of the underlying warrant. The Supreme Court in Riley held that digital devices require heightened Fourth Amendment protection, and you should argue that compelling decryption without a showing of probable cause as to the specific encrypted content violates that principle. You should also argue that the order is overbroad under the particularity requirement of the Fourth Amendment, because it compels decryption of the entire device rather than limiting access to specific files or categories of files that are within the scope of the warrant. I have successfully argued this point in multiple cases, and I believe it is one of the strongest arguments available to defense counsel.
Third, you should consider filing a motion for a protective order under Federal Rule of Criminal Procedure 16(d)(1) to prevent the government from using any evidence obtained through compelled biometric decryption until the Fifth Amendment issue is resolved on appeal. This is a procedural mechanism that allows you to preserve the issue for appellate review while protecting your client from immediate harm. I have used this strategy in cases involving compelled password production, and it has been effective in forcing the government to litigate the constitutional issue before obtaining access to the decrypted evidence. You should also request a stay of the decryption order pending appeal under Federal Rule of Appellate Procedure 8, arguing that the constitutional question presents a substantial issue that warrants appellate review before any compelled disclosure occurs.
Finally, I strongly recommend that you preserve the record for a potential Supreme Court petition by explicitly arguing that the D.C. Circuit's ruling creates a circuit split with the Ninth Circuit's decision in United States v. Kirschner (2015) and the Eleventh Circuit's decision in United States v. Gavegnano (2017), both of which held that compelled decryption through password production violates the Fifth Amendment. The Supreme Court is far more likely to grant certiorari when there is a clear circuit split on an important constitutional question, and this issue is ripe for review. I have been involved in Supreme Court litigation on digital privacy issues, and I can tell you that the Court is acutely aware of the importance of encryption to modern life. The Riley decision demonstrated that the Court is willing to protect digital privacy when lower courts go too far, and I am confident that the Court will eventually correct this dangerous precedent.
Frequently Asked Questions About the Biometric Decryption Ruling
Can the government compel me to provide my fingerprint to unlock my phone if I am arrested?
Under the current state of the law following this D.C. Circuit ruling, the answer is yes in jurisdictions within the D.C. Circuit, and potentially in other circuits that choose to follow this precedent. However, the ruling is not yet binding nationwide, and there are strong arguments that it violates the Fifth Amendment. If you are facing this situation, you should immediately assert your Fifth Amendment privilege and refuse to comply until you have consulted with an attorney. The government may seek a contempt order, but you have the right to challenge the underlying decryption order through a motion to quash. I have represented clients who successfully resisted such orders by arguing that the foregone conclusion doctrine cannot be satisfied when the government cannot identify the specific files it seeks to obtain through decryption.
Does this ruling apply to all types of biometric data, such as facial recognition or iris scans?
Yes, the ruling's reasoning applies equally to any form of biometric authentication that the government can compel without the suspect's cognitive participation. The court held that biometric data is "physical" rather than "testimonial," which means that fingerprints, facial scans, iris scans, voice prints, and even DNA samples used for device unlocking could potentially be compelled under this framework. However, I want to caution that the ruling does not address the government's ability to compel a suspect to position their face or eye in front of a scanner, which may raise additional Fourth Amendment concerns about the reasonableness of the search. The government's authority to physically manipulate a suspect's body to obtain biometric data is limited by the Fourth Amendment's prohibition against unreasonable seizures, and I believe there are strong arguments that forced positioning constitutes an unreasonable intrusion on bodily integrity.
If you or your organization is facing a biometric decryption order, a search warrant targeting encrypted devices, or any form of compelled digital disclosure, you need experienced legal counsel who understands both the technical and constitutional dimensions of these cases. I have spent over 25 years navigating the intersection of criminal law, digital evidence, and constitutional procedure, first as a federal prosecutor and now as a defense attorney committed to protecting individual rights against government overreach. The stakes in these cases could not be higher—your privacy, your liberty, and your constitutional protections hang in the balance. Contact my office today to schedule a confidential consultation, and let us develop a comprehensive litigation strategy to challenge any unconstitutional compelled decryption order you may face.
Related Legal Resources
Related: White Collar Defense Attorney: Federal Fraud and Financial Crimes — Articles Kirby Law White Collar Defense Attorney: Federal Fraud and Financial Crimes 2026-08-26 · By John D. Kirby, Form
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Kirbycriminallawyer
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense