Quick recap/background:
Activist Samuel Tunick was stopped by airport CBP officers when he returned to the US, and was instructed to provide a password to unlock his phone. Instead, he provided a "duress code" that triggered a wipe of his device, so he was then arrested for "destroying or removing property to prevent a government seizure."
I've been thinking about this a lot. I disagree with the reach of government and think this case will generate a lot of debate regarding what constitutes a detention or seizure, but I think the government has a winning case because the agents were operating in their recognized capacity, and he admits that he deliberately took an action AFTER his first encounter with law them to destroy what the agents wanted to review.
So my hypothetical question is:
What if he had set it up on a dead man's switch instead, which would have automatically deleted the data if he DIDN'T provide a code within, say, two hours after starting the countdown?
My "big picture" questions are whether the government legally treats inaction that results in deletion the same as they would action that results in deletion, and whether or not an individual has an obligation to act or could be compelled to act?
But since I'm not a lawyer and I'm sure I'm not making myself clear, here's a scenario:
My understanding is that for US citizens, CBP:
- cannot force you to disclose or enter a password (although they can input your biometrics if enabled)
- cannot refuse you entry for refusing to provide a password (though they can prolong your detention)
- can seize your device long enough to finish their investigation or copy your data (and must allow you entry in the interim)
Assume the above rules (and anything else that's currently in play in the real world). Let's assume someone, John the activist, is flying back to the US from Europe. He has a "dead man's switch" program on his phone, which will delete his phone a certain number of minutes after activation if a deactivation code is not entered (if it is entered, then the timer resets). He has disabled his phone's biometrics.
He's flying into DFW and, though he has not done anything illegal, has reasonable concern that he'll be singled out for additional CBP review due to his activism and social media presence, both critical of the current administration and of CBPs parent agency. He is concerned that if he is, a list on his phone of associates "unfriendly to the administration" would be compromised. But he's not sure of anything- he gets picked for additional review about half the times he travels, otherwise it's a quick 30-60 process to go through entry customs and immigration.
Before disembarking the plane-ie, before his first contact with CBP and before he even knows whether his device will be reviewed or seized, he sets the dead man's switch for two hours.
He deplanes and retrieves his luggage quickly, and at t minus 60 minutes is concluding his entry screening questions when he's approached and informed he's been selected for additional review. He's been through this before, and initially the interview is quite cordial, with routine questions about his job and travels. But before long his activism status is brought up, and the interview becomes more adversarial.
Based on his prior experience, and the advice of counsel, he answers the questions that he knows he must, and deflects questions where appropriate. He also makes it clear that beyond the legally required customs questions, he will not be answering any questions without counsel. The interviewing agent requests a password for his phone; John replies that he will not be providing him a password for the phone, and that if CBP so desires, they are welcome to temporarily seize the device, and he requests to go. The agent demands a password, and John again refuses. This escalates to the agent holding the phone in front of John's face, before he realizes that biometrics have been disabled.
Around this time, the phone flags with a pop-up notification "Warning: this data on this device will be permanently deleted if the abort password is not entered within the next 10 minutes." This is the first time that the agent has seen something like this, and again demands John give him the abort password, which he refuses to do. The agent retrieves his supervisor, who also unsuccessfully demands the password... And everybody watches as the phone screen freezes, and after a few seconds goes black.
Several more hours in in interrogation lapse, with agents demanding an explanation as to what exactly happened and why, and John refusing to answer anything without the presence of an attorney. He is eventually released and drives to his home, but the next day is visited by law enforcement who informs him that he is under arrest under 18 U.S.C. § 111, interfering with an officer performing their official duties, and further actions based on an adverse inference would be forthcoming.
By the end of the day, it's an international news story, with John and his attorney asserting both the reasonable need for privacy given John's employment, as well as citing a belief that under the fifth amendment, his inaction was appropriate, that the arrest was invalid due to the absence of physical interference with the agents' duties and that any attempts that were made to compel him to release the password constituted infringement of his right against self-incrimination, even though there was no underlying criminal activity.
So...
What would come of that case? If there was an app like that which shifted phone deletion from being a deliberate action chosen while already in CBP jurisdiction to instead be an issue of inaction and how far the government could compel someone to take action, would that be a better defense from a legal standpoint? For bonus points, what if John didn't know the password- what if successfully keeping the data meant linking up with his wife in the pickup lane and having her enter the code?
EDIT: I'm very much enjoying the thoughtful responses. to reiterate, this doesn't reflect on the "real world" case, nor the debate about privacy. Although there's obviously a question about substance that can't be fully ignored, it's intended to be more about technicalities, which is how many of these cases are likely to be decided... and I could forsee "John's" case to be very realistic in the near future, as software like this exists and, like the duress password, is likely being used currently. it's just a matter of time before the theoretical case isn't so theoretical...