People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume.
Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason.
Wiping is obviously extremely suspicious and asking for trouble
"Wiping is obviously extremely suspicious and asking for trouble"
It's sad this is the default view. It's his device, his data, his life on that phone. If he had wiped the phone before the interrogation it wouldn't be a problem. How long before? A second before? A week before? But wiping the data a minute later is suddenly asking for trouble.
I don't like it and I wish we had more privacy, but realistically there is no such "right".
If you're going to be in a situation where you're in a room with some goons backed by the full power of the state, it is what it is.
Maybe because I'm not American I don't have any hangups about seeing the US government this way, but my own government is no different - you can (and people have) get stopped at Heathrow, taken to a dimly lit backroom and given a going over for hours
I don't know that there is case law on this but I imagine that "prior to the admissibility inspection" is likely to be treated differently from "during the admissibility inspection" or "during administrative detention or secondary inspection" (or "in response to a request or question by a border agent"!).
Edit: a bigger picture question is the difference between things that may be legally punishable and things that may cause suspicion from CBP agents, which aren't the same thing at all.
it seems to me that if you give them a password to unlock the phone and when it unlocks it has been wiped that will cause problems whether it is the password that causes the wiping or not?
A US citizen has an almost unlimited right to enter the USA. The border search rule permits officials to search for things that are illegal to import. A blank phone is not illegal to import.
A non-citizen who arrives with a blank phone might be denied entry because it seems suspicious.
well OK, luckily my checking of media informs me no citizens have been stopped and held in custody by immigration without due process or any particular grounds, especially recently, so it all sounds good.
We noted in the border search guide that lying to the agents in response to their questions is potentially a crime in its own right (even if it's not done in order to hide anything illegal). We thought that this made hidden volumes quite tricky, particularly if one's intent was to pretend to comply with a question or request while actually not complying.
Sure - but the point is, if you're instructed by the officer to enter a password so they can inspect your device, and you enter a fake password and show them a fake version of your data, that could easily be found later to constitute a lie and lead to serious legal trouble.
They can't compel you, no. However, they can ask you to do so, and if you enter a privacy password that shows them something other than your real device (which is what this thread was about), you can very likely be faced with charges of obstruction of justice or even perjury. The point was that it's better to simply refuse, and accept the consequences of that, rather than trying to use technical means to trick them or to wipe data.
Note that if you're not a citizen of the USA, refusing to comply with a request like this is very likely to have you sent back to your country and denied access to the USA forever. While they can't legally force you to comply, they can absolutely deny you entry for any reason like this, regardless of having a valid visa and everything else in order. This even applies to legal residents.
If you want to gamble on that, that's your prerogative. But if they suspect you did this, computer forensics techniques can easily reveal this, especially if the rest of the data on the device is recoverable to you as well.
Edit to add: beyond forensics, they can also simply ask you to enter the other password, to prove that the account you showed them first was the right one.
Not enough, e.g. when crossing the Russian border (even as a citizen) your phone can be connected via USB to a device that uses exploits and whatnot to download all of the data. Surely US border guard can do something similar.
And using encryption will only make you more suspicious, and may be a reason to get jail time until the situation is "cleared up" one way or another (e.g. by getting even more jail time).
Only a second phone works, if you can make it seem like a device you're actually using (though also not a silver bullet as e.g. a lot of messenger metadata is available to governments and border control can physically coerce you to log in to your real accounts)
Problem is „are you sure you marked for deletion all the correct things” because you could have already deleted it before traveling or moved to other device you don’t travel with.
Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem.
Ideally you would like to have all wiped just in case but then you really stand out…
That's a more risky strategy. What if you added new files since the last time you updated the deletion profile? It's also technically more challenging. You have to think about what might be in RAM, caches, backups, etc.
The good thing about a total wipe is that it's very easy to implement, and it's hard for it to go wrong. You just encrypt the whole drive and, when you want to wipe it, erase the key.
Yes, this also has the advantage of speed perhaps. I can see, deleting specific apps (and their data) as thing #1, and thing #2 would be certain directories. Of course, the problem is, are icons going to be vanishing off the home screen, when the agent is looking at it? Or will the unlock -> screen coming on, be super slow?
Of course the problem there is, many people have an app store installed, and app stores have histories. And logs. And "what you used to have installed" is so easily found under Google Play, for example.
As someone else said in this thread, the law isn't code. It's not if-then statement based. It's also predicated upon intent in many cases. What actions did a person take, and why, when told to (for example) unlock their phone.
The problem here is that if you are asked to unlock your phone, any action you take to thwart that request by "trickery" to get data deleted, could be construed as 'deleting evidence'. So while some methods might make it more difficult for the border agent to realise "something happened", if they're suspicious still, then you're still in hot water.
In the eyes of the law, the court, and likely the jury, you've done a sneaky thing to thwart evidence collection.
The only safe method is a full wipe prior to travel. In this manner, you're not deleting evidence when told to hand it over. It's an entirely different bar. They can be cruel about it, and take your phone for a few months, but you're not going to be in legal hot water.
