The Digital Security Digest, by Freedom of the Press Foundation (FPF), is a weekly newsletter with security tips that keep you, your sources, and your devices safe. If someone shared this newsletter with you, please subscribe here.

DOJ charges U.S. activist for using ‘duress’ passcode to wipe phone during border stop

Upon returning to the United States from a vacation in the Dominican Republic in January 2025, activist Samuel Tunick was stopped by border officials for interrogation at Hartsfield-Jackson Atlanta International Airport. According to a motion filed by Tunick’s public defenders to suppress evidence obtained during the stop, and reported by The Guardian, border officials ordered Tunick to unlock his phone or risk having it seized if he did not comply. When he finally offered a passcode and authorities entered it, “the screen went blank, flashed several times and the phone appeared to restart,” the motion said.

According to TechCrunch, “Prosecutors later charged Tunick under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it.”

The Justice Department alleges that Tunick used a “duress” passcode instead of the passcode to unlock the phone. A duress passcode wipes data from a smartphone when typed in anywhere the credentials are requested, including on the lock screen. Tunick’s attorneys confirmed his phone ran GrapheneOS, a security-focused free and open source operating system that runs on many modern Google Pixel devices, intended for compatibility with Android apps. It offers a substantial range of security features, including the ability to use a duress passcode. Tunick has pleaded not guilty. Read more.

What you can do

This is our first time seeing a case like this — the targeting of an American in alleged connection with the use of a duress passcode. We will certainly monitor this closely in the coming months.

For now, what we can say is that while border searches affect a very small percentage of international travelers, we know these searches disproportionately affect people who are not U.S. citizens. Depending on what information you carry — such as sensitive reporting materials or information about confidential contacts — even this remote risk may still be too high.

  • Understand what border officials might do. It’s important to know that when you are at a U.S. port of entry, as an American citizen you cannot be barred from entering the country. But border officials may make your life extremely inconvenient by stalling your travel or searching your device. They may conduct a “basic” search of your electronics (manually looking through an unlocked device). However, in rare circumstances they may also conduct an “advanced” search that involves the use of external equipment to, for example, make forensic copies of your data. They may also seize your electronic devices. If this happens, you may not see them for weeks or even months. Non-U.S. citizens have even fewer rights, and may be denied entry entirely.
  • Prepare your data for a search. The good news is that there is a lot you can do to prepare your electronic devices for a potential search before traveling to a U.S. border.
    • Stay up to date. We recommend keeping your device up to date with the newest security patches.
    • Use a long, unique passcode. Consider even using an alphanumeric passcode to make it even harder for someone to get into your phone without your permission. To learn how, read our guide to mobile maintenance.
    • Power down your devices. When you fully power down your phone or computer, this enables disk encryption — essentially, making your data illegible to anyone who doesn’t have the passcode.
    • Should you decide to unlock your device, remove the “crown jewels.” If you do consent to a search, consider carefully what is on your phone and computer in the first place. Take care in advance to delete any information that would be intolerable to share with a third party. Note that when you delete files, photos, or messages, they may be stored in a “trash bin” in the file explorer, photo app, or — sometimes — in messaging apps, where they need to be deleted a second time.
  • Read all about it! If we wrote everything you can do here, this would need to be an extremely long newsletter. So in collaboration with the Electronic Frontier Foundation, we wrote a checklist to help you get started. Read our guide.

Updates from our team

  • We are thrilled to kick off our inaugural J-school digital security training program, supporting over a dozen journalism educators with a curriculum to help them integrate digital security fundamentals into their coursework. If you weren’t able to join the four-week program this year and have interest in joining us during the next round, please reach out. We are excited to support journalism educators. In the meantime, check out our U.S. J-school security curriculum.

Our team is always ready to assist journalists with digital security concerns. Reach out here, and stay safe and secure out there.

Best,
Martin

Martin Shelton
Deputy Director of Digital Security
Freedom of the Press Foundation