The Privilege Against Cellphone Incrimination

Response - Online Edition - Volume 97


The standard approach to the problem of compelled decryption of cellphones has been to treat cellphones like glorified lockboxes. The contents are assumed to be the equivalent of private papers, leaving only the passcode subject to dispute. Orin Kerr has helpfully labeled this dichotomy as the “treasure” versus the “key.”[1]

Much of the debate has centered on whether the government may compel production of the key. When the passcode is a memorized phrase, it is a classic example of “contents of the mind” that may be withheld under the Fifth Amendment privilege against self-incrimination. Some courts have sidestepped this obstacle (1) by allowing the government to compel decryption as long as the passcode itself is never revealed[2], or (2) by finding that the passcode is not privileged testimony.[3] By contrast, other courts have refused to allow compelled decryption for any reason—even when the passcode is a fingerprint or other biometric feature that is typically non‑testimonial, physical evidence.[4]

Kerr’s position is that this debate over the key is essentially moot, because the treasure itself can never be privileged.[5] Whether that treasure is encrypted or unencrypted should not change its availability to law enforcement. Other commentators, including Laurent Sacharoff, are more circumspect, arguing that the “foregone conclusion” doctrine[6] restricts the government from compelling decryption of any files it cannot describe with particularity.[7] In that regard, Sacharoff sees connective tissue tying the Fifth Amendment back to the particularity requirement in the Fourth Amendment.[8]

This Essay takes a different tack: How might the line of cases refusing to compel decryption of cellphones be consistent with Fifth Amendment principles? The theory advanced here is that those judicial decisions are best understood as treating cellphones as an extension of “self.”[9] This reframing counters Kerr’s key/‌treasure metaphor, not by challenging the “key” comparison—as is usually done—but by challenging the “treasure” comparison. A cellphone is not like a lockbox; it is more like the mind. In other words, decrypted data is always privileged testimony when it is extracted directly from within the chassis of a cellphone.

The strongest support for this radical notion comes straight from the horse’s mouth. In Riley v. California[10], the Supreme Court introduced a new rule of cellphone exceptionalism, marveling at the “immense storage capacity,” the “pervasiveness” of popular use, and the “qualitatively different” precision and comprehensiveness of recordkeeping performed by everyday cellphones.[11] The Court began this discussion with a passing quip that “the proverbial visitor from Mars might conclude [cellphones] were an important feature of human anatomy.”[12] Four years later, in Carpenter v. United States[13], the Court quoted the same language—that cellphones are “almost a ‘feature of human anatomy’”—to extend the rule of cellphone exceptionalism and strike down the warrantless use of a cellphone’s locational data.[14] As the Court made clear in both cases, this holding is one of exceedingly narrow scope: it extends only to cellphones, not to any other devices.[15]

Cellphones are always-in-use devices. Unlocking a cellphone reveals the user’s last activities, including which apps are open, the sequence in which they were last used, and notes that are in the midst of being composed. It also offers user-facing background data, such as notifications and reminders, fitness and locational tracking, and recent payments. Deeper in the background are valuable system performance metrics such as network usage, memory usage, battery usage, and other metadata generated dynamically rather than statically.[16] In aggregate, the modern cellphone snapshots its user’s thoughts in real time.[17] Even accepting arguendo that every cellphone user voluntarily “consents” to the automatic creation of a nanosecond-by-nanosecond record of their existence, the lesson of Riley and Carpenter is that when it comes to cellphones, quantitative differences are qualitative ones too.[18]

Although both Riley and Carpenter were brought as Fourth Amendment petitions, the Court understood that the implications would run into the Fifth Amendment. In Carpenter, Justice Alito wrote a strident dissent that affording cellphones special protections was akin to “resurrect[ing]” Boyd v. United States[19]—the landmark case that had erected the Fourth and Fifth Amendments as overlapping protections for private papers.[20] Only Justice Thomas joined Justice Alito. Meanwhile, in a separate opinion, Justice Gorsuch mused that “we would do well to reconsider” the testimony doctrine, because “there is substantial evidence that the privilege against self-incrimination was also originally understood to protect a person from being forced to turn over potentially incriminating evidence.”[21] Justice Gorsuch’s dicta echoed more forceful statements made by Justice Thomas in an earlier case, United States v. Hubbell.[22]

Taken together, these cases reveal deep discomfort with treating cellphones like other digital devices. And the expressed nature of that discomfort signals that the reverberations may stretch from the Fourth Amendment to the Fifth Amendment and well beyond.

