I don't agree with all this and this increasingly fascist regime but... this was the most predictable outcome. Consider these two scenarios.

1. You factory reset your phone before entering the US and give it to CBP blank. There's nothing to find;

2. You have a self-destruct PIN like this guy did and give it CBP so it destroys the phone's contents.

Tech people will say that these two things are functionally the same. This is a fundamental misunderstanding of how the law works. If you factory reset your phone first with the intention of restoring it after entry, that's completely fine (legally). You could've factory reset that for any reason. But as soon as an officer wants to search your phone, now you're engaging in evidence destruction (spoliation). The destruction to the phone's contents was done in response to an unfortunately lawful search.

Even if you don't want to factory reset your phone, you can probably just delete (or even log out) of key apps. They can still get messages but if you're so concerned about that, use WhatsApp or whatever.

None of this should be necessary but we are where we are. But whatever you do, don't use a self-destruct PIN if you don't want to be charged with a felon and likely to be found guilty.

A court has not yet determined whether the use of the duress PIN/password was legal. There's definitely no consensus among legal experts of it being illegal as you're portraying it. The US has strong legal protections against self-incrimination and unreasonable searches despite erosion of how much people's rights are respected.

A factory reset done in anticipation of a search is not as different from using a duress feature as you believe it is. Forensics software would have clearly identified the device was recently factory reset. It would provide another defense argument by arguing it was wiped for another reason, but whether that would be believed by a court is unknown. It would make a difference if there was a good argument about why it was done, but it isn't necessary for this to have been done instead for wiping the device to have been legal.

Once he was in the situation already, the best move was very likely refusing to provide the PIN/password indefinitely and only talking to them to demand access to lawyer. There are strong protections against data extraction and it's highly unlikely they would have been able to get the data from it. Refusing to provide a PIN/password is protected under the 5th amendment in the US and these rights do exist at the border. They can turn away a non-citizen but they can't refuse entry to an American citizen because they won't provide a PIN/password. They could waste a lot of his time but he'd get access to a lawyer and would get released. They could make a court case over demanding the PIN/password and they'd nearly certainly lose. He'd likely spend months or even years without getting back his phone of course.

If they had a video recording of him entering the PIN/password from somewhere, they could have used that to get the data. By using the duress PIN/password, he prevented it. It was probably not necessary to keep the data safe, but that's unknown.

With only a tiny bit of preparation time, rebooting or powering off the device would have gotten it into Before First Unlock state without the locked device auto-reboot timer needing to complete. In Before First Unlock state, a decent random 6 digit PIN is enough for the data stored protected with it to be highly secure without an extremely sophisticated secure element exploit. If the device had a strong passphrase, then no level of sophisticated exploits would recover that data.

> A factory reset done in anticipation of a search is not as different from using a duress feature as you believe it is. Forensics software would have clearly identified the device was recently factory reset. It would provide another defense argument by arguing it was wiped for another reason, but whether that would be believed by a court is unknown.

This is where machine-like personal consistency is deeply important to opsec. Not just for technical reasons, but for legal reasons also.

If you wipe your phone before every national border crossing and restore it after every border crossing as a part of your standard procedure for travel, it will be much harder for a prosecutor to argue that you have ever done so in anticipation of some particular search. If your employer's security policy mandates doing so, that is even more evidence against anticipating a specific search. If a large body of infosec/cybersecurity professionals advise a wipe/reset of your phone before any and all international travel, that is further evidence for defense.

I used a very specific word for a very specific reason. That word was "spoliation". It is a legal word. It means destroying evidence but it means more than that.

If you're the subject of a lawful search and you destroy evidence rather than handing it over, that's spoliation. It has legal consequences. Courts are allowed to assume that whatever was destroyed was detrimental to you or your case. You can be charged with it as well. That's basically what happened here.

Consider this example: many companies have an email retention policy where emails will be automatically deleted after a period. I've heard of cases where this has been as little as 14 days. Typically though it's 1-5 years. One of the reasons companies do this is so discovery can't go and dredge up something really old in a lawsuit.

If this is a company policy then that's actually fine (ignoring any regulations or legislation tabout required retention).

Once you get subpoenaed you may get a hold on your email. The company is then required to retain it reagardless of this policy. If you then delete an email, that too is spoliation.

Do you see the difference? CBP can search your device. As soon as they request it, deleting the contents, regardless of what it contains is a crime. Wiping your phone before every border crossing as standard practice is not.