Open · taking new casesMon–Fri 8a–6p67 FL countiesFlat fees, published
★★★★★Florida Bar member · 9 years
← The Probate Archive
Knowing it is not the same as being allowed to use it · 10-min read

The password problem

The most common digital estate plan in America is a spouse who knows the passwords. It fails on the two-factor code, it fails when the phone line is cancelled, and in the worst case it puts a grieving person on the wrong side of a felony statute.

Trustee & fee warsFlorida case
Macro photograph of a USB hardware security token used for two-factor authentication.
A hardware second factor. The password stopped being the lock some years ago; this is.
Tony Webster · Creative Commons Attribution 2.0 Generic (CC BY 2.0) · source
Florida's computer-crimes chapter
Ch. 815 · §815.06
Baseline offence under §815.06
Third-degree felony
Federal statutes in play
18 U.S.C. §1030 · 18 U.S.C. §2701
Chapter 740 on impersonation
Prohibited · §740.05(2)(d)
The safe harbour
§740.05(5) · authorised user

Ask a hundred people what their digital estate plan is and ninety of them will say some version of the same sentence. “My wife knows my passwords.” “It's all in a notebook in the desk.” “My son can get into everything.”

That is not a plan. It is three separate problems wearing one coat.

It fails technically, because the password is no longer the lock. It fails practically, because the thing that generates the second factor gets switched off in the first week. And it fails legally, because knowing a credential and being authorised to use it are different questions, and the second one is answered by a criminal statute.

The distinction the whole entry turns on
Access is not authority. Every computer-misuse statute in the United States — federal and state — is built around whether the person had authorisation, not around whether they had the password. A credential obtained lawfully and used without permission is the fact pattern those statutes were written for.
— The technical failure

The phone is the account now

For most of the accounts that matter, the password is one of two factors and it is the less important one.

The second factor is almost always tied to a physical device or a phone number: an SMS code, an authenticator app, a passkey held in a secure enclave, a hardware key on a keyring. A password without the device is a key without a keyhole.

Which produces the most common irreversible mistake families make in the month after a death. Somebody cancels the mobile line. It is a sensible-looking economy — the bill arrives, the person is gone, the account is closed. And with it goes every SMS verification code, every account-recovery route that runs through that number, and frequently the two-factor app itself if the phone is then wiped or sold.

Do not disconnect the number until the accounts are dealt with. Keep the phone charged, keep it unlocked if you lawfully can, and keep the line active. A few months of a mobile bill is the cheapest insurance in probate administration.

The other half of this is that the credential vault is usually excluded from the tools built for exactly this purpose. Apple's Legacy Contact documentation is explicit that a legacy contact does not receive “data stored in your iCloud Keychain (payment information, passwords, and passkeys).” Google's Inactive Account Manager releases an export of selected data, not credentials. A Facebook legacy contact never logs in at all. Every one of the online tools deliberately stops short of handing over the keys, which means the password problem survives all of them.

The east face of the Florida State Capitol in Tallahassee.
Tallahassee. Chapter 815 — Computer-Related Crimes — and Chapter 740's safe harbour were both written here.
Michael Rivera · Creative Commons Attribution-Share Alike 3.0 Unported (CC BY-SA 3.0) · source
— The legal failure

Three statutes, and one of them is a felony

This is the part that surprises people, and it should be said carefully: the ordinary case of a spouse logging into a dead partner's email is not one anybody is prosecuting. The risk here is not that a widow gets arrested. It is that the conduct sits on the wrong side of statutes that other parties — a hostile beneficiary, an employer, a litigation opponent, a platform's counsel — can point at, and that a fiduciary who does it has no defence if the access is later questioned.

Florida's chapter is Chapter 815, “Computer-Related Crimes.” §815.06 — “Offenses against users of computers, computer systems, computer networks, and electronic devices” — makes it an offence to willfully, knowingly, and without authorization or exceeding authorization access a computer, system, network or electronic device knowing that the access is unauthorised. The baseline violation is a third-degree felony, with second- and first-degree enhancements for damage above $5,000, fraud schemes, disruption of governmental or public services, or conduct endangering life.

