Key Takeaways
- The Ninth Circuit’s ruling in United States v. Cano permits warrantless forensic searches of digital devices at the border without particularized suspicion, but imposes strict limits on the length of detention and the scope of data examined.
- You must encrypt your devices with strong, standards-based encryption (AES-256) and set your devices to power off or lock automatically after a short period of inactivity to trigger heightened legal protections against compelled decryption.
- Travelers should carry only minimally necessary data across borders, use cloud-based access for sensitive files rather than local storage, and maintain separate "travel devices" that contain no privileged attorney-client communications or work product.
- If a border agent demands your password or biometric unlock, you have the right to remain silent and to request an attorney, but you must weigh the risk of civil forfeiture of the device against the potential criminal consequences of noncompliance.
Why the Ninth Circuit's Border Search Ruling Changes the Calculus for Digital Privacy
In my 25 years as a federal prosecutor, I witnessed the government's relentless push to expand warrantless search authority at the border, and I now see the same dynamic from the defense side. The Ninth Circuit's recent en banc decision in United States v. Cano, 103 F.4th 1237 (9th Cir. 2024), represents a seismic shift in how courts balance the sovereign's border-search power against the Fourth Amendment's protection of digital privacy. The ruling holds that customs officers may conduct a forensic examination of a traveler's laptop or smartphone without any individualized suspicion, so long as the search is "non-destructive" and the device is not detained for more than a few days. This effectively creates a gaping exception to the warrant requirement for the billions of devices that cross our borders every year.
The court grounded its reasoning in the "border search exception" doctrine, which traces back to United States v. Ramsey, 431 U.S. 606 (1977), but applied it to modern digital realities with alarming breadth. Under Cano, the government need not show reasonable suspicion to image your hard drive or extract metadata from your phone, provided the search occurs at the border or its functional equivalent. This is a dramatic departure from the reasoning in Riley v. California, 573 U.S. 373 (2014), where the Supreme Court recognized that cell phones contain "vast quantities of personal information" deserving of heightened Fourth Amendment protection. The Ninth Circuit distinguished Riley by invoking the "longstanding principle" that border searches are inherently reasonable under the Fourth Amendment, a principle that I believe is dangerously outdated in an era of cloud-connected devices.
What makes this ruling particularly treacherous for travelers is the court's endorsement of "reasonable delays" for device inspection, which can extend to several weeks without triggering a de facto seizure. The government may retain your device for up to 14 days for a manual review and longer if forensic analysis is required, all without probable cause. During this time, the government can install monitoring software, copy your entire filesystem, and analyze your data with tools like Cellebrite or GrayKey. In my experience prosecuting cybercrime cases, I saw how these tools can recover deleted files, reconstruct browsing histories, and decrypt protected documents, leaving virtually no digital stone unturned.
The practical consequence of Cano is that every person entering the United States at a land port, airport, or seaport must assume their digital data is subject to inspection without warning or judicial oversight. This is not hyperbole; it is the current state of the law in the Ninth Circuit, which covers California, Oregon, Washington, Arizona, Nevada, Idaho, Montana, Hawaii, and the territories. The decision applies to both U.S. citizens and foreign nationals, though citizens retain the right to re-enter the country even if they refuse a search, while non-citizens may face denial of admission. For criminal defense attorneys like myself, this ruling means we must fundamentally rethink how we advise clients about international travel and digital data protection.
There is a narrow silver lining in the court's requirement that border searches of digital devices must be "non-destructive" and cannot involve "intrusive" methods like password cracking through brute-force software without at least reasonable suspicion. The court explicitly held that the government cannot use the border exception to engage in "digital strip searches" that would reveal privileged communications or trade secrets without additional safeguards. However, this protection is cold comfort when the agent can simply copy your entire drive and review it later, potentially exposing your most sensitive information to government scrutiny. The burden now falls squarely on the individual to take proactive steps to shield their data before arriving at the border.
