Suspects can refuse to provide phone passcodes to police, court rules

A recent Utah Supreme Court ruling found that criminal suspects can refuse to provide phone passcodes to police and that such refusals cannot be used against them at trial, raising important questions about how the Fifth Amendment applies to digital devices. Commenters contrast this protection with jurisdictions like the UK and parts of Australia, where withholding decryption keys can itself be a crime, and note that biometric unlock methods (like Face ID or fingerprints) generally do not enjoy the same legal safeguards. The conversation broadens into practical security advice, the role of tools like GrayKey, and worries about expanding law-enforcement powers at borders and within a large “border zone” in the U.S.

Scope of the ruling

  • Utah Supreme Court held that a suspect’s refusal to provide a phone passcode is protected and that prosecutors cannot use that refusal as evidence of guilt at trial.
  • Applies only in Utah; other US states have conflicting rulings, and some expect eventual US Supreme Court review.
  • Discussion notes distinction between:
    • Compelling the password (testimony) vs.
    • Compelling the unlocking of a device vs.
    • Police independently breaking in with tools/exploits.

Fifth Amendment and self‑incrimination

  • Many argue the Fifth clearly covers memorized passcodes and combinations (products of the mind), analogizing to safe combinations.
  • Others note the Amendment text only bars being “a witness against oneself,” so courts have sometimes treated passcodes as “keys” rather than testimony.
  • Key nuance: providing a password also implicitly concedes ownership/control of the device, which itself can be incriminating.
  • Some highlight that in other countries (e.g., UK, parts of Australia) refusal to decrypt can itself be a crime, which many find dangerous.

Biometrics vs passcodes

  • Strong sentiment against using biometrics: can be physically compelled, aren’t clearly Fifth‑protected, and are always “on your person.”
  • Counterpoint: passcodes are vulnerable to shoulder‑surfing and cameras, especially in public; biometrics plus a quick “lockdown” kill‑switch may be safer in practice.
  • Practical tips discussed:
    • iOS/Android shortcuts to disable biometrics and require passcode.
    • Using long alphanumeric passwords instead of short PINs.
    • Screen filters and randomized keypads to reduce observation risk.

Law‑enforcement technical workarounds

  • Tools like GrayKey/Cellebrite likely rely on exploits, older/low‑end devices, or weaker hardware security; effectiveness against modern iPhones/flagship Androids is debated and unclear.
  • Even if police can’t compel passwords, raising the technical and financial cost of access is seen as valuable.

Borders and jurisdictional caveats

  • US border and “100‑mile zone” practices may be different: refusal to unlock can be used to deny entry for non‑citizens.
  • Several comments stress: this Utah ruling does not apply at borders, in other US states, or in countries with key‑disclosure laws.

Strategies and risks

  • Ideas floated: decoy profiles/volumes, “under‑duress” passphrases, self‑wiping or booby‑trapped data.
  • Many warn these can trigger additional charges (obstruction, destruction of evidence) and are legally risky; repeated advice is to say nothing and ask for a lawyer.