CLOSED NETWORK
no trackers

An Atlanta Man Used a Duress Password on His Phone. Now the Government Is Prosecuting Him for It.

Samuel Tunick entered a passcode that wiped his GrapheneOS Pixel during a border search at Atlanta's airport. Prosecutors call it a crime — the first known U.S. case charging someone over a duress password. Is erasing your own data, on your own device, obstruction of justice?

On 24 January 2025, Samuel Tunick landed at Hartsfield-Jackson and got pulled into secondary inspection. Border agents demanded the passcode to his phone — a Google Pixel running GrapheneOS. According to his own defense filing, he gave them one. The screen went blank, flashed a few times, and the phone appeared to restart. He'd handed over a duress password: a code that, instead of unlocking the device, wipes it. Eighteen months later, federal prosecutors in Atlanta have charged him with a crime for it. As far as anyone can tell, it's the first case of its kind in the country.

The one-sentence version: The government isn't charging Tunick for what was on his phone — it's charging him for making the phone unreadable, under an old statute meant to stop people from destroying evidence about to be seized. The question the court now has to answer is whether entering your own passcode, on your own device, during a warrantless border search, is "destruction of property" — or just a citizen exercising a right the Constitution is supposed to protect.

Why I'm covering a single arrest on a privacy show

Because this is the exact moment the abstract becomes concrete. We spend a lot of time on this show talking about threat models, device encryption, and "what happens if someone powerful demands your data." Duress passwords are a feature I've mentioned approvingly more than once — the idea that if you're forced to unlock, you can hand over a code that quietly destroys the sensitive contents instead. It's elegant, it's built into GrapheneOS, and until now the open question was always legal, not technical: what happens to you afterward?

Now we have an answer, or at least the beginning of one. And it's worth sitting with, because a lot of the security advice floating around — mine included — assumes that protecting your data is legally neutral. This case is the government arguing it isn't.

What actually happened

Here's the sequence, drawn from the reporting and Tunick's motion to suppress.

Tunick is an Atlanta resident and, by the government's own account, associated with Defend the Atlanta Forest — the movement opposing the police training facility critics call "Cop City." That association matters, because his lawyers argue it's the real reason he was stopped.

At the airport, CBP officers pulled him into secondary inspection and demanded his phone's passcode. The stated pretext, per the defense, was a search for child sexual abuse imagery — a justification his attorneys say the agents had no evidence to support. He was, they allege, repeatedly denied access to an attorney and never informed of his rights. No warrant was involved; border searches operate under an exception that lets agents inspect devices without one.

Tunick gave them a passcode. It was the duress code. The phone wiped itself. Agents seized the now-blank device anyway and let him into the country.

The charge came later. Prosecutors indicted him under 18 U.S.C. § 2232 — a statute that makes it a crime to "knowingly destroy or damage property" to prevent authorities from seizing it. The government's theory is clean and, on its face, unsettling: by entering the code that erased the phone, Tunick knowingly destroyed the contents to stop the government from taking control of them. He has pleaded not guilty. An Atlanta federal court is expected to rule on his motion to suppress later this year.

What a duress password actually is

Let me be precise about the technology, because the whole case turns on it.

GrapheneOS — a hardened, privacy-focused version of Android that runs on Pixel hardware — lets you configure a second passcode alongside your normal one. Enter the normal code, the phone unlocks. Enter the duress code, and the device performs an immediate, irreversible wipe: it deletes the encryption keys that make the data readable and powers down. There is no confirmation prompt, no warning, no visible tell that the code you just typed did anything other than fail to unlock. To an observer, it looks like a phone restarting.

That design is deliberate. The feature exists for exactly the scenario Tunick describes — a moment where you're compelled to hand over access and your only leverage is to make sure the access you hand over is worthless. It's the digital equivalent of a document that shreds itself when the wrong person opens the drawer.

How a duress passcode works: one phone, two codes — one unlocks, one destroys the keys and wipes the device with no visible tell.

The elegance is also the legal problem. Because the wipe is silent and instantaneous, there's no ambiguity for a prosecutor to work with about intent. You don't accidentally type a duress code. The government's argument leans entirely on that: he knew what it did, and he did it anyway, while the property was about to be seized.

Strip away the specifics and there are two collisions here, and both are bigger than one defendant.

First: is your data your property to destroy? Section 2232 was written for a world of physical evidence — flushing drugs, burning ledgers, smashing a hard drive as the agents come through the door. Applying it to a passcode is novel enough that digital-security experts who've watched this space for years — Bill Budington at the EFF, Runa Sandvik of Granitt — said they'd never seen a charge like it. The defense's position is essentially that you cannot "destroy property to prevent its seizure" by making your own device return to a locked, empty state, especially when there was no warrant and no lawful seizure yet underway. The government's position is that the wipe itself was the crime, independent of what the phone held.

Second: the border exception is doing enormous work. The reason none of the usual protections applied is that this happened at the border, where the government claims broad authority to search devices without a warrant or probable cause. Tunick's team argues the stop was pretextual — that the child-exploitation justification was a cover for investigating his activism — and that he was denied counsel and never read his rights. If the court agrees the stop and seizure were unlawful, the case against him may not survive. If it doesn't, we have a precedent that says protecting your data at the border can itself be charged as a crime.

That's the trap worth naming: the same warrantless-search power that lets agents demand your passcode in the first place is now paired with a theory that says defeating that demand is obstruction. You can be compelled to open the drawer, and punished for having shredded what was inside.

What I take away from it — and what it means for the rest of us

I want to be careful here, because this is exactly the kind of story where it's tempting to overreach in either direction.

This is one case, at the trial level, not yet decided. A motion to suppress could end it. It sets no binding precedent yet. Nobody should read it as "duress passwords are now illegal" — they aren't, and the feature does exactly what it's designed to do.

But it does change the calculus, and honestly it lands right where the security professionals have been pointing for years. Runa Sandvik's advice in the coverage is the whole lesson in one line: "it's better to not have that data on you when you cross certain borders." That's the through-line of everything we talk about on this show. The most robust protection isn't a clever feature that defeats a search — it's not carrying the sensitive data across the checkpoint at all. Travel with a clean device. Sync what you need from the cloud once you're through. Minimize what's physically on you at the exact moment your rights are at their weakest, which at a border is very weak indeed.

A duress password is a good tool. It may even be the right tool in some threat models. But this case is a reminder that a technical countermeasure and a legal countermeasure are not the same thing, and the gap between them is where a person like Samuel Tunick is now standing. The phone did exactly what he asked. Whether the law lets him ask it is now a question for a federal judge in Atlanta — and the answer is going to matter far beyond one Pixel.

I'll be watching the ruling on the motion to suppress, and I'll update here when it lands.

Sources & further reading

If you want the fast version in your ears, this'll be a segment on an upcoming episode of Closed Network.

— Simon

// Encrypted Dispatches

Become A
Smaller Target.

One email per week. Real privacy news, working tools, no fearmongering. We don't sell your address. We don't even want your real email address.

Subscribe
5,000+ readers · unsubscribe in one click · consider supporting the show