Digital Forensics

Evidence review

The Legal Questions Around Mobile Device Extraction Are Not One Question

Searching the device, defining the search, compelling a passcode, compelling a biometric and reaching cloud data are five different legal questions. Two have Supreme Court answers. Two are split. This is a source review, not legal advice.

Published and sources verified 6 September 2026  ·  12 min read

DEVI Digital Forensics  ·  ORCID iD 0009-0007-6471-1759

How to read this

Entry type
Evidence review
Sources verified
6 September 2026
Evidence classes
holding, government

This entry reviews evidence published by other people. DEVI did not test any tool or examine any device for it. Blocks marked with an evidence class quote or summarize a source; sentences beginning “we” describe what DEVI did with those sources, which was to read them. Anything DEVI could not confirm is marked as such and left as an open question rather than written up as a finding. Sources change without notice, which is why the verification date is stated.

"Can we get into this phone" and "may we" are different questions, and "may we" is not one question either. An examiner who treats it as one will eventually answer a question nobody asked.

This entry separates five of them, says which have Supreme Court answers and which do not, and shows the conflicting authority where courts have reached opposite results. Every case below was read in full on 6 September 2026 — five from the deciding court's own published PDF, and two (Valdez and Brown) from the opinion text in a public case-law database, which is noted where they appear.

This is a source review for forensic practitioners, not legal advice. Applicable law depends on jurisdiction and on case-specific facts, and DEVI does not determine anyone's lawful authority. Where courts disagree, we show the disagreement rather than picking a side.

The five questions

  1. Searching the device. May the contents be searched at all, and on what authority?
  2. Defining the search. Once a warrant exists, how precisely must it say what may be looked at?
  3. Compelling a passcode. May a person be made to say it?
  4. Compelling a biometric. May a person be made to press a finger or show a face?
  5. Reaching remote data. What changes when the material is not on the handset?

They are answered by different bodies of law, and an answer to one does not carry to the next.

Searching the device

Riley is the settled part of this entry, and its own words mark the limits. It decided the search-incident-to-arrest question. It did not hold that phone data is beyond reach, did not remove exigency, and did not address compelled passcodes, biometrics or cloud accounts — none of which were before it.

A warrant answers whether. It does not automatically answer how much.

Two things worth carrying from that, and they pull in opposite directions. A warrant authorizing a search of everything on a phone was held invalid in Maryland — and the evidence came in anyway. An examiner who reads only the first half will overestimate how often a particularity defect changes an outcome.

The same opinion notes that a judge presented with a warrant lacking search restrictions "may require the affiant to add one or more of them in a revised warrant." That is a description of one court's practice, not a national rule, and we did not survey how other jurisdictions handle protocols.

Compelling a passcode

This is where the map stops being a map of the law and becomes a map of jurisdictions. Courts are divided, and two state supreme courts have reached opposite results on materially the same question.

In Utah, the court held that saying a passcode aloud is testimony. In New Jersey, the court held that an order to disclose passcodes does not violate the privilege. Both are state supreme courts; neither binds the other; and the answer to "may this person be made to give up the passcode" therefore differs by jurisdiction.

Note also the distinction Valdez drew and that is easy to lose: saying a passcode and producing an unlocked device are not necessarily the same act, and a court that treats the first as testimony has not necessarily decided the second.

Compelling a biometric

Analytically related to the passcode question, and not the same question. A passcode is something a person knows. A fingerprint is something a person is. Older cases treating physical traits as non-testimonial — blood draws, fingerprinting at booking, handwriting exemplars — do not automatically settle what happens when a physical trait is used to open a device.

Two federal circuits have now reached opposite conclusions.

That is a split between two federal circuits in which the later court knew of the earlier one and disagreed with it. It is unsettled, it is not resolved by any Supreme Court decision we located, and the answer in a given case depends on where the case is.

Local data and remote data

Entry #2 set out that extraction depth and device state are not the same thing. A third axis sits beside those two, and it is legal rather than technical: whether the material is on the handset or somewhere else.

An extraction can surface account tokens, credentials and synchronized identifiers. Using them reaches a provider's servers. That is a different act from reading a file already on the phone, and the authority for one does not obviously carry to the other.

