The U.S. Justice Department has brought forth charges against an American citizen, Samuel Tunick, for allegedly providing U.S. border authorities with a passcode that subsequently triggered a data wipe on his mobile device. This case is believed to be the first of its kind in the United States where federal prosecutors have charged an individual for the alleged destruction of data through the use of a "duress" password, a security feature built into certain phone software. The indictment, filed against Tunick, centers on an incident that occurred as he returned to the United States last year, raising significant legal questions about privacy rights at the border and the interpretation of federal statutes concerning the prevention of evidence destruction.
The Genesis of the Charges: A Duress Password and Border Interrogation
The core of the legal battle revolves around a specific feature found in GrapheneOS, a custom Android operating system known for its enhanced privacy and security. This operating system, which can be installed on many modern Google Pixel devices, includes a function allowing users to set a distinct passcode. When this "duress" passcode is entered, instead of unlocking the device, it is designed to intentionally erase all data stored on the phone.
According to reports and the indictment itself, Samuel Tunick, an Atlanta resident, was returning to the U.S. from overseas on January 24, 2025. Upon arrival at Atlanta’s Hartsfield-Jackson International Airport, he was subjected to a secondary inspection by U.S. Customs and Border Protection (CBP) officers. During this inspection, Tunick’s phone was seized. His legal team contends that this seizure was unlawful from its inception, arguing that CBP lacked the proper justification and that Tunick was denied his constitutional rights, including access to an attorney and notification of his legal rights, during the process.
The indictment alleges that Tunick provided a passcode to the border agents, which, when entered, caused the phone to "delete the digital contents" before it was officially seized. This act, prosecutors argue, falls under a federal statute, specifically 18 U.S. Code § 2232, which criminalizes the knowing destruction or damage of property to prevent its seizure by authorities. Tunick has pleaded not guilty to the charges.
Legal Arguments and Defense Strategies
Tunick’s attorneys have mounted a vigorous defense, filing a motion to suppress the evidence. Their primary argument is that the detention and seizure of Tunick’s phone were unlawful. They assert that CBP’s actions violated Tunick’s Fourth Amendment rights, which protect against unreasonable searches and seizures. The defense team also claims that the government’s initial pretext for demanding access to the phone – the search for child exploitation imagery – was unsubstantiated and that the true objective was to investigate Tunick’s involvement with the "Defend the Atlanta Forest" movement. This environmental group is actively opposing the development of a controversial law enforcement training facility in Atlanta, widely known as "Cop City."
The motion to suppress further details that border agents claimed they did not require a warrant to search Tunick’s phone because he had not yet officially crossed the U.S. border. This position aligns with the long-standing assertion by the U.S. government that it possesses broad authority to search and seize electronic devices at the border without a warrant or court order, until an individual is formally admitted into the country. This practice has been a subject of ongoing debate and legal challenges regarding the extent of privacy rights at international borders.
When Tunick entered the duress passcode, the indictment describes the event as follows: "the screen went blank, flashed several times and the phone appeared to restart." Despite this outcome, the authorities proceeded to seize the device. It was only after the seizure that Tunick was informed he was free to enter the United States.
Precedent-Setting Case and Expert Reactions
The prosecution of Samuel Tunick for activating a duress password on his phone is considered a landmark case, being the first known instance in the United States where federal prosecutors have pursued charges for such an action. Legal experts and cybersecurity professionals have expressed surprise and concern over the government’s strategy.
Matthew Dodge, an assistant federal public defender on Tunick’s legal team, highlighted the rarity of the specific federal statute being invoked in an indictment of this nature. This suggests that the government’s approach in this case is unconventional, potentially setting a new precedent for how digital evidence at the border is handled.
Security experts have echoed these sentiments. Bill Buddington, a senior staff technologist at the Electronic Frontier Foundation (EFF), and Runa Sandvik, a digital security expert and founder of the security consultancy firm Granitt, stated they had not encountered similar cases involving the use of duress passwords leading to criminal charges.
Sandvik commented, "I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years. I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders." She further advised, "With a little planning ahead of time, you can always download the data you need once you get to where you’re going." This statement underscores the growing awareness among privacy advocates about the risks associated with carrying sensitive digital information across borders.
Broader Implications for Digital Privacy and Border Security
The Tunick case brings to the forefront the complex and often contentious intersection of national security, border control, and individual privacy rights in the digital age. The U.S. government’s broad authority to conduct searches at the border is a well-established legal principle, stemming from the sovereign right of nations to control their borders and prevent illicit activities. However, the increasing reliance on electronic devices for communication, information storage, and personal data has amplified concerns about the scope and intrusiveness of these border searches.
The use of a duress password, intended as a security feature for users to protect their data in situations of coercion, has now become the subject of a criminal prosecution. This raises questions about whether the government can interpret the activation of such a feature as an intentional act of obstructing justice or destroying evidence, rather than a defensive measure by a user fearing potential misuse of their data.
The Electronic Frontier Foundation (EFF) has been a prominent advocate for digital privacy rights at the border. They provide resources and guides for individuals on how to protect their data and understand their rights when encountering border searches. Their ongoing work highlights the tension between government security imperatives and the expectation of privacy for individuals, even in the context of border crossings.
The Road Ahead: Legal Battles and Future Precedents
The Atlanta federal court overseeing the case is expected to rule on Tunick’s motion to suppress later this year. The outcome of this ruling could have significant implications for how similar cases are handled in the future. If the motion is granted, it could set a precedent for challenging the legality of border searches and seizures of electronic devices based on the specific circumstances of their access and any subsequent data alteration. Conversely, if the motion is denied, it could embolden prosecutors to pursue similar charges in cases involving data-wiping features on electronic devices.
A Justice Department spokesperson declined to comment on the ongoing case. The legal proceedings involving Samuel Tunick represent a critical juncture in the ongoing debate about digital privacy at the U.S. border, and the world of cybersecurity and civil liberties will be closely watching its resolution. The case underscores the evolving landscape of law enforcement’s access to digital information and the critical need for individuals to be aware of their rights and the potential legal ramifications of the technology they employ. The legal battle over Tunick’s phone could redefine the boundaries of digital privacy at the threshold of national borders.
