That's a misconception. Border/immigration agents can operate inside this zone, including making stops with reasonable suspicion or running checkpoints where everyone is stopped with no suspicion. The checkpoints are limited in scope, and do not provide authority for searching electronic devices. Some people, including a couple dissenting supreme court justices do feel the checkpoint part violates the constitution.
That's distinct from the border search exemption, which allows inspection of everyone and everything crossing the border. It only exists when someone is actually crossing the border and does not allow CBP to stop or search people who are not crossing the border.
Fun fact. Lack of parking is not a legitimate reason to attempt to drive past this region. I was once flagged crossing into canada on a day they were interviewing a lot of travelers. I spotted parking in what looked to me like an overflow lot on the other side of a fence, and when I slowly drove that direction sirens blasted and guns were drawn. Nothing gives you clarity like a gun pointed at you.
Seems like so far it didn't create any problems, so public is ok with that.
What are you even talking about?
Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password.
How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password does a wipe based on location? Either way, the user complied, and did not take action to wipe their device.
I don't see why this would be any different.
Could you be charged with destruction of evidence?
The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.
On the other hand, I'm worried that the publicity will only make explicit targets out of GrapheneOS users, and that you would only be using it "if you have something to hide".
A duress password isn't a booby trap. Nothing was damaged except for the fragile egos of the man-children who weren't able to bully someone into giving up their wrong-think.
"Give us the PIN for your phone"
"I don't want you to search my phone, and I want to talk to my lawyer"
"If you don't comply, you're going to be in a lot of trouble"
"Can I please just go, I don't want to answer questions or be searched"
"If you don't comply we will seize your phone and detain you indefinitely until we can unlock your phone!"
"I want my lawyer."
"Just tell us the PIN and you'll be on your way. Otherwise it's gonna be bad."
"Look if I have no choice my PIN is 1234, but I don't want you searching my phone without my lawyer present."
...
"Hey! We tried to search your phone and the phone wiped itself! You're going to prison for destruction of evidence!"
However, did that evidence really exist? And if it did, was it for something else? Perhaps, the guy just worried about something far more mundane being discovered? We shall never know.
Think Schrodinger's password.
I'm not taking sides here, I just wanted to make that clear.
And you should understand that they can lie to you. That's OK and legal, but you cannot lie to them.
In Belarus, such "search" means plugging a USB cable and downloading everything from your phone AND connected clouds (Google Photos, iCloud etc). Then their software (bought for millions of dollars from a foreign security company) compares every single face in your photos/videos with every single face gov has in their database. And you don't have control of the downloaded data.
And ongoing publicity as the trial happens.
US Government targets Cop City protester over phone operating system
When I was designing my secure vault app for iOS[0], my approach was to make one of the “folders” (I call them vaults), to trigger the wipe out without any sign of doing so while retaining the data in the opened vault. It technically only deletes the index and the keys, and obfuscates them by replacing them with random bytes.
I already heard from a person that was forced to open their app but was let go, because they complied.
Then when in travel, and about to pass a border, you enter that selective mode. You can enter a different password as the proxy to unlock the phone in this bare minimal data mode. The agents can access it, etc but wont have all the data. That data shouldn't even be visible in the OS, and if they try to copy the hard drive they will get encrypted data in the other blocks.
You still legally comply with orders and unlock the phone but the other partitions don't unlock/decrypt unless you specifically unlock them.
Duress hidden profiles viability statement:
https://xcancel.com/GrapheneOS/status/2082153517234676150#m
Regular defenses statement:
https://discuss.grapheneos.org/d/40700-grapheneos-protection...
Discussion: https://news.ycombinator.com/item?id=49055169
TBF, similar mindset if I ever attend defcon, etc. as well.
Now, is this what's at stake here? Evidence of what? Surely at some point, clear allegations need to me made for which the content of the phone is evidence for.
There's alot of speculation of what the indicted person was involved in, or motives of the border agents. Or the insinuation that the tooling that allowed the alleged destruction of evidence is (or should be) ilegal or indications of nefarious intent by those who use such tools. This is all BS.
Am I missing something?