People have been doing this since way back in the TrueCrypt days - IIRC you could configure it to run a whole fake version of Windows if you wanted without easily revealing your actual main volume.
Most hardware crypto wallets also have a "duress wallet" feature where you keep a low balance for the same reason.
Wiping is obviously extremely suspicious and asking for trouble
It's sad this is the default view. It's his device, his data, his life on that phone. If he had wiped the phone before the interrogation it wouldn't be a problem. How long before? A second before? A week before? But wiping the data a minute later is suddenly asking for trouble.
Edit: a bigger picture question is the difference between things that may be legally punishable and things that may cause suspicion from CBP agents, which aren't the same thing at all.
If you're going to be in a situation where you're in a room with some goons backed by the full power of the state, it is what it is.
Maybe because I'm not American I don't have any hangups about seeing the US government this way, but my own government is no different - you can (and people have) get stopped at Heathrow, taken to a dimly lit backroom and given a going over for hours
A non-citizen who arrives with a blank phone might be denied entry because it seems suspicious.
Note that if you're not a citizen of the USA, refusing to comply with a request like this is very likely to have you sent back to your country and denied access to the USA forever. While they can't legally force you to comply, they can absolutely deny you entry for any reason like this, regardless of having a valid visa and everything else in order. This even applies to legal residents.
Edit to add: beyond forensics, they can also simply ask you to enter the other password, to prove that the account you showed them first was the right one.
If they can't compel you to enter a password (courts have ruled passwords are 'speech' and the government can't compel or constrain speech, absent some well-defined grounds for doing so. There IS law around spoliation of evidence but AFAIK this requires a judge issuing an order. Of course, suddenly taking actions you wouldn't otherwise have on learning you're under suspicion could be claimed by a prosecutor in court as circumstantial evidence of guilt but it's not a cause of action in the first place until you're notified by a court to preserve evidence. Can a prosecutor try to construct a theory that the alleged actions do amount to obstruction? They can try but it's a serious long shot. I think this is a case of this administration directing the justice department to bring yet another dubious, likely-to-lose case as an extremely aggressive way to make a point by trying to assert and establish rights they don't actually have. So far, their track record in such cases hasn't been good.
> Note that if you're not a citizen of the USA
Yes, everything is different in this context if you're not a U.S. citizen. The U.S. govt can deny entry to non-citizens essentially without justification. I think this sucks as it goes against long-held American ideals around presumption of innocence, consistent treatment under the law, standards of evidence and having cause, but it's not currently prohibited.
Note that I'm not talking about a situation where they have you in custody or are about to, but haven't (yet) removed your phone for whatever reason, and you quickly take some action to clear it. I'm talking about a situation where they are questioning you, and in the course of questioning, request that you unlock your phone for them to inspect, you agree to do so, and proceed to wipe the phone or enter a dummy password for a fake account while pretending that you are complying with the request.
It is this second situation that happened in the article - the man being charged was held in custody and repeatedly asked to unlock the phone or risk having it seized; the man finally agreed to unlock it and provided a passcode to the officers, but the passcode instead wiped the phone.
And using encryption will only make you more suspicious, and may be a reason to get jail time until the situation is "cleared up" one way or another (e.g. by getting even more jail time).
Only a second phone works, if you can make it seem like a device you're actually using (though also not a silver bullet as e.g. a lot of messenger metadata is available to governments and border control can physically coerce you to log in to your real accounts)
Selection on border control might be arbitrary, they can hold you or send you back over a photo or something you wouldn’t think should be a problem.
Ideally you would like to have all wiped just in case but then you really stand out…
and
you can’t be sure which things can get you in trouble.
By default, new material will be deleted. So you don't have to prepare again and again.
> you can’t be sure which things can get you in trouble.
When in doubt, don't mark it as keep.
Of course the problem there is, many people have an app store installed, and app stores have histories. And logs. And "what you used to have installed" is so easily found under Google Play, for example.
As someone else said in this thread, the law isn't code. It's not if-then statement based. It's also predicated upon intent in many cases. What actions did a person take, and why, when told to (for example) unlock their phone.
The problem here is that if you are asked to unlock your phone, any action you take to thwart that request by "trickery" to get data deleted, could be construed as 'deleting evidence'. So while some methods might make it more difficult for the border agent to realise "something happened", if they're suspicious still, then you're still in hot water.
In the eyes of the law, the court, and likely the jury, you've done a sneaky thing to thwart evidence collection.
The only safe method is a full wipe prior to travel. In this manner, you're not deleting evidence when told to hand it over. It's an entirely different bar. They can be cruel about it, and take your phone for a few months, but you're not going to be in legal hot water.
In as no one will see the phone is wiped until you are compelled to unlock it, there's no greater change of the phone being seized. You're already being investigated. Just be blunt, say "Whenever I travel, I just wipe it", and that's that.
This is why it's a shame that GrapheneOS has no viable backup solution. Its build in method is unreliable, and doesn't work very well, and is gitchy, it's a very well known problem.
And Android and ADB sometimes have issues with large backups of directories, and so you have to manage that with tar + stream and other business, but at least working around that is easy.
But if you could backup individual apps and all their data, you could uninstall all your privacy laden stuff, cross the border, and reinstall in minutes.
That's the true, legal way to travel safely. Especially if the app removal resulted in a 'shred' of the data files instead of delete.
If anyone has ever struggled with large data backup/restore, here's the only real method I've found for copying large swaths of files from/to via adb:
adb exec-out 'tar --dereference --create /storage/emulated/0/dir/ 2>/sdcard/backup-errors.txt' |dd of=/tmp/backup-$(date +%Y%m%d).tar && adb shell cat /sdcard/backup-errors.txt
and to restore dd if=backup-20250309.tar | \
adb exec-in 'cd /storage/emulated/0/tempdir; tar xpvf - 2>/sdcard/restore-errors.txt' && \
adb shell cat /sdcard/restore-errors.txt
Or something similar.... where I seemed to recall it was a social media post, but it is unclear whether it's private messaging, public social media, or private messaging under a public social media account.
[EDIT] according to [1] it was on WhatsApp with a U.S national.
My understanding is that refusal to provide social media accounts, or passwords to devices, or passwords to social media accounts, can be considered suspicious in its own right and ground to be held in custody for further exam, and/or denied entry; foreigners do not get to have the same "give password" == "right to not incriminate yourself" that U.S of A. citizen have. In doubt I would assume I don't.
[0]: https://www.lemonde.fr/en/international/article/2025/03/20/f...
[1]: https://www.lemonde.fr/international/article/2025/03/22/le-r...
The good thing about a total wipe is that it's very easy to implement, and it's hard for it to go wrong. You just encrypt the whole drive and, when you want to wipe it, erase the key.
Also they can plant evidence if you unlock the phone.