
In brief
- Samuel Tunick, an Atlanta activist, became the first known American charged under federal law for allegedly using a “duress password” during a warrantless border search at Hartsfield-Jackson airport in January 2025.
- The feature is built into GrapheneOS, a hardened Android OS released for Google Pixel phones; when the duress code is entered, it deletes all encryption keys and wipes the device instantly and irreversibly.
- A federal judge is expected to rule on the motion to suppress no earlier than the end of October.
Samuel Tunick faces prison for using a “duress” password on his phone.
The Atlanta resident has been charged under a rarely invoked federal statute—18 U.S.C. § 2232, a law that makes it illegal to knowingly destroy property to prevent authorities from seizing it—after he allegedly triggered a “duress password” on his phone during a warrantless border search at Atlanta’s Hartsfield-Jackson airport on January 24, 2025. According to The Guardian, this is the first known criminal prosecution in the United States involving the feature due to the use of a password.
A duress password is a second unlock code you set up alongside your regular one. Enter the real PIN and your phone opens normally. Enter the duress code and the device performs an immediate, irreversible wipe—deleting the encryption keys (the mathematical locks that scramble your data and make it unreadable to anyone without the right code) and leaving the phone as blank as the day it left the factory.
The feature lives inside GrapheneOS—a privacy-hardened version of Android built exclusively for Google Pixel phones and favored by journalists, activists, and security researchers. Edward Snowden hyped it after tweeting that he was a daily user, but the ROM has been around for years.
The OS added the duress PIN in June 2024, targeting precisely this kind of scenario: someone physically forced to hand over their device.
It has shown up in legal disputes before. In 2023, as Decrypt covered, courts encountered the limits of smartphone monitoring when devices running privacy-focused operating systems including GrapheneOS proved resistant to surveillance software installed per a judge’s order.
Tunick’s lawyers say that’s exactly what happened. Customs and Border Protection agents pulled him into a secondary inspection room as he returned from the Dominican Republic and demanded access to his phone without a warrant—under the so-called “border search exception” to the Fourth Amendment, CBP claims the right to inspect devices before a traveler formally enters the country. He was also denied a lawyer, according to his attorneys, and never read his Miranda rights.
When he provided a code, per court filings, “the screen went blank, flashed several times, and the phone appeared to restart.” Agents seized the device anyway and released him into the country shortly after.
The government’s own indictment accuses Tunick of providing “a passcode to border agents that caused the phone to delete the digital contents,” prior to the device being seized.
The Electronic Frontier Foundation has a public guide on device rights at the U.S. border, part of a broader push toward privacy-first tools that’s been accelerating for years. Tunick has pleaded not guilty. A federal judge is expected to rule on his motion to suppress no earlier than the end of October.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Be the first to comment