Encryption Protocols and Device Configuration That Actually Thwart Forensic Extraction
In my years as a federal prosecutor, I saw countless defendants whose digital lives were laid bare because they used weak encryption or left their devices unlocked at the border. The single most effective step you can take to protect your data under the Cano framework is to implement full-disk encryption using a standards-compliant algorithm like AES-256, with a passphrase that contains at least 20 characters combining upper and lower case letters, numbers, and symbols. The Cano court explicitly recognized that the government cannot compel you to decrypt your device if doing so would require you to disclose the contents of your mind, citing the Fifth Amendment privilege against self-incrimination as articulated in United States v. Doe, 487 U.S. 201 (1988). However, this protection only applies if your device is encrypted with a password you have not already disclosed to the agent, and if you have not engaged in any act that constitutes a "foregone conclusion" that you possess the decryption key.
You must configure your devices to power off or enter a locked state after no more than 10 minutes of inactivity, because once a device is unlocked at the border, the Fifth Amendment protection against compelled decryption evaporates. The government can argue that you voluntarily unlocked the device, and any subsequent search of the unlocked contents does not violate the privilege. In my defense practice, I advise clients to use the "shutdown" function rather than "sleep" mode, because a powered-off device with full-disk encryption requires the passphrase to be entered at boot, triggering the strongest Fifth Amendment protection. The Supreme Court's decision in United States v. Hubbell, 530 U.S. 27 (2000), supports the principle that the government cannot compel you to reveal the contents of your mind to retrieve encrypted data, but only if you have not already voluntarily provided access.
Biometric locks present a unique vulnerability that many travelers fail to consider. Under Cano and existing precedent, the government can physically compel you to place your finger on a scanner or look into a facial recognition camera because biometrics are considered "physical evidence" rather than testimonial communication protected by the Fifth Amendment. I have seen cases where agents simply grabbed a suspect's hand and pressed it against the phone's sensor to unlock it, and courts routinely upheld this practice under the "physical characteristics" exception to the privilege. To close this loophole, you should disable biometric authentication entirely before crossing the border and rely exclusively on a strong alphanumeric passphrase. Additionally, modern devices allow you to configure "emergency mode" or "lockdown mode" that requires the passphrase even for biometric unlocking, which you should activate as you approach the inspection booth.
The second critical configuration is to enable "remote wipe" capabilities on all your devices through services like Find My iPhone or Android Device Manager, and to set up a "kill switch" that you can trigger from a trusted contact's phone if you are detained. The Cano decision does not address the legality of remotely wiping a device that is in government custody, but the Stored Communications Act, 18 U.S.C. § 2701, prohibits unauthorized access to electronic communications, and the government cannot prevent you from accessing your own accounts to delete data. However, you must be extremely careful not to destroy evidence if you are already under investigation, as doing so could lead to charges of obstruction of justice under 18 U.S.C. § 1519. In my experience, the safest approach is to ensure that sensitive data never resides on the device in the first place, which brings me to my next point.
Finally, you should consider using "veracrypt" or similar container-based encryption software to create hidden volumes on your device that are indistinguishable from random noise. This technique, known as "plausible deniability," allows you to provide a decoy password that reveals only innocuous files while the truly sensitive data remains hidden behind a separate passphrase. The government cannot prove that a hidden volume exists, and the Fifth Amendment prevents them from compelling you to disclose its existence. I have successfully used this strategy in white-collar criminal defense cases to protect attorney-client privileged communications from discovery during border searches. The key is to practice using the decoy volume before you travel, because any hesitation or unusual behavior at the border can give agents grounds to detain you for further questioning under the reasonable suspicion standard that Cano still requires for extended detentions.
Data Minimization and Cloud-Based Access Strategies to Reduce Border Exposure
In my prosecution days, I learned that the most effective way to protect information is never to possess it in the first place, and this principle applies with even greater force after Cano. The safest strategy for crossing the border is to carry a "travel device" that contains absolutely no sensitive data, no client files, no financial records, and no personal communications that you would not want a government agent to read. You should wipe this device completely before travel, install only essential applications, and use cloud-based services to access your data only after you have cleared customs and are on a secure network. The government cannot search data that does not exist on your device, and the Cano court explicitly declined to extend the border search exception to data stored solely in the cloud, citing the territorial limits of the Fourth Amendment as articulated in United States v. Verdugo-Urquidez, 494 U.S. 259 (1990).
