A fingerprint is convenient. So is looking at your phone to unlock it. But convenient access and recovery of encrypted information solve different problems—and biometric unlocking raises legal questions that a reassuring button cannot answer.
At CoClient, resetting your account password does not recover your encrypted case content. We do offer optional passkey unlock on supported browsers and devices, which may involve a face scan or fingerprint. We do not treat that as a replacement for keeping your recovery key.
The federal case: United States v. Payne
On April 17, 2024, the Ninth Circuit decided United States v. Payne, 99 F.4th 495. During a parole search, an officer physically used Payne’s thumb to unlock a phone he had already identified. The court held that this did not violate the Fifth Amendment: on those facts, using his physical characteristic did not require him to communicate knowledge from his mind.
The distinction matters because the privilege against self-incrimination protects compelled, incriminating testimony. Something can reveal incriminating evidence without being legally “testimonial.” The court also upheld the phone search under the Fourth Amendment in the particular parole-search circumstances.
Payne was narrow. The judges expressly cautioned against extending their decision to every biometric unlock. They noted that requiring someone to choose the correct finger could change the analysis. It was a thumbprint case, not a blanket ruling about every face-recognition system. Read the Ninth Circuit opinion, especially pages 32–33.
This was a federal appeals decision, not a Supreme Court merits ruling. The Supreme Court declined to hear Payne’s appeal on November 25, 2024; that denial did not turn the lower court’s reasoning into a nationwide Supreme Court holding. See the Supreme Court docket.
Another federal court found a constitutional violation
On January 17, 2025, the D.C. Circuit reached a different result in United States v. Brown, 125 F.4th 1186. The relevant phone belonged to co-defendant Peter Schwartz. Agents directed him to open it, and he used his thumb.
The court held that his compliance communicated knowledge: he knew how to open the phone and had access to and control over it. That made the compelled act testimonial. The court found that the evidence should have been suppressed and sent the case back for an assessment of whether the error was harmless.
The court distinguished Payne’s physically applied thumb from Schwartz being instructed to unlock the device. It described the holdings as consistent given those different facts. So “the government can always force you to use your fingerprint” overstates the law. The action demanded, the circumstances and the governing court all matter. Read Brown, particularly pages 22–33 and footnote 2.
A password is not an absolute legal shield either
It would also be misleading to promise that a password makes compelled access impossible. Courts have permitted compelled decryption in some circumstances, including where the relevant facts were already known to the government—the “foregone conclusion” doctrine. For example, the Third Circuit upheld a contempt order arising from compelled decryption in United States v. Apple MacPro Computer, while limiting parts of its analysis to plain-error review. Read the 2017 decision.
These cases concern access to devices and evidence. They do not establish a universal rule for recovering an online account, and they do not make an app immune to lawful process. If you face an actual demand to unlock a device or disclose a key, get advice from a lawyer familiar with the relevant jurisdiction and circumstances.
Three different things people call “recovery”
- Account password reset: restoring access to your CoClient account. This does not recreate the key needed to decrypt your case records.
- Convenient workspace unlock: using a workspace password or supported passkey you previously enrolled in this browser. This opens an existing protected copy of your key.
- Recovery of encrypted case content: regaining access using a usable key or saved unlock method. CoClient cannot reconstruct your key if all usable copies and methods are lost.
A passkey is a cryptographic credential, not your fingerprint itself. A device may use a biometric check or a PIN to authorize its use. WebAuthn keeps biometric recognition within the authenticator rather than sending biometric samples to the website. That technical boundary does not settle whether someone could lawfully compel its use. See the WebAuthn specification.
Why CoClient keeps recovery under your control
Your case records can include sensitive correspondence, financial details and questions you are still trying to understand. Our recovery design rests on a concrete limit: CoClient does not hold your case-data recovery key. Verifying who you are—even perfectly—does not give us the missing cryptographic secret.
If you enroll passkey unlock, it can remain a useful way to reopen your workspace in that browser. Your provider may sync its passkey credentials, but that does not sync CoClient’s browser-local unlock settings or your case data. Keep your recovery key in a secure place you control, separately from your case-data backup. A key without the records, or encrypted records without a usable key, is not a complete recovery plan.
The lesson from these cases is to understand each access method’s limits. We can explain where the key lives and what a reset can do. We cannot promise that a fingerprint, password or recovery key carries an automatic constitutional exemption.
General information about U.S. decisions and CoClient’s current web recovery design, not legal advice. CoClient is not a law firm.