The True Meaning of Consent in ‘Consent Extractions’

August 24th, 2026 by Oleg Afonin
Category: «General»

In law enforcement use a “consent extraction” means the examiner knows the passcode. It rarely signals owner agreement. That would be a vocabulary issue if the passcode remained the whole key. Since iOS 26.4 it does not. Stolen Device Protection is on by default, and away from familiar locations it requires Face ID or Touch ID before the “Trust This Computer” prompt. The passcode still unlocks the device and confirms Trust. SDP adds a second requirement on top. An extraction that once needed one credential now needs two, and legal systems treat the two credentials as different kinds of thing.

This article maps technical requirements against legal ones. The subject is not linear: the same iPhone, passcode and authority produce different outcomes depending on build, location, clock and jurisdiction.

In practice, the same English word can mean four different situations.

  • Actual consent. A cooperating owner, usually a victim or witness. Revocable, limited in scope, and the only case where you can ask the owner to change device settings in advance.
  • Compelled disclosure. The passcode obtained under a formal notice or order: RIPA s.49 UK, art. 434-15-2 France, s.3LA Australia, s.130 Search and Surveillance Act New Zealand, s.39 Criminal Procedure Code Singapore. Lawful where it applies. It is not consent.
  • Compelled biometrics. A warrant clause or order authorising a finger or face. A different legal test from the passcode, a different record, and since iOS 26.4 the more frequently decisive one.
  • Manufactured consent. The roadside “you don’t mind if I have a quick look?” The Ontario Court of Appeal addressed this in R. v. O’Brien 2023 ONCA 197: coercive circumstances, no informed consent, no meaningful chance to reach counsel. Writing “consent extraction” on the exhibit sheet does not create one.

The label travels with the evidence. If your report says consent and the defence shows it was one of the other three, you have created an argument the method never required. Record the mechanism, not the shorthand: the notice, the order number, the warrant clause, what the person was told and when. In United States v. Brown, 125 F.4th 1186 D.C. Cir. 2025, ambiguity about what the agent said to the suspect did real work in the outcome.

So, three different terms instead: consent extraction, compelled-credential extraction, compelled-biometric extraction.

What each credential opens

Multiple factors can affect this.

Credential What it does Limitations
Passcode Unlocks the device. Confirms the Trust prompt. Required for Developer Mode on iOS 16 and later, with confirmation after restart. Required after every reboot. With SDP active away from a familiar location, the passcode alone is no longer sufficient.
Face ID or Touch ID With SDP on and the device away from a familiar location, satisfies the extra check before the Trust prompt and other actions. Supplements the passcode requirement; the passcode remains required.
Existing pairing record Lets you connect without a new Trust handshake, so the SDP pairing check never fires. Leaves the device locked; USB Restricted Mode still requires an unlock. Ends on reboot and expires 30 days after last use on iOS 11 and later.

A quick note: reports that iOS 18.2 allows the “Trust This Computer” prompt to be confirmed with Face ID instead of the passcode trace to a single beta observation posted 5 November 2024. No Apple documentation confirms it. Testing shows the passcode is still required to establish pairing.

For the purpose of data extraction (that is, pairing to a new workstation), SDP adds a credential. The passcode fires everywhere, at home and away, with SDP on or off. The biometric fires only away from familiar locations and only when SDP is on. Familiar locations are Significant Locations the phone has learned, in practice home and work. SDP adds a second credential; it does not move the first.

Compelled-decryption statutes were drafted for one credential, the passcode.

RIPA s.49 reaches a “key.” France’s art. 434-15-2 reaches a convention secrète de déchiffrement, a secret decryption convention. Singapore’s CPC s.40 reaches decryption information. These are knowledge words written for the era when knowing the code was the whole problem. The UK backs s.49 with up to two years under s.53, five where national security or indecent images are involved. France provides three years and a €270,000 fine, and the Court of Cassation settled in November 2022 that a phone PIN qualifies where the device is encrypted, which is every modern phone.

None of that covers a face. The jurisdictions that criminalised digital silence built a lever for exactly the credential SDP has made insufficient alone.

One exception: Australia’s s.3LA of the Crimes Act, inserted by the Cybercrime Act 2001, allows a magistrate to order a specified person to provide passwords, PINs, or biometric access, with a maximum of ten years for refusal in serious federal matters. Australia legislated for the two-credential world twenty-five years early. Hong Kong is the other route: Article 43 Implementation Rules as amended by L.N. 27 of 2026, in force 23 March 2026, empower officers to require “decryption assistance” from a specified person, read as covering biometric unlocking along with passwords and keys. Refusal carries a year and HK$100,000, with a heavier penalty for a wrong password. Authorisation comes from a senior officer rather than a court.

Germany and the Netherlands cannot compel a passcode from a suspect. Germany’s StPO protects the right to silence in the digital realm, reinforced by the Federal Constitutional Court’s 2008 recognition of a fundamental right to confidentiality and integrity of IT systems. Dutch art. 125k allows a decryption order but excludes the suspect. Both nevertheless permit forced biometric unlock. The Hoge Raad held on 9 February 2021 that handcuffing a suspect and pressing his thumb to the sensor does not breach privilege, reasoning from Saunders and Jalloh that a fingerprint exists independently of the suspect’s will. The Bundesgerichtshof reached the same result on 13 March 2025 in 2 StR 232/24, relying on §81b StPO and describing the body as a natural key, subject to a court order covering the phone search and a proportionality assessment.

