Uncategorized

The Government’s Indictment of an Activist Tests Whether You Have a Right to Wipe Your Phone

An Atlanta activist faces federal charges after giving border agents a duress passcode that deleted all of the data from his phone during an airport interrogation in 2025.

Privacy advocates say the indictment raises questions about whether data-wiping features, like the duress passcode in GrapheneOS installed on Samuel Tunick’s Google Pixel phone in this case, provide a tool to keep your data from search and seizure or whether they could open you up to additional scrutiny or similar charges.

The indictment of Tunick, an outspoken activist in the Stop Cop City movement, stems from his detainment while re-entering the US from a trip in January 2025. After being repeatedly pressed to turn over his phone’s passcode, Tunick is accused of giving the duress passcode. According to the indictment, “the screen went blank, flashed several times and the phone appeared to restart” after the code was entered. 

Tunick’s legal team confirmed he had GrapheneOS installed on his Google Pixel phone — a custom Android-based operating system that includes the passcode data wipe feature.

Tunick’s attorney said in a motion to suppress evidence (PDF) that the detention, which agents claimed was about alleged child sexual abuse materials, was a “fishing expedition into Mr. Tunick’s connections with the Defend the Atlanta Forest movement.”

It highlights the risks activists face when going through airport security — when federal agents have an opportunity to detain, interrogate or search phones or other devices, Maria Villegas Bravo, a legal counsel at the Electronic Privacy Information Center, told CNET.

“More and more political activism is done online through conversations with associates and finding like-minded people on social media,” Villegas Bravo said in an email. “Phones contain incredibly sensitive information, from contact information to organizing messages to location history.”

Representatives for the Department of Justice and Tunick’s legal team didn’t immediately respond to requests for comment.

TSA agents screen airline passengers before allowing them to continue into the country.
Border authorities have less stringent requirements to meet before detaining you and seizing your phone. It’s legally contested which constitutional rights you even have at the US border.Patrick T. Fallon/AFP/Getty Images

What the case means for your privacy

The case could decide how much digital data security — and which constitutional rights — you legally have at the US border.

“I hope people understand that the charges against me are meant to intimidate people against protecting their data and their privacy, and the government hopes to set a precedent that no one has the right to privacy,” Tunick told 404 Media during an interview.

Bill Budington, senior technologist at the Electronic Frontier Foundation, told TechCrunch that he hadn’t seen a court case centered on the duress passcode feature before.

The indictment hinges on a federal statute that makes it illegal to knowingly destroy property that could be used as evidence in a criminal trial. The case tests whether data on a mobile phone would be governed by those same rules.

“We would not recommend wiping devices in this way when under legal scrutiny,” Budington told CNET over email. “A judge is unlikely to view this action as compelling, no matter what the intention.”

Tunick’s attorney argued (PDF) that he wasn’t given cause for his detainment, wasn’t read his rights and wasn’t provided access to an attorney upon request.

Villegas Bravo called the interrogation behavior described in court documents disturbing, but unsurprising, saying it “falls in line with [CBP’s] escalation of intimidation tactics.”

“Despite the fact that searches of the contents of cellphones are among the most invasive searches that can be done in modern day, the courts have given deference to law enforcement at the border and lowered the requirements needed to search a phone,” Villegas Bravo wrote. “Depending on the judicial circuit, border searches may be done with mere administrative subpoenas or without any judicial authorization at all.”

A Google Pixel 6 phone stands upright on a desk with its lock screen on display.

GrapheneOS’ duress passcode feature is a stealthy way to delete all of your on-device data on a Google Pixel phone, like the one pictured above. But it might not be the safest way to protect yourself against border authorities.

Patrick Holland/CNET

How to keep your data private when traveling

While a duress passcode provides on-device data security, the Tunick case makes clear that it isn’t without risk. The experts I spoke to shared other advice to keep your data safe — while staying out of court.

Bravo and Budington both told CNET that minimizing the amount of data on your phone is the best way to avoid any issues at the border.

According to Budington, wiping your device and removing all sensitive communications is the only way to truly ensure that data doesn’t fall into the wrong hands. He also acknowledged that this advice is impractical for some people, and that a dedicated travel phone is an easier way to achieve the same results.

“Using a travel device separate from your personal mobile phone may be prudent. This will allow you to keep the history of your communications on the device you don’t travel with safely at home,” Budington wrote. “Travelers should take precautions not to communicate on the new device information they would not want seen by others, including border security.”

Crossing the border with your main mobile phone carries inherent data security risks, especially when the government tries to argue that your Fifth Amendment right not to incriminate yourself doesn’t apply until after you’re waved through onto US soil. Though it’s your legal right not to share your mobile phone access with border authorities, they can still confiscate your device before letting you into the country. Villegas Bravo warned that DHS has plenty of tools to access the data contained within your phone, even without your passcode.

“Technology like Cellebrite and Graykey can bypass passwords and encryption on all but the newest software updates that devices have rolled out,” Villegas Bravo wrote. “If law enforcement takes physical possession of your phone, the entire contents of your device is up for grabs, and there are few systems available that offer sufficient protection against these universal forensic extraction devices.”

Villegas Bravo said that this is likely why Tunick felt the need to use a duress passcode, but cautioned against anyone else doing the same thing. Destroying data increases the likelihood of litigation, and that’s a costly and stressful experience, even if you’re constitutionally protected, and the suit is eventually dropped.

Some things you can do instead: “Leave your phone on airplane mode, always update your operating system software, and use alphanumeric passcodes instead of biometric recognition like fingerprint and face ID,” Villegas Bravo wrote.

The EFF has a guide on how to minimize your data exposure at the US border, detailing your rights and sharing ways to protect your digital privacy.

Also, keep in mind that the Fifth Amendment protects you against self-incrimination: Border agents can’t force you to decrypt data, divulge passcodes or answer questions.

“Law enforcement can coerce individuals to ‘consent’ to the search of their device,” Villegas Bravo wrote. “It’s imperative to not comply in advance whenever it is within your capability to do so.”

Source link

Visited 1 times, 1 visit(s) today

Leave a Reply

Your email address will not be published. Required fields are marked *