Decrypting — AES, DES & Motorola ADP on P25 (Scanners) · Volume 6
Decrypting — Vol 6: The Law and the Public-Access Debate
Why you may listen, why they may encrypt, and the fight over what taxpayers are entitled to hear
6.1 About this volume
This is the question that follows once the technical dust settles, and it’s a fair one: taxpayers pay for these agencies, so why is it legal for a police department to lock the public out of the radio it bought — and why is it the listener who would be breaking the law by decoding it? It’s a genuinely good question, and it deserves a real answer rather than a shrug. The honest answer has two halves that people tend to run together. There’s the law as it actually is, which is fairly settled and not really in dispute. And there’s the policy fight over what the law should be, which is very much live, with bills moving through statehouses right now. This volume keeps those two halves separate, because most of the frustration on this topic comes from mistaking one for the other.
The legal parts are a careful reading of the statutes and the reporting, not legal advice. But the shape of it is clear enough, and it’s worth understanding whichever side of the debate one lands on.
6.2 Why it’s legal to listen at all
Start with the thing people find surprising: there is no general “right to listen” to the radio in American law. What there is instead is a specific carve-out in the federal wiretap statute that makes it lawful to receive certain radio communications, and public-safety voice sits squarely inside it. The Electronic Communications Privacy Act generally forbids intercepting electronic communications, but 18 U.S.C. §2511(2)(g)(ii) makes it lawful “to intercept any radio communication which is transmitted … by any governmental, law enforcement, civil defense, private land mobile, or public safety communications system, including police and fire, readily accessible to the general public.” That clause is the reason scanning your local police and fire is legal.
Everything then turns on that last phrase — “readily accessible to the general public” — and the statute defines it, at 18 U.S.C. §2510(16), in a way that puts encryption first on the list of disqualifiers. A radio communication is not readily accessible to the general public if it is, among other things, “scrambled or encrypted.” So the very same statute that permits listening to the clear channel defines the encrypted channel as not something the public is permitted to access. That is the whole legal mechanism in one move: encryption doesn’t just technically lock the listener out, it moves the traffic into a legal category the listening exception was written not to cover.
Two older threads round this out. The Communications Act of 1934, at 47 U.S.C. §605, has long said that a person who receives a radio communication generally may not “divulge or publish” its contents — which is why the traditional rule is that listening to a scanner is fine, but broadcasting what you heard can be a separate problem. And federal penalties are structured leniently for the hobbyist: a private, non-commercial listener who merely receives an unscrambled radio signal is, at most, looking at a minor violation, not the felony that attaches to serious interception. The practical upshot for a scanner owner has been the same for decades: listen to what’s open, don’t decrypt what’s closed, and be careful about republishing what you hear.
One more wrinkle that trips people up: state law. Federal law makes home listening lawful, but a number of states layer on their own restrictions — usually on using or carrying a scanner in a vehicle, or using one in the commission of a crime, rather than on listening as such. Florida and Indiana are commonly cited examples of the in-vehicle-and-a-crime pattern. Michigan has an old provision that gets badly misdescribed on aggregator sites; the practical lesson is to read the relevant state’s actual statute rather than a summary, because the details vary and the summaries are often wrong.
6.3 Why an agency is allowed to lock you out
Here is the part that surprises people the other direction: no federal law requires public-safety radio to be open. Agencies license their systems under the FCC’s Part 90 rules and run them as their own operations, and nothing compels them to leave the public a way in. If anything, the one firm federal encryption rule cuts against openness only on shared channels — the FCC prohibits encrypting the designated interoperability and mutual-aid calling channels, precisely so responders from different agencies can always reach each other. There is no matching rule that says the rest must stay in the clear. Openness, historically, was a side effect of the technology being analog and unencryptable, not a legal guarantee.
So when agencies started encrypting, they were exercising authority they’d always had. The justifications they give are officer and tactical safety, and — increasingly the decisive one — privacy of the personal data that flows over the radio. This last driver is worth understanding, because it’s the real engine behind the recent wave, and it’s more defensible than “the police just want secrecy.” When a dispatcher runs a name, a plate, or a driver’s license over the air, that pulls personally identifiable information and criminal-history data out of state and federal law-enforcement databases, and the FBI’s CJIS Security Policy requires that kind of data to be protected in transit. Broadcasting it in the clear is, arguably, its own privacy violation against the citizens whose data it is.
The clearest single document in the whole debate is California’s. In October 2020 the California Department of Justice issued Information Bulletin 20-09-CJIS, on the confidentiality of information from the state’s law-enforcement telecommunications system (CLETS). It told agencies that access to certain criminal-justice and personally identifiable information “must be limited to authorized personnel; and the transmission of such information must be encrypted,” and that this was “particularly relevant to the radio transmission of protected data.” Crucially, it did not order full encryption. It offered a choice: encrypt the radio traffic, or “establish policy to restrict dissemination of specific information … while allowing for radio traffic with the information necessary to provide public safety.” Agencies had until the end of 2020 to file a plan. Many read that choice and picked blanket encryption as the simplest way to comply — which is exactly what lit the transparency fire, because a mandate to protect a citizen’s driver’s-license number got turned, in practice, into silence on the whole channel.
