September 14, 2026

The GrapheneOS Case Testing Privacy Rights at the Border

In July, a confrontation at Hartsfield-Jackson Atlanta International Airport transformed an obscure smartphone security feature into the focus of a widening constitutional dispute over privacy, government power and the rights of travelers entering the United States.

a picture of a phone with the graphineos logo

Atlanta, Georgia - In July, a confrontation at Hartsfield-Jackson Atlanta International Airport transformed an obscure smartphone security feature into the focus of a widening constitutional dispute over privacy, government power and the rights of travelers entering the United States.

Samuel Tunick, an American activist associated with the “Stop Cop City” protest movement, was detained by Customs and Border Protection officers after arriving at the Atlanta airport. When agents demanded access to his Google Pixel phone, Mr. Tunick provided a passcode.

But the code did not unlock the device.

Instead, it activated a security feature known as a “duress PIN,” triggering an immediate factory reset that erased the phone’s cryptographic keys and data. The device was running GrapheneOS, a privacy-focused operating system designed to protect users from surveillance, hacking and unauthorized forensic searches.

Federal prosecutors subsequently charged Mr. Tunick with obstruction of justice, arguing that wiping the phone during a government inspection amounted to the destruction of property intended to prevent its seizure. Mr. Tunick has pleaded not guilty, and his lawyers contend that the underlying detention and warrantless search were unlawful.

The prosecution appears poised to test a question that has become increasingly urgent as mobile devices hold larger quantities of personal, professional and political information: Can the government treat the use of a built-in privacy feature as a federal crime?

A Hardened Alternative to Standard Android

GrapheneOS is an open-source mobile operating system based on the Android Open Source Project. It is designed specifically for Google Pixel phones and uses the devices’ hardware security infrastructure, including the Titan M security chip and Verified Boot process, to detect tampering and protect encrypted information.

Unlike standard Android installations, GrapheneOS removes Google Play Services from the operating system’s privileged core. Users can install Google services later, but they operate as ordinary, restricted applications inside a sandbox rather than receiving broad access to the device.

The operating system also gives users unusually strict control over individual applications. Apps can be denied access to the internet, storage, sensors and other hardware without necessarily preventing them from performing their basic functions.

Those features have made GrapheneOS attractive to investigative journalists, activists, whistleblowers and security researchers who may carry confidential communications or information sought by governments, corporations or hostile actors.

Its defenses extend beyond conventional password protection.

A hardened memory allocator is designed to stop certain software exploits before malicious code can execute. An auto-reboot feature can restart a device after it has remained locked for a specified period, returning it to what security specialists call a “Before First Unlock” state. In that condition, encrypted data is substantially more difficult for forensic extraction tools to reach.

The duress PIN is more drastic. When entered, it immediately initiates a secure factory reset, destroying the cryptographic keys necessary to access information stored on the device.

That feature is intended for situations in which a user believes that a phone has been seized or that a passcode is being demanded under coercion.

In Mr. Tunick’s case, prosecutors appear to view the same protection as an instrument of obstruction.

The Expanding Power of the Border Search Exception

The legal conflict arises from the broad authority granted to federal officers at ports of entry.

Under the border search exception to the Fourth Amendment, Customs and Border Protection officers generally have greater freedom to inspect people and property entering the country than police officers conducting searches within the United States.

Federal appellate courts have repeatedly held that officers may conduct manual searches of electronic devices at the border without obtaining a warrant, establishing probable cause or demonstrating individualized suspicion.

In such searches, officers may scroll through photographs, contacts, messages and other information stored directly on a device.

More intrusive forensic searches, involving specialized software capable of copying or deeply analyzing a phone’s contents, have generally received greater scrutiny. Some courts require reasonable suspicion before officers may conduct these advanced examinations.

The Ninth Circuit has also limited the permissible purpose of border device searches, ruling that officers cannot use the border exception as a general law enforcement fishing expedition. Under that court’s approach, searches must be connected more closely to the government’s border-related authority, including efforts to identify digital contraband.

But the protections vary by federal circuit, leaving travelers with different privacy rights depending on where they enter the country.

The Supreme Court has recognized the exceptional sensitivity of cellphone data outside the border context. In Riley v. California, the court unanimously ruled that police generally need a warrant before searching the digital contents of a phone seized during an arrest.

That ruling emphasized that smartphones are not ordinary physical containers. They can reveal years of messages, photographs, movements, relationships, medical details and financial records.

The court has not extended Riley’s warrant requirement fully to border searches, allowing federal officers to continue operating under broader search powers at airports and other ports of entry.