SDP adds, in Germany and the Netherlands, a factor those states can obtain, on top of a factor they never could. It changes nothing for them. It is a problem only for jurisdictions that could already compel a passcode.

Command or manipulation?

The doctrinal line is not passcode versus biometric. It is whether the state orders the suspect to act or acts on the suspect’s body.

The American split is quite narrow. In United States v. Payne, 99 F.4th 495 9th Cir. 2024, officers took a parolee’s thumb and used it. The Ninth Circuit held the act non-testimonial: no cognitive exertion, like a blood draw. In Brown, the D.C. Circuit held a compelled thumbprint unlock testimonial and suppressed the results. The D.C. Circuit noted that in Payne police did not instruct the man to open his phone. In Brown an agent told him to, and compliance with the instruction was the testimonial act.

The implication is uncomfortable: under this reading American police are on safer ground applying more physical force, not less.

The same distinction appears in three other systems.

  • Germany: permitted because the suspect merely tolerates the measure.
  • Netherlands: permitted because it requires no active cooperation.
  • Belgium: art. 88quater draws the line in the statute. Under §2 an investigating judge cannot order the suspect to operate the system; under §1 the state can require access-enabling information from him, and after the 2020 rulings of the Court of Cassation and Constitutional Court can punish refusal.

Four jurisdictions lead to a single conclusion: the state may act on one’s body, but may not order one to act.

Touch ID is manipulation. You take the hand, press the finger, and it works whether or not the owner cooperates. Face ID is different. With Require Attention on, the default, Face ID needs open eyes directed at the device. A suspect who shuts their eyes cannot be overcome by force; they can only be told to open them, and being told to open them is the mode Brown found testimonial. On a Face ID iPhone with SDP active and an uncooperative owner, the second credential may be legally unavailable in some jurisdictions and physically unavailable in all of them.

The other jurisdictions

“No authority found” means my Google skills were not enough to find a decided case or express power. It does not point either way – just means I didn’t find a definite source.

Jurisdiction Passcode Biometric by order Biometric by force
United Kingdom Yes, RIPA s.49 notice Arguable under the s.56 definition of “key”; untested No authority found; no express power
France Yes, art. 434-15-2 Untested Art. 55-1 CPP covers identification prints, not unlocking; untested. See CJEU C-371/24, 19 March 2026
Australia Yes, s.3LA Yes, named in the provision Not addressed
New Zealand Yes, SSA s.130; separate border regime under Customs and Excise Act 2018 Probably within s.130 assistance Not addressed
Singapore Yes, CPC ss.39 and 40; CMA s.39A Probably within “assistance”; practice is to ask for the PIN No authority found
Hong Kong Yes, L.N. 27/2026 Yes, as reported Not addressed
Belgium Yes, art. 88quater §1 No, §2 excludes the suspect Likely permitted on §2 reasoning; untested
Germany No No Yes, BGH 2 StR 232/24
Netherlands No, art. 125k excludes the suspect No Yes, HR 9 February 2021
Canada No, R. v. Shergill 2019 ONCJ 54 No, OCJ 16 March 2026 Not addressed; the same reasoning points that way
United States Contested; foregone conclusion doctrine, circuit by circuit Contested; Brown Contested; Payne
India Split; Karnataka and Kerala for, Delhi CBI Special Court against Same split, same reasoning Kathi Kalu Oghad 1961 supports it; untested for phones

A note on Canada. Justice Trevor Brown of the Ontario Court of Justice refused a general warrant on 16 March 2026 that would have compelled a target to unlock devices by fingerprint or facial recognition, holding the biometric scan would violate the right to silence and protection against self-incrimination. It is trial-level authority. Bill C-370, which would create judicially authorised unlock orders with a ten-year maximum, is separately in play.

India treats passcode and biometric as one question, on the strength of Kathi Kalu Oghad 1961, which held physical specimens are not testimonial because they do not by themselves incriminate. Everyone else splits them; India mostly does not.

SDP relaxes at familiar locations. That creates an overlap: the place where SDP stands down is generally where you execute a search warrant.

Taking the phone back to the suspect’s kitchen table converts a two-credential problem into a one-credential problem. In the UK, France or Singapore that is the difference between a credential the state can lawfully compel and one for which it may have no mechanism. On-scene extraction at the residence becomes a matter of which law applies.

So, the geography caveats are:

  1. Check that your authority covers extraction on premises rather than seizure alone, and whether a later return requires fresh entry.
  2. “Require Security Delay: Always” is designed to close this route, and Apple does not document exactly what Always changes; test it on a matching build before planning around it.
  3. Apple has never documented the pairing check. Whether it follows the location rule rests on testing. Ours says it does. Keep your own notes current.

The clocks

Timing matters a lot; without a known passcode, nothing can be taken for granted.

