
Know Your Enemy: The Border Phone Wipe and the Adversary We Actually Fight
About this episode
Summary:
Samuel Tunick triggered a GrapheneOS duress wipe on his Google Pixel during a warrantless but lawful CBP border search. He's now charged with destroying property to prevent lawful seizure.
This episode rejects two easy narratives. First, that Tunick is a victim: he made a deliberate choice with foreseeable consequences, and agents operated within their authority. Second, that the privacy tool is the villain: GrapheneOS, like Signal, is legitimate infrastructure. Blaming encryption for occasionally protecting a bad actor is an old deflection.
Key Points:
Accountability, not victimhood - Tunick configured a feature designed to destroy data, knew what it did, and triggered it during an authorized search. That was a choice.
The tool is never the strategy - A duress wipe defends against thieves, stalkers, or abusers. Triggered during a lawful search, the same feature becomes evidence destruction.
Tools aren't the bad guys - Blaming the OS is the same trick: a tool that protects everyone sometimes protects a bad actor, therefore the tool is the threat. It's deflection. The fix they want removes protection from all of us.
Law enforcement isn't the enemy - Treating the agent as a personal adversary leads to emotional, losing decisions where the law is most stacked against you.
The real enemy is warrantless mass collection - Ad bidstream, data brokers, Big Tech retention, and license plate reader dragnets like Flock collect on everyone with no warrant because it's built into commerce.
The real risk is getting swept into someone else's investigation - Geofence warrants order providers to hand over every device in an area during a window, sweeping up bystanders.
Aim your OPSEC at the machine, not the badge and not your tools - Keep the tools, respect them, and deny the collection machine your data in daily life. Fight the system where it's vulnerable: local contracts, the courts, and your platform choices.
Not Legal Advice: This episode discusses criminal cases and legal risk for general education. It is not legal advice, and Allen is not a lawyer. If you're ever in a situation like this, consult a licensed attorney.**
Sources:
- [US accuses American of wiping his phone with a duress password during a border search (TechCrunch)](https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/)
- [A man gave border agents his passcode. It wiped everything. Now he faces federal charges (Decrypt)](https://decrypt.co/374394/border-agents-phone-duress-passcode-grapheneos)
- [Google tracked his bike ride past a burglarized home and made him a suspect (NBC News)](https://www.nbcnews.com/news/us-news/google-tracked-his-bike-ride-past-burglarized-home-made-him-n1151761)
- [Google changes Location History to limit geofence warrants (The Register)](https://www.theregister.com/2023/12/15/google_location_history_geofence/)
- [Get the Flock Out campaign (ACLU)](https://www.aclu.org/campaigns-initiatives/get-the-flock-out)
- [Why some cities are ditching their Flock license plate readers (NPR)](https://www.npr.org/2026/02/17/nx-s1-5612825/flock-contracts-canceled-immigration-survillance-concerns)
- [Digital privacy at the US border (EFF)](https://www.eff.org/issues/border-searches)
Call To Action:
Two things this week. First, examine the tools you rely on. For each one, ask not just what it protects you from, but when could it become a liability.
Second, aim at the machine. Pick one source of ambient collection and cut it: reset your mobile ad ID, add DNS-level blocking, or find out whether your town runs Flock cameras and show up to the contract vote.
For more visit OPSECPodcast.com.
Your privacy and your security is your responsibility.Get every episode summarized
Each time The OPSEC Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
297 searchable segments. Every word is indexed and playable.
Full transcript
The OPSEC Podcast — Know Your Enemy: The Border Phone Wipe and the Adversary We Actually Fight. Machine-transcribed; use the interactive transcript above to jump the player to any line.
