The duress-PIN gambit just got someone federally indicted

5 min read 1 source clear_take
├── "Using the duress PIN during a lawful search is evidence destruction, regardless of the mechanism"
│  ├── top10.dev editorial (top10.dev) → read below

The editorial argues that the legal system focuses on the act and intent, not the technical mechanism used. Destroying evidence during a lawful search is a crime whether accomplished with a shredder, hammer, or four digits — the duress PIN is just a tool, and prosecutors charge people for what they do with tools.

│  └── Federal prosecutors (via indictment) (TechSpot) → read

Prosecutors' theory as reported: entering the duress PIN in front of agents actively demanding access is functionally identical to shredding a subpoenaed document in front of the FBI. The intent to destroy evidence is what matters, not the specific method used to accomplish it.

├── "The 'you can't criminalize a sequence of digits' theory is being tested — and failing"
│  └── top10.dev editorial (top10.dev) → read below

The editorial identifies a persistent piece of privacy-community folk wisdom — that if typing one PIN is legal, typing another must also be legal — and frames the Atlanta indictment as the first high-profile test of that theory. The editorial's assessment is blunt: it's going badly, suggesting the digits-are-speech defense won't survive contact with a courtroom.

└── "GrapheneOS's duress PIN works exactly as designed — and that's precisely the legal problem"
  └── @eecc (submitter) (Hacker News, 1155 pts) → view

By surfacing the TechSpot story to HN's front page (1155 points), the submitter frames this as a cautionary tale about a legitimate, documented privacy feature. The duress PIN isn't an exploit or jailbreak — it's a setting designed exactly for coerced-unlock scenarios, and the fact that it worked as advertised is what created the criminal exposure.

What happened

A US citizen returning through Hartsfield-Jackson in Atlanta was pulled into secondary inspection by Customs and Border Protection. According to the indictment reported by TechSpot, agents ordered him to unlock his phone. He entered a PIN — but not the one that unlocks the device. He entered his duress PIN, a GrapheneOS feature that triggers an immediate factory wipe of the device and its encryption keys. By the time the agents realized what had happened, the phone was a brick with no recoverable data.

Federal prosecutors have now charged him with destruction of records and obstruction. The government's theory is straightforward: entering the duress PIN in front of agents who were actively demanding access is functionally identical to shredding a subpoenaed document in front of the FBI. The mechanism doesn't matter. The intent does.

GrapheneOS's duress PIN is a legitimate, documented feature — not a jailbreak or exploit. You set a secondary PIN in settings; entering it wipes the device and any eSIMs. It's designed for exactly this scenario: someone with physical control of you demands your unlock code. The feature works as advertised. That's the problem.

Why it matters

There's a persistent bit of folk wisdom in the privacy community that goes roughly: the government can't criminalize a specific sequence of digits. If typing 1234 is legal, typing 5678 must also be legal, even if 5678 happens to wipe your phone. The Atlanta indictment is the first high-profile test of that theory, and it's going badly.

The legal system does not care about the technical mechanism; it cares about the act and the intent behind it. Destroying evidence during a lawful search is a crime whether you do it with a shredder, a magnet, a hammer, or four digits on a touchscreen. The duress PIN is a tool. Prosecutors charge people for what they do with tools, not for the tools themselves. A locksmith is legal; using lockpicks to break into a house is not.

The border context makes this worse, not better. Under the border search exception, CBP can inspect electronic devices without a warrant and without probable cause. Courts have carved out some limits — the Ninth Circuit requires reasonable suspicion for forensic searches — but the baseline authority is broad and well-established. Citizens cannot be denied re-entry for refusing to unlock a device, but they can be detained, have the device seized, and now, apparently, be criminally charged if they destroy data mid-search.

The Hacker News thread on this story surfaced the operational reality quickly. One commenter, DanHulton, put it bluntly: *"If your threat model means you can't afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side."* Another, sfRattan, noted that choosing to enter a duress PIN in front of agents is a choice with foreseeable legal consequences — the Constitution doesn't hand you a mulligan for evidence destruction just because the destruction was elegant.

The GrapheneOS duress PIN was designed for a threat model where the person demanding your unlock is a criminal, not a federal agent with the authority to charge you with obstruction. Against a mugger, a kidnapper, or a hostile foreign customs officer with no reciprocal legal relationship, wiping is a rational move. Against your own government's border agents, in your own airport, with a legal system that can put you in prison — you have just handed prosecutors a much cleaner case than they had five minutes ago.

What this means for your stack

If you're a developer, security researcher, journalist, or anyone else who carries sensitive data across borders, the operational lesson is now well-defined: don't bring the data across the border in the first place. The duress PIN is not a border-crossing tool. It never really was, but the ambiguity is now gone.

The working pattern is boring and effective. Before travel, back up your phone to an encrypted cloud service or a device you're leaving behind. Factory reset. Fly with a clean device — signed into nothing sensitive, containing nothing sensitive. On arrival, restore. On the return leg, wipe again. CBP can inspect a phone that contains your boarding pass, some podcasts, and a fresh install of Signal all day long; there's nothing to find and nothing to destroy. A blank phone that arrives blank is not evidence destruction; a duress-wiped phone during an active search is. That's the entire distinction the law cares about.

For the truly paranoid, VeraCrypt-style plausible deniability — a decoy OS with a decoy password, real data hidden in what looks like free space — has been floated for years and got a mention in the HN thread. It's technically clever and legally untested at the US border. It also requires you to lie convincingly to a federal agent, which is its own felony surface area. Most practitioners will find the burner-phone approach cheaper, safer, and less morally taxing.

Corporate security teams should treat this as a policy trigger. If your engineers travel internationally with laptops or phones holding source code, customer data, or production credentials, the answer is not "install GrapheneOS and set a duress PIN." The answer is a documented travel-device program: loaner hardware, temporary credentials, MDM-enforced clean images, and re-provisioning on return. This is what defense contractors and journalists working in hostile regions have done for a decade. The threat model has finally caught up with the rest of us.

Looking ahead

The indictment will be litigated, and there's a non-zero chance an appeals court eventually draws a line around duress PINs — perhaps distinguishing between passive protection (auto-wipe on failed attempts, which is clearly legal) and active destruction (a specific input entered during a search). But betting your freedom on a favorable circuit split is a poor security posture. The pragmatic read is that any anti-forensic feature triggered in front of law enforcement is now presumptively obstruction, regardless of how the trigger is dressed up. Design your travel workflow around not needing the feature, and the legal ambiguity stops mattering.

Hacker News 1155 pts 861 comments

US citizen charged after GrapheneOS phone wipes during airport search

→ read on Hacker News
schoen · Hacker News

I co-wrote a border search guide for EFF some years ago. I was very interested in finding clever technical approaches but I later ended up feeling that I hadn't given enough thought to the overall threat model questions (even though the guide did address them, perhaps even somewhat usefully).Th

cameldrv · Hacker News

I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers

sfRattan · Hacker News

Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explic

Grimblewald · Hacker News

VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give pro

whats_a_quasar · Hacker News

Here is the indictment: https://www.documentcloud.org/documents/28513012-samuel-tuni...Here is the statute Tunick is indicted under: https://www.law.cornell.edu/uscode/text/18/2232There is an immediate problem: the device was being searched, and this

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.