The NYT report frames the case as prosecutors treating the phone like a filing cabinet an agent asked a suspect to open — emptying it in front of them constitutes obstruction regardless of contents. The charge hinges entirely on the act of deletion occurring after CBP signaled a search was imminent, not on what was on the device.
The long-standing advice for developers and security professionals — wipe before you fly, restore from backup on arrival — assumed the sensitive action happened at home with plausible deniability. Tunick's indictment tests whether the timing of the wipe is what makes it criminal, which would be a meaningful shift from what most travel-security guides currently recommend.
Under the current CBP directive and Riley v. California, 'basic' warrantless device searches are permitted at the border while 'advanced' forensic searches technically require reasonable suspicion. Citizens cannot be denied entry for refusing to unlock, but no court had squarely addressed what happens when a traveler acts first to erase data — Tunick's case is the test.
Samuel Tunick, a US citizen returning to the country, was pulled into secondary inspection by Customs and Border Protection. According to the federal charging documents reported by the New York Times on August 21, agents told him his phone would be searched. While waiting, he factory-reset the device. He is now facing felony obstruction charges — specifically, destruction of records with intent to impede a federal investigation, a statute that carries up to 20 years.
The case does not turn on what was on the phone. It turns on the act of deletion itself, at the moment CBP had signaled a search was imminent. Prosecutors are treating the phone the way they would treat a filing cabinet an agent had just asked a suspect to open: emptying it in front of them, they argue, is obstruction regardless of whether the contents were incriminating.
The legal backdrop here is already messy. Under the current CBP directive and the *Riley v. California* line of cases, warrantless "basic" device searches at the border are permitted; "advanced" (forensic) searches technically require reasonable suspicion, though enforcement is uneven. Citizens cannot be denied entry for refusing to unlock a device, but non-citizens can. What no court had squarely addressed until now is what happens when the traveler acts first.
The developer-and-security-professional playbook for border crossings has, for years, been some version of: wipe before you fly, restore from backup on the other side, never carry secrets through customs. That advice assumed the sensitive action — the wipe — happened at home, days earlier, with plausible deniability about intent. Tunick's indictment tests whether the *timing* of the wipe is what makes it a crime, which would be a meaningful shift from what most travel-security guides currently tell you.
The HN thread on the story (709 points, heavy legal-adjacent commentary) split cleanly along two lines. One camp argues this is a straightforward obstruction case: agents told him a search was coming, he destroyed the target of that search, that's the elements of the offense. The other camp — including several commenters citing their own EFF-guided travel setups — argues the charge is a novel expansion, because the underlying search itself had no warrant and no articulated suspicion, and you cannot obstruct an investigation that has not been lawfully predicated.
Both readings have force. The stronger version of the government's case is that border-search authority is its own constitutional carve-out; agents don't need a warrant, so "there was no warrant" isn't a defense to interfering with the search. The stronger version of the defense is that treating a factory reset as felony evidence destruction, when the underlying "evidence" was a citizen's entire personal digital life that the government had no particularized reason to see, effectively converts the border-search exception into a compelled-decryption regime by the back door. If deleting is a crime and refusing is only *sort of* allowed, the practical asymmetry pushes hard toward compliance.
For anyone who carries a work device — source code, customer PII, unreleased product data, signed commits, cloud credentials — the practical takeaway is that the safe window for wiping has moved. It is now at home, before the trip, with a paper trail (calendar reminder, backup timestamp, whatever) that the wipe happened as routine hygiene, not as a response to an agent's request.
Concrete adjustments to make if you cross US borders with a laptop or phone that touches production:
Wipe on a schedule, not on a prompt. A monthly or pre-trip factory reset of a travel device is defensible; a reset at the CBP counter is now, per this indictment, a federal charge. If your company issues travel laptops, the policy should be that the wipe-and-reimage happens at IT before departure and is logged in a ticketing system. That log is your intent evidence.
Separate travel devices from primary devices. The old advice — carry a burner, restore from a cloud backup after clearing customs — holds up better than ever. If the device that crosses the border genuinely contains nothing sensitive, the entire deletion-vs-obstruction question is moot. This is more annoying operationally (MFA re-enrollments, SSH key regeneration) but the cost is now measured against a felony statute.
Assume the device you present will be imaged. CBP's advanced-search authority extends to forensic copies that persist inside the agency. Anything you unlock is not just seen — it's potentially retained. Rotate credentials on any account that was accessible from a device that went through secondary inspection, on principle, the same way you'd rotate after a lost laptop.
For teams: write it down. Update your security handbook now, before someone on your team learns this at the airport. The relevant line is short: *do not modify, delete, or reset a device once a border agent has indicated a search will occur.* Wipes belong in the pre-travel checklist, not the interview.
Tunick's case will almost certainly be litigated on the obstruction elements — did he know a search was imminent, was the reset a "corrupt" act under the statute — rather than on the broader Fourth Amendment question everyone actually wants answered. That means the near-term precedent, if any, will be narrow and fact-specific, and the ambient chilling effect on travelers with sensitive devices will do most of the policy work regardless of how the case comes out. EFF and ACLU will almost certainly weigh in; expect an amicus wave and, eventually, a circuit-split-driven Supreme Court petition on whether the border-search exception implicitly includes a duty to preserve. Until then, treat the border like a jurisdiction where the safest action on your phone is the one you took a week ago.
And this is why companies in the EU have a business travel rule to take a freshly wiped laptop on international trips, not just a locked one with a "distress code".
For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.There's no deception required to protec
I read a pretty compelling argument by a lawyer that we're looking at this the wrong way. (I Am Not A Lawyer)Their point was that if the law is knocking on your door to legally search your house, and you have records of your criminal empire printed out in boxes in your attic, or just non-illega
The decoy passcode feature should boot into a separate partition that looks like a normal phone setup, and during that time quietly erase the user's actual data. They would never have known if it worked like this.
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
From Universal Declaration of Human Rights (UDHR) accepted by the United Nations General Assembly on 10 December 1948-------- Article 12No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has th