6.4 The wave: how it got here
The move from analog-open to digital-encrypted has been playing out for about a decade, and it accelerated sharply after 2020. Aurora and then Denver, Colorado encrypted around 2019; Hennepin County, Minnesota did the same that year. After California’s 2020 CLETS bulletin, a wave of California agencies followed. Some went to a hybrid model instead of full encryption — San Francisco, reportedly around mid-2021, kept a public dispatch channel while moving the sensitive database lookups to a separate encrypted channel. Chicago encrypted its police radio zone by zone through 2022 and 2023, offering the public only a single delayed audio feed (reported as a 30-minute delay). Minneapolis went fully encrypted in 2025. These are secondary reports and the exact dates shift depending on the source, so they should be held loosely — but the direction is unmistakable, and it’s toward closed.
6.5 The debate: “we paid for it”
Now the policy argument, stated fairly, because it’s a serious one. The case for public access runs roughly like this: public-safety agencies are funded by taxpayers and act in the public’s name; a free press has historically relied on scanner monitoring to cover breaking news, hold agencies accountable, and warn communities in real time; and a government that can conduct its street-level operations entirely in secret, with no independent real-time window, has lost a meaningful check. On this view, full encryption trades a real and longstanding public good — transparency and press access — for a privacy problem that could be solved more narrowly, by encrypting only the channels that carry personal data while leaving routine dispatch open.
The counter-argument is the one the agencies make: officer safety when a suspect or a bystander can hear the tactical plan in real time; the genuine privacy interest of citizens whose data crosses the radio; and the operational reality that maintaining a hybrid system, with dispatchers correctly sorting sensitive from routine on the fly, is harder and more error-prone than just encrypting everything. Both sides are describing real costs. What makes it a hard problem, rather than an obvious one, is that the cheapest way for an agency to protect the one citizen’s PII is the way that shuts out every other citizen’s access.
The press-freedom organizations have taken this up directly. The Radio Television Digital News Association made encryption its signature advocacy issue, arguing that it harms transparency and the public’s access to information. The Reporters Committee for Freedom of the Press has tracked the trend and pushed the middle-ground model — encrypt only the PII and tactical channels, keep dispatch open, or give credentialed media a delayed feed or a decryption arrangement — while candidly acknowledging the hard question hiding inside “credentialed media”: who counts, and who decides. The Reporters Committee also states the legal reality plainly, and it’s the same one this volume keeps landing on: there is no federal law requiring public access to police radio.
6.6 What’s actually being tried
Because there’s no existing right to fall back on, the fight is legislative, state by state, and it’s genuinely active. A representative sampling of what’s been attempted:
- California SB 1000 (2022), from Senator Josh Becker, would have required agencies to protect confidential information while restoring public access — through an encrypted media side-channel, a data terminal, or a phone arrangement — with a 2024 compliance date. It passed the state Senate but died in the Assembly’s appropriations committee in August 2022, on cost grounds.
- California SB 719 (2023), also Becker, was the narrower successor, aimed at guaranteeing real-time access to credentialed media with carve-outs for tactical and undercover operations. Its final outcome could not be confirmed, so none is stated here.
- Colorado HB21-1250 (2021) folded in a provision requiring fully-encrypted agencies to adopt a “communications access policy” giving local news media access to primary dispatch — though reporting a year later found agencies still without media agreements in place.
- Illinois HB 4339 (2024) would require encrypting agencies to give real-time access to FCC-licensed broadcasters and newspapers; as of this writing it had not been enacted, and it drew criticism both for being media-only and for lacking an enforcement mechanism.
- New York (2025) passed a bill through its legislature to require departments to grant journalists and emergency-services organizations access to encrypted radio, with an exemption for sensitive traffic; it went to the governor. Whether it was signed could not be confirmed.
The pattern across all of these is telling. Every one of them tries to carve out access for the press specifically — not for the general public, and certainly not a right to decrypt for anyone with a scanner. That’s a realistic read of where this is going: if broad access comes back, it will likely come back as a negotiated, credentialed, possibly delayed arrangement for news organizations, not as a return to the days when anyone with a $30 scanner heard everything live.
6.7 Is there a right to listen?
Put directly: no court has recognized a First Amendment or other legal right for the public to monitor police radio in real time. The First Amendment protects the right to record police officers in public — a well-established and important doctrine — but that’s a different thing from a right to intercept their communications, and the two don’t cross over. A search for litigation that established a public right to listen, or that successfully challenged an agency’s decision to encrypt, found no court that has recognized one, and no such case is cited here.
What the public does have is the records path, and it’s worth not overlooking, because it’s the access that actually exists. Public-records law — the federal Freedom of Information Act and the state equivalents — generally reaches recordings and logs after the fact: dispatch (CAD) records, radio recordings, body-camera footage. That access is real, but it’s bounded: it comes after the event, not in real time, and it’s subject to investigatory, privacy, and safety exemptions that agencies use freely. So the accurate summary of what taxpayers are entitled to is this: not a right to decrypt, and not a right to listen live, but a qualified right to obtain records of what happened, after it happened, through the records laws — plus whatever real-time access the policy fights described above manage to win back.