Federally, the Computer Fraud and Abuse Act, 18 U.S.C. §1030, uses two phrases: acting “without authorization” and “exceeding authorized access.” In Van Buren v. United States, 593 U.S. 374 (2021) — decided June 3, 2021, 6–3, Barrett J. — the Supreme Court narrowed the second one. Exceeding authorised access means going into areas of a system that are off limits to you, not using access you legitimately have for a purpose the owner would dislike. That is a real and welcome narrowing. But the Court expressly did not resolve the “without authorization” clause, which is the clause that covers logging into an account that is not yours.

And on that clause the case law is less comfortable. In United States v. Nosal, No. 14-10037 (9th Cir., July 5, 2016), the Ninth Circuit held that a former employee who accessed a system using the password of a current employee — shared with her permission, but without the employer's — acted “without authorization.” The password was given freely. It was still unauthorised access, because the person entitled to authorise was not the person who handed over the credential.

Then the Stored Communications Act, 18 U.S.C. §2701, adds a separate offence for intentionally accessing without authorisation a facility through which an electronic communication service is provided, and thereby obtaining stored communications. This is the statute that made providers say no to grieving families for a decade, and it is why Chapter 740 is drafted as a consent mechanism rather than an override.

Put together: the credential is not the authority. The authority comes from the account holder's consent, or from a statute, or from a court.

— The Florida safe harbour

What Chapter 740 does and does not bless

Florida's Fiduciary Access to Digital Assets Act contains one sentence that solves a meaningful slice of this, and one that closes the rest.

§740.05(5) provides that a fiduciary with authority over the tangible personal property of a decedent, ward, principal or settlor has the right to access the property and any digital asset stored in it, and is an authorized user for the purpose of computer fraud and unauthorized computer access laws, including under chapter 815. That is a genuine statutory safe harbour. The personal representative who takes the decedent's laptop under §733.607 and opens it is an authorised user by operation of law, and §815.06 does not reach them.

§740.05(2) then draws the line. A fiduciary's authority over a digital asset is subject to the terms-of-service agreement except as §740.003 provides, is subject to other applicable law including copyright law, is limited by the scope of the fiduciary's duties, and — the clause that matters here — “may not be used to impersonate the user.”

Logging in as the deceased is impersonating the user. Even with the correct password. Even with the best intentions. Even where the decedent would obviously have wanted it. The statute gives a route, and the route is a written request to the custodian under §740.006 or §740.007 — not the login screen.

  • Opening the decedent's own device: authorised. §733.607 plus §740.05(5).
  • Reading files stored on that device: authorised. §740.05(5) reaches digital assets stored in the tangible property.
  • Logging into a remote account as the decedent: not authorised. §740.05(2)(d), and outside Chapter 740, the CFAA and the Stored Communications Act are in the frame.
  • Asking the custodian, in writing, with a death certificate and certified letters: the actual mechanism. §740.007 for the catalogue, §740.006 for content, §740.06 for the 60-day clock and the route to a circuit court order.
— The fix

What a properly drafted digital-assets clause says

The problem is solved by four things, and only one of them is a document.

  • A password manager with emergency access, configured. This is the single highest-value step, and it is not legal work. A named recovery contact, a waiting period you choose, and a vault that opens to them if you do not respond. It reaches every account, not just the three big ecosystems, and it hands over credentials that the legacy tools deliberately withhold.
  • The online tools set. Apple Legacy Contact, Google Inactive Account Manager, Facebook memorialisation. Under §740.003(1) an online-tool direction overrides a contrary instruction in a will, trust, or power of attorney. Ten minutes, and it outranks the rest of the plan.
  • Express consent in the will and the trust. Not “my executor may deal with my digital assets.” The clause has to give the personal representative express consent to disclosure of the content of electronic communications, because that is the specific thing §740.006 requires before a custodian will release content. Without those words the estate gets the catalogue under §740.007 and nothing more.
  • The express grant in the durable power of attorney. §740.008 requires the power of attorney to expressly grant the agent authority over the content of electronic communications. Florida's power-of-attorney statute does not supply that authority by default — it comes from Chapter 740, not Chapter 709 — so it has to be written in. A superb durable power of attorney drafted for banking does not reach the email unless somebody put the sentence in.

And one thing the clause must not do: contain the passwords. A Florida will is deposited with the clerk within 10 days of death under §732.901, and the probate file is a public court record. (The inventory under §733.604(1) is confidential and exempt; the will is not.) Credentials go in the password manager and the seed phrases go in a safe. The documents say that they exist and where, never what they are.