In as no one will see the phone is wiped until you are compelled to unlock it, there's no greater change of the phone being seized. You're already being investigated. Just be blunt, say "Whenever I travel, I just wipe it", and that's that.
This is why it's a shame that GrapheneOS has no viable backup solution. Its build in method is unreliable, and doesn't work very well, and is gitchy, it's a very well known problem.
And Android and ADB sometimes have issues with large backups of directories, and so you have to manage that with tar + stream and other business, but at least working around that is easy.
But if you could backup individual apps and all their data, you could uninstall all your privacy laden stuff, cross the border, and reinstall in minutes.
That's the true, legal way to travel safely. Especially if the app removal resulted in a 'shred' of the data files instead of delete.
If anyone has ever struggled with large data backup/restore, here's the only real method I've found for copying large swaths of files from/to via adb:
Note that in the USA and a few other jurisdictions, I believe there is now a recognized possibility for the border agents to ask for access to your social media, so even wiping the phone, or even traveling without a phone, is not entirely safe.
As far as facts go I was thinking of this one case:
... where I seemed to recall it was a social media post, but it is unclear whether it's private messaging, public social media, or private messaging under a public social media account.
[EDIT] according to [1] it was on WhatsApp with a U.S national.
My understanding is that refusal to provide social media accounts, or passwords to devices, or passwords to social media accounts, can be considered suspicious in its own right and ground to be held in custody for further exam, and/or denied entry; foreigners do not get to have the same "give password" == "right to not incriminate yourself" that U.S of A. citizen have. In doubt I would assume I don't.
Yes, as a foreigner there is no such thing as a right to enter the USA - the CBP agents can refuse you entry for any reason whatsoever and you have no recourse (they could be breaking various laws of their own and face personal liability for their own actions, of course, such as if they were seeking a bribe from you - but that doesn't give you any right to sue over their refusal to admit you). The only exception is asylum seeking, where there is a legal right for your asylum case to be heard.
Yes I thought this was the standard solution?
People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume.
Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason.
Wiping is obviously extremely suspicious and asking for trouble
"Wiping is obviously extremely suspicious and asking for trouble"
It's sad this is the default view. It's his device, his data, his life on that phone. If he had wiped the phone before the interrogation it wouldn't be a problem. How long before? A second before? A week before? But wiping the data a minute later is suddenly asking for trouble.
I don't like it and I wish we had more privacy, but realistically there is no such "right".
If you're going to be in a situation where you're in a room with some goons backed by the full power of the state, it is what it is.
Maybe because I'm not American I don't have any hangups about seeing the US government this way, but my own government is no different - you can (and people have) get stopped at Heathrow, taken to a dimly lit backroom and given a going over for hours
I don't know that there is case law on this but I imagine that "prior to the admissibility inspection" is likely to be treated differently from "during the admissibility inspection" or "during administrative detention or secondary inspection" (or "in response to a request or question by a border agent"!).
Edit: a bigger picture question is the difference between things that may be legally punishable and things that may cause suspicion from CBP agents, which aren't the same thing at all.
it seems to me that if you give them a password to unlock the phone and when it unlocks it has been wiped that will cause problems whether it is the password that causes the wiping or not?
A US citizen has an almost unlimited right to enter the USA. The border search rule permits officials to search for things that are illegal to import. A blank phone is not illegal to import.
A non-citizen who arrives with a blank phone might be denied entry because it seems suspicious.
well OK, luckily my checking of media informs me no citizens have been stopped and held in custody by immigration without due process or any particular grounds, especially recently, so it all sounds good.
We noted in the border search guide that lying to the agents in response to their questions is potentially a crime in its own right (even if it's not done in order to hide anything illegal). We thought that this made hidden volumes quite tricky, particularly if one's intent was to pretend to comply with a question or request while actually not complying.
IANAL but I think while lying to some questions might lead to obstruction charges, not answering is simply exercising the right to remain silent.
Sure - but the point is, if you're instructed by the officer to enter a password so they can inspect your device, and you enter a fake password and show them a fake version of your data, that could easily be found later to constitute a lie and lead to serious legal trouble.
I'm pretty sure they can't compel you to enter a password.
They can't compel you, no. However, they can ask you to do so, and if you enter a privacy password that shows them something other than your real device (which is what this thread was about), you can very likely be faced with charges of obstruction of justice or even perjury. The point was that it's better to simply refuse, and accept the consequences of that, rather than trying to use technical means to trick them or to wipe data.
Note that if you're not a citizen of the USA, refusing to comply with a request like this is very likely to have you sent back to your country and denied access to the USA forever. While they can't legally force you to comply, they can absolutely deny you entry for any reason like this, regardless of having a valid visa and everything else in order. This even applies to legal residents.
How would they discover you entered a wrong password?
If you want to gamble on that, that's your prerogative. But if they suspect you did this, computer forensics techniques can easily reveal this, especially if the rest of the data on the device is recoverable to you as well.
Edit to add: beyond forensics, they can also simply ask you to enter the other password, to prove that the account you showed them first was the right one.
They can't, but that will put you in another "suspicious" bucket.