A man handed his phone, passcode to a federal agent, and the phone erased itself. He set that up. He chose a code that would destroy everything on the device. The instant it was entered, and he handed it over during a search that the agent was legally authorized to run. The phone wiped, and now he is being charged with a federal crime. Let me say the part a lot of media coverage is dancing around. This is not a story about a victim. It is a story about a decision, and that decision has consequences. Today we talk about what actually happened, why the privacy tool involved is not the villain, and how to think clearly about who the real adversary is. I am Alan Pace, and this is the Opset Podcast. Let me lay out the facts, because the details here matter. The man's name is Samuel Tunic. He's an American citizen, and an activist out of Atlanta, Georgia. On January 24th, 2025, he flew home from the Dominican Republic and landed at Hart's
Field Jackson Airport. Customs in border protection pulled him into secondary inspection, took his Google Pixel phone, and asked for the passcode. He gave them a code, and the officer entered it, and instead of unlocking the device, the phone wiped itself completely. That phone was running graph ENOs, a hardened version of Android that installs on Pixel devices. Graph ENOs offers a Dress Pen function. You set a secondary code, and if that code is entered, the phone does not unlock. It instantly and permanently wipes the device beyond recovery. The feature was added for a specific scenario. Someone physically compelled to hand over their phone under Dress. In 2026, the Justice Department's charges became public. Tunic was charged under a federal statute that criminalizes destroying property to prevent its lawful seizure. It carries up to a five-year federal prison sentence. Legal and security experts say that this is the first known case in the United States
of a person being federally charged over data destroyed by a Dress password. And here's the update. Tunic has pled not guilty, and his lawyers have filed a dismissal for the case, arguing that initial search and seizure at the border were themselves unlawful. So the fight now is partly about whether the border search was valid in the first place. The case is not finished, and the court will decide the specifics. But strip away the framing, and the court is simple. A destructive action was taken during a search the government was authorized to run, and that is what the charge is about. Here is the law as it stands, stated plainly, and without any spin or opinion of it. The border search exception gives agents brought authority to inspect electronic devices at the border. At a much lower bar than they would need anywhere else in the country. Courts are still sorting out exactly how far that reaches for funds, and in Tunic's motion to dismiss is aimed right at that question.
The court ultimately decides the agents in the room were operating inside the authority of the law, currently given to them. Here's where I part ways with a lot of the coverage that we see in the media. A good deal of it wants to make Tunic a martyr, a privacy hero caught in the gears of the evil state. I don't see it that way, and I don't think that you should either. He was not ambushed. He was not being held illegally. He configured a feature which the entire purpose is to destroy the data when a specific code is entered. He knew what it did. And then he put himself in a setting where his device was subject to a lawful search, and the device code was entered. That is not something that happened to him. That is something that he said in motion. We have set on the show more than once that your decisions have consequences. Opsek is not a magic word that makes the law disappear, and a privacy feature is not a get out of jail free card.
Owning a tool that can wipe a phone is fine, triggering it in the middle of a search that the government is legally authorized to conduct is a choice. And that choice at the border of all places carries weight. He is accountable for it. Frame it as victimhood, and you walk away with exactly the wrong lesson. And this was not some obscure trap. The risk was known. We walked through it on an earlier episode. The moment a wipe function is triggered during a lawful search, you have moved from protecting your privacy into potentially destroying evidence. And that is an obstruction problem, not a privacy one. His own motion to dismiss argues that the search was unlawful, and if a court agrees that changes the picture. But you do not want to bet your freedom on winning that argument after the fact. The tool was never the strategy. The judgment around the tool is the strategy. Now the other thing I need to address because the headlines are already running with it.
A lot of coverage is treating the operating system in question graphene OS as the problem, as if a hardened phone is a loophole for criminals. As if the duress feature is some menace that needs to be reigned in. That message is backwards, and it's a very old, entire trick that we have seen over and over again by the government. Graphene OS did nothing wrong here. It is a legitimate privacy tool used by journalists, activists, executives, and ordinary people who simply do not want their entire lives sitting exposed on a device that leaks their data. That duress wipe is a real defense for someone whose phone is grabbed by a mugger or a stalker or an abusive partner and is forced to unlock it without their consent. The tool is neutral. What matters is the judgment of the person holding it. We have seen this exact narrative before. The FBI has spent years trying to pin the blame on signal.
