Border Device Wipe Leads to Indictment
A federal case involving a duress password suggests new legal risks for travelers using privacy-focused mobile software.
A federal prosecution in Atlanta is highlighting the intersection of advanced privacy features and border security mandates. The U.S. Justice Department has charged an American citizen, Samuel Tunick, with allegedly destroying evidence after he provided border agents with a secondary passcode that triggered a factory reset on his device.
The Mechanics of Device Wiping
The case centers on the functionality of GrapheneOS, a privacy-centric custom Android operating system. The software includes a duress feature specifically designed to protect user data from unauthorized access. When a user enters this pre-configured passcode, the device deliberately wipes the contents of that device rather than unlocking the normal user profile.
Prosecutors contend that by providing this code to authorities at Atlanta’s Hartsfield-Jackson airport on January 24, 2025, the defendant violated a federal statute prohibiting the knowing destruction of property to prevent government seizure. Legal experts suggest this is an unprecedented application of the law, marking a potential shift in how federal agencies address encrypted hardware.
Legal Challenges to Border Authority
Tunick’s legal team has filed a motion to suppress the evidence, arguing that the initial seizure of his phone was unlawful. The defense claims that agents lacked proper suspicion for the search and that the defendant was denied access to legal counsel during the secondary inspection process.
The defense further alleges that the inquiry was not related to its stated premise—investigating child exploitation imagery—but was instead linked to the defendant's affiliation with the “Cop City.” protest movement. This friction underscores the long-standing legal debate regarding the government’s ability to search and seize people’s devices without a search warrant or court order while individuals are in the process of entering the country.
The Limits of Privacy Tools
Security experts note that while duress features provide a technical safeguard, they may also serve as the basis for legal escalation. The government’s indictment specifically highlights the digital erasure as a criminal act, creating a scenario where the act of protecting one’s privacy is interpreted as an obstruction of justice.
“I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.”
— Runa Sandvik, digital security expert and founder of the security consultancy firm Granitt
- January 24, 2025: Date the device was seized at Hartsfield-Jackson airport.
- 1 federal statute cited in the indictment for destruction of property.
- 1 motion to suppress evidence currently pending before the court.
Implications for Cross-Border Privacy
For individuals traveling with encrypted or privacy-hardened devices, this case signals a potential increase in scrutiny. If the court upholds the government’s interpretation of the law, it could establish a precedent where using built-in software security features is framed as criminal interference. Moving forward, the outcome of the pending motion to suppress could dictate whether travelers are legally required to keep their devices in a state accessible to border agents or if current protections remain legally viable.
Sources
- TechCrunch Original source
- to The Guardian Also reporting
- deliberately wipes the contents of that device Also reporting
- motion to suppress the evidence Also reporting
- dubbed “Cop City.” Also reporting
- search and seize people’s devices without a search warrant or court order Also reporting
Continue Reading
AI Agents Automate Post-Exploitation Task
A newly uncovered intrusion suggests threat actors are leveraging autonomous AI tools to streamline lateral movement and enumeration.
Hotel Wi-Fi DNS Hijacks Target M365
Researchers report that compromised hotel network gateways are redirecting business travelers to sophisticated phishing portals.
US Visa Curbs Target Cybercrime Networks
New policy restrictions leverage the Immigration and Nationality Act to deny entry to foreign nationals linked to digital fraud.