[tooling] · · 1 min read
US Prosecutes Citizen for Using 'Duress Password' to Wipe Phone at Airport
Sam Tunick faces rare charges after allegedly using GrapheneOS's duress feature to wipe his device during a border search, raising questions about encryption and digital rights.
By ByteBulletin Editors · Editorial Team
The US government is prosecuting American citizen Sam Tunick for allegedly using a 'duress password' to wipe his phone when federal agents tried to seize it at Atlanta's Hartsfield-Jackson airport on January 24th, 2025. The case, which hinges on a rarely-used statute against destroying property to prevent seizure, centers on Tunick's use of a feature in the privacy-focused Android operating system GrapheneOS.
According to court filings, agents detained Tunick and questioned him about child exploitation images—a claim his lawyers call "a pretext for a fishing expedition" into his ties to the Stop Cop City movement. Tunick's attorneys argue the detention and seizure were unlawful, noting agents refused him access to a lawyer, did not provide a warrant, and failed to inform him of his rights. The government counters that a warrant was unnecessary because Tunick had not formally entered the US.
The case tests the boundaries of digital privacy at borders, where courts have historically granted authorities broad latitude. GrapheneOS's duress password feature—designed to allow users to unlock a decoy profile or wipe the device under coercion—is legal software, but using it to thwart seizure may invite legal liability. As Marlon Kautz of the Atlanta Solidarity Fund told The Guardian, "We all have a right to secure our private data against unconstitutional searches."
For developers and privacy-conscious users, the prosecution sends a chilling signal: even citizens exercising technical self-defense at the border may face criminal charges. With the Trump administration intensifying scrutiny of travelers' devices, the only reliable protection may be to carry no data at all—an increasingly untenable position.
SOURCES
SHARE
RELATED
[tooling] ·
serve-avd: A Local Streaming Server for Android Emulators, Built for AI Agent Workflows
Open-source tool lets you host and stream Android emulators over HTTP/WebSocket, enabling remote access and direct integration with AI coding agents like Codex and Cursor.
[tooling] ·
awsmux runs one AWS CLI command across hundreds of accounts in parallel — safely
A new open-source tool fans out AWS CLI commands across a fleet of accounts with STS verification, an approval gate for mutations, and built-in MCP support for AI agents.
[tooling] ·
Hugging Face CEO Demands 'Radical Transparency' After OpenAI Agent Breached Its Systems
Clem Delangue calls for OpenAI to release attack traces and commit $100M in compute to bolster open-source defenses following what he calls the first autonomous agent cyberattack.