This should be an interesting case in today’s legal climate
Obviously grafeneOS has no liability. But the owner of the device didn’t take the action to remove the data, the CBP officer entered it. We already have some precedent around being forced to give up your password.
How does that change if you are forced to give up a password that is destructive? What if the password works fine at home and the same password does a wipe based on location? Either way, the user complied, and did not take action to wipe their device.
If you have a safe in your home and you knowingly wire up a bomb that goes off when a certain lever is pulled then you lie to the police and tell them the way to open the safe is to pull that lever you'd pretty clearly be responsible for the damage done when the bomb goes off.
I don't see why this would be any different.
You put a sticky note with the duress PIN on your phone. When detained, the officer notices a PIN in plain sight on the phone, enters it, and the phone wipes itself. You were never asked for a PIN.
Could you be charged with destruction of evidence?
> Either way, the user complied, and did not take action to wipe their device.
The user claimed to offer a password to access the contents of the device, and instead offered a password that deleted the device. That is false testimony / lying to an investigation, and is almost certainly punishable in itself.
Intentions matter. If the intent is to trick the officer to enter a PIN code that will destroy potential evidence then it does not matter that you didn't type the PIN code. Your speech is the thing that triggers a series of events that you know will lead to a wipe. Just like you can be charged with destruction of evidence even if you trick someone else to take the action.