It sounds like they suspect the files were downloaded directly to the external drive, perhaps there's a pointer in a log file or something with the path. Clearly they haven't proven that, hence their wish to inspect the decrypted drive.
IMHO, if they really wanted to charge him and take him to trial, they have plenty of evidence. I doubt a jury would be sympathetic to the "I forgot my password" argument and the logic would be that if the files _were not_ on the external drive then he would willingly decrypt it to prove as much.
IMHO, if they really wanted to charge him and take him to trial, they have plenty of evidence. I doubt a jury would be sympathetic to the "I forgot my password" argument and the logic would be that if the files _were not_ on the external drive then he would willingly decrypt it to prove as much.