US Citizen Charged After GrapheneOS Duress PIN Wipes Phone During Airport Search
US Citizen Charged After GrapheneOS Duress PIN Wipes Phone During Airport Search
Federal Prosecution Over GrapheneOS Duress PIN
A US citizen in Atlanta is facing federal charges after his GrapheneOS-powered smartphone wiped its data during a Customs and Border Protection (CBP) search at Hartsfield-Jackson Atlanta International Airport. The Department of Justice is prosecuting the individual, Sam Tunick, under a federal statute that criminalizes the destruction of property to prevent it from being seized.
The case centers on the use of a "duress PIN"—a security feature in GrapheneOS that allows a user to enter a specific passcode that irreversibly wipes the device and its eSIMs. Prosecutors argue this was an intentional act to destroy evidence, while the defense contends the search violated constitutional rights and that the evidence should be suppressed.
Case Background and Legal Conflict
The Airport Incident
On January 24 of the previous year, Sam Tunick was stopped for questioning upon returning from the Dominican Republic. According to court testimony, federal agents had already flagged Tunick for investigation regarding "suspected terrorism activities" due to alleged associations with the movement against "Cop City," a police training facility in Atlanta.
During the interrogation, agents repeatedly requested that Tunick unlock his phone. When he finally provided a passcode, the device appeared to restart, the screen flashed, and all data was lost. The defense claims Tunick was denied access to a lawyer four times and was not read his rights or presented with a warrant.
The "Border Search Exception"
This case highlights the tension between privacy rights and the "border search exception," a long-standing legal doctrine. As noted by legal experts and contributors in the community:
"The border search doctrine says that border agents do not need a reason to examine you or your possessions when you are entering the country. They do not need to believe that you are doing something wrong or committing a crime."
While border agents have broad authority to search devices, the defense argues that the specific statute used for the charge—which prohibits destroying property to prevent seizure—may not apply to a routine search where the device was not yet being seized.
Technical Implications for Privacy Software
GrapheneOS and the Duress PIN
GrapheneOS is an open-source, privacy-hardened operating system for Google Pixel phones. The duress PIN is designed as a last-resort security measure. However, cybersecurity experts warn that treating the use of such tools as evidence of criminal intent could criminalize the OS itself.
Christophe Boutry, a surveillance expert, noted that authorities in other regions, such as Catalonia, Spain, have already begun profiling users of Pixel phones under the assumption that they are running GrapheneOS and are involved in criminal activity.
The Debate Over Plausible Deniability
Technical discussions following the case suggest that a "wipe" function is a high-risk strategy because it provides a clear signal of intent to destroy data. Experts and users suggest alternative "plausible deniability" strategies:
- Decoy Profiles: Instead of wiping the device, a duress PIN could boot the phone into a "sanitized" profile containing innocuous data, making the user appear compliant while protecting sensitive information.
- Hidden Volumes: Similar to VeraCrypt, some suggest cryptographically indistinguishable hidden partitions that are impossible to prove exist without the correct key.
- Travel-Specific Devices: The most conservative security advice remains using a "burner" or travel-specific device that contains no sensitive data, which is then wiped and restored upon return.
Summary of Legal and Technical Risks
| Action | Potential Legal/Technical Risk |
|---|---|
| Using Duress PIN | May be interpreted as "destruction of evidence" if the wipe occurs during an active investigation. |
| Refusing Unlock | May lead to prolonged detention or seizure of the device for forensic imaging. |
| Using Privacy OS | May lead to profiling by border agents who associate hardened OSs with criminal activity. |
| Travel Backups | Safest approach; involves wiping the device before travel and restoring from an encrypted backup after crossing the border. |