Not sure why this hasn't been slapped down a long, long time ago.
Not sure why this hasn't been slapped down a long, long time ago.
So there's a common argument that the 5th amendment only protects you against being forced to give evidentiary testimony against yourself. Giving up a passcode is arguably different, since the passcode is not (necessarily) evidence in itself, in the sense that it might not be introduced as evidence at trial to establish guilt or innocence. Rather, it is information that will allow law enforcement to access other non-testimonial evidence.
I'm not arguing for this position, just providing a perspective on why this isn't as open-and-shut as people often think it should be.
I don’t use a password or pin, I use a passphrase, and my passphrase is an instance of me confessing to some extremely mild crime.
But I can say that the 1988 America's cup does not support either of those points.
----
Background:
First of all, the opinion of the appellate court is better written and clearer than the Wikipedia article: https://nycourts.gov/reporter/archives/mercury_sandiego.htm I'm going to be quoting it a lot because it says things more plainly and authoritatively than I could.
"The America's Cup, a silver cup trophy, is the corpus of a charitable trust created in the 19th century under the laws of New York." Such a charitable trust is governed by a "Deed of Gift" written by those who gave the cup to the trust. "[George] Schuyler executed [wrote/signed] the present Deed of Gift in 1887, donating the Cup to the New York Yacht Club".
The gist of the deed is that one yacht club can challenge the current holder of the cup to a race to win the cup (the race is 10 months after the challenge is issued); the two clubs are free to agree to whatever rules they want, but if they fail to agree then the deed gives some fallback rules. One of the rules that the 1887 deed gave is that for single-mast vessels the load water-line length must be between 65 and 90 feet. However, "In 1956 the New York Yacht Club obtained a court order amending the Deed of Gift to reduce the minimum load water-line length to its present 44 feet". For context, the America, the ship for which the cup was named, was 89ft 10in.
From 1956 until 1987 all challengers agreed to a lower maximum length than that 90ft limit, because even though longer boats were faster, they were more expensive.
----
Why I don't believe that this supports your points:
- Because the issue was about the Deed of Gift, not The Racing Rules of Sailing, this was decided by the NY courts, not by the International Yacht Racing Union (IYRU).
- Because reasons ("see, e.g., Crouch v National Assn. For Stock Car Auto Racing, 845 F2d 397, 403; Finley & Co. v Kuhn, 569 F2d 527, 539") the court specifically did not interpret The Racing Rules of Sailing, and just interpreted the deed. If Mercury Bay wanted The Racing Rules of Sailing to come into it, they should have brought it to the IYRU--which they totally could have done--and not to the NY Supreme Court.
- The discussion in the decision of the court by word-count I would say is 90% about about the spirit and intent of the deed and what the author intended, and 10% about rigid textual interpretation.
Also destruction of evidence is a crime, so you could pick up additional charges as well.
Don't play games with the law: talk to a lawyer. The law is not code, you generally aren't going to win with clever interpretation (see myriad cases where the "intent" of the people making the law is considered by the court) or "hack". If you're ever dealing with legal issues, civil or criminal, talk to a lawyer.
> "since the passcode is not (necessarily) evidence in itself"
a little similar to the courts treating the law as computers?
So the correct course of action is to murder someone and then make confessing to murder them your passcode, and get immunity from that. #lifehack #modernsolutions :D :D
For example, you could make your password the latitude/longitude of a top secret nuclear missile silo you’ve stumbled across, or something like that?
I suppose for the most part one critical function of judges is to override legislation when it appears that injustice would take place. We can't have murderers who say "sorry found some sweet loophole lol". And similarly we can't have abusive cops/prosecutors who want to harass citizens "tell us all your secrets and I'm sure you're guilty of something lol". Judges should be able to make sane tradeoff in the name of justice.
USSS, please refer to: https://www.youtube.com/watch?v=eg3_kUaYFJA
Or, what if the passphrase includes top secret information?
Or, what if you passphrase is a declaration that you are under one of those secret court warrant thinamajiggies.
The Brandenburg v. Ohio (1969) Supreme Court case allows for criminalizing speech only if the speech is "directed to inciting or producing imminent lawless action and is likely to incite or produce such action" [1]. "imminent" means that there has to be a near-future, clear time window. "I will kill X president within 3 days" could be illegal. "I will kill X president within a year" is too vague. Regardless, either one could be interpreted as evidence of criminal intent to harm the president. (If you were only joking about killing the president and the jury believes you, then you're fine.)
https://www.aclu.org/issues/national-security/detention/inde...
We have humans to apply the law and use their judgment for exactly this reason.
The "I do not recall" answer in high profile trials is so common that it's essentially become a meme. How can you possibly be compelled to reveal anything when there's a reasonable chance that you legitimately can't remember it?
In particular, I don’t remember the pin or password to some devices and accounts. They are shapes, on the pin-pad or keyboard. There are enough alternative ways of logging in (the apple face thingy, yubikey, you could hypothetically have devices setting up arbitrarily complex interlocking login processes) that I suspect the court would just define what they want, rather than how they want you to do it.
I could be wrong though, no actual experience here with the legal system at all.
Unless the passcode is a decryption key, in which case the evidence simply does not exist without the passcode. It is indistinguishable from random noise. It’s less like “unlocking a safe,” and more like “instructing nanobots to reassemble a pile of dirt into evidence.”
on edit: huh, what do you know, everybody had the same idea!
You might argue, well the police will have ways to prove it's your phone. Okay, so let them prove it, don't assist them. Well, then they can force you to produce your password, whether you admit it's your phone or not. But by divulging a password, you're admitting you own a phone somewhere, and part of your defense might be (however implausible) that you don't own/use a phone.
