First known US federal prosecution over a phone's duress PIN: a traveler at Atlanta airport hands border agents a passcode, the device (GrapheneOS, per the indictment) irreversibly wipes itself - and he's now charged with destruction of property to prevent seizure. Up to 5 years. He's pleaded not guilty; a court decides this fall whether destroyed key material counts as "property." The operational lesson isn't about the tool. The tech did its job - the keys are unrecoverable, exactly as designed. Owning it is legal - triggering it during an active search is what produced the charge. A safeguard became a legal problem at the exact moment it was supposed to protect. After 30 years in security ops, my travel rule is simpler: the best defense isn't a wipe button, it's a device with nothing on it. Clean device or clean work profile · only what the trip needs · mail in the browser, nothing offline · company access and VPN after arrival · backups stay home. What you don't carry can't be seized - and nothing gets destroyed. Not just a US thing: under Schedule 7 in the UK, port officers can demand device passwords with no prior suspicion, and refusing can itself be an offence. Source: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/ #opsec #privacy #infosec #grapheneos