The only way the password itself can be self-incrimination is if it's something along the lines of "fraudrealestateisfun". The government said, "Fine, don't tell us the content of the password: enter the password so that we can access the contents of what's behind it."
People's arguments that you have an expectation of privacy are irrelevant: you have a genuine expectation of privacy in your home. If the state shows there's a compelling interest to enter your home (i.e. obtains a warrant), you can't stop them. Similarly, you can't stop them from decrypting your data. Well, you can, but you're going to suffer as a result.
Similarly, you don't have to show your hiding places. Suppose you had an encrypted folder structure and one of the folders was hidden to someone who doesn't understand how to see hidden folders. You don't have to say "there's a hidden folder", just like you don't have to say, "There's a false floor." Encryption isn't a 'hiding place': they've found the data.
Encryption is a locked door. The state wants to know what's behind it. Opening your front door to the police holding a warrant isn't self-incrimination (i.e. it in no way points to your guilt or innocence). Similarly, entering the password to your encrypted drive isn't self incrimination if the state has proved you're the sole possessor of the device.
Although the only way the password content can be incriminating is via the language of the password, the fact that a password works on a particular machine may be incriminating. This is the only line of argument that could work, for what it's worth, and none of these 'privacy' lines of argument. "Your honor, the state has no compelling basis for thinking my client had possession or knowledge of the drive in question. Compelling my client to enter a password on the chance it could unlock the files would prove that they did have possession or knowledge of the drive." &c. But once the state can show it's your encrypted data, it's game over. Fortunately, it's this "foregone conclusion" line of argument that the EFF actually pursues, and not the 'Privacy' line that seems to be popular in these replies.
In particular note the precedent from Hoffman v. United States, which you can find in context at http://caselaw.lp.findlaw.com/scripts/getcase.pl?navby=case&..., which says The privilege afforded not only extends to answers that would in themselves support a conviction under a federal criminal statute but likewise embraces those which would furnish a link in the chain of evidence needed to prosecute the claimant for a federal crime.
Providing the password obviously could furnish a link in the chain of evidence needed to prosecute the claimant for a federal crime. Therefore it is protected.
Decryption is not about finding data which is inside something, it is about making sense of data you already have. Forcing someone to decrypt something is asking them to provide a plausible explanation of what the data means.
Do not get confused by real-world analogies. When you have a safe, you can map the space within the safe and be sure you aren't missing something. When you have data, you have no way to make sure that a given explanation is the right one.
If I have something illegal and incrementing on my encrypted hard drive, am I not helping incriminate myself by giving the password? That is the basis of the law, and if indeed you are incrementing yourself by providing a passphrase for an encrypted container, you don't have to provide it; in a nutshell you are dead wrong.
Your metaphors about a password being a locked door and this and that is nonsense, a password is not a locked door. A locked door is a locked door. An encrypted file that is password protected is an encrypted file that is password protected, I don't have to let anyone look at anything If I don't want to, regardless if they have a warrant; they will just bust in anyway.
When police have a warrant, lots of times they don't even knock on the door, but just barge their way in. They can attempt to do the same with the encrypted file, they can brute their way in, but you are not required by law to help them accomplish this.
"Although the only way the password content can be incriminating is via the language of the password,". This is you guessing and making things up. This is you spouting your opinion 100%. If I have something extremely illegal on an encrypted container, than giving the password is most certainly incriminating my own self. This fantasy you have that the only self-incrementing that can occur is if the password itself is a sentence stating guilt is the biggest load of bullshit I've read on ycombinator in a long time, wherever did you come up with this nonsense I'll never know.
Your attitude towards bending over and letting any government official rape you, is unsettling at the least, and a terrible sign of where our society is at the most. I pray there are as little people sharing your opinion out there as possible, else I weep for the future of society.
Also, please tell me what they could possibly do if one claims to have forgotten the passphrase? Presidents for years have gotten away with everything by stating, "I can't recall" on tough questions; who's to say with all the fuss and scary guns pointed at you during the raid, you totally forgot your passphrase? How could anyone ever prove you actually forgot it or not? Charged with obstruction of justice you say? Imagine if the contents on the encrypted container itself would get me into 10,000 times more trouble than an obstruction of justice charge, then obviously I've done the smart thing.