The encrypted messenger app arguing that the strong encryption is a gift to criminals and that the company ought to weaken it or build in a backdoor. Before signal, it was other encryption apps and other tools before that. The argument never changes. Therefore, the tool is the threat in their opinion. This is a deflection, and it's a dangerous one, because the fix they are selling is to strip away the protection from all of us. So hear me clearly. The tool is not the bad guy. A locked door on your home that protects your family and now and then a criminal hides behind one. And we do not respond by outlying locks on doors. The bad guys are the bad guys. Blaming the encryption or the operating system or the dress feature is how you get talked into surrendering the very things that keep the rest of us safe. This is a tired and old message and it is a trap. Do not fall for it and do not let the story convince you that privacy tools are the enemy
or need to be weakened. They are not. So if it's not the tool, let me be just as clear that it is not the officers or the law enforcement either. That is the enemy here. There's a reflex within the privacy community to treat every person with a badge as the adversary. As an operational matter, that framing is wrong and it leads to bad decisions. The agents in that inspection room were doing their job under a policy written far above them inside of the legal gray area that Congress and the courts have left unsettled for decades. When you cast the officer in front of you as the enemy in any circumstance, you are making emotional decisions in setting where the law is most stacked against you. You escalate, you reach for the dramatic move and that is exactly the road that ends where Tunic is now. Knowing your enemy means knowing who actually holds power over your privacy and who does not. The agent at the border did not build the machine that tracks you. He is a person doing a shift, coming to work every day.
Aim there and you spend your energy on the wrong target while the real ones run untouched. So who is the enemy? Let's name it plainly. The enemy is the ambient commercial warrantless surveillance machine that collects on everyone. All the time with no cause, no court order because it was built into the ordinary business of daily life. It does not need a warrant because it never had to ask for one. It just collects the advertising bid stream that broadcasts your location to 100 companies every time and ad loads and then sells it to anyone including the government or law enforcement or our commercial entity. The data brokers who assemble your life from that exhaust and put it up for sale, they call it a consumer profile. And in the intelligence field, we call it a target package. Right now, let's add flock safety.
Automated license plate readers, going up on poles in thousands of towns, photographing every car that passes, not just suspects everyone. Building a searchable vehicle fingerprint and holding it for weeks, sometimes months. This is called a pattern of life. Police can query where your car has been with no warrant and no suspicion. In 2026, the backlash has gotten real. Roughly two dozen jurisdictions have moved to cancel or reject flock contracts and the ACLU is in court arguing the practice violates the fourth amendment. That is the enemy. Not the officers who run the plates, the system that logged the plate of every car in the county forever without asking and without a vote from the citizens and traveling right alongside it is the second adversary I already named. The narrative that blames the tools so that you will give up your own defenses and freedoms and let the collection run unopposed.
Now I want to sharpen the point a bit because on the show I talk constantly about your data being collected and about that data being accessible to law enforcement and it's easy to hear that and think that the danger is a cop looking you up or that the enemy is law enforcement getting your data. That is not the real danger. Let me be precise about what it is. The real risk is that data collected about you for ads and for convenience can pull you into an investigation that you have nothing to do with. You do not have to be a suspect. You do not have to do anything. You just have to have been in the wrong place or made the wrong search while the machine is quietly logging it. The clearest example is the geofence warrant. If you're not familiar with that, here's how it works. A crime happens somewhere. Investigators, law enforcement, go to the company that holds the location data, often Google and or Apple and they request in effect every device that was in that area during a certain
window of time. Not a name suspect, everyone. The provider searches this entire pool of user locations and hands over a list of people who happen to be nearby, most of whom have no connection to anything related to the crime. This is not hypothetical. A man named Zachary McCoy in Gainesville, Florida used a fitness app that logged his bike rides to Google. His normal route took him past a house that got burglarized on the day it happened. A geofence warrant swept him up and Google notified him that his data was about to go to the police. He was innocent. He had to hire a lawyer to keep himself from being handed over as a suspect in a crime that he had nothing to do with. Clearly because an app knew where he had tettled his bike, that is the threat. Not that the police are evil because they look for this data. It's that your ordinary collected location made you a suspect by proxy. The law enforcement are going to try to use every tool that they have to their advantage
to catch criminals. It is what you should expect. But the fact that this data is available is the problem. Now the laws around geofence warrants are unresolved. In August 2024, the fifth circuit court of appeals in the United States ruled that the geofence warrants are unconstitutional general warrants under the Fourth Amendment. In the same era, the Fourth Circuit went the other way and held that pulling that kind of limited location history was not even a search. So depending on where you are in the country, the courts disagree on whether this is legal at all. That split is the current state of the law and it may take the Supreme Court to settle it. There has been one meaningful shift on the collection side. Google moved its location history now called timeline onto your device so it no longer holds that giant central pool the way it used to, which makes those specific Google geofence drag nets much harder to run.