Citizens and Noncitizens Face Different Risks

The consequences of refusing a device search differ sharply depending on a traveler’s immigration status.

American citizens cannot be denied entry into the United States merely because they refuse to unlock a phone. But border officers may detain them for questioning, seize their devices and send those devices for forensic examination.

Noncitizens face greater risks.

Visa holders and tourists do not possess an absolute right to enter the country. Refusing to unlock a phone can lead to denied admission, visa consequences and immediate removal from the United States.

Lawful permanent residents generally possess stronger re-entry protections than temporary visitors, but they may still face detention, questioning and immigration proceedings when the government alleges criminal conduct, fraud or another basis for inadmissibility.

The distinction means that a privacy decision that may cost an American citizen a phone could cost a noncitizen the ability to enter or return to the United States.

Journalists and Confidential Sources

The prosecution of Mr. Tunick is unfolding alongside another dispute involving electronic devices seized at an American airport.

In July, Customs and Border Protection officers stopped independent journalist Max Blumenthal at Dulles International Airport after he returned from a reporting trip. Officers seized two cellphones and retained them for approximately a week.

The American-Arab Anti-Discrimination Committee filed an emergency motion challenging the seizure, arguing that the government violated the First Amendment, the Fourth Amendment and the Privacy Protection Act.

The case highlights the stakes for journalists whose devices may contain unpublished reporting, confidential source identities, communications with editors and information belonging to people who never consented to government inspection.

GrapheneOS and similar security tools are designed in part to protect that material. Yet the Tunick prosecution suggests that activating the strongest available protections during a border encounter could expose a traveler to criminal liability.

That creates a difficult conflict for journalists, lawyers and human rights defenders.

A reporter may have an ethical obligation to protect a source. A lawyer may have a professional obligation to protect attorney-client communications. An activist may possess information identifying people involved in political organizing.

At the border, those responsibilities may collide with the government’s demand for immediate access.

Privacy Tool or Evidence Destruction?

The central dispute in Mr. Tunick’s case may turn on how a court characterizes the duress PIN.

Federal prosecutors portray the phone wipe as a deliberate act intended to prevent the government from seizing evidence. Privacy advocates are likely to view the feature as a preconfigured security measure designed to protect personal information from coercive access.

The timing may prove critical.

Deleting information before encountering law enforcement is different from destroying it after officers have initiated a search or asserted control over the device. Prosecutors are expected to argue that once the inspection began, wiping the phone interfered with a lawful federal function.

The defense is challenging the premise that the search itself was lawful.

That dispute raises broader constitutional questions. The Fifth Amendment protects people from being compelled to incriminate themselves, although courts have reached differing conclusions about whether forcing someone to provide a passcode is testimonial. The Fourth Amendment protects against unreasonable searches, but border doctrine substantially reduces those protections.

The case may also force courts to confront the difference between passively refusing to provide access and actively triggering a device wipe.

A citizen may decline to disclose a passcode and still be admitted into the United States, though the phone may be seized. The government’s theory in Mr. Tunick’s case suggests that activating an automated security response crosses a legal line from noncooperation into obstruction.

Where that line begins has not been clearly established.

A Test of Digital Rights at the Border

The Tunick prosecution arrives as smartphones increasingly function as comprehensive records of a person’s life.

A traveler’s device may contain location histories, political associations, medical information, private photographs, financial accounts and years of personal correspondence. For journalists and lawyers, it may also contain information belonging to hundreds of other people.

GrapheneOS was built around the idea that users should control access to that information even when a device is stolen, hacked or physically seized.

The federal government’s case presents a competing principle: that a person cannot destroy information to frustrate a lawful inspection or seizure.

A ruling against Mr. Tunick could give prosecutors a new tool for pursuing people who activate data-wiping protections during border inspections. It could also discourage journalists, activists and other high-risk travelers from using security features intended to protect confidential information.

A ruling in his favor could limit the government’s ability to prosecute travelers for deploying privacy protections while strengthening constitutional challenges to suspicionless electronic searches.

For now, the case leaves travelers facing an unsettled and consequential choice.

They may protect their devices against intrusion. They may refuse to unlock them and risk detention or seizure. But if they activate a system designed to make the data disappear, they may find that the government considers the act itself a crime.

 

Stay Informed

Get the latest articles from New England Gazette - Bringing The World The News delivered to your inbox.

Weekly by default · More options

We use cookies to analyse traffic, personalise content, and serve ads. Choose what you allow.