I'm not sure if that bit relies on the 5th amendment, or something else. But how is a passcode for a phone any different than a combination for a safe?
Meaning: its point isn't to prevent access to real evidence. It's not an attempt to grant you privacy. It's an attempt to ensure justice is served correctly.
This is also why you lose that right when you're granted immunity. The state can force you to provide testimony in that case.
Corollary here is that it's actually quite surprising courts are willing to side with the accused here. It's probably only a matter of time before rulings come to the contrary. If you care about privacy as a human right, you really need another amendment to make it solid.
You would need some kind of catch-all amendments stating that the enumeration of certain rights shall not be construed to deny others, and that the powers not delegated to the feds are reserved to the States or to the people. You could put them right at the end of the original amendments for emphasis as a closing statement of the Constitution.
But if we enacted those who would ever enforce them? The feds would probably treat them as if they didn't exist.
If you make them vague then it'll be easy to interpret them narrowly.
If you make them crystal clear, courts would presumably enforce them, like they have in the past.
The short response here is: How often do you see that happening in the US?
But in any case, note that I'm explaining what it was intended to do and what its meanings and implications are. Whether it is successful in achieving its goal is beside the point for this conversation.
Actually, the case is even stronger than you make it out to be. IIRC, one of the key constitutional issues is that providing a password is equivalent to saying "yes, this is mine". So even if we disregard the contents of the device, the issue is that you are establishing a legally relevant relationship with a piece of evidence.
I'm recalling this from a looong time ago, when I took a constitutional law class, so I hope those with fresher knowledge not hesitate to jump in.
Police can easily get warrants for your phone; you just can't be compelled to give the code to unlock. I suspect in the future we'll see a different level of cooperation from phone makers.
They screw up very frequently. Sometimes maliciously, sometimes through incompetence, sometimes both. I can't convey the depth of this in a small comment box, but there's abundant evidence around on this topic if you care to look.
Overall, even when you're talking about legitimately designated authority given to a person ... it's VERRRY easy for a human being to screw up and get it wrong, and it has huge impact over the lives of their targets. Needs to be approached by the authorities with extreme caution. In practice, probably many of them aren't aware of the weight of their actions, or don't care.
Do you have a source for that? Frequently is a relative term. 1,000 fuck-ups can be a lot or a little depending on the total number of interactions we are talking about.
These don't include number of cases where legal action wasn't taken or which got thrown out due to qualified immunity (these are somewhat related, if case is unlikely to get past qualified immunity it's quite unlikely legal action will be taken). And probably cases which actually went to trial as it seems to focus on settlements.
Additionally there is for example https://www.nyclu.org/en/publications/cop-out-analyzing-20-y... which covers 2000-2020 misconduct complaints. According to it disciplinary actions were taken 4283 times, meaning that even if conduct was enough to reach settlement it doesn't necessarily mean it results in any actions taken against the officer.
A phone is unique thing not because it contains so many secrets, but because you have to give testimony (as opposed to property, like a key) in order to open it, and it's impossible to open by bashing the door down or cutting it open. It's a technological coincidence, not a legal/philosophical doctrine, that makes phones secure against compulsion by law enforcement.
Is it different from compelling someone to enter a text password to unlock a vault? What if it's self-destructive otherwise?
What happens if the password itself - or act of unlocking - is something self-incriminating (in form, in contents, or otherwise)?
Reminds me of Ian Watkins: https://www.huffingtonpost.co.uk/2013/11/26/lostprophets-sin....
A court on the other hand, can compel you to open something.
An order to unlock something coming from the cops is entirely different, even if they have a warrant. Warrants would allow them to seize a phone, but you don’t have to provide the password.
No, they can't
Actually, the government cannot compel you to give the combination to a safe [1]. If it's locked with a key, not a keypad or combination lock, they can force you to give the key. The distinction is that the former is a product of the mind, while the latter is a physical object. Furthermore, what if you forgot the combination? There's no real way to tell if someone has forgotten the combination or is deliberately withholding it.
The UK's laws to compel people to give up passwords seems to make it a de facto crime to forget one's password. Worse yet, it seems like it's illegal to possess random bytes on your devices. I wonder if the UK would change course if people started emailing random bytes to politicians and other supporters of this law, while giving tips to law enforcement that these individuals are coordinating criminal acts over encrypted communications.
But ... If you're going to compell someone to give up the contents of their mind under threat of being found guilty if their mind isn't working properly, you may as well just do away with trial.
IOW, if you're going to compell speech, just compell the suspect to confess; it's the same thing.
Sounds a bit silly. The location of the key is "a product of the mind." What if you forgot the location of the key?
No, they can't. They can force you to let them try to open it, but they can't force you to open it for them.
If you have some mechanism like "if you try to open this incorrectly it destroys the contents", and you intentionally don't disclose that with the expectation that they're going to try and fail and destroy the contents, you might get charged with destruction of evidence.
(EDIT: Replies suggest that disclosure may not suffice.)
https://www.hecklawoffices.com/blog/2020/11/its-illegal-for-...
Does it only become destruction after you have been informed the police are interested in you? What if you do it before a warrant is issued? What if your device will self destruct if a password is not entered every N days and you withhold that information?
News articles suggests this happens a lot at the borders or during customs.
https://www.yesmagazine.org/social-justice/2018/03/23/two-th...
The state can install a keylogger if they have a warrant, and the results of the keylogger can be admitted as evidence.
It’s “you can’t be forced to open it because it requires you saying the password,” not “you can’t be forced to open it because it contains important secrets.”
Right, if they can figure out a way to reveal your secrets without forcing you to say something, they’re allowed to do that (with warrant of course).