* * *

At least three salutary effects follow from the premise that cellphones are not only a feature of human anatomy but an extension of self.

First, this shift in framing would help resolve the uncomfortable doctrinal split between memorized passphrases and biometric passcodes.[23] Within the computer security field, biometric means of authentication are generally regarded as more secure than conventional passcodes, because they are more easily guarded, more difficult to spoof, and less likely to go missing.[24] In the legal domain, the opposite holds true: biometric features are readily seized and repurposed for law enforcement aims.[25] Under the current situation, it is as though straw houses were legally shielded from police entry but brick houses were not.

An increasing number of courts have begun to rebel against this artificial schism. Thus far, a slight majority of courts that have considered this question have adopted Kerr’s approach and authorized compelled decryption of cellphones regardless of what the mode of authentication is. This judicial turn achieves the desired result of harmonization—but at the cost of twisting the doctrine beyond recognition. In the past, a subject would never have been required to lift a finger to produce arbitrary, unspecified documents without first receiving an offer of immunity from prosecution.[26]

A sharp minority view has refused to compel decryption regardless whether the passcode is memorized or biometric. This approach is quite straightforward to parse as soon as one treats the cellphone as an extension of the subject’s mind. Under that assumption, the government may not compel the cellphone to read a passcode in order to reveal its contents, any more than the government may compel the subject to read aloud his own diary in order to reveal his state of mind.[27] The fact that the government has access to the biometric feature turns out to be inconsequential, because the thing to be unlocked—the cellphone—remains privileged.

Second, this personification of cellphone ex rel. owner applies only to the device itself, not to the data contained therein.[28] Even if the Fifth Amendment bars the government from extracting any encrypted data residing “at rest” on the cellphone, it does not stand in the way of other surveillance techniques to capture data after it has departed the cellphone.[29] By analogy, a thought remains a thought only as long as it remains locked in one’s mind. Thus third-party informants will always remain a weak link, even with end-to-end encryption.[30] Additionally, intermediaries will continue to have access to routing and quality-of-service metadata, such as cell-site location information, which can be obtained with warrant.

Another important implication of this division between device and data is that it throws further weight behind those judicial decisions that have allowed compelled decryption of specific files known by the government to exist.[31] A subpoena for specific digital files does not implicate the cellphone itself, just as a subpoena for specific tax files does not implicate the subject himself.[32] There, the target is the known files, not the cellphone, such that the location of those files becomes irrelevant. Thus, this Essay corroborates Sacharoff’s proposed rule of particularity for compelled decryption cases.[33] One flag of caution, however, is the potential to exploit the required records doctrine as an end run around any such rule of particularity.[34]

Third, compelled production of an entire decrypted cellphone is not like compelled production of discrete, named files. Direct access to the cellphone itself allows law enforcement to freeze-frame the user’s state of mind at the time of arrest or seizure. A cellphone is more than the sum of its files. To be sure, certain files are static—such as image files and text messages—but those static files are situated within a dynamic environment that automatically captures the user’s ongoing cognitive engagement. Cellphones never turn fully off; their memory state is preserved in transient files that remember the user’s last active moment. In fact, when law enforcement requests blanket decryption of a cellphone, that just-in-time memory is a prime objective because it is the only type of evidence that cannot be produced in any other way. This capture of evanescent evidence is the antithesis of document production.[35]

* * *

This Essay closes by anticipating three key objections and offering a few additional thoughts on downstream implications for a personhood theory of cellphones.

First: The most substantial objection is that disallowing compelled decryption erects an impregnable zone of privacy that has never existed before—other than in the human mind.[36] For Kerr, the equilibrium- adjustment theorist, this change is unwelcome: a Fourth Amendment warrant has always been sufficient in the past to yield access to incriminating evidence, but that access would now be impeded by a new, extraneous barrier.[37] The balance of power would swiftly tilt in favor of criminals, to the detriment of public interest.