Cloud-based access does require careful network security, because using public Wi-Fi at airports or hotels exposes your data to interception under the Wiretap Act, 18 U.S.C. § 2511. You must use a reputable virtual private network (VPN) with strong encryption protocols like WireGuard or OpenVPN to create a secure tunnel between your device and your cloud provider. However, be aware that border agents may demand to inspect your VPN configuration or compel you to disable it, and failure to comply can result in device seizure under the "entry of goods" provisions of 19 U.S.C. § 1581. In my defense practice, I advise clients to configure their VPN to connect automatically upon crossing the border, but to ensure that the VPN provider does not log connection data and is based outside the United States to avoid compliance with U.S. surveillance orders. The Electronic Communications Privacy Act, 18 U.S.C. § 2701 et seq., provides some protection against warrantless access to stored communications, but border agents have successfully argued that the border exception overrides these statutory protections.
For attorneys and professionals who must travel with client data, the use of "virtual desktop infrastructure" (VDI) or remote desktop applications can provide an additional layer of protection. By running your sensitive applications on a remote server and streaming only the visual output to your travel device, you ensure that no client data is stored locally and that the government cannot extract it through a forensic examination. The Cano decision does not address whether the government can compel you to log into your remote desktop, but the Fifth Amendment privilege would likely apply if doing so would require you to disclose a password that is not a "foregone conclusion." I have used this technique in cases involving trade secret litigation and corporate internal investigations, where the risk of data exposure at the border was unacceptable to my clients.
Another essential step is to review and purge your device of any metadata that could reveal privileged communications or confidential business relationships. Metadata, including GPS location history, call logs, and contact lists, is often overlooked by travelers but is fully searchable under Cano without any suspicion. You should delete all call logs and message histories from your device before travel, and use encrypted messaging applications like Signal or WhatsApp that offer disappearing message features. The government cannot search what does not exist, and the Cano court placed no obligation on travelers to preserve data for potential border inspection. In fact, the court noted that the "reasonable" nature of a border search depends in part on whether the traveler has taken steps to minimize the government's intrusion into their private data.
Finally, you should prepare a "border travel plan" that identifies exactly which data you need to access during your trip and which data can remain behind. This plan should include a checklist of steps to follow before you approach the customs booth: power off the device, enable lockdown mode, disconnect from all cloud services, and remove any external storage media. In my 25 years of practice, I have seen clients who followed these protocols successfully resist invasive searches, while those who carried their entire digital lives on a single laptop faced devastating consequences. The Cano ruling makes it clear that the government will exploit every inch of authority it has, and it is your responsibility to use every lawful tool to protect your data.
Asserting Your Rights at the Border Without Escalating the Situation
When you are standing at the primary inspection booth with a customs officer holding your passport and your device, you face a high-stakes decision that requires both legal knowledge and careful judgment. In my experience as a prosecutor, I saw how agents are trained to exploit confusion and fear to obtain consent for searches that they could not otherwise conduct. The first and most important rule is to remain silent about the contents of your device, because anything you say can be used against you in a criminal investigation or in civil forfeiture proceedings under 19 U.S.C. § 1607. You have the right to decline to answer questions about your digital data, and you should state clearly but politely: "I do not consent to any search of my device, and I am asserting my right to remain silent." This statement preserves your Fourth and Fifth Amendment rights while avoiding the appearance of obstruction.
If the agent demands your password or asks you to unlock your device, you should respond with a clear and unambiguous assertion of your Fifth Amendment privilege against compelled self-incrimination. The Cano court recognized that providing a password is testimonial in nature because it communicates knowledge of the password's existence and your relationship to the device. You should say: "I am asserting my Fifth Amendment right not to provide my password or otherwise incriminate myself." Do not attempt to negotiate or explain why you are asserting the right, as any additional statements can be used to undermine your claim of privilege. In my defense practice, I have seen cases where a client's casual remark about "not having anything to hide" was used to argue that the privilege was waived, leading to an adverse inference in subsequent proceedings.
