<https://news.ycombinator.com/item?id=49060780>
(From the HN GrapheneOS account about a month ago.)
We were talking about an attacker taking an image of the SSD prior to it being wiped not helping them because information needed to derive the key encryption keys is gone from the secure element. It similarly doesn't help them to do a brute force on a server farm since they're rate limited by the secure element. It only allows 20 attempts and has rapidly increasing delays between those. There's also hardware bound key derivation but that only helps improve the strength of a decent password. The secure element rate limiting makes even a random 6 digit PIN highly insecure unless an attacker can exploit the secure element.
(Very much appreciate your active participation here.)
OP is talking about just backing up what you need off-phone and then wiping it.
I would not present a phone to customs that had clearly just been wiped.
It's legal to refuse to provide a PIN/password in the US. He's a US citizen so they couldn't refuse him entry. If he wasn't then the result would be getting deported.
It likely would have been a much better decision to refuse to provide the PIN/password and rely on the encryption and device security instead. He could have done a reboot or shutdown in advance but even without that it would have done it automatically via the locked device auto-reboot timer. The secure element only allows 20 attempts for key derivation with rapidly growing delays between those. If he had a strong passphrase then even a secure element exploit wouldn't obtain the data protected by it.
That kind of thinking has landed a whole lot of people in prison.
You know how they say ignorance of the law is no excuse? That holds true even if the law seems unreasonable or incomprehensible.