Privacy tools are legal. Using them can still land you in federal prison.
That is the terrifying message coming out of a federal courtroom in Georgia, where an Atlanta activist named Samuel Tunick is facing up to five years behind bars. His crime? Giving customs agents a specific passcode that instantly wiped his phone clean.
If you travel internationally or care about digital privacy, this case changes everything. It tests the boundaries of what border agents can demand and how far citizens can go to protect their personal data.
What Actually Happened at the Airport
The timeline dates back to January 2025. Tunick was returning to the United States from a trip to the Dominican Republic. When he passed through security at Hartsfield-Jackson Atlanta International Airport, U.S. Customs and Border Protection (CBP) agents pulled him aside for an extended secondary inspection.
Border agents do not need a warrant to search electronic devices. They operate under broad customs authority. Agents demanded Tunick unlock his Google Pixel phone. Tunick refused to answer questions without his lawyer present and balked at handing over open access to his digital life.
According to court filings from his defense team with the Federal Defender Program in Atlanta, agents told him they had the authority to search his phone anyway. Court records show agents claimed they needed to check for child exploitation material. Tunick’s lawyers argue that justification was entirely a pretext. The real target? His association with "Defend the Atlanta Forest," a local activist movement that heavily protested the construction of the Atlanta police training facility known as Cop City.
Faced with relentless pressure, Tunick gave the agents a code. It was not his main unlock PIN. Instead, it was a duress password built into GrapheneOS, a security-focused open-source operating system.
The moment agents typed it in, the screen went blank, flashed, and the device factory-reset itself. Every piece of data vanished into the ether.
The Core Conflict Over GrapheneOS
GrapheneOS is designed for people who take privacy seriously. Built as a hardened alternative to standard Android, it strips away tracking and adds heavy-duty security layers. One of those features is a panic wipe profile or duress password. Enter the secondary code, and the phone acts like it is booting up normally while secretly erasing every file, photo, and app.
Until now, using privacy software was a cat-and-mouse game between tech enthusiasts and security agencies. Now, federal prosecutors are treating the feature as an active criminal act.
The U.S. Attorney’s Office for the Northern District of Georgia charged Tunick with obstruction and destruction of evidence. Prosecutors argue that by entering a wipe code, he intentionally impaired the government's lawful authority to inspect his property.
This marks what legal and cybersecurity experts believe is the first criminal case of its kind targeting a specific operating system function. It sets a dangerous legal trap. Is choosing to delete your data a constitutional right against self-incrimination, or is it a federal felony?
Why the Defense Is Fighting Back
Tunick’s defense attorneys have filed motions to toss out the case entirely. They point out glaring flaws in the government's narrative.
For starters, the initial detention smelled heavily of political retaliation. Activists connected to the Stop Cop City movement had reported being watched, tracked with hidden cameras, and harassed by law enforcement for months leading up to the incident. The defense contends that customs checks were weaponized to bypass standard constitutional protections against unwarranted domestic surveillance.
Furthermore, the legal team argues that compelling someone to turn over encryption keys or passwords forces them to testify against themselves, violating the Fifth Amendment. When the government demands access to your private thoughts and memories stored on a device, handing over a self-destruct code might be the only defense left.
Tunick himself has been vocal about the bigger picture. In interviews, he noted that the government hopes to establish a legal precedent that scares people away from using encryption tools. They want citizens to feel helpless at the border.
What This Means for Travelers and Privacy Advocates
You might not be an activist protesting police infrastructure, but this case impacts you the next time you board an international flight.
Border agents claim sweeping powers under federal customs laws. They routinely demand passcodes, social media handles, and access chats. If you refuse, they can seize your hardware for weeks or months. If you comply, you hand over your entire digital footprint—banking apps, personal emails, medical records, and family photos.
Using privacy-hardened tools like GrapheneOS, encrypted messaging apps, or cloud-backup routines where local data can be purged is becoming a necessity for journalists, lawyers, and everyday citizens traveling abroad. Yet, the Tunick prosecution shows that exercising digital hygiene can put a target squarely on your back.
If you value your data privacy, keep these practical steps in mind:
- Travel light. Leave your primary personal or work devices at home if you can. Use a cheap, burner travel phone loaded with minimal data.
- Understand border rules. CBP agents have vast authority at ports of entry, and standard privacy expectations shrink drastically when you cross international borders.
- Separate your profiles. If you must carry sensitive devices, ensure your cloud backups are secured and local synchronization is paused before approaching any checkpoint.
The federal government wants to make an example out of Samuel Tunick. How the courts handle his defense team's motion to dismiss will determine whether your phone remains your private property or an open book for federal inspectors.