Notes ·
The GrapheneOS Duress Password Case Is Becoming a Test of Whether Privacy Can Be Treated as Obstruction
Source
American Who Wiped His Phone With 'Duress' Password During Border Search Gets Felony Charges
Slashdot, summarizing new reporting from The New York Times
In July I wrote about a duress password being treated as destruction of evidence when federal prosecutors charged an American who allegedly entered a GrapheneOS duress password during a CBP phone search.
I have been following the Samuel Tunick case because it could become an important test of what happens when strong privacy tools collide with government searches.
The case is getting considerably more attention now after The New York Times interviewed Tunick and federal officials about the prosecution.
Tunick was returning to the United States through Atlanta in January 2025 when Customs and Border Protection officers pulled him into secondary inspection and demanded access to his Google Pixel.
The phone was running GrapheneOS.
After repeated demands for access, Tunick eventually provided officers with a passcode. The officers entered it. According to the government's account, the screen went blank, flashed several times and restarted.
The phone's contents were gone.
Reporting has identified the credential as GrapheneOS's optional duress password, which is deliberately designed to erase the device rather than unlock it when someone is being forced to provide a credential.
There is an important distinction in the actual court record: the indictment itself does not identify GrapheneOS or call the credential a duress password. It alleges that Tunick knowingly caused the contents of the Pixel to be deleted to prevent the government from taking the property into custody.
That distinction matters because this is still an allegation, not a finding by the court.
Federal prosecutors charged Tunick under 18 U.S.C. § 2232(a), a rarely discussed statute covering destruction or removal of property to prevent an authorized search or seizure. The charge carries as much as five years in prison.
The government's position is becoming much clearer.
U.S. Attorney Theodore Hertzberg said people who destroy property, including data, to prevent a lawful search and seizure should expect prosecution.
The word I keep coming back to is lawful.
Tunick's attorneys are challenging the legality of the detention, interrogation and search itself. They say the government was actually interested in his association with the movement opposing Atlanta's Cop City project and used other allegations as a pretext to get into his phone.
At a July evidentiary hearing, officers acknowledged they did not have evidence that Tunick possessed child sexual abuse material despite that apparently being raised during his interrogation.
Tunick is not charged with any crime connected to the Defend the Atlanta Forest movement.
His lawyers are asking the court to suppress evidence and statements from the airport encounter. Briefing on that motion currently runs through October, so the court has not yet decided whether the underlying search and seizure were lawful.
That may end up determining much more than whether one person should have entered a particular password.
There is a broader question here about what ownership of our own data actually means.
Refusing to provide a password is one thing.
Encrypting a device is another.
Traveling without sensitive information is another.
Configuring a device so that it automatically reboots into a stronger encrypted state is another.
And a duress password sits farther down that same spectrum by intentionally making the information unavailable.
At what point does protecting data stop being privacy and become destruction of evidence?
The government appears to be arguing that once an authorized seizure is underway, intentionally eliminating the data can cross that line.
But that creates another uncomfortable question.
If the search was not lawful in the first place, can protecting your own information from that search itself become the crime?
That is why this case matters far beyond GrapheneOS.
GrapheneOS did not invent the idea that people should be able to protect information when they are coerced. Duress credentials, encrypted containers, remote wipe systems and automatically expiring information have existed for years.
What GrapheneOS did was make an unusually strong version of that protection available to an ordinary person carrying an ordinary smartphone.
Now we may get a federal court decision defining some of the legal consequences of actually using it.
Tunick told The New York Times that the government does not own our communications or relationships and that people have to defend their fundamental right to privacy.
Whatever eventually happens to his case, I think that is the larger issue worth following.
A privacy feature is easy to defend in theory.
The real test comes when someone uses it at exactly the moment it was designed for.