The police do not require a warrant to search your immediate person (also your bags and your car) incident to an arrest.
They can't search you without arresting you, and they can't arrest you for literally no reason and have that stand (and, apparently, they generally won't arrest you for no reason if you don't provoke them while being detained and sound like you know enough to tell a lawyer what's happened). "Arrest" has a very specific meaning and is a big deal.
This guy got arrested, apparently during a hand-to-hand drug sale to an informant. He was screwed no matter what.
There are grey areas at play here, but if your phone has no security and they can literally just push a button to see your text messages, I'm not even remotely surprised that what they find there is admissable as evidence. They had the contents of your pockets and your bag. If you had "4 for 80" written in a piece of paper (and, damn, X is expensive!) in a notebook in your bag, that would clearly be admissable after an arrest. Why is your phone different?
If you don't want this to happen to you, PIN-lock your phone. They'll ask you for the PIN. You'll refuse. They'll get a warrant almost instantly, and then you won't be able to refuse anymore. So, also, if you don't want this to happen to you, don't get arrested.
This headline is extremely misleading. The police in California cannot simply dragnet cellphones. They have to arrest you first.
It's still a bit problematic. There are two kinds of searches that happen when a person is arrested.
The first is called "search incident to arrest". It's purpose is to identify any weapons, escape tools or immediate means of destroying evidence on or around a suspect during arrest. Removing a phone from a suspect's immediate control is justified under each theory: the phone may actually be a disguised weapon, it may conceal escape tools and there may be evidence on it that the suspect could destroy. Accessing the data on the phone is not justified under any of these theories.
The second is called an inventory search, which usually takes place when a suspect is booked in to jail, a car is impounded or similar. Its purpose is to identify anything dangerous (corrosive chemicals, explosives, etc...) and to protect the authorities from liability for the loss of any property while in custody. Generally, a suspect is presented with a list of property found and asked to sign a declaration that it is complete so that he cannot later claim property was lost or stolen. An inventory search probably does not require or allow accessing the data on a computer or storage device.
The court ruled that it was a valid search incident to arrest, and that the police were entitled to inspect the contents of an item taken from the person of a suspect during a legal arrest. The justification for inspecting contents is, as I understand it similar to the above: to identify potentially dangerous items before storing the defendant's property, and to have an accurate inventory of what property the authorities are assuming responsibility for. Examining the data on a device almost certainly doesn't meet the first standard, and seems very questionable for the second.
(a) A search incident to a valid arrest is not limited to a frisk of the suspect's outer clothing and removal of such weapons [...]
(b) A custodial arrest of a suspect based on probable cause is a reasonable intrusion under the Fourth Amendment and, a search incident to the arrest requires no additional justification, such as the probability in a particular arrest situation that weapons •••or evidence••• would, in fact, be found upon the suspect's person [..., em mine]
Also, since part of the overtly stated purpose of searches incident to arrest is to protect evidence from destruction, how much more compelling a case can you get than "stuff that is sitting on the guy's cellphone that anyone could erase with the touch of a button should they get their hands on it before the warrant arrived"?
From the same opinion (quoted but also affirmed):
"In addition, it is entirely reasonable for the arresting officer to search for and seize any evidence on the arrestee's person in order to prevent its concealment or destruction."
And later, directly:
We do not think the long line of authorities of this Court dating back to Weeks, or what we can glean from the history of practice in this country and in England, requires such a case-by-case adjudication. A police officer's determination as to how and where to search the person of a suspect whom he has arrested is necessarily a quick ad hoc judgment which the Fourth Amendment does not require to be broken down in each instance into an analysis of each step in the search. The authority to search the person incident to a lawful custodial arrest, while based upon the need to disarm •••and to discover evidence•••, does not depend on what a court may later decide was the probability in a particular arrest situation that weapons or evidence would, in fact, be found upon the person of the suspect. A custodial arrest of a suspect based on probable cause is a reasonable intrusion under the Fourth Amendment; that intrusion being lawful, a search incident to the arrest requires no additional justification. It is the fact of the lawful arrest which establishes the authority to search, and we hold that, in the case of a lawful custodial arrest, a full search of the person is not only an exception to the warrant requirement of the Fourth Amendment, but is also a "reasonable" search under that Amendment. [em mine]
If there's any meaningful risk of someone erasing content from a cell phone in a police evidence locker, no evidence stored in said locker can be considered reliable. As an example, the barrel of a firearm could be replaced between logging in to evidence and ballistic testing[0] or possible drugs could be swapped with real or fake drugs before lab testing.
Physical objects can't be reconfigured via the net. My cellphone can; I could use Chrome2Phone to direct it to a page containing a script causing my phone to reformat its data card, for example.
