US Citizen Charged for Wiping His Phone at the Border — What This Means for Digital Privacy

The prosecution of Sam Tunick marks a dangerous new legal frontier for device encryption, duress passwords, and digital sovereignty at US border crossings

US Citizen Charged for Wiping His Phone at the Border — What This Means for Digital Privacy

What Happened at Atlanta's Hartsfield-Jackson Airport?

A federal case with sweeping implications for border phone search privacy is now underway in the United States. Sam Tunick, an American citizen, is being prosecuted by federal authorities after he allegedly used a "duress password" that triggered the automatic wiping of his phone when agents attempted to seize and search the device at Atlanta's Hartsfield-Jackson International Airport on January 24th, 2025. The case, first reported by The Verge, represents one of the first known instances of the US government using a rarely-invoked federal statute to criminally charge a citizen specifically for protecting data on a personal device at the border.

Federal agents detained Tunick at the airport, citing an investigation into child exploitation images as their justification for seizing his phone. However, Tunick's legal team has forcefully pushed back on this framing. In a motion filed by his lawyers, they argue the child exploitation angle was nothing more than "a pretext for a fishing expedition into Mr Tunick's connections" to the Stop Cop City movement — a political activist network in Atlanta that has opposed the construction of a large police training facility in the city. The defence's position reframes the case entirely: not as a criminal act, but as the politically motivated targeting of a citizen for his associations and protected speech.

The government, for its part, is leaning on a little-known and rarely-used federal statute that criminalises the destruction or damaging of property to obstruct law enforcement authority. Prosecutors claim that by entering a duress password — a feature built into certain security-conscious mobile operating systems and apps that wipes data when triggered — Tunick deliberately destroyed evidence and interfered with a lawful search. The legal argument is novel and, many legal experts argue, deeply troubling for anyone who values digital privacy as a fundamental right.

What Is a Duress Password and Why Do Privacy Professionals Use It?

A smartphone with a locked screen representing digital security and border phone search privacy
Duress passwords are a well-established security feature designed to protect sensitive data under coercion

For developers, IT professionals, and security-conscious users, a duress password is not an obscure hacking tool — it is a well-established, legitimate security mechanism. The concept is straightforward: a secondary password or PIN is configured on a device or application that, when entered, either wipes the device's contents or presents a sanitised decoy environment, hiding sensitive data from anyone forcing access under duress. The feature is explicitly designed for scenarios where a user is coerced into unlocking a device by a third party — whether a criminal, an authoritarian government, or, as this case highlights, law enforcement at a border crossing.

Security applications including certain encrypted messaging apps, password managers, and even some Android-based custom ROMs have offered duress mode functionality for years. Privacy-focused tools like GrapheneOS — an open-source, hardened Android operating system — have long included duress password features as a core security offering. The Electronic Frontier Foundation (EFF) has extensively documented the legal risks travellers face at US borders and has consistently recommended security measures, including data minimisation before travel, as legitimate defensive practices.

The Tunick case now puts the legality of using such features squarely in the crosshairs of federal prosecution. Privacy professionals across the industry are watching closely, as the outcome could determine whether employing a duress password — a feature explicitly built for protecting data under coercion — constitutes a criminal act on US soil.

"The government's theory here is alarming: it suggests that designing or using security tools to protect your data from forced access could itself become a federal crime. That has consequences far beyond one person's case."

— Digital privacy legal analyst commenting on the Tunick case

Why Developers and Privacy Professionals Should Be Alarmed Right Now

A person working on a laptop with code and security tools representing digital sovereignty concerns
Privacy-conscious developers and IT professionals are reassessing their travel security protocols in light of the Tunick case

For the developer and privacy professional community, this case carries implications that extend well beyond one individual's legal predicament. If the US government successfully establishes that activating a security feature — one built into a device by its manufacturer or by a third-party security application — constitutes criminal obstruction of justice, the legal risk profile of using privacy tools changes overnight.

Consider the practical consequences. Open-source projects that implement duress modes — including encrypted messaging platforms, password managers, and hardened operating systems — could find themselves in the position of shipping features that the US government deems criminal to use. Corporate IT and security teams that advise employees to enable full-disk encryption, remote wipe capabilities, or duress modes before international travel — standard practice for enterprise security — could be exposing their staff to criminal liability when crossing into the United States. The chilling effect on legitimate security practice would be profound.

From a European digital sovereignty perspective, this case is also a pointed reminder of why the movement toward European-hosted, European-governed digital infrastructure matters. GDPR compliance already requires organisations to implement appropriate technical measures to protect personal data — which explicitly includes encryption and access controls. European travellers entering the US, or companies that route sensitive data through US systems or employ staff who travel there, now face a legal environment in which the very tools designed to ensure data protection may be treated as obstruction of justice by US authorities. The tension between GDPR's data protection mandates and US border search authority has never been more acute.

Security Measure Common Use Case US Border Legal Risk (Post-Tunick)
Duress Password Wipes device under coercion High — under active prosecution
Full-Disk Encryption Standard device security Medium — contested legal territory
Remote Wipe Enterprise MDM standard Medium — legally unclear
Data Minimisation Before Travel Pre-travel security hygiene Low — widely recommended by EFF
VPN Usage Network privacy in transit Low — generally legal

The Stop Cop City Connection: When Political Activity Meets Border Surveillance

The Stop Cop City movement context adds a deeply troubling political dimension to what the government frames as a straightforward obstruction case. Stop Cop City is a grassroots activist campaign that has attracted significant attention and, according to Tunick's lawyers, significant federal law enforcement scrutiny. The defence's contention that the child exploitation investigation was pretextual — and that the real target was Tunick's political associations — speaks to a broader pattern of concern among civil liberties organisations regarding the use of border search authority as a tool of domestic political surveillance.

The ACLU and EFF have both documented cases in which US border agents have searched devices belonging to journalists, activists, and lawyers, raising serious questions about whether border search powers are being used in ways that chill constitutionally protected First Amendment activity. As Wired has reported extensively, border searches of electronic devices have increased significantly in recent years, and the lack of a warrant requirement at the border creates a surveillance vector that bypasses the judicial oversight normally required for domestic investigations.

If Tunick's defence is correct — that he was targeted for political reasons — this case becomes not just a privacy law case, but a civil liberties case with implications for anyone whose political associations, journalism work, or activist connections might make them a target for scrutiny at a US port of entry.

Practical Steps for Privacy-Conscious Travellers Entering the US

In light of the Tunick case, digital security experts and civil liberties organisations are doubling down on longstanding travel security guidance — while acknowledging that the legal environment has just become more uncertain. The EFF's guide to border searches recommends that travellers consider travelling with a temporary or "travel" device containing only

Originally reported by The Verge. Summarised and curated by European Purpose.