The honest summary of this entire entry: the password is the least durable part of the plan and the most dangerous part to rely on. Replace it with consent — recorded in a settings page, in a will, in a trust, and in a power of attorney — and the family never has to decide whether to guess.

— How it unfolded

Timeline

  1. 1984
    Congress enacts the Computer Fraud and Abuse Act, 18 U.S.C. §1030, built around the concepts of acting without authorization and exceeding authorized access.
  2. 1986
    The Stored Communications Act, 18 U.S.C. §2701 et seq., adds a separate offence for unauthorised access to stored electronic communications — and the rule that made providers refuse grieving families for a generation.
  3. Apr 2012
    United States v. Nosal, 676 F.3d 854 (9th Cir. en banc): “exceeds authorized access” does not reach mere violations of computer-use policies.
  4. Jul 5, 2016
    United States v. Nosal, No. 14-10037 (9th Cir.): a former employee who used a current employee's password — shared with her permission, but without the employer's — acted “without authorization.”
  5. Jul 1, 2016
    Florida's Chapter 740 takes effect. §740.05(5) makes a fiduciary with authority over tangible property an authorised user for purposes of chapter 815; §740.05(2)(d) forbids impersonating the user.
  6. Jun 3, 2021
    Van Buren v. United States, 593 U.S. 374: the Supreme Court narrows “exceeds authorized access” to accessing off-limits areas of a system — and expressly leaves the “without authorization” clause undecided.
  7. Dec 2021
    Apple ships Legacy Contact, documenting that a legacy contact does not receive iCloud Keychain data — payment information, passwords, and passkeys.
  8. 2026
    Passkeys and hardware-bound second factors continue to spread. Every one of them makes “my spouse knows my passwords” less of a plan than it was the year before.
— The teachable part

What actually went wrong

  • The phone line gets cancelled in week one. Every SMS second factor and most account-recovery routes go with it, and the loss is usually irreversible.
  • The password list is out of date. A notebook in a desk drawer is a snapshot of whatever was true the last time somebody updated it, and rotation, resets and new accounts make that a shrinking fraction of the total.
  • The credential is treated as the authority. Florida's §740.05(2)(d) forbids a fiduciary from impersonating the user, and the Ninth Circuit has held that using a password shared by someone who was not entitled to authorise it is access “without authorization.”
  • The legacy tools are assumed to include the passwords. They deliberately do not. Apple excludes the Keychain, Google exports data rather than credentials, and a Facebook legacy contact never logs in.
  • The documents are silent on content. Without the express consent §740.006 requires and the express grant §740.008 requires, the personal representative gets metadata and the agent gets nothing.
— The Florida answer

Would it have gone that way in Florida?

Florida's computer-crimes chapter is Chapter 815, and §740.05 tells you exactly where the line is: open the device, do not log in as the person.

The chapter number people ask for is 815 — “Computer-Related Crimes.” The operative section is §815.06, “Offenses against users of computers, computer systems, computer networks, and electronic devices,” which reaches conduct undertaken willfully, knowingly, and without authorization or exceeding authorization, with knowledge that the access is unauthorised. The baseline offence is a third-degree felony, escalating to second- and first-degree felonies where damage exceeds $5,000, where the access furthers a scheme to defraud, where governmental or public services are disrupted, or where human life is endangered.

Now the safe harbour, which is generous and specific. §740.05(5) provides that a fiduciary with authority over the tangible personal property of a decedent, ward, principal or settlor has the right to access the property and any digital asset stored in it, and is an authorized user for the purpose of computer fraud and unauthorized computer access laws, including under chapter 815. Read alongside §733.607, which gives the personal representative the right to take possession or control of estate property and preserve it, that is a clear statutory answer to the question every fiduciary asks: yes, you may take the laptop and open it.

And now the line. §740.05(2) subjects fiduciary authority to the terms of service, to other law including copyright, and to the scope of the fiduciary's duties — and provides that it may not be used to impersonate the user. Signing into a remote account as the decedent is impersonation, whatever the password situation. The device is yours to open; the account is the custodian's to disclose.

The mechanism Florida actually provides. For the catalogue — every institution the decedent corresponded with — §740.007 requires only a written request, a certified death certificate, and certified letters of administration. No consent record. For content, §740.006 requires the user's consent through an online tool or a record, or a court order, on top of the same documents. §740.06 gives the custodian 60 days and lets the fiduciary apply to a Florida circuit court for an order compelling compliance — an order that must include a finding that compliance does not violate 18 U.S.C. §2702. A custodian that complies in good faith is immune.

