What Happened at Atlanta's Hartsfield-Jackson Airport?
A federal case with sweeping implications for border phone search privacy is now underway in the United States. Sam Tunick, an American citizen, is being prosecuted by federal authorities after he allegedly used a "duress password" that triggered the automatic wiping of his phone when agents attempted to seize and search the device at Atlanta's Hartsfield-Jackson International Airport on January 24th, 2025. The case, first reported by The Verge, represents one of the first known instances of the US government using a rarely-invoked federal statute to criminally charge a citizen specifically for protecting data on a personal device at the border.
Federal agents detained Tunick at the airport, citing an investigation into child exploitation images as their justification for seizing his phone. However, Tunick's legal team has forcefully pushed back on this framing. In a motion filed by his lawyers, they argue the child exploitation angle was nothing more than "a pretext for a fishing expedition into Mr Tunick's connections" to the Stop Cop City movement — a political activist network in Atlanta that has opposed the construction of a large police training facility in the city. The defence's position reframes the case entirely: not as a criminal act, but as the politically motivated targeting of a citizen for his associations and protected speech.
The government, for its part, is leaning on a little-known and rarely-used federal statute that criminalises the destruction or damaging of property to obstruct law enforcement authority. Prosecutors claim that by entering a duress password — a feature built into certain security-conscious mobile operating systems and apps that wipes data when triggered — Tunick deliberately destroyed evidence and interfered with a lawful search. The legal argument is novel and, many legal experts argue, deeply troubling for anyone who values digital privacy as a fundamental right.
What Is a Duress Password and Why Do Privacy Professionals Use It?

For developers, IT professionals, and security-conscious users, a duress password is not an obscure hacking tool — it is a well-established, legitimate security mechanism. The concept is straightforward: a secondary password or PIN is configured on a device or application that, when entered, either wipes the device's contents or presents a sanitised decoy environment, hiding sensitive data from anyone forcing access under duress. The feature is explicitly designed for scenarios where a user is coerced into unlocking a device by a third party — whether a criminal, an authoritarian government, or, as this case highlights, law enforcement at a border crossing.
Security applications including certain encrypted messaging apps, password managers, and even some Android-based custom ROMs have offered duress mode functionality for years. Privacy-focused tools like GrapheneOS — an open-source, hardened Android operating system — have long included duress password features as a core security offering. The Electronic Frontier Foundation (EFF) has extensively documented the legal risks travellers face at US borders and has consistently recommended security measures, including data minimisation before travel, as legitimate defensive practices.
The Tunick case now puts the legality of using such features squarely in the crosshairs of federal prosecution. Privacy professionals across the industry are watching closely, as the outcome could determine whether employing a duress password — a feature explicitly built for protecting data under coercion — constitutes a criminal act on US soil.
"The government's theory here is alarming: it suggests that designing or using security tools to protect your data from forced access could itself become a federal crime. That has consequences far beyond one person's case."
— Digital privacy legal analyst commenting on the Tunick caseThe Obscure Federal Statute That Could Reshape Border Search Law
The statute the government is deploying in this case is one that legal scholars describe as extraordinarily broad in its potential application. By characterising Tunick's phone as "property" that was being destroyed to impede a lawful search, prosecutors are stretching a law typically associated with physical obstruction of justice into the digital realm. Legal experts writing for outlets including TechCrunch have noted that no comparable case has resulted in a criminal conviction in the United States, making this prosecution a genuine test of how far the government can extend obstruction statutes into the domain of personal data security.
Critically, the legal landscape around border searches of electronic devices remains contested and unsettled. US Customs and Border Protection (CBP) has long maintained that it has near-unlimited authority to search electronic devices at the border without a warrant — a position that stands in stark contrast to the Fourth Amendment protections that apply within the country's interior. The Supreme Court's landmark 2014 decision in Riley v. California established that police generally need a warrant to search a mobile phone following an arrest, but border searches operate under a different legal framework — one that courts have not yet definitively clarified with respect to encrypted devices, according to analysis published by the American Civil Liberties Union (ACLU).