A pro forma response is that equilibrium-adjustment theory may be irrelevant to a Fifth Amendment analysis, which is typically thought to be more strictly categorical than the Fourth Amendment framework.[38] As long as the definition of “self” can be construed to encompass cellphones, it is not clear that the rule requires a coherent rationale.[39]

A more principled defense rests on the ground that a privilege against cellphone incrimination guards only the isolated contents of the device. As long as data remains sequestered within the cellphone, it can cause no more harm to the outside world than an idle murderous thought. But any data that contacts the outside world immediately loses its privilege, just as any thought communicated to another person does.[40] Thus ordinary surveillance methods should continue to remain quite effective.[41] Data communications are pervasive and highly leaky, and even the widespread availability of end‑to‑end encryption cannot erase the basic incentives for third parties (including but not limited to co‑conspirators) to cooperate with prosecutors.[42] In short, it is not empirically obvious that extending the self-incrimination privilege to cellphones would alter overall rates of criminal prosecution.[43] A privilege limited to cellphones does not “resurrect Boyd” any more than a privilege limited to spouses or to clergy.[44] And to the extent that the government’s true purpose is something other than prosecution (such as victim rescue or anti-terrorism), it can always compel decryption by offering immunity.[45]

Second: Even if one accepts the premise that cellphones are a “feature of human anatomy,”[46] one might resist the conclusion that anatomical features are per se eligible for self-incrimination privileges.[47] The Supreme Court has authorized all manner of bodily invasions, as long as the need is sufficiently great.[48] Why should cellphones be any different?

The thin answer is that a nonconsensual giving of bodily evidence can be compelled only for authentications of identity or for inspections of physical attributes such as body shape, movement, or timbre.[49] Any time one’s body is commandeered without being tethered to one of those limited, enumerable purposes, such compulsion should be privileged by default because it is likely a pretext for intercepting one’s cognitive processes. Compelled decryption of cellphones does not ever meet either of those limited purposes.[50]

The thicker claim is that the Court’s analogy to “human anatomy” refers specifically to the mind, not merely to an outer appendage. Being parted from one’s cellphone is like losing one’s memory and one’s mental map of the world.[51] The intrusion of allowing the government to browse freely through one’s phone is that it infringes on one’s unpublished thoughts before they can be composed and put in order.[52] Prosthetic limbs do not trigger comparable concern, even when they are wired directly into the brain. Cellphones are not an extension of physical anatomy; they are an extension of thinking anatomy.

Third: What are the limits of a rule recognizing cellphones as an extension of self? The clear directive of Riley and Carpenter is that cellphones are unique, full stop.[53] By proposition, this rule cannot extend to laptops, portable drives, home electronics, or other generic personal devices. While all digital devices share the same basic architectural design, none other captures the pervasive and comprehensive cognitive engagement that cellphones do. For another device to receive equivalent recognition, it would need to match the profound intimacy of the cellphone. In that regard, this Essay stakes out a different position than Kerr and others who see no easy limiting principles to draw between digital devices.[54]

At the same time, a cellphone remains merely an extension of self.[55] Death moots any specter of self-incrimination; the cellphone does not embody a person after death.[56] Likewise, cellphones can be replaced or discarded without implicating loss of self. Impoundment and damage by law enforcement may be subject to laws governing chattel rather than bodily injury.[57] In these and other sanity tests, the lodestar should be whether the claim of cellphone qua self is directed against law enforcement action that materially interferes with the subject’s freedom of thought.[58]

Two edge cases are worth special mention. The more trivial case is the unencrypted cellphone. In the Fourth Amendment setting, opening the device remains a “search” but the device’s unencrypted status makes available justifications such as plain-view and exigency. Likewise in the Fifth Amendment setting, the cellphone remains part of the “self” but the device’s unencrypted status voids the element of compulsion.[59] That said, the case of the unencrypted cellphone may be a rapidly diminishing set as device manufacturers move to make encryption the default setting.

The more troubling edge case is where title and possession are split.[60] The most well-known case to date is that of the San Bernardino shooter, where the cellphone at issue was owned by an employer and provided to an employee for business use.[61] Other popular split arrangements include lease financing, family plans, and short-term rentals. Resolution of these cases may depend on diverse factors such as the titleholder’s right of access, the frequency of such access, and the licensee’s customary use.

Finally: This Essay has focused on compelled decryption and the privilege against self-incrimination, but it is worth leaving a few breadcrumbs on where a cellphone–personhood theory might lead in other related contexts. For example, the literature on data commodification is already abundantly rich,[62] but more could be written on the ethics of allowing users to monetize their cellphone use.[63] Other debates potentially enriched by a cellphone–personhood theory are those rooted in equal protection and due process concerns, such as net neutrality,[64] border searches,[65] and right to record.[66] Last, the vexing issue of government hacking takes on an entirely different tenor when one characterizes the host as not just a repository of personal effects but as the emergent manifestation of a person’s mind.[67]