We record two limits on what that establishes. The statute addresses process directed at providers; it does not, on its face, describe what happens when credentials taken from a handset are used directly against an account. And the Fourth Amendment question is separate again: Carpenter is the Court's most relevant reasoning about digitally-held records, and it is expressly narrow.

Carpenter is about historical cell-site location information held by a carrier. It is used here as context for how courts reason about third-party-held digital records, not as a decision about forensic extraction, tokens, or cloud accounts generally. The Court said it was not deciding matters not before it, and extraction was not before it.

These are independent, and each can fail while the other holds.

A search can be entirely lawful and still produce an extraction that is incomplete, mis-parsed, or missing an application — which is what government testing keeps recording. And a technically clean extraction establishes nothing about whether it was lawfully obtained or within the warrant's scope.

Neither question answers the other, and an examiner is usually the only person in the room positioned to notice when one of them has been assumed.

What the Supreme Court has not decided

On the material we reviewed, and stated as an absence rather than a conclusion: we did not locate a Supreme Court decision resolving whether a compelled passcode is testimonial, whether a compelled biometric unlock is testimonial, or how the particularity requirement applies to a warrant for an entire phone. Riley and Carpenter are national authority on the questions they took. They do not decide these.

What this means for an examiner

Practical, and deliberately narrow:

  • Keep the five questions separate in your notes and your testimony. Authority for the search is not authority for the compulsion.
  • Record which jurisdiction you are in. For the passcode and biometric questions, that is the fact that changes the answer.
  • Record how the device was opened — a passcode spoken, a passcode typed by the owner, a biometric applied, or a technical method — because those are different acts and courts have treated them differently.
  • Do not read a technical capability as authority, or authority as capability. Entry #2 covers the first confusion; this entry covers the second.

What we could not verify

Not independently verified

Whether any of the decisions above has since been overruled, vacated, reheard en banc or superseded. We searched the CourtListener opinion database on 6 September 2026 for later treatment of Payne and Brown and found none, but a search of one database on one date is not a substitute for a citator, and we did not run one.

Not independently verified

How many jurisdictions fall on each side of the passcode and biometric questions. We verified two conflicting authorities on each and did not attempt a count, so this entry makes no majority or minority claim in either direction.

Not independently verified

What legal authority governs the use of tokens or credentials recovered from a handset to reach a remote account. We did not locate an appellate decision addressing that act directly, and the Stored Communications Act provisions we read address process directed at providers rather than that scenario.

Not independently verified

How the CLOUD Act bears on ordinary domestic extraction work. It appears in the research behind this entry, we did not establish that it changes anything for an examiner working a seized handset, and we have therefore not described its effect rather than guessing at it.

Not independently verified

How particularity is applied outside Maryland. We verified one state high court decision holding an all-content phone warrant invalid on particularity grounds while admitting the evidence under the good faith exception. We did not survey other jurisdictions, and we make no claim that this is the general rule.

Sources and evidence

Sources verified on 6 September 2026

Platform
iOSAndroid
Source
United States Reports volume 573 (Riley v. California)Supreme Court slip opinion (Carpenter v. United States)Maryland Judiciary published opinion (Richardson v. State)Utah Supreme Court opinion (State v. Valdez)New Jersey Judiciary published opinion (State v. Andrews)Ninth Circuit published opinion (United States v. Payne)D.C. Circuit published opinion (United States v. Brown)Stored Communications Act, 18 U.S.C. 2703CourtListener opinion database
Jurisdiction
United States Supreme CourtNinth CircuitD.C. CircuitMarylandNew JerseyUtah
Case
Riley v. California, 573 U.S. 373 (2014)Carpenter v. United States (2018)Richardson v. State (Md. 2022)State v. Valdez, 2023 UT 26State v. Andrews (N.J. 2020)United States v. Payne, 99 F.4th 495 (9th Cir. 2024)United States v. Brown, 125 F.4th 1186 (D.C. Cir. 2025)

Indexed under

  • iOS
  • Android
  • Mobile Extraction
  • Examiner Workflow

Independent and educational. DEVI Digital Forensics is an independent educational project created by digital forensic practitioners outside of their official employment. It is not sponsored, reviewed, approved, or endorsed by any contributor's employing agency.

Forensic behavior changes between operating system versions, application versions, extraction methods, and tool versions. Validate every finding against your own data, and do not interpret an artifact in isolation. Read the full statement and methodology.

← All findings