  • AFU to BFU. One reboot and file keys are gone. Every method except a bootrom attack with a known passcode closes at that moment. The Inactivity Reboot feature that appeared in iOS 18.1 causes seized iPhones to restart themselves inside locked evidence rooms, apparently in 3 days.
  • Pairing records. 30 days since last use on iOS 11 and later. Invalid immediately after restart.
  • Security Delay. Biometric, one hour, second biometric. Applies to turning SDP off, changing Apple Account password, signing out, Reset All Settings.
  • Biometric availability. Face ID and Touch ID switch off after restart, after repeated failures, after a period without unlock, and after the SOS button combination. Thresholds change; confirm on the build in front of you.
  • Legal process. An assistance order, s.49 notice or warrant clause covering biometrics takes days. The reboot timer is 72 hours.

In every jurisdiction that requires judicial authorisation before a biometric can be taken, authorisation routinely arrives after the credential has expired. That access constraint exists because two systems were designed without reference to each other.

Real consent is limited in a way an order is not.

Someone who agrees to let you look at WhatsApp has not agreed to a full file system image containing the keychain, deleted records, location history, health data and every credential the device has stored. Most true consent cases are victims and witnesses, and a full extraction routinely takes far more than was asked for. Consent can be withdrawn, raising a question about an image already on your storage that most labs have no written answer to.

SDP sharpens this. Where the second credential cannot be compelled, cooperation becomes the only reliable route, and cooperation arrives with limits. The examiner ends up depending on the one form of authority that is scope-bound while using methods that respect scope least.

Record the agreed scope in the person’s own words before extraction, not after. Where the case allows, choose the method that matches the request; an advanced logical extraction that answers the question is better than a full file system image that answers it and forty others.

Where SDP is not part of the conversation

  • Any iPad. SDP is iPhone-only.
  • Anything before iOS 17.3, released 22 January 2024.
  • iOS 17.3 through 18.x, where SDP existed but was opt-in and rarely used. Check Settings.
  • checkm8-capable hardware, A11 and earlier. Bootrom acquisition happens below iOS, so iOS policy cannot gate it. The passcode is still needed to decrypt user data; legal questions remain.
  • Any case with a valid pairing record on a device that has not rebooted.

From iOS 26.4 onward, assume SDP is on until checked. Apple enables it on new setups, restores and updates from 26.4, and 26.4.1 extended it to enterprise and MDM-managed devices on 8 April 2026.

What we did about it

Pairing-free sideloading of the extraction agent shipped in iOS Forensic Toolkit 10.10. The agent installs over a developer-signed distribution path and communicates over a local network link, so no step depends on the USB pairing SDP guards. More on that: Bypassing Stolen Device Protection: Alternative Ways of Installing the Extraction Agent and Sideloading the extraction agent: a Stolen Device Protection workaround.

That removes the biometric requirement. It leaves untouched the passcode requirement, a paid Apple Developer account, physical handling of an unlocked device, and a device not locked down by MDM. It returns the case to a single credential and restores the match between what a s.49 notice or s.3LA order can compel and what the device asks for.

That is a narrow claim. It helps in jurisdictions that can compel a passcode. It does nothing for Germany, the Netherlands or Canada, because the credential they cannot obtain is the one still required. No tool changes that.

It also does not help the person SDP was built to stop. That threat model is specific: someone who watched you type your passcode in a bar, took the phone, and used those two facts to reset your Apple Account. A pickpocket does not enrol in the Apple Developer Program.

Checklist

  1. Record exact iOS build, SDP state and enrolled biometric type. Face ID and Touch ID are no longer equivalent.
  2. Record which credentials you have and how you obtained each one. Use notice, order number, warrant clause, conversation, not “consent”.
  3. If a biometric will be used, confirm authority covers it and confirm whether your jurisdiction distinguishes ordering the person from acting on them.
  4. Seize host computers in parallel. Preserve the lockdown directory. A pairing record is worth 30 days at most and nothing after reboot.
  5. Preserve AFU state. Faraday containment with pass-through power, documented chain of custody for power state. SDP requires Find My to be on and blocks turning it off, so a live wipe channel is guaranteed for as long as the device can reach a network.
  6. Consider extraction at a familiar location where authority allows it, and document location context as it happens.
  7. For a cooperating owner, arrange SDP state in advance and budget the hour if Security Delay is set to Always.
  8. For victim and witness devices, record agreed scope before extraction and check output against it.

Conclusion

SDP was designed against a thief in a bar, and it works against him. Its effect on lawful extraction is a side effect, and a lopsided one. Where the law lets the state compel a memorised code, SDP now asks for something the statute was never written to reach. Where the law protects the code absolutely, SDP asks for the one thing the state was already allowed to take, and changes nothing.

Two consequences follow. First, a device policy written in Cupertino now determines which national laws are effective, and the drafters did not consider that question. Second, the safest route to a biometric in USA, the country with the most developed case law, is to take it by force rather than ask for it. That is where the reasoning has led, and it is worth noticing before it becomes routine.

Finally, everything above is subject to change. Apple revises SDP without announcements, support pages have been edited more than once, and three legal positions changed between this article and the previous ones I wrote on compelled decryption.