That is real and it is good. But do not mistake it for the end of the problem. Your location still leaks from the ad bit stream and from many other apps and from your carrier and from license plate readers and reverse keyword search warrants can still reach those sources. So the lesson holds the exposure was never really about who can ask for your data. It was about how much of your data exists to be asked for. Now I'd like to turn this into something that you can use a quick and honest caveat first. I am not a lawyer. This is not legal advice. If you are ever in a situation like tunics or dealing with any law enforcement, you need a real attorney, not a podcast episode. First, know your tools. Keep your tools and respect them. Graphene OS, signal messenger to rest wipe all of these things are legitimate, all worth using in the right circumstances. The lesson is not to abandon them or to use them irresponsibly.
It is to understand precisely what each one does and the exact context in which it turns from a shield into a liability. A wipe code that protects you from legitimately dangerous situation can become an obstruction charge in a lawful search. Same tool, different context. Know the difference before you ever need it. Second, know your target. Aim your op sec at the machine, not at law enforcement and not at your own tools, not at weakening your stance. The whole game is to generate as little exploitable data as possible in daily life so that when anyone goes looking commercial or government and whether or not it has anything to do with you, there is very little to find. That is data minimization and it is quiet, it is boring, but is effective. It is also your only real defense against the geofence problem because you cannot be swept up over data that was never collected in the first place.
Third, know your scenario. The border, for example, is its own world with its own rules and the smart move is to not bring the fight into that location or that scenario. It is to not carry sensitive data through it at all. Travel light, travel clean and read the rules before you go. I like to travel with sanitized devices that don't have information on them and I can download the information in the location when I get there. The EFF border guide is in the show notes. Read more there. Fourth, know the fight. Put your energy where it can actually win and matter. Local councils counseling flock contracts, for example. Courts weighing in on fourth amendment and geofence splits. Your own choice is about which platform you feed. That is where the ground is moving and it moves because people aim it at the system instead of at the person in the uniform or the app on their phone. So here's the message I want you to leave with today.
A man made a deliberate choice to destroy data during a search. The government was authorized to run and he's answering for that choice. Even as his lawyers fight over whether that search was lawful to begin with, this man is not a victim or a martyr. He made a decision and is now dealing with the consequences. That is accountability working itself out. The tool he used was not the villain either and the agents in the room are not the enemy. Do not let the media coverage talk you into either mistake. Those thought processes are a trap. Know your enemy. It is the warrantless surveillance machine that collects on all of us without cause and it is the tired narrative that scapegoats privacy tools so that you will hand your defenses over willingly. And remember, the real risk that comes with all that data being collected on you. It is not that someone can look you up. It is that your ordinary data can drop you into an investigation you were never a part
of. Keep those straight. Own your decisions. Select your tools and the law both and spend your effort where it actually changes something. Vote with your feet and vote with your dollar is what I like to say. What that means is I voted with my feet by exiting the Google platform and using graphene. I voted with my feet and my dollar by moving away from Google services and into protons environment that respects privacy. That is the beauty of having the choice that we have in the digital world. Keep that in mind. Thank you for listening to the Opset Podcast. If this episode earned its value, lock in the habit. Follow us and subscribe wherever you are listening so that you never miss a drop and sign up for our newsletter at OpsetPodcast.com to get the latest tools and trade crafts straight to your inbox. Subscribing is the easiest way to help this podcast succeed. And tell your friends and family members about us as well.
We are not doing any sponsorships or paid ads at this time and we would like to keep it that way. So spread the word. I am Alan Pace. And remember, your privacy and your security is your responsibility.
More episodes
More from The OPSEC Podcast

Follow the Money: The Complete Surveillance Picture Built by Your Payment Histor...
The OPSEC Podcast

Podcast Update: What's New, What's Not, and What's Next
The OPSEC Podcast

Permanent Record: How School Data Breaches Put Your Child's Identity on the Mark...
The OPSEC Podcast

The Smart Home Is a Listening Post: Amazon, Google, and the Surveillance You Pai...
The OPSEC Podcast