🟡 Medium  |  Source: Schneier on Security


A US citizen is facing prosecution after using a duress password feature in GrapheneOS to wipe his phone when border officials demanded access during a search. The case hinges on whether activating a built-in security feature constitutes obstruction, and challenges the legal grey area of constitutional rights at US borders. This sets a significant precedent for how device security features can be treated as potential evidence of wrongdoing.

Security Architect’s Take: Review your organisation’s mobile device and travel security policies to explicitly address duress/wipe features and border crossing procedures — employees travelling to the US should be briefed on the legal risks of using such features, and consider whether issuing clean travel devices with no sensitive data is the safer operational choice.

Original advisory: American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials