By Douglas E. Huff  |  Partner, Deandra Grant Law  |  Dallas, Texas

In March 2026, Apple released iOS 26.4. Buried in the release was a change that has (quietly) reshaped the landscape of mobile-device forensics. A feature called Stolen Device Protection, or SDP, which Apple introduced in iOS 17.3 in early 2024 as an opt-in option, is now switched on by default. Most iPhone users updating to iOS 26.4 or later, or restoring or setting up a new iPhone since the release, have the protection enabled without ever having found the toggle.

For ordinary iPhone owners, that is straightforward consumer security. For people whose phones become evidence in criminal cases, it is more interesting than that. Forensic examiners who specialize in extracting data from iPhones report that the single most consequential thing SDP does (putting Face ID or Touch ID in front of the “Trust This Computer” prompt when the phone is away from a familiar location) effectively blocks the standard first step of advanced data extraction, even when the examiner has the passcode. The forensic vendor Elcomsoft, which builds tools sold to law enforcement and government labs, recently called this “the most disruptive change Apple has made to iPhone pairing behavior in roughly a decade.”

So the question a lot of defendants will start asking their lawyers is the question this post is about: can the police actually get into my phone? The honest answer is that it depends on three things: the phone, the law, and what the prosecutor can prove. None of those is what most people assume.

First, Police Need a Warrant

Before any of the forensic-extraction questions matter, there is a constitutional threshold. In 2014, the United States Supreme Court held unanimously in Riley v. California, 573 U.S. 373, that police generally need a warrant to search the contents of a cell phone seized incident to an arrest. The court was direct about why. A modern smartphone is not just one container of information; it is a portal into a person’s correspondence, photographs, financial records, location history, medical information, and political and religious life. The court called the search of a phone “a far more serious intrusion on privacy than the search of a person.”

So in any Texas state-court prosecution, the first question a defense lawyer asks when a phone is in evidence is whether the search of that phone was authorized by a valid warrant, supported by probable cause, and reasonably particularized. There are narrow exceptions to the warrant requirement, but in routine cases involving seized phones, the answer is supposed to be: warrant or no search.

The warrant requirement is necessary, but it is not the end of the story. A warrant authorizes the search; it does not, by itself, make the search physically possible. That is where the rest of this post lives.

What “Phone Extraction” Actually Means

In ordinary speech, “getting into” a phone sounds like one thing. In forensics, it is several different things, and the law and the technology behave differently for each.

  • Logical extraction. The examiner connects the phone to a computer (the “forensic workstation”) and uses Apple’s own backup mechanisms, or commercial forensic software that exercises those mechanisms, to pull a copy of the user-accessible data. This is what most people picture when they imagine a phone being “extracted.” It is also the most common form of extraction in everyday casework.
  • File-system or full-file-system extraction. A deeper extraction that reaches into more of the device’s storage than a logical backup exposes. This typically requires the phone to be paired to a workstation and an extraction agent installed onto the device.
  • Cloud acquisition. Rather than reading data from the physical phone, investigators pull a copy of the user’s iCloud data. This is a separate legal regime (typically a search warrant served on Apple itself) and is not affected by what is happening on the seized device.
  • Low-level, chip-level, or bootrom extraction. On older hardware, examiners can sometimes bypass operating-system protections entirely and read the device’s memory directly through hardware-level techniques. This category is limited to a defined window of older Apple chips and is shrinking over time.

The reason this taxonomy matters is that Apple’s Stolen Device Protection only operates at the operating-system level. It changes nothing about cloud data sitting on Apple’s servers, and it changes nothing about the small remaining set of devices that can be acquired at the hardware level. What it changes is the standard logical and full-file-system extraction pathway (the most common workflow in U.S. labs) by closing the gate at the very first step: pairing the phone to the workstation.

What Stolen Device Protection Changed

On an iPhone with SDP enabled and Find My on (which is the default state on a current iPhone) certain sensitive operations now require Face ID or Touch ID, with no passcode fallback, when the device is away from a familiar location (essentially anywhere that isn’t the owner’s home or workplace). One of those operations is establishing a new “trust” relationship with a computer the phone hasn’t paired with before. In practice, that means the standard forensic-lab workflow (plug the phone into a workstation, enter the passcode, confirm the trust prompt, install an extraction agent) is now interrupted at the trust prompt.

The examiner has the passcode. The phone is on. The phone is unlocked. The phone still refuses to pair with the workstation without a biometric from the owner. Where the lab work used to require the suspect’s passcode and nothing else, it now requires the suspect’s face or fingerprint as well.

That shifts the legal pressure point. For years, the central Fifth Amendment fight in this space has been about whether the State could compel a defendant to give up the passcode. That fight is not going away (it is still alive and still divides courts) but for a growing share of iPhones, the passcode by itself is no longer enough to extract anything. The question becomes whether the State can compel a defendant’s face or fingerprint, and that is a different legal question, with a different answer in many courts.

The Fifth Amendment: Passcode vs. Biometric

The Fifth Amendment to the United States Constitution provides that “no person… shall be compelled in any criminal case to be a witness against himself.” That protection has always been narrower than its plain English suggests. The Supreme Court has long held that the privilege protects only testimonial communications which are acts that disclose the contents of a person’s mind. It does not protect compelled physical evidence. Blood samples, fingerprints for identification, voice exemplars, handwriting samples, and standing in a lineup have all been treated, since Schmerber v. California in 1966, as non-testimonial physical acts that the State can compel.

A passcode is generally treated as different. A passcode is information stored in a person’s memory. To produce it, a defendant has to look inside their own mind and communicate what they find. That is testimonial in a way a blood draw is not. The Supreme Court drew that distinction in Doe v. United States, 487 U.S. 201 (1988), and the lower courts have been working out what it means for digital decryption ever since.

