With regard to that guy who gave his wipe password to the fuzz, and is now in legal trouble for doing it...
A legal case involving a traveler who allegedly used a 'duress password' on a GrapheneOS phone to wipe data during a Customs and Border Protection (CBP) search at a US airport. The incident raises complex legal questions about the use of duress passwords, warrantless device searches at ports of entry, and constitutional protections. The traveler was charged with a felony for wiping his phone, which CBP alleges destroyed evidence. The case highlights ongoing debates about privacy rights, government surveillance of activists, and the legality of device searches without warrants at US borders.
AI Analysis
Technical Summary
This security-related incident concerns a traveler, Samuel Tunick, who allegedly used a GrapheneOS 'duress password' to wipe his phone during a CBP search at a US airport. The duress password triggers a factory reset or data wipe, which CBP claims destroyed evidence. The legal context is complex: courts have differing opinions on whether warrantless searches of devices at ports of entry violate constitutional rights, particularly the Fifth Amendment. CBP contends that constitutional protections do not fully apply at borders. The case also reflects increased scrutiny of activists' devices by US border agents, with concerns about surveillance and potential misuse of search powers. The technical aspect involves the use of a wipe password feature on GrapheneOS, which is not standard on all devices. The incident is not a vulnerability or exploit but a legal and privacy issue arising from device security features and government search policies.
Potential Impact
The impact is primarily legal and privacy-related rather than a direct technical vulnerability. The use of a duress password to wipe a device during a government search can lead to criminal charges, as in this case. It also underscores the risks travelers face regarding device searches at US borders, where warrantless searches may be conducted. The incident may deter use of security features designed to protect privacy or lead to legal challenges over constitutional rights. There is no indication of a technical exploit or malware involved, nor of widespread compromise of devices.
Mitigation Recommendations
This is not a traditional vulnerability with a patch or fix. The vendor (GrapheneOS) does not provide a standard duress password feature that creates a fake homescreen; the wipe password triggers a factory reset requiring device restart. Privacy experts recommend backing up and wiping devices before travel rather than during interrogation. Legal counsel should be sought regarding rights at border searches. There is no official patch or remediation applicable. Users should be aware of the legal risks associated with using duress passwords in such contexts.
With regard to that guy who gave his wipe password to the fuzz, and is now in legal trouble for doing it...
Description
A legal case involving a traveler who allegedly used a 'duress password' on a GrapheneOS phone to wipe data during a Customs and Border Protection (CBP) search at a US airport. The incident raises complex legal questions about the use of duress passwords, warrantless device searches at ports of entry, and constitutional protections. The traveler was charged with a felony for wiping his phone, which CBP alleges destroyed evidence. The case highlights ongoing debates about privacy rights, government surveillance of activists, and the legality of device searches without warrants at US borders.
Reddit Discussion
Seems to me that it would make much more sense for the "safe/wipe" password to bring up a fake homescreen, with apps and personal docs and all, while doing the wiping in the background.
Not sure if this is implemented anywhere, but it certainly isn't the standard on GrapheneOS.
I realize that there are technical limitations at play. The phone needs to restart for a proper factory reset, but, in lieu of that, the wipe pw could prompt the quiet burning of all personal files that aren't hardlinked to the OS itself. If you can get rid of everything personal, then there's no reason for a factory reset at all, no? So, even better, as it leaves the cops none the wiser.
Story here: https://www.theverge.com/report/972146/cbp-phone-search-airport-duress-password
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security-related incident concerns a traveler, Samuel Tunick, who allegedly used a GrapheneOS 'duress password' to wipe his phone during a CBP search at a US airport. The duress password triggers a factory reset or data wipe, which CBP claims destroyed evidence. The legal context is complex: courts have differing opinions on whether warrantless searches of devices at ports of entry violate constitutional rights, particularly the Fifth Amendment. CBP contends that constitutional protections do not fully apply at borders. The case also reflects increased scrutiny of activists' devices by US border agents, with concerns about surveillance and potential misuse of search powers. The technical aspect involves the use of a wipe password feature on GrapheneOS, which is not standard on all devices. The incident is not a vulnerability or exploit but a legal and privacy issue arising from device security features and government search policies.
Potential Impact
The impact is primarily legal and privacy-related rather than a direct technical vulnerability. The use of a duress password to wipe a device during a government search can lead to criminal charges, as in this case. It also underscores the risks travelers face regarding device searches at US borders, where warrantless searches may be conducted. The incident may deter use of security features designed to protect privacy or lead to legal challenges over constitutional rights. There is no indication of a technical exploit or malware involved, nor of widespread compromise of devices.
Defensive Guidance
This is not a traditional vulnerability with a patch or fix. The vendor (GrapheneOS) does not provide a standard duress password feature that creates a fake homescreen; the wipe password triggers a factory reset requiring device restart. Privacy experts recommend backing up and wiping devices before travel rather than during interrogation. Legal counsel should be sought regarding rights at border searches. There is no official patch or remediation applicable. Users should be aware of the legal risks associated with using duress passwords in such contexts.
Technical Details
- Source Type
- Subreddit
- ExploitDev+pwned+hacking
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a6b06399c2644c7f8c3dcc5
Added to database: 07/30/2026, 08:07:21 UTC
Last enriched: 07/30/2026, 08:07:57 UTC
Last updated: 09/09/2026, 16:57:14 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.