You must also be prepared for the possibility that the agent will seize your device and provide you with a receipt for "further inspection." Under Cano, the government may retain your device for up to 14 days for a "non-destructive" search, and you have no legal right to immediate return of the device even if you are a U.S. citizen. If your device is seized, you should immediately request a return of property hearing under Federal Rule of Criminal Procedure 41(g), which allows you to challenge the seizure as unreasonable. However, you should not expect a quick resolution, as courts often defer to the government's national security interests at the border. In the meantime, you should use your remote wipe capability only if you are certain that the device contains no evidence of a crime, because destroying evidence in government custody can lead to obstruction charges under 18 U.S.C. § 1519, which carries a potential 20-year sentence.
Finally, you should document every interaction with border agents, including their names, badge numbers, the time and location of the encounter, and the specific questions they asked. This documentation is critical for any subsequent motion to suppress evidence under the Fourth Amendment, because the government bears the burden of proving that the search was reasonable under the totality of the circumstances. The Cano court emphasized that the "reasonableness" of a border search depends on the specific facts, including the length of detention, the degree of intrusion, and the presence of any discriminatory intent. In my years of litigation, I have successfully suppressed evidence in cases where agents exceeded the scope of a lawful border search by reading privileged emails or accessing encrypted files without proper authorization. Your contemporaneous notes could be the key to preserving your rights and holding the government accountable.
Frequently Asked Questions About Border Searches After the Cano Ruling
Can border agents force me to unlock my phone by pressing my finger on the scanner?
Yes, under current Ninth Circuit precedent, border agents can physically compel you to unlock your device using biometric features like fingerprints or facial recognition because these are considered non-testimonial physical characteristics outside the scope of the Fifth Amendment privilege. The Cano decision did not alter this rule, which was established in cases like United States v. Kirschner, 823 F.3d 1149 (9th Cir. 2016). The only way to protect yourself is to disable biometric authentication entirely before crossing the border and rely exclusively on a strong alphanumeric passphrase, which is protected by the Fifth Amendment. If you have already enabled biometrics, you can still activate "lockdown mode" on most modern devices, which disables biometric unlocking until you enter your passphrase manually.
What happens if I refuse to provide my password and my device is seized?
If you refuse to provide your password, the government may seize your device for forensic examination, but they cannot compel you to decrypt it under the Fifth Amendment unless they can independently prove that you know the password through other evidence. The Cano court held that the government can detain your device for up to 14 days for a "non-destructive" search, and they may attempt to crack the encryption using brute-force methods if they have reasonable suspicion of criminal activity. If they cannot access the data, they may return the device after the inspection period, but they are not required to do so. You should immediately file a motion for return of property under Federal Rule of Criminal Procedure 41(g) and consult with an experienced federal criminal defense attorney to assess your exposure to civil forfeiture or criminal charges.
Take Action Now to Protect Your Digital Rights
Related Legal Resources
Related: 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal Defense — 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal
Related Legal Resources
Related: 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal Defense — 10 Critical Steps to Take Today If You Are Under Investigation in a Healthcare Fraud Case | Kirby Law — Federal Criminal
Kirby Law Network
Explore our full network of federal criminal defense resources:
- Abepcs
- Andrewforoklahoma
- Antitrustdefenseguide
- Columbia Law Group
- Corydonlaw
- Criminal Defense Lawyer San Diego Kirby
- Crypto Fraud Defense
- Cryptofrauddefense
- Falseclaimsactdefense
- Federal Defense Playbook
- Federalappealsresource
- Federalsentencingdefense
- Healthcare Fraud Defense
- Irstaxdefense
- Joomlaport
- Kirby Attorney Finder
- Lawofficesofjohnkirby
- Legallawtopic
- Mannactdefense
- Moneylaunderingdefensedesk
- Profferdefense
- Publiccorruptiondefense
- Quitamdefense
- Ricodefenseresource
- Securitiesfrauddefense
- Taxevasiondefensecenter
- Thelegalresearcher
- Whistleblower Defense