Not enough, e.g. when crossing the Russian border (even as a citizen) your phone can be connected via USB to a device that uses exploits and whatnot to download all of the data. Surely US border guard can do something similar.
And using encryption will only make you more suspicious, and may be a reason to get jail time until the situation is "cleared up" one way or another (e.g. by getting even more jail time).
Only a second phone works, if you can make it seem like a device you're actually using (though also not a silver bullet as e.g. a lot of messenger metadata is available to governments and border control can physically coerce you to log in to your real accounts)
Or that just selectively wipes only stuff you have marked for deletion. That way the profile stays up to date and believable.
Problem is „are you sure you marked for deletion all the correct things” because you could have already deleted it before traveling or moved to other device you don’t travel with.
Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem.
Ideally you would like to have all wiped just in case but then you really stand out…
That's why you do it the other way round: you mark things that you don't want deleted.
That is not really making any difference if you can prepare beforehand
and
you can’t be sure which things can get you in trouble.
It does make a difference: you only mark enough to be kept to make your phone looks like it's in use, as opposed to obviously wiped.
By default, new material will be deleted. So you don't have to prepare again and again.
> you can’t be sure which things can get you in trouble.
When in doubt, don't mark it as keep.
That's a more risky strategy. What if you added new files since the last time you updated the deletion profile? It's also technically more challenging. You have to think about what might be in RAM, caches, backups, etc.
The good thing about a total wipe is that it's very easy to implement, and it's hard for it to go wrong. You just encrypt the whole drive and, when you want to wipe it, erase the key.
Obviously, you'd go the other way round and marks things that you don't want deleted.
Deleted stuff can easily be recovered. I think the full clean will remove the encryption keys hence making it unrecoverable.
Yes, this also has the advantage of speed perhaps. I can see, deleting specific apps (and their data) as thing #1, and thing #2 would be certain directories. Of course, the problem is, are icons going to be vanishing off the home screen, when the agent is looking at it? Or will the unlock -> screen coming on, be super slow?
Of course the problem there is, many people have an app store installed, and app stores have histories. And logs. And "what you used to have installed" is so easily found under Google Play, for example.
As someone else said in this thread, the law isn't code. It's not if-then statement based. It's also predicated upon intent in many cases. What actions did a person take, and why, when told to (for example) unlock their phone.
The problem here is that if you are asked to unlock your phone, any action you take to thwart that request by "trickery" to get data deleted, could be construed as 'deleting evidence'. So while some methods might make it more difficult for the border agent to realise "something happened", if they're suspicious still, then you're still in hot water.
In the eyes of the law, the court, and likely the jury, you've done a sneaky thing to thwart evidence collection.
The only safe method is a full wipe prior to travel. In this manner, you're not deleting evidence when told to hand it over. It's an entirely different bar. They can be cruel about it, and take your phone for a few months, but you're not going to be in legal hot water.
In as no one will see the phone is wiped until you are compelled to unlock it, there's no greater change of the phone being seized. You're already being investigated. Just be blunt, say "Whenever I travel, I just wipe it", and that's that.
This is why it's a shame that GrapheneOS has no viable backup solution. Its build in method is unreliable, and doesn't work very well, and is gitchy, it's a very well known problem.
And Android and ADB sometimes have issues with large backups of directories, and so you have to manage that with tar + stream and other business, but at least working around that is easy.
But if you could backup individual apps and all their data, you could uninstall all your privacy laden stuff, cross the border, and reinstall in minutes.
That's the true, legal way to travel safely. Especially if the app removal resulted in a 'shred' of the data files instead of delete.
If anyone has ever struggled with large data backup/restore, here's the only real method I've found for copying large swaths of files from/to via adb:
and to restore Or something similar.Note that in the USA and a few other jurisdictions, I believe there is now a recognized possibility for the border agents to ask for access to your social media, so even wiping the phone, or even traveling without a phone, is not entirely safe.
As far as facts go I was thinking of this one case:
... where I seemed to recall it was a social media post, but it is unclear whether it's private messaging, public social media, or private messaging under a public social media account.
[EDIT] according to [1] it was on WhatsApp with a U.S national.
My understanding is that refusal to provide social media accounts, or passwords to devices, or passwords to social media accounts, can be considered suspicious in its own right and ground to be held in custody for further exam, and/or denied entry; foreigners do not get to have the same "give password" == "right to not incriminate yourself" that U.S of A. citizen have. In doubt I would assume I don't.
[0]: https://www.lemonde.fr/en/international/article/2025/03/20/f...
[1]: https://www.lemonde.fr/international/article/2025/03/22/le-r...
Yes, as a foreigner there is no such thing as a right to enter the USA - the CBP agents can refuse you entry for any reason whatsoever and you have no recourse (they could be breaking various laws of their own and face personal liability for their own actions, of course, such as if they were seeking a bribe from you - but that doesn't give you any right to sue over their refusal to admit you). The only exception is asylum seeking, where there is a legal right for your asylum case to be heard.
Or travel with a diary containing a post-it note labelled "p4sswd"
[dead]