There is common sense, there is common decency, and there is the Law. As you must know, the law sometimes isn't sensible nor decent.
I think everyone here agree about the humane thing to do here: never ever force someone to either (i) incriminate herself, (ii) lying under oath, or (iii) risk contempt of court. Similarly, probably everyone here agree about the sensible attitude towards passwords: never force anyone to give hers.
But the letter of the Law isn't the same. And I think Boredguy8 was talking about the Law.
Detailed. But wrong. Although courts and DAs have tried to argue that a password is like a physical key, or tried to give you immunity for speaking the key, higher courts (e.g. the 5th circuit of appeals) regard giving the password as testimony - and therefor protected by the 5th.
Although passwords are new, combination locks are not. There is a lot of case law on this.
"In distinguishing testimonial from non-testimonial acts, the Supreme Court has compared revealing the combination to a wall safe to surrendering the key to a strongbox. The combination conveys the contents of one's mind; the key does not and is therefore not testimonial. A password, like a combination, is in the suspect's mind, and is therefore testimonial and beyond the reach of the grand jury subpoena. "
Edit: Why it matters in this case: FTA "the government seized an encrypted laptop from the home she shares with her family"
The government cannot prove that the laptop is hers. If she provides a password, and it works she has proven that the laptop is hers, and further that the contents are under her control. Therefor the act of provided the password would be testimony.
This is interesting. In all discussions on this subject, the comparison to physical keys comes up and the trivial conclusion is that passwords are not protected under the 5th amendment. If combinations to wall safes are protected by the 5th, I'd say the situation is clear cut: a password is exactly like the combination to a safe. You'd have to give up physical tokens required to login/boot a device, but not the subsequent password.
This interpretation is strengthened vastly by the fact that the EFF is arguing this case. They are not known for attempting to argue futile points.
a password is exactly like the combination to a safe
I disagree. A safe is a physical object that contains other physical objects. It can be forcefully open.
OK, maybe there are some very sophisticated safes that would act exactly like a password, not allowing to extract the objects inside without damaging them beyond recognition.
But I'd say it's the exception. Possibly helped by the safe manufacturers, the police will eventually access the contents of most safes.
This situation creates a different set of incentives. You can open your safe as soon as the judge requests it, or you can wait to be punished for refusing and the safe be opened forecefully later... that will uncover what you were hiding anyway.
Edit: I'd like to add that the punishment for not telling the password is a very, very, very bad idea. It's impossible to produce a password that you don't know. It's impossible to demonstrate that you don't know a password. It's impossible to demonstrate that a file is just a pile of random garbage instead of an encrypted one. Setting a punishment for things that are impossible to objectively know doesn't seem a good idea.
> A safe is a physical object that contains other physical objects. It can be forcefully open.
A computer is a physical object. A hard drive contains data, physically, much like papers in a safe contain data, physically.
And it can be forcefully opened, too - it's merely a matter of magnitude of effort. Cracking a safe could take hours or days, cracking a password could take millennia. It should not be my problem that the government has locksmiths with drills on staff, but not supercomputers capable of breaking encryption.
I suppose it depends on what it takes for the police to be allowed to forcefully open a safe. If the police obtains a warrant to search your premises, are they already allowed to forcefully open safes? I don't expect so, since they have only established 'probable cause' and are looking for evidence, contraband or what-have-you in general, but are not looking for anything specific of which they can reasonably suspect it is hidden in the safe.
I wouldn't expect the case law to be predicated on the fact that most safes can in fact be opened even if the combination is not supplied, specifically because, as you point out, there are safes that would destroy the evidence in such a case. The justification "meh, who cares if he gives the combination, we'll just open it forcefully and obtain the evidence anyway" doesn't hold for, probably the more important, cases.
