If only these phones could have a feature where you can enter a mode to encrypt segments of data with different encryption keys, all able to be unlocked still by one single master encryption key that you could also enter at any time.
Then when in travel, and about to pass a border, you enter that selective mode. You can enter a different password as the proxy to unlock the phone in this bare minimal data mode. The agents can access it, etc but wont have all the data. That data shouldn't even be visible in the OS, and if they try to copy the hard drive they will get encrypted data in the other blocks.
You still legally comply with orders and unlock the phone but the other partitions don't unlock/decrypt unless you specifically unlock them.
This feature exists today – it's called "leave your gadgets at home". S3 bucket and / or laptop with Tails on USB stick is all you need.
if u read the grapheneos tweet about this, any form of minimal account puts all ur other accounts at risk. agents should never get any form of code execution on ur device, even from a sandbox account. the linux kernel is not secure, and they can just hold the device till the next public disclosure or use one of their existing cellebrite attacks.
duress password to shutdown instead of wipe could be an option.
duress password to restore to snapshot, effectively wiping all data after snapshot, is another option, as it would be hard to know what happened. all the now "free space" gets overwritten with prng.
when entering the duress password, maybe grapheneos needs to put some UI theatre, like saying battery low, shutting down... so the agents think the phone is just shutting down due to low battery.
another theatre could be a fake shutdown, that appears to not startup again... just wipe and kexec a fake kernel that just mimics a dead phone, till the batter actually dies. any attempts by the agents to charge the phone , is met with a fake boot and a charging error. This is just a phone with a bad battery, nothing to see here.