Cron job - deadman switch. I would assume a full forensic workover of your phone just like a computer, if arrested for anything: police will collect it and let the DA argue admissibility later, in court.
If you don't want this to happen to you, PIN-lock your phone. They'll ask you for the PIN. You'll refuse. They'll get a warrant almost instantly, and then you won't be able to refuse anymore.
I was under the impression that in the US you can't be compelled to disclose your password or encryption key, even with a warrant.
It looks like you're totally right to point this out, but the situation is not "you have the right to refuse to disclose a key"; its, "you may or may not also be charged with obstruction if you refuse a warrant that demands a key, and the case law isn't settled".
Since we're talking about PINs here, by the way, this is a moot point; presumably any major LEO can contract out "recover data on PIN-protected phone".
Having worked for a computer forensic software company I can tell you that these days they most likely don't have to contract it out even... It's cheap enough that a lot of departments have people on staff who can recover data easily from all kinds of devices.
If you use the SIM cards SMS storage (on a GSM phone) it's not that trivial to obtain the PIN. However, it's very likely that your mobile provider is able to gain access to the card (e.g., by using the PUK code to reset your PIN code).
Other means would be to use an application such as TextSecure (for Android) that uses public key encryption to immediately enrypt all incoming SMS and that requires a password to unlock the private key needed to decrypt the SMS.
In the long-term what I'm waiting for is some open-source Android fork that provides full-root encryption using LUKS. This should suffice in preventing others from reading your messages.
Probably the best idea is to create a personal data policy wherein you document a standard practice to delete unnecessary electronic data at specified intervals and change your PIN at other intervals. Given the amount of identity theft it's a very prudent practice that prevents criminals and other unauthorized parties from accessing your data.
Neither did this guy. What are we arguing about? I agree: encrypt your drug dealing receipts; they grey area over obstructing search warrant is vastly preferable to the high-fidelity dump of your transactions they'd automatically get.
Are you suggesting that the plainly visible SMS logs on your phone are in some special digital domain that, in stark contrast to the notebook in your bag, the police should not have access to in an incident-to-arrest search for evidence? That seems pretty silly to me, but that doesn't make you wrong.
"Are you suggesting that the plainly visible SMS logs on your phone are in some special digital domain that, in stark contrast to the notebook in your bag, the police should not have access to in an incident-to-arrest search for evidence?"
It's one thing to say that the last 48 hours of SMS messages are fair game. But most people have the last several years worth of SMS conversations on their phone. And considering the average teenager sends 3339 texts a month, I don't buy that police should be able to read your 80,000+ most-recent text messages on the grounds that this is similar to a pocket notebook.
I'll admit that when I was arrested I had notice but I'll tell you what I brought with me on my person.
A piece of ID (so I didnt get held longer while they 'established' my identity), and enough cash for a pack of smokes and a cab for when I got out.
I didn't even bring a number for a lawyer as my friends were going to take care of it. My blackberry, cell phone, other electronic records, keys to my car, my ATM card, credit card, etc, were left with friends.
When they arrested me I gave them my ID confirmed my self as being the person on the ID and remained silent. Even the guy in my cell who was 'charged' with something errily similar I said nothing to in regards to what I was doing there. He kept asking me for advice of what I would do in his situation and all I could tell him was remain silent and speak to a lawyer. I think he was a cop as I never saw him again, where as most of the other people I ran into I saw the next morning, and I was never formally interrogated.
If you think the police should be able to search 80000 of your SMS records then by all means bring them to your arrest. If you don't then take the steps you feel are appropriate to prevent this from happening.
There is no law requiring the average person to retain their SMS records for police inspection upon arrest.
What? Most arrests don't go down that way, and the accused frequently don't have time to:
1. Drop off their car and keys, two phones, laptop ("other electronic records?"), wallet at home or with friends;
2. Stop by the ATM to ensure they have post-jail money
3. Casually dispose of any other incriminating evidence.
If you have the luxury though, I agree with everything you said. Don't bring child pornography or other incriminating evidence to the police station for your arrest.
Also, if LEOs are required to obtain a court order to read these from the network provider's archives and logs, why should that not also be true for your phone?
Right. I understand the legality of it, however I was more referring to the moral case.
Since a court order has to be argued for, it should also hold true that a search of an electronic data store would also require more than just plain-sight standards, especially given a scrap of paper in my pocket feels to me not 'plain sight' equivalent to a text message on a phone, or an email on my computer.
I think this is just one more instance of our collective false understanding in the legal system as to how data, electronics and the like truly work - and we're going to have to wait it out longer before this stuff is all better represented.
