The Duress PIN Is a Felony: How the US Border Turned a Safety Feature Into a Crime

Imagine you’re crossing the US border. A customs officer asks for your phone. You hand it over, type a special code – the duress PIN – that wipes your data. It’s a feature designed to protect you from coercion, built into privacy-focused operating systems like GrapheneOS. And then you’re charged with a felony.

This isn’t a hypothetical. It happened to Samuel Tunick. And the charge isn’t for terrorism, drug trafficking, or anything you’d expect. It’s for obstructing an investigation – a generic, catch-all law that prosecutors are now weaponizing against the simple act of exercising digital self-defense at the border.

Let that sink in: The state is now treating the absence of data as a criminal offense.

You’ve probably heard the advice: if you’re ever forced to unlock your phone, use a duress PIN. It’s a standard privacy tool, echoed by security experts and civil liberties groups. But the law is reinterpreting that tool as intentional destruction of evidence. The paradox is staggering: a feature explicitly designed to protect people in coercive state environments is now being used to put them in prison.

Here’s what happened. Tunick, a US citizen, was returning from abroad. He uses GrapheneOS – a security-hardened Android OS. When the border officer demanded his phone, he entered the duress PIN. The phone wiped itself. The officer noticed. And now Tunick faces a federal felony charge that could carry years in prison.

This is not about what Tunick did. It’s about what the law says you can’t do: protect your own privacy.

The legal theory is dangerous. Prosecutors argue that by using a duress PIN, Tunick knowingly destroyed evidence – even though there was no warrant, no suspicion, no probable cause. The burden of proof has shifted: you now have to prove you weren’t hiding something, instead of the state proving you were.

Every traveler with a smartphone is now caught in a legal gray zone. The same tools that keep your data safe from hackers, stalkers, and oppressive regimes can now trigger a felony charge at the border. Your choice: hand over your entire digital life, or risk prosecution for protecting it.

Privacy is not a crime. But the US border is making it one.

This isn’t an isolated incident. It’s a pattern. The government is using generic obstruction laws to criminalize the use of privacy-enhancing technologies. The same logic could apply to encrypted messaging apps, VPNs, or even clearing your browsing history. If the absence of data is a crime, then every privacy tool becomes a potential trap.

So what do you do? Burner phones, encrypted devices, even leaving your phone at home – these are now the rational precautions. But the real question is: why should a citizen have to choose between digital security and legal safety?

The duress PIN was supposed to protect you. Now it’s a weapon against you. The next time you cross a border, remember: the law isn’t on your side. It’s treating your privacy as a threat.

FAQ

Q: Isn't deleting data when an officer asks for it just obstruction of justice?

A: No. The duress PIN is a pre-set security feature, not a deliberate act of destruction at that moment. The law is being misapplied to criminalize a defensive mechanism that was designed to protect users from coercion. There was no warrant, no probable cause, and no evidence of a crime before the wipe.

Q: What's the practical implication for me? Should I stop using privacy tools at borders?

A: The practical implication is that you now face a real legal risk. The safest option is to carry a burner phone with minimal data when crossing the US border. But the deeper issue is that this sets a precedent where any privacy-enhancing behavior – encryption, VPNs, clearing history – could be interpreted as obstruction. The law needs to be clarified, but until then, assume your digital privacy is not protected at the border.

Q: Could there be a legitimate argument that the government needs to prevent destruction of evidence at borders?

A: Yes, but that argument relies on the assumption that the border is a zone where normal Fourth Amendment protections don't apply. The contrarian view is that if you have nothing to hide, you shouldn't be using a duress PIN – but that's a dangerous standard. The real issue is the lack of clear legal standards. The government should have to get a warrant before it can demand your data, and using a duress PIN should be a lawful act of self-protection, not a crime.

📎 Source: View Source