Digital Rights
The duress password trap: when wiping your phone becomes a crime
Sam Tunick faces federal charges after using a GrapheneOS duress password to wipe his phone during a border detention. The case tests whether encryption features can be criminalized and challenges the reach of warrantless border searches.
Emmanuel Fabrice Omgbwa Yasse AI-assisted
2026-07-31 · 2 min read

What happened at the airport
On January 24, 2025, federal agents detained American citizen Sam Tunick at Atlanta's Hartsfield-Jackson Airport. According to a motion filed by his lawyers, agents questioned him about child exploitation images, a charge the defense calls "a pretext for a fishing expedition" into his ties to the Stop Cop City movement. Tunick provided a password. Instead of unlocking his phone, it triggered a factory reset. The device erased itself as regulators expand their reach into tech.
The obscure statute and the duress password
The government charges Tunick under an obscure federal statute that makes it illegal to destroy property to prevent seizure. At the heart of the case is the duress password feature in GrapheneOS, a privacy-focused Android fork. The feature is designed for extreme scenarios: a user gives a special passcode that wipes the device rather than decrypting it. Prosecutors argue Tunick knowingly destroyed evidence. The defense counters that the detention and seizure were unlawful, and that Tunick had a right to protect his data from what they allege was an illegal search similar to opaque government actions seen in the DJI crackdown.
Border search rights and privacy precedent
Tunick's attorneys say agents refused him access to a lawyer, did not present a warrant, and failed to inform him of his legal rights. The government maintains that no warrant was needed because Tunick had not yet been granted permission to enter the United States. This case sits at the intersection of the border search exception, which historically allows warrantless searches at ports of entry, and the growing digital privacy expectations of citizens. Under the current administration, even American citizens face hours-long detentions and scrutiny of their social media accounts. A ruling against Tunick could set a precedent that using a duress password to protect personal data is itself a crime. The timing aligns with a broader trend of government authority expansion, as seen in the FCC's new retroactive powers.
Implications for activism and data security
"We all have a right to secure our private data against unconstitutional searches," Marlon Kautz of the Atlanta Solidarity Fund told the Guardian. "And we should, especially in a time of rising authoritarianism." The charge against Tunick warns activists that the features designed to protect them can be turned against them. If handing over a duress password becomes a crime, the safety tool becomes a trap. The need for robust data protection is underlined by sophisticated threats: early this year, researchers uncovered the first fully AI-run ransomware attack, and ransom demands have reached record levels. The Stop Cop City connection hints that Tunick may have been targeted for his political associations, raising questions about pretextual border stops and the future of digital rights.
Get the tech essentials in 3 minutes every morning
One email, every weekday, with what actually matters in AI and tech.