The drafting, in four places, and they must agree with each other. One: the online tools, because §740.003(1) makes a direction given through an online tool override a contrary instruction in a will, trust, power of attorney or other record. Two: the will — express consent to disclosure of the content of electronic communications to the personal representative, plus authority over digital assets generally. Three: the trust — the same consent language, plus authority to hold and administer digital assets; and note that where the trustee is the original user of an account, §740.01 requires the custodian to disclose everything with no further showing, which is a strong argument for opening accounts in the trustee's name. Four: the durable power of attorney — the express grant of authority over the content of electronic communications that §740.008 demands, which Florida's Chapter 709 does not supply by default.

The honest caveat. None of this creates a right the decedent did not have. §740.004(2) says so: no new or expanded rights beyond those held by the user. A non-transferable licence stays non-transferable, a self-custodied private key stays lost, and a platform with no US presence stays out of reach.

Do this, in this order. Set up emergency access in a password manager and name a real person — that is the only mechanism that covers every account rather than three ecosystems. Set the online tools so tier one is not empty. Get the §740.006 consent language and the §740.008 grant into the will, the trust, and the power of attorney. Keep a one-page list of what exists and where the access material is kept, stored with the estate documents and never inside the will, because the will becomes a public court filing under §732.901. And tell whoever will be handling this not to cancel the mobile phone line. That last one is free, and it saves more estates than the other four combined.

— The statutes doing the work
Florida's computer-crimes offence: willful, knowing access without or exceeding authorization. Third-degree felony at baseline.
The safe harbour. A fiduciary with authority over tangible property may access it and any digital asset stored in it, as an authorised user for purposes of chapter 815.
The line. Fiduciary authority may not be used to impersonate the user.
Content of a deceased user's communications — needs the user's recorded consent or a court order.
Agent under a power of attorney: content requires an express grant of authority over the content of electronic communications.
Personal representative's right to take possession or control of estate property — including the devices.
The Computer Fraud and Abuse Act. Van Buren (2021) narrowed “exceeds authorized access” and left “without authorization” open.
Stored Communications Act — unauthorised access to stored electronic communications. The reason Chapter 740 is built on consent.
— Common questions

What people ask us about this.

Chapter 815, “Computer-Related Crimes.” The section that matters here is §815.06, which reaches willful and knowing access to a computer, system, network or electronic device without authorization or exceeding authorization, with knowledge that the access is unauthorised. The baseline offence is a third-degree felony.
In the public record
The west front of the United States Supreme Court Building in Washington, D.C.
2012
Washington, D.C. Van Buren narrowed “exceeds authorized access” in 2021 — and left “without authorization” alone.
Architect of the Capitol / USCapitol · Public domain (PD-USGov — Architect of the Capitol)
— Show your work

Sources

  1. Fla. Stat. §815.06 — Offenses against users of computers, computer systems, computer networks, and electronic devicesThe Florida Senate
  2. Fla. Stat. §740.05 — Fiduciary duty and authorityThe Florida Senate
  3. Fla. Stat. §740.006 — Disclosure of content of electronic communications of deceased userThe Florida Senate
  4. Fla. Stat. §740.008 — Disclosure of content of electronic communications of principalThe Florida Senate
  5. Van Buren v. United States, 593 U.S. 374 (2021)Supreme Court of the United States, Jun 2021
  6. United States v. Nosal, No. 14-10037 (9th Cir. Jul 5, 2016)U.S. Court of Appeals for the Ninth Circuit
  7. 18 U.S.C. §1030 — Fraud and related activity in connection with computersCornell Legal Information Institute
  8. 18 U.S.C. §2701 — Unlawful access to stored communicationsCornell Legal Information Institute
  9. How to add a Legacy Contact for your Apple AccountApple Support
These are not our cases. Everything on this page is drawn from published court records and news reporting, cited below. It is general information about how probate and trust law works — not legal advice, and not a prediction about any case. Reading it does not create an attorney-client relationship. Other states' law differs from Florida's, which is usually the whole point of the story.
— Your estate is not a headline

Free 30-minute consult. Plain English. No pressure.

Nearly every case in this archive turned on something ordinary — an unwitnessed page, a stale beneficiary line, a document nobody could find. Those are cheap to fix while you're alive and expensive to fix afterward.