What makes the Tunick case even more legally complex is the First Amendment dimension raised by his lawyers. If the government is — as the defence alleges — using the border search as a pretext to investigate protected political activity linked to the Stop Cop City movement, then the prosecution may face constitutional challenges well beyond Fourth and Fifth Amendment arguments. The intersection of political surveillance, border search authority, and encryption rights creates a legal landscape that is, by any measure, unprecedented.
Why Developers and Privacy Professionals Should Be Alarmed Right Now

For the developer and privacy professional community, this case carries implications that extend well beyond one individual's legal predicament. If the US government successfully establishes that activating a security feature — one built into a device by its manufacturer or by a third-party security application — constitutes criminal obstruction of justice, the legal risk profile of using privacy tools changes overnight.
Consider the practical consequences. Open-source projects that implement duress modes — including encrypted messaging platforms, password managers, and hardened operating systems — could find themselves in the position of shipping features that the US government deems criminal to use. Corporate IT and security teams that advise employees to enable full-disk encryption, remote wipe capabilities, or duress modes before international travel — standard practice for enterprise security — could be exposing their staff to criminal liability when crossing into the United States. The chilling effect on legitimate security practice would be profound.
From a European digital sovereignty perspective, this case is also a pointed reminder of why the movement toward European-hosted, European-governed digital infrastructure matters. GDPR compliance already requires organisations to implement appropriate technical measures to protect personal data — which explicitly includes encryption and access controls. European travellers entering the US, or companies that route sensitive data through US systems or employ staff who travel there, now face a legal environment in which the very tools designed to ensure data protection may be treated as obstruction of justice by US authorities. The tension between GDPR's data protection mandates and US border search authority has never been more acute.
| Security Measure | Common Use Case | US Border Legal Risk (Post-Tunick) |
|---|---|---|
| Duress Password | Wipes device under coercion | High — under active prosecution |
| Full-Disk Encryption | Standard device security | Medium — contested legal territory |
| Remote Wipe | Enterprise MDM standard | Medium — legally unclear |
| Data Minimisation Before Travel | Pre-travel security hygiene | Low — widely recommended by EFF |
| VPN Usage | Network privacy in transit | Low — generally legal |
The Stop Cop City Connection: When Political Activity Meets Border Surveillance
The Stop Cop City movement context adds a deeply troubling political dimension to what the government frames as a straightforward obstruction case. Stop Cop City is a grassroots activist campaign that has attracted significant attention and, according to Tunick's lawyers, significant federal law enforcement scrutiny. The defence's contention that the child exploitation investigation was pretextual — and that the real target was Tunick's political associations — speaks to a broader pattern of concern among civil liberties organisations regarding the use of border search authority as a tool of domestic political surveillance.
The ACLU and EFF have both documented cases in which US border agents have searched devices belonging to journalists, activists, and lawyers, raising serious questions about whether border search powers are being used in ways that chill constitutionally protected First Amendment activity. As Wired has reported extensively, border searches of electronic devices have increased significantly in recent years, and the lack of a warrant requirement at the border creates a surveillance vector that bypasses the judicial oversight normally required for domestic investigations.
If Tunick's defence is correct — that he was targeted for political reasons — this case becomes not just a privacy law case, but a civil liberties case with implications for anyone whose political associations, journalism work, or activist connections might make them a target for scrutiny at a US port of entry.
Practical Steps for Privacy-Conscious Travellers Entering the US
In light of the Tunick case, digital security experts and civil liberties organisations are doubling down on longstanding travel security guidance — while acknowledging that the legal environment has just become more uncertain. The EFF's guide to border searches recommends that travellers consider travelling with a temporary or "travel" device containing only
Originally reported by The Verge. Summarised and curated by European Purpose.