That theoretical line (contents of the mind protected, physical characteristics not protected) is the reason a passcode and a biometric are not, in most courts, the same thing under the Fifth Amendment. A growing number of state and federal courts have held that compelling a person to apply their fingerprint or face to a device to unlock it is no more testimonial than compelling them to give a blood sample. It is, in this analysis, a physical act with no communicative content.

A smaller but real line of cases pushes back. Some courts, including federal magistrate judges in California and Illinois, have reasoned that biometric unlocking is functionally testimonial because it confirms the defendant’s relationship to the specific device which in effect, is communicating, “this phone is mine, and I have the ability to open it.” On that reasoning, biometric compulsion is treated more like a passcode and afforded Fifth Amendment protection. The case law is genuinely split, and the Supreme Court has so far not resolved it.

For passcodes themselves, the case law is even more fractured. Several state supreme courts (including those of Indiana, Pennsylvania, and New Jersey) have reached materially different conclusions about whether the State can compel a defendant to disclose a passcode under the so-called “foregone conclusion” doctrine. That doctrine is the prosecution’s usual workaround, and it deserves its own section.

The Foregone Conclusion Doctrine

In Fisher v. United States, 425 U.S. 391 (1976), and later in United States v. Hubbell, 530 U.S. 27 (2000), the Supreme Court developed an exception to the Fifth Amendment privilege for the “act of production.” If the government already knows that specific evidence exists, that the defendant possesses it, and that it is what the government says it is, then the act of producing it is not meaningfully testimonial because it adds nothing to what the government already knows. The defendant’s production is, in the Court’s phrase, a “foregone conclusion.”

Prosecutors have argued, with mixed success, that the foregone conclusion doctrine reaches compelled passcode disclosure. The argument runs: we know the phone exists, we know the defendant possesses it, and we know the defendant knows the passcode (often because the defendant unlocked it in front of officers). Under those circumstances, the State says, compelling the defendant to enter the passcode is not testimonial in any meaningful way.

Courts have responded in different ways. The Massachusetts and New Jersey supreme courts have, in different cases, allowed compelled passcode disclosure where the State could make a sufficient showing under the foregone conclusion doctrine. The Indiana Supreme Court reached the opposite result, holding that compelling a passcode reaches further into the contents of the mind than the doctrine permits. The Pennsylvania Supreme Court has held that compelled passcode disclosure violates the Fifth Amendment without exception. Federal circuits have split. The result is a national patchwork in which the same fact pattern would yield different outcomes in different states.

Texas appellate courts have not produced the kind of clear, leading appellate decision on compelled smartphone decryption that some other states have. That means there is room for argument in any given case and that means the litigation matters.

What This Means If Your Phone Has Been Seized

Putting all of this together, a few practical points are worth understanding before they come up in a real case.

  • A search warrant for the phone is not the same as a court order to unlock it. Even when investigators have a valid warrant to search a phone, they often cannot execute it without help such as the passcode, the biometric, or a forensic capability that bypasses both. If the State seeks a separate court order to compel a defendant to unlock the device, that order is a separate legal event and is challengeable on Fifth Amendment grounds.
  • There is a meaningful legal difference between a passcode and a biometric. In most courts, applying a face or fingerprint to a phone is treated as a physical act the State can compel. Entering a passcode is treated, by most courts, as testimonial with the foregone-conclusion exception sometimes opening the door. The two are not interchangeable, and a defendant’s choice of unlock method on a personal device can have real legal consequences if the device is ever seized.
  • The technology and the law are both moving. Apple’s Stolen Device Protection change is one of the larger consumer-side movements in this area in a decade, and it shifts pressure from the passcode fight onto the biometric question. Courts in different states will work that out at different speeds and with different answers. The state of the law in 2026 will not be the state of the law in 2029.
  • Talk to a lawyer before you talk to anyone else about your device. Voluntary consent to unlock a phone, voluntary disclosure of a passcode, or voluntary application of a fingerprint or face waives the constitutional questions this post is about. Investigators understand that. A person who is asked, at the scene of an arrest or in a back room at the station, to “just open the phone real quick” is being asked, in plain terms, to waive rights that a court might otherwise enforce. The right time to decide whether and how to cooperate is after consulting counsel, not in the moment.

The Bigger Picture

A modern phone is the most concentrated record of a person’s life that has ever existed. It is photographs and messages, but it is also location data, financial activity, search history, biometric records, contacts and relationships, medical information, calendar entries, and saved passwords for everything from email to bank accounts. When that record becomes evidence, it becomes evidence about every part of a person’s life and not just the part the investigation is interested in.

The constitutional rules that govern access to that record are still being written. They are being written one case at a time, in trial courts that are working out warrant applications and motions to compel in real time, and in appellate courts that are reaching different answers to the same questions. Apple’s product decisions are part of that conversation. So are prosecutors’ charging decisions, magistrates’ evidentiary rulings, and defense lawyers’ motions practice. None of it is settled.

If you are facing a criminal investigation or charge in Texas and there is a phone in the picture (yours, a co-defendant’s, a witness’s, an alleged victim’s) the digital-forensics piece of your case is rarely an afterthought. It is often the case.

Douglas E. Huff is a partner at Deandra Grant Law, an ACS-CHAL Forensic Lawyer-Scientist, and past president of the Dallas Criminal Defense Lawyers Association. His practice includes criminal cases in which digital forensics, electronic discovery, and search-and-seizure law are central. To discuss a pending case, call (214) 225-7117 for a free, confidential consultation.