Federal prosecutors are trying to turn a phone’s privacy defense into a felony.
Samuel Tunick faces up to five years in prison after a Customs and Border Protection officer entered a passcode that allegedly erased the contents of his Google Pixel during an airport search. According to Tunick’s attorneys and TechCrunch, the phone ran GrapheneOS and the credential triggered its duress feature. The indictment itself makes a narrower allegation: Tunick knowingly caused the phone’s digital contents to be deleted to stop the government from taking them into custody.
Tunick has pleaded not guilty. No judge has ruled on his motion to suppress the search, and the indictment does not name GrapheneOS or a duress credential. Those distinctions matter because the government’s theory threatens anyone who relies on security software when federal agents demand a look through a phone without a warrant. “The government doesn’t own our data,” Tunick told The New York Times. That principle should survive a trip through an airport.
The charge depends on whether the search was lawful
The federal law Tunick is accused of violating punishes someone who acts on property to prevent the government from exercising its lawful authority to seize it. That last requirement is the entire dispute.
The government’s best argument starts with border doctrine. Border searches have operated under a broad exception to the Fourth Amendment’s warrant requirement for generations. CBP says travelers must present devices and the information stored on them in a condition that allows inspection. If a device cannot be inspected because of a passcode or encryption, the agency says it may detain the device or take other action.
The Eleventh Circuit, which covers Georgia, has given the government even more room. In 2018, United States v. Touset held that border agents may conduct forensic searches of electronic devices without a warrant, probable cause, or individualized suspicion. If that rule made this search lawful, prosecutors can argue that knowingly supplying a credential that erased data fits the broad language of the obstruction statute.
U.S. Attorney Theodore Hertzberg made that case bluntly. His office told Atlanta News First that people who destroy data to prevent a lawful search should expect punishment.
Evidence destruction is a real offense. Someone who smashes a drive while agents execute a valid warrant cannot hide behind a privacy slogan. But the government does not get to assume the word “lawful” and use the felony charge to avoid proving it.
A phone search exposes a life
The border-search exception was built around people and goods crossing a national boundary. A phone changes the scale of the intrusion. As the Supreme Court explained in Riley, a modern device can hold years of messages, photos, medical information, financial records, location history, contacts, and political associations. Searching it is closer to searching a home, a filing cabinet, and a private conversation at once than opening a suitcase.
The Supreme Court recognized that difference in Riley v. California. The case concerned a phone searched after an arrest, not at the border, so it does not automatically decide Tunick’s case. But the Court held that police generally need a warrant before searching a seized phone because digital devices differ from ordinary objects in both quantity and quality. Chief Justice John Roberts described phones as minicomputers that can function as libraries, diaries, maps, photo albums, and far more.
The Eleventh Circuit rejected that logic at the border in Touset. Its comparison was revealing: if agents can search a vehicle’s fuel tank for drugs, they can search a flash drive for illegal images. But a fuel tank cannot reveal every person you have spoken to, everywhere you have been, what you have read, and which causes you support. Treating both as generic “property” protects an old legal category at the expense of the human being carrying the device.
CBP says electronic searches are rare. In fiscal year 2025, the agency searched devices belonging to 55,318 international travelers out of more than 419 million people processed. That small percentage is no comfort to the person selected. CBP also says information retained after a device search can remain in its Automated Targeting System for up to 15 years and may be shared with other agencies. The intrusion does not end when the traveler leaves the airport.
CBP becomes a domestic shortcut
Tunick’s defense says this search was never really about what he carried across the border. His motion to suppress alleges that FBI personnel coordinated with CBP to question him because of his association with Defend the Atlanta Forest, the movement that opposed Atlanta’s police training center. The filing says officers demanded his passcode after he asked for a lawyer and invoked child exploitation even though the government’s reports offered no evidence that he possessed such material.
Those are defense allegations, not judicial findings. The government will get its chance to contest them. An evidentiary hearing began in July, and briefing is scheduled to continue through October. Tunick has not been charged with any crime connected to Defend the Atlanta Forest movement.
The contrast with Touset still matters. Before searching Karl Touset’s devices, investigators had linked him to three payments sent to an account associated with an email containing child sexual abuse material. The Eleventh Circuit held that the government did not need suspicion, then found that it had reasonable suspicion anyway. In Tunick’s case, his lawyers say the investigation began with political association and agents used a border stop to gather evidence for a domestic investigation unrelated to anything crossing the border.
Under the government’s theory, a domestic agency could wait for its target to take an international flight, ask CBP to pull the person aside, and exploit a legal exception designed for the border. If a privacy feature blocks the fishing expedition, prosecutors could point to the blocked search as a new felony.
GrapheneOS says its duress PIN and password irreversibly wipe a device and its eSIMs when entered wherever device credentials are requested. Its documentation says the wipe cannot be interrupted. That is what a duress feature is built to do: give the owner one last defense after consent has disappeared.
The government can seek a warrant when it wants the intimate contents of an American’s phone. It should not get five years of someone’s life because his security software refused to become a witness against him.