Samuel Tunick typed a passcode into his phone at Newark Airport, and the U.S. government decided that single action was worth five years in federal prison.
The charge: allegedly wiping his GrapheneOS device before TSA officers could search it during a warrantless inspection in 2023. Tunick, an activist and privacy advocate, says the government isn’t really prosecuting him for the act itself — it’s prosecuting him to send a message. “I hope people understand that the charges against me are meant to intimidate people,” he told 404 Media in an interview about the case.
- The Charge: Tunick faces up to 20 years in federal prison for using a built-in duress password feature on his GrapheneOS phone during a warrantless airport search.
- The Legal Trap: Federal law does not explicitly address the use of a device’s own security features during a search, leaving a gap prosecutors are now exploiting to argue obstruction.
- The Precedent Risk: If prosecutors succeed, using encryption, duress passwords, or wipe features on your own phone during a law enforcement encounter could constitute a federal felony.
What makes this prosecution extraordinary is what it targets: not the phone itself, not what was on it, but the act of protecting it. If prosecutors succeed, they will have established a legal precedent that citizens can face felony charges simply for using security features their devices already contain.
Tunick’s phone ran GrapheneOS, a hardened version of Android designed specifically for privacy and security. Like many privacy-focused operating systems, GrapheneOS includes a duress password feature — a secondary passcode that, when entered, wipes the device completely rather than unlocking it. The feature exists precisely for situations like airport searches: if someone is compelled to unlock their phone under duress, they can instead trigger a complete erasure. For activists, journalists, and data collection targets who carry sensitive communications, this is not a fringe tool — it is a documented, advertised security function.
What Actually Happened at Newark Airport?
On the morning of the search, TSA officers approached Tunick at Newark Airport without a warrant and demanded access to his device. According to the charges filed by the U.S. Attorney’s Office for the District of New Jersey, Tunick entered his duress password, which triggered the phone’s wipe function. Within moments, the phone’s data was gone.
The government alleges this constitutes obstruction of justice and destruction of evidence. The obstruction charge alone carries a maximum sentence of 20 years; the destruction of evidence charge carries up to five years. Tunick faces the possibility of a decade behind bars for using a feature built into his operating system.
• Maximum sentence for the obstruction charge alone: 20 years in federal prison
• Maximum sentence for destruction of evidence: 5 years
• Warrants required for the Newark airport search: zero
• Prior criminal charges against Tunick at the time of the search: none
As the ACLU has documented, the government has long claimed that Fourth Amendment protections prohibiting warrantless searches do not apply at the border and in border-adjacent zones like international airports. That legal position has been contested for years, but it remains the operational framework under which TSA and CBP officers conduct device searches daily. Tunick’s case now pushes that framework into new territory: not just whether agents can search a phone, but whether a citizen can be criminally prosecuted for preventing that search.
Is Using a Security Feature Now Evidence of Guilt?
Here is the legal and technical trap the case reveals: federal law prohibits obstruction of justice and destruction of evidence. But it does not explicitly address what happens when someone uses their own device’s security features to prevent access to their own data. The government’s argument, in essence, is that any intentional data destruction during a search — even on your own device, even using built-in security tools — can constitute a federal crime.
The indictment suggests that Tunick’s use of the duress feature demonstrates consciousness of guilt — that he must have had something to hide, or he wouldn’t have protected his data so thoroughly. This inverts the logic of privacy rights entirely. It treats the act of protecting yourself as evidence against you. Congressional Research Service analysis of warrantless electronic device searches at the border has noted the unresolved constitutional tensions in this space, but the Tunick prosecution moves beyond Fourth Amendment questions into criminal liability for the act of resistance itself.
If that argument prevails in court, it creates a chilling effect with teeth. Activists, journalists, and ordinary people who rely on privacy tools won’t just face social pressure to unlock their devices — they’ll face the concrete threat of felony prosecution for using the security features they installed for exactly this purpose. The precedent would effectively criminalize the act of protecting your own data from warrantless search.
• Legal scholarship published in the Duke Law Journal has examined the Fourth Amendment limits of warrantless device searches at the border, identifying the absence of clear constitutional guardrails as a structural vulnerability that invites prosecutorial overreach.
• The Tunick case exploits precisely this gap: by framing a security feature as obstruction, prosecutors sidestep the constitutional debate entirely and move directly to criminal liability.
• The practical implication is that the legal risk of protecting your device may now exceed the legal risk of surrendering it — a calculation that benefits only one party.
The Cambridge Analytica Parallel: Who Controls Access to Your Data?
Tunick’s case echoes a pattern visible in how governments and institutions have historically responded to technologies that threaten their access to behavioral and personal data. During the Cambridge Analytica scandal, the core mechanism of harm wasn’t a single data breach — it was the routine, systematic harvesting of psychological profiles on tens of millions of people without meaningful consent. Facebook’s architecture made that harvesting possible; users had no practical way to prevent it. The scandal exposed how data collection at scale, when unopposed by technical barriers, becomes a tool for manipulation and control.
What’s happening to Tunick represents the inverse pressure: the government prosecuting someone precisely because they erected a technical barrier to data access. Where Cambridge Analytica succeeded because users couldn’t stop the collection, the government’s case against Tunick assumes that users shouldn’t be allowed to stop it. Both scenarios share the same foundational assumption — that data access is inevitable, and that resistance to it is the aberration. As the legacy of Cambridge Analytica demonstrated, when institutions treat data access as a default entitlement rather than a conditional privilege, accountability collapses.
What Does “Evidence” Mean When You Haven’t Been Accused of Anything?
The case also raises a fundamental question about what “evidence” means in the digital age. The government’s theory assumes that data on your phone is automatically evidence of a crime. But Tunick had not been accused of any crime at the time of the airport search. TSA officers simply wanted to inspect his device as part of routine screening. Under what legal theory does routine inspection of an innocent person’s phone create a duty to preserve data that might someday become evidence of something?
GrapheneOS, the operating system Tunick used, has become increasingly popular among people concerned about surveillance and privacy. It is based on Android but removes Google’s tracking infrastructure and adds additional security hardening. The duress password feature is not a hidden hack — it is a documented, advertised security tool. Tunick didn’t jury-rig his phone or use some obscure exploit. He used his device exactly as its designers intended. Yet the prosecution treats that intentional design choice as evidence of criminal intent.
What This Means for Anyone Carrying a Phone Through an Airport
For ordinary people carrying phones through airports, the implications are immediate and personal. Your phone contains your location history, your messages, your photos, your financial data, your health information, your browsing history. If the government can compel you to unlock it, all of that becomes accessible. If you refuse, you can be charged with obstruction. If you use a security feature to prevent access, you can be charged with destruction of evidence. The logical endpoint of the government’s theory is a legal environment in which there is no path forward that protects your data.
The broader surveillance architecture that makes this possible — the assumption that digital data is always accessible, always preservable, always subject to state inspection — is the same architecture that enabled behavioral surveillance to become normalized across commercial and governmental contexts alike. The Tunick prosecution is not an isolated legal curiosity. It is a pressure test on whether technical privacy tools can survive contact with prosecutorial power.
Tunick’s case is still in the early stages. He has not been convicted. But the fact that prosecutors brought the charges at all — and that they are willing to pursue a felony case over the use of a built-in security feature — signals how seriously the government takes the ability to access phones without consent. The precedent they hope to set would make privacy tools themselves into evidence of criminality.
The question now is whether courts will accept that theory. If they do, the message to activists, journalists, and anyone else concerned about surveillance will be unmistakable: protecting your data is not a right. It is a risk. And the government is betting that fear will be more effective than any warrant.
