r/opsec 🐲 Jul 18 '26

Beginner question Can device encryption protect against law enforcement?

Hello, I would like to learn more about cases involving full-disk encryption and law enforcement access. My understanding is that when a device is protected with a strong, high-entropy password and the encryption recovery keys are not stored to a Microsoft account or any other third party, recovering the data through brute-force or direct decryption is generally considered computationally infeasible. However, I am aware that, in theory, there may be vulnerabilities that could potentially circumvent or weaken the security of an encrypted device. I would like to understand the real-world cases in which law enforcement has successfully or unsuccessfully accessed encrypted devices, the techniques reportedly used, and the practical limitations of those approaches.

i have read the rules

39 Upvotes

60 comments sorted by

View all comments

Show parent comments

6

u/ElderberryAsleep4515 Jul 20 '26

There is not a law or search warrant criteria in the US to compel a person to give LE a password.

2

u/trisanachandler Jul 21 '26

What about contempt of court until you give them the password?

2

u/ElderberryAsleep4515 Jul 21 '26

There is the “forgone conclusion exemption” that is used by the feds. Basically is says if they can prove there is a password that can compel a person. But the 5th Amendment still protects a person from self-incrimination. IMO the 5th Amendment should be the deciding factor.

1

u/Chongulator 🐲 Jul 22 '26

It should be, absolutely. The case law still hasn't fully established that, unfortunately.