6.8 Weighing the trade-off
The law and the policy question are best kept clearly apart. As a matter of law, the current arrangement is coherent even if it is frustrating: encryption is lawful, no one is required to leave the channel open, and the listening exception was written to cover what is already in the clear, not to force anything open. As a matter of policy, the positions described above converge on a middle ground. Most advocacy — from the press-freedom organizations to the bills that have actually been drafted — lands on the hybrid model: encrypt the channels that carry a citizen’s personal data, which has a genuine claim not to be broadcast, and keep routine dispatch open, preserving real-time public and press oversight of emergency services. The critique of blanket encryption is that it solves a narrow privacy problem by giving up a broad public good, largely because the narrow solution is more work; the agencies’ answer is that the narrow solution is harder to operate reliably. The legislative pushback is an attempt, so far imperfect, to force the narrower solution.
That is a question of what the law should be, not what it is. What it is, today, is what this dive has described: the clear channel is open to the listener, the encrypted one is not the listener’s to break, and the path back to openness runs through statehouses and records requests, not through a scanner or an SDR.
Glossary
A compact index of the terms used across this dive:
- ADP — Advanced Digital Privacy. Motorola’s proprietary 40-bit RC4 encryption; ALGID 0xAA; the weakest option (Vol 2).
- AES-256 — Advanced Encryption Standard, 256-bit key; ALGID 0x84; the federal P25 standard, with no practical break (Vol 2).
- ALGID — Algorithm ID. The 8-bit clear-text value naming which cipher a transmission uses.
- CJIS — the FBI’s Criminal Justice Information Services and its Security Policy, which requires protecting PII/criminal-history data in transit — a main driver of encryption.
- DES — Data Encryption Standard, 56-bit; ALGID 0x81; broken since the 1990s, legacy only.
- ENC — the indicator a scanner shows for an encrypted, un-decodable transmission.
- ESS — Encryption Sync. The clear-text ALGID/KID/MI a receiver reads before decrypting.
- KEK — Key Encryption Key. A key used only to wrap other keys for safe delivery (Vol 3).
- KID — Key ID. The 16-bit clear-text value naming which key to use — not the key itself.
- KVL — Key Variable Loader. The device that loads keys into a radio over a cable (Vol 3).
- MI — Message Indicator. The 72-bit clear-text initialization vector that seeds the keystream.
- OFB — Output Feedback. The mode P25 block ciphers run in, generating a keystream XORed against the voice.
- OTAR — Over-The-Air-Rekeying. Distributing/updating keys remotely from a Key Management Facility (Vol 3).
- TEK — Traffic Encryption Key. The working key that actually encrypts voice.
Sources
- 18 U.S.C. §2510(16), definition of “readily accessible to the general public”: https://www.law.cornell.edu/uscode/text/18/2510
- 18 U.S.C. §2511 (the interception statute and its §2511(2)(g) exceptions): https://www.law.cornell.edu/uscode/text/18/2511
- 47 U.S.C. §605, Communications Act (receive vs. divulge/publish): https://www.law.cornell.edu/uscode/text/47/605
- RTDNA, on §605 and police scanners (listening vs. divulging): https://www.rtdna.org/use-of-information-from-police-scanners
- California DOJ Information Bulletin 20-09-CJIS, Confidentiality of Information from CLETS (Oct. 12, 2020) — the load-bearing “why agencies encrypt” document: https://www.oag.ca.gov/sites/all/files/agweb/pdfs/info_bulletins/20-09-cjis.pdf
- FCC, public-safety licensing (Part 90; agencies control their own systems): https://www.fcc.gov/public-safety-licensing
- Reporters Committee for Freedom of the Press, on the police-radio-encryption trend and model policies: https://www.rcfp.org/police-radio-encryption-trend/
- RTDNA, “Why radio encryption is RTDNA’s biggest issue in 2023”: https://www.rtdna.org/news/why-radio-encryption-is-rtdnas-biggest-issue-in-2023
- Colorado Freedom of Information Coalition, on Colorado encryption and HB21-1250: https://coloradofoic.org/a-year-after-the-legislature-passed-a-law-on-police-radio-encryption-denver-area-news-outlets-are-still-blocked-from-listening/
- California SB 1000 (2022) coverage (Senate passage; death in committee): https://www.paloaltoonline.com/news/2022/05/26/senate-approves-beckers-bill-to-limit-police-radio-encryption/ · https://www.pleasantonweekly.com/news/2022/08/12/state-bill-on-police-radio-encryption-dies-in-committee/
- Illinois HB 4339 (2024) coverage: https://cwbchicago.com/2024/01/newspapers-broadcast-news-outlets-would-get-live-access-to-scrambled-police-radio-traffic-under-proposed-illinois-law.html
- New York (2025) media-access bill coverage: https://www.police1.com/communications/new-york-legislators-vote-to-preserve-media-access-to-encrypted-police-radio-communications
Comments (0)