Border Device Wipe Leads to Indictment
A federal case involving a duress password suggests new legal risks for travelers using privacy-focused mobile software.
A federal prosecution in Atlanta is highlighting the intersection of advanced privacy features and border security mandates. The U.S. Justice Department has charged an American citizen, Samuel Tunick, with allegedly destroying evidence after he provided border agents with a secondary passcode that triggered a factory reset on his device.
The Mechanics of Device Wiping
The case centers on the functionality of GrapheneOS, a privacy-centric custom Android operating system. The software includes a duress feature specifically designed to protect user data from unauthorized access. When a user enters this pre-configured passcode, the device deliberately wipes the contents of that device rather than unlocking the normal user profile.
Prosecutors contend that by providing this code to authorities at Atlanta’s Hartsfield-Jackson airport on January 24, 2025, the defendant violated a federal statute prohibiting the knowing destruction of property to prevent government seizure. Legal experts suggest this is an unprecedented application of the law, marking a potential shift in how federal agencies address encrypted hardware.
Legal Challenges to Border Authority
Tunick’s legal team has filed a motion to suppress the evidence, arguing that the initial seizure of his phone was unlawful. The defense claims that agents lacked proper suspicion for the search and that the defendant was denied access to legal counsel during the secondary inspection process.
The defense further alleges that the inquiry was not related to its stated premise—investigating child exploitation imagery—but was instead linked to the defendant's affiliation with the “Cop City.” protest movement. This friction underscores the long-standing legal debate regarding the government’s ability to search and seize people’s devices without a search warrant or court order while individuals are in the process of entering the country.
The Limits of Privacy Tools
Security experts note that while duress features provide a technical safeguard, they may also serve as the basis for legal escalation. The government’s indictment specifically highlights the digital erasure as a criminal act, creating a scenario where the act of protecting one’s privacy is interpreted as an obstruction of justice.
“I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.”
— Runa Sandvik, digital security expert and founder of the security consultancy firm Granitt
- January 24, 2025: Date the device was seized at Hartsfield-Jackson airport.
- 1 federal statute cited in the indictment for destruction of property.
- 1 motion to suppress evidence currently pending before the court.
Implications for Cross-Border Privacy
For individuals traveling with encrypted or privacy-hardened devices, this case signals a potential increase in scrutiny. If the court upholds the government’s interpretation of the law, it could establish a precedent where using built-in software security features is framed as criminal interference. Moving forward, the outcome of the pending motion to suppress could dictate whether travelers are legally required to keep their devices in a state accessible to border agents or if current protections remain legally viable.
Sources
- TechCrunch Original source
- to The Guardian Also reporting
- deliberately wipes the contents of that device Also reporting
- motion to suppress the evidence Also reporting
- dubbed “Cop City.” Also reporting
- search and seize people’s devices without a search warrant or court order Also reporting
Continue Reading
Boston Scientific earnings hit by cyberattack fallout
Medical device giant warns August intrusion will dent Q3 and full-year sales and earnings as recovery drags on.
Spending Spree Unravels $240M Crypto Heist
Young scammers' lavish purchases led FBI to suspects in $240M bitcoin theft.
Grindr's £26M Settlement and the Stakes for User Trust
Grindr agrees to pay £26m to settle U.K. claims over pre-2020 data sharing, without admitting liability.