Because most people don't have their network provider with them upon arrest.
For instance if when arrested you had 1kg of contraband on you it would be admissible, for instance if when arrested you had 1kg of contraband at your network provider's NOC then they'd need a warrant to search it.
I wonder how this would fare if the device had been secured with a PIN or some other password. Are we now back around to a situation similar to the warrantless searches US Customs and Border Patrol can do when crossing a border?
Edited to add: I just perused the decision linked to in the article[1] and it doesn't appear that the court addressed that issue. The majority's decision does make reference to a "locked footlocker" that was opened without a warrant, and that the US Supreme Court ruled that the search was invalid because it was "distant from the arrest." It doesn't seem to address breaking open the lock.
No. If you had read the article carefully, you'd find that the person who had been searched had already been arrested (and with very strong PC). Every ACLU-style "Know Your Rights" video makes this distinction clear: it is not like at the US border, where you can be searched for no reason; there are very specific cases where you can and can't refuse searches.
Unlike --- I might add --- large stretches of Europe, where police have far stronger rights to search personal property.
I understand that the person had been arrested and was in custody. The question I have is whether or not the police could have demanded the password from his phone if one existed, and what consequences would result from his refusal to provide it. The reference to CBP's searches is that there is some question as to whether or not someone must provide the password to a secured device during an otherwise-legal search.
I was under the impression that there is no law in the US that requires me to surrender my password. Has there been any court decisions requiring people to surrender passwords?
This seems quite dangerous, as we push more and more data into the cloud and use cell phones as the a way to access it. Does this mean when you are arrested, they can read all your emails, get your bank information, amazon shopping history, etc as long as the access is on your phone? If you have a laptop can they do the same thing?
There's going to be an interesting Supreme Court case when the police bother to recover a Gmail session cookie from someone's phone or laptop and use it to dive into their email. My guess is the Gmail account owner will win, because when you seize my housekey during an arrest, you do not get to search my house.
The reason this hasn't happened already, though, is that the police aren't generally trawling through the Gmail accounts of drug suspects. They have more drug suspects on eyewitness and hand-to-hands than they can deal with; read _Cop in the Hood_ for examples of state prosecutors refusing to pursue cases because drugs seized from suspects "could, for all the apprehending officer knew, have been an Oreo cookie".
Password locking your iPhone is not a forensically secure technique. A better idea would be to keep anything incriminating off it, and (obviously) not to get arrested.
Actually the best way would seem to be some device that would instantly disable the iPhone if you were pulled over. I somehow doubt they are going to start confiscating everyone's phones with dead batteries (with no other reason for arrest or search) just to check the contents.
"I'm sorry officer, my phone's battery is dead so I clearly wasn't texting while driving. Am I being detained, or am I free to go?"
But probably the easiest thing to do is to quickly slide your phone into a compartment (not hidden, just closed) in your car when you get pulled over. Then they must get a warrant to search your car. Most cops don't push it to this level unless you actually did do something.
I know that the iPhones are notoriously bad at securing data when the device is on, but what about the remote wipe option? It's my understanding that 3GS and 4 phones have encrypted HDDs, with the remote wipe clearing the keys. I'm no expert, but wouldn't that be equivalent to any other disk encryption technique (which, to my knowledge, is practically unbreakable if keys are unavailable)?
If they power it off, using the same exploits as the iPhone jailbreaks (and using forensic tools by Jonathan Zdziarski; http://twitter.com/JZDZIARSKI) they can easily recover the data.
Before the boot-up ROM used on the iPhone was exploited, though, this was much more difficult (if not impossible).
They can't search you without arresting you, and they can't arrest you for literally no reason and have that stand (and, apparently, they generally won't arrest you for no reason if you don't provoke them while being detained and sound like you know enough to tell a lawyer what's happened). "Arrest" has a very specific meaning and is a big deal.
This guy got arrested, apparently during a hand-to-hand drug sale to an informant. He was screwed no matter what.
There are grey areas at play here, but if your phone has no security and they can literally just push a button to see your text messages, I'm not even remotely surprised that what they find there is admissable as evidence. They had the contents of your pockets and your bag. If you had "4 for 80" written in a piece of paper (and, damn, X is expensive!) in a notebook in your bag, that would clearly be admissable after an arrest. Why is your phone different?
If you don't want this to happen to you, PIN-lock your phone. They'll ask you for the PIN. You'll refuse. They'll get a warrant almost instantly, and then you won't be able to refuse anymore. So, also, if you don't want this to happen to you, don't get arrested.
This headline is extremely misleading. The police in California cannot simply dragnet cellphones. They have to arrest you first.