Physical data at the US border is now a criminal exposure
A person using GrapheneOS gave a border official the Duress PIN, which wiped the device as designed. They are now facing felony charges for it. The thread noted the dark irony: technically the official erased the data, not the traveler. The device did exactly what it was built to do.
The legal theory being used here is likely obstruction, and the thread was skeptical it would hold up. But the signal is clear regardless of how this specific case resolves: US border crossings are now a meaningful threat surface for anyone carrying a device with sensitive data, and the government is willing to pursue criminal charges for using privacy features that ship in mainstream operating systems.
Practical advice surfaced fast: travel with a burner phone. The discussion among technically sophisticated people has moved past 'should I be worried' to 'what is my actual protocol.'
So what?
Founders and engineers who travel internationally for work and carry devices with customer data, proprietary code, or confidential communications are now in a different risk environment than they were two years ago. A written travel security policy for your company that covers device preparation before border crossings is no longer paranoid. It is basic due diligence.