Skip to content

Notes ·

The GrapheneOS Duress Password Case Is Becoming a Test of Whether Privacy Can Be Treated as Obstruction

Slashdot, summarizing new reporting from The New York Times, covers the Samuel Tunick case: an American charged with a felony after allegedly entering a GrapheneOS duress password during a CBP phone search in Atlanta.

In July I wrote about a duress password being treated as destruction of evidence. I have been following this because it could become an important test of what happens when strong privacy tools collide with government searches. The case is getting considerably more attention now after The New York Times interviewed Tunick and federal officials.

Tunick was returning through Atlanta in January 2025 when CBP pulled him into secondary inspection and demanded access to his Google Pixel running GrapheneOS. After repeated demands, he provided a passcode. Officers entered it. According to the government, the screen went blank, flashed, and restarted. The contents were gone.

Reporting has identified the credential as GrapheneOS's optional duress password, designed to erase the device rather than unlock it under coercion. The indictment itself does not name GrapheneOS or call it a duress password — it alleges Tunick knowingly caused the contents to be deleted to prevent the government from taking the property into custody. That distinction matters because this is still an allegation, not a court finding.

Prosecutors charged him under 18 U.S.C. § 2232(a), covering destruction or removal of property to prevent an authorized search or seizure — as much as five years in prison. U.S. Attorney Theodore Hertzberg said people who destroy property, including data, to prevent a lawful search should expect prosecution. The word I keep coming back to is lawful.

Tunick's attorneys are challenging the detention, interrogation, and search itself. They say the government was interested in his association with the movement opposing Atlanta's Cop City project and used other allegations as a pretext. At a July evidentiary hearing, officers acknowledged they did not have evidence that Tunick possessed child sexual abuse material despite that apparently being raised during interrogation. Tunick is not charged with any crime connected to Defend the Atlanta Forest. Briefing on the suppression motion runs through October, so the court has not yet decided whether the underlying search was lawful. That may end up determining much more than whether one person should have entered a particular password.

Refusing a password, encrypting a device, traveling without sensitive information, and using a duress credential sit on a spectrum of protecting your own data. At what point does privacy become destruction of evidence? The government appears to argue that once an authorized seizure is underway, intentionally eliminating the data can cross that line. But if the search was not lawful in the first place, can protecting your information from that search itself become the crime?

GrapheneOS did not invent duress credentials or remote wipe. What it did was make an unusually strong version available on an ordinary smartphone. Now we may get a federal court decision defining some of the legal consequences of actually using it.

Tunick told The New York Times that the government does not own our communications or relationships and that people have to defend their fundamental right to privacy. A privacy feature is easy to defend in theory. The real test comes when someone uses it at exactly the moment it was designed for.

Read the Slashdot summary of the Times reporting.

All notes