The Duress Code That Erased a Phone — and Built a Federal Case
One traveler's use of a privacy feature at the U.S. border turned a routine customs stop into a felony charge, exposing how far the government will go to get past encryption.
Source material: arstechnica.com
A Phone That Refused to Talk
When Samuel Tunick landed at a U.S. international airport in early 2025, he was carrying a Google Pixel running GrapheneOS, a security-hardened version of Android. Customs and Border Protection agents pulled him aside for a secondary inspection. They told him they were looking for anything prohibited, then demanded he unlock the phone. Tunick, an Atlanta resident active with the group Defend the Atlanta Forest, had a feature most travelers don't own: a duress code.
Typing that code didn't open the device. It triggered an immediate wipe, erasing the phone's contents on the spot. The agents got a blank screen and Tunick got a set of federal felonies. The first hearing happened last week in federal court, where government attorneys described the encounter as a standard stop. Tunick's lawyers tell a different story, alleging their client had been placed on a watchlist for his activism and that CBP agents had discussed over email a plan to detain him for "suspected terrorism activities" upon his return.
Inside the Wipe Mechanism
The feature at the center of the case is built into GrapheneOS, an operating system that only supports Google Pixel phones from the Pixel 6 onward. The OS is designed for users who treat their data as a hard boundary. It includes memory protection and automatic reboots that lock the device, but the duress code is its most dramatic tool.
A user can set a secondary PIN that looks identical to the real one. Entering it does not just fail to unlock the phone — it instructs the system to perform a full secure erase, destroying local data immediately. There's no confirmation prompt, no undo. The phone simply presents itself as a freshly reset device.
For Tunick, the feature functioned exactly as designed. The question for the court is whether using it amounts to obstruction. Government agents argued they were performing a lawful search — if the data is gone, they say, the evidence was destroyed. Defense attorneys counter that a person cannot be charged for declining to incriminate themselves, and that the wipes are akin to a traveler who forgets a password, except the traveler in this case made a deliberate choice with a tool his phone offered.
The Watchlist and the Cop City Connection
Tunick's legal team claims the customs stop was no random screening. The activist had been involved with Defend the Atlanta Forest, a group opposing the construction of a massive law enforcement training center in Atlanta — a project commonly called Cop City. His lawyers say he was targeted for that opposition.
According to his lawyers, Tunick was unaware he had been placed on a watchlist. The emails allegedly exchanged among CBP officials, referencing "suspected terrorism activities," suggest the stop was premeditated, not incidental.
During the interrogation, agents told Tunick they were searching his phone for evidence of child sexual abuse, and warned that if he did not unlock it, the device would be confiscated. Tunick says he requested legal counsel several times and was refused, and that he was never read his rights. The government's position rests on long-held border authority: customs agents assert broad power to examine and seize electronic devices for nearly any reason.
The Border Exception to Your Privacy
The Fourth Amendment protects against unreasonable searches, but at the border, the rule bends. Courts have granted customs agents wide latitude to inspect people and belongings crossing into the country, treating the border as a unique zone where national security interests overshadow individual privacy.
For most travelers, that means handing over a phone without incident. The normal end to a stop like Tunick's would be confiscation, with the traveler sent on their way while investigators attempt to break into the device later — either by brute force, exploiting software flaws, or demanding the passcode through a subpoena. Some agents attempt forensic extraction on the spot.
Tunick short-circuited all of those paths. By wiping the phone during the encounter, he forced the legal question into the open: what happens when a traveler prevents a search not by refusing, but by making the data physically unrecoverable? The government's answer is felony charges. Civil liberties lawyers argue that if the border exception lets agents seize a phone, it does not obligate the owner to make its contents easy to read.
The Cost of a Fail-Safe
The duress code is a fail-safe for people who face real threats, but its existence creates a strike against anyone who uses it. The dilemma is that the very act of activating the wipe can be seen as suspicious. In Tunick's case, CBP agents described the stop as routine, with the request for the phone based on a standard border search. The defense says the plan was to target an activist, and the felony charge is the result of a failure to obtain what they wanted. Tunick's case is now a test of whether a privacy feature can be considered a criminal tool. The outcome could shape how custom Android builds are adopted by people who carry sensitive data across borders. If using a duress code means risking a federal prosecution, the calculus changes for every traveler who has ever considered installing GrapheneOS.
Where this came from. This breakdown is based on source material published at arstechnica.com. Images above are used with the credits shown beneath each one.