The solution is to solve a technological problem with an analog solution -- don't know the password, and store it in behind a suitable physical barrier.
An example of this is a retail drop safe -- it can only be opened by specific people at a specific time.
At the end of the day, you need to weigh the options. If you are an attorney performing your ethical duty, you have an obligation to rot in jail while the illegal warrant is litigated.
"Detailed. But wrong...The government cannot prove that the laptop is hers."
I wrote, "the fact that a password works on a particular machine may be incriminating. This is the only line of argument that could work...it could...prove that they did have possession or knowledge of the drive." Seems like we're saying the same thing.
At issue here is likely the status of what constitutes a "Foregone Conclusion". In Fisher, the courts established that, "The existence and location of the papers are a foregone conclusion and the taxpayer adds little or nothing to the sum total of the Government's information by conceding that he in fact has the papers. Under these circumstances by enforcement of the summons 'no constitutional rights are touched. The question is not of testimony but of surrender.'"
In Boucher there's clearly not a foregone conclusion, and the motion to quash the grand jury subpoena was upheld because the password's production was "purely testimonial." Here, it might not be "purely testimonial."
Also, for what it's worth: having a password is certainly better than locking a system via biometrics. At least with a password, the law is (currently) indeterminate. Biometric locks: you're screwed.
So why can't everyone just claim they forgot their password? Additionally, what stops you from setting up some kind of hard drive degausser inside your case that is set to go off if the case is moved? Would you be responsible if the police officer removing your computer from your home inadvertently set off the degausser?
Not if you had it setup prior to any sort of court order to degauss the drive regardless of who tampers with your system or why. For example, Coca-cola might do that on a manufacturing system that controls the quantities and timing of the raw ingredients to produce the formula and is evidence only that they want to protect it. However, once the court has ordered you to turn over your system as evidence, you can't simply point and say "Sure, it's over there... take it" knowing full well that it will get wiped as soon as it's moved. That would be destruction of evidence.
I am not a lawyer. This type of device can have legitimate use as well though. Think about if you are the guy that knows the coca-cola recipe. The destruction of the recipe by hd degaussing is good when a competitor comes to your office and steals your computer. Though, you would need a pretty large degaussing device to erase the hd beyond forensic analysis.
Absolutely not. As another poster pointed out, if it predated the court order, it would be 100% legit. Say I wanted to make sure my data was safe in the event of theft? Wiping the data on movement would be a clear way to do that.
I thought about that, but wouldn't it only be destruction of evidence if YOU were the one that destroyed the evidence? Just because it was set off when the cop/FBI/whomever moved your computer doesn't mean you wanted it to happen, right?
People's arguments that you have an expectation of privacy are irrelevant: you have a genuine expectation of privacy in your home. If the state shows there's a compelling interest to enter your home (i.e. obtains a warrant), you can't stop them. Similarly, you can't stop them from decrypting your data. Well, you can, but you're going to suffer as a result.
Similarly, you don't have to show your hiding places. Suppose you had an encrypted folder structure and one of the folders was hidden to someone who doesn't understand how to see hidden folders. You don't have to say "there's a hidden folder", just like you don't have to say, "There's a false floor." Encryption isn't a 'hiding place': they've found the data.
Encryption is a locked door. The state wants to know what's behind it. Opening your front door to the police holding a warrant isn't self-incrimination (i.e. it in no way points to your guilt or innocence). Similarly, entering the password to your encrypted drive isn't self incrimination if the state has proved you're the sole possessor of the device.
Although the only way the password content can be incriminating is via the language of the password, the fact that a password works on a particular machine may be incriminating. This is the only line of argument that could work, for what it's worth, and none of these 'privacy' lines of argument. "Your honor, the state has no compelling basis for thinking my client had possession or knowledge of the drive in question. Compelling my client to enter a password on the chance it could unlock the files would prove that they did have possession or knowledge of the drive." &c. But once the state can show it's your encrypted data, it's game over. Fortunately, it's this "foregone conclusion" line of argument that the EFF actually pursues, and not the 'Privacy' line that seems to be popular in these replies.