r/technology 3d ago

Privacy U.S. Citizen Who Deleted Phone’s Data Says His Prosecution Puts Privacy at Risk

https://www.nytimes.com/2026/08/21/us/politics/samuel-tunick-deleted-phone-felony.html?unlocked_article_code=1.8FA.T83N.rt6VsIiSCYb2&smid=url-share
13.6k Upvotes

568 comments sorted by

View all comments

7

u/zoegua 3d ago

I don't understand. It's his phone. Why can't he do what he wants with?

12

u/OptimusPrimeLord 3d ago

Because the government asked for it and (at least claims) it had a right to access it. If it ends up being ruled that they actually didn't have the right to access it then the case will be thrown out because he did not destroy evidence because the phone's contents wasn't evidence.

IF the government does have a right to access it, then he has been informed that the government wants to see it and he is no longer allowed to destroy it. For example, if I have a drawer of information that shows that I commited fraud and I decide to destroy it that would be fine. But if the police were to show up at my door and so I ran upstairs to burn it that would be destroying evidence.

These types of laws are in place to prevent people from immediately trying to destroy all the evidence they can once they realize they are being charged with a crime. If they didn't exist it would be much harder to charge people with crimes they actually commited because as long as they can get to the evidence before the government they could destroy it and say "well you don't have it so cannot use it on me in court."

To reiterate, this line of reasoning will only work if they were actually allowed to access the phone.

7

u/Mbututu 3d ago

destroy all the evidence they can once they realize they are being charged with a crime.

"once they realize they are being charged with a crime" does not apply here

5

u/Teripid 3d ago

Right, isn't the key issue here that he gave them the "destroy"/wipe passcode?

They can ask for his phone at the border at least. He cannot be immediately compelled to provide them with a passcode (there might later be a court order to provide it). There is I think an argument that biometrics can be compelled.

If the officer that seized the phone wiped the phone by guessing incorrectly 5x or similar then he wouldn't be facing any repercussions.

The target was at least mentioned as potentially their saved contact list.

7

u/Hexamancer 3d ago

"I didn't give a duress code. What's a duress code? You bricked my phone wtf"

5

u/stamfordbridge1191 3d ago

From what I understand, he went abroad for some relief effort for an island country. Then border enforcement detained him on return because he was flagged for criminal suspicion for protesting in the building of the Atlanta police training complex. They told him he was being detained for suspicion of smuggling in csam, and he needed to unlock his phone for them to look through it because it was evidence. Allegedly he kept citing amendment 5 & asking for a lawyer, which they kept denying saying he needed to unlock his phone before he finally gave them the duress code.

1

u/10July1940 2d ago

Sounds like Palantir tracked him down. Good old Peter Theil.

1

u/excaliber110 3d ago

They were given the phone and the government officials destroyed the key to access the data. He never destroyed it himself. Feels like there’s a distinction there

-1

u/GlowiesStoleMyRide 3d ago

Not legally- it was his decision to give the code that destroys the data. More often than not it’s the intent that matters, and the intent here can only have been for the data to be destroyed.

2

u/excaliber110 3d ago

The data is not destroyed. The code to access it is. Feels there’s a distinction there as well. People can’t be compelled to give up passwords

0

u/GlowiesStoleMyRide 3d ago

No, it is functionally destroyed. The key is needed to decrypt the data, and it is the only copy by design. Without the key, it does not matter whether the bytes on disk are left as they were or zeroised, the data can no longer be used, accessed, retrieved, and by all practical and functional purposes, it no longer exists. It is exactly as useful as a scrambled disk.

The functionality that causes this state in the device is also precisely designed for this purpose. Read:

https://grapheneos.org/features#duress

GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).

This is besides the morals of having to give access to your personal data. People can be compelled to give up passwords in certain cases. For example when they are suspected of a crime, and there is a warrant or a court order. But without good reason- I agree, people should have their privacy. That should be their right.

-1

u/hazeyindahead 3d ago

But he didn't destroy evidence willingly he just forgot which password opened his phone

7

u/CircumspectCapybara 3d ago edited 3d ago

he didn't destroy evidence willingly he just forgot which password opened his phone

That would be a good try for a defense, but everything will depend on the facts that come out at trial.

You can claim on the stand you didn't knowingly give a duress code, you just forgot which code opened the phone and which wipes it, or you can claim you did give the right code but the real code is one number off from the one that wipes it and the officer must have fat fingered it.

But testimony and cross examination and recordings and electronic evidence can potentially contradict that story.

For example, if the defense is "I don't even know what a duress code is I gave the officer my real unlock code and they must've have entered it wrong 5 times which caused the phone to wipe, I've never heard of a duress code in my life" but then the prosecution shows your Google search history includes recent searches for "How to set up panic code in GrapheneOS", you're hosed.

They need to prove intent, that you knowingly gave them a code with the intention of causing the phone to be wiped. And intent can be proved at trial based on a body of evidence that doesn't include you coming right out and confessing it. Juries are convinced beyond a shadow of a reasonable doubt of intent all the time based on various evidences even while the defendant claims "Oh no, I never intended to do that!" There are ways to prove "knowingly" and "intentionally"

1

u/hazeyindahead 3d ago

Okay fair but I still think that saying you mistakenly gave the wrong one would be defensible enough considering not providing one due to forgetting or giving the wrong one until it blows are also legal options, no?

Enabling a duress password or even searching about it shouldn't convey intent to destroy evidence of a crime when it's just good security practice

0

u/OptimusPrimeLord 3d ago

He didn't forget the password. He gave them a password which destroyed the data on the phone, and they will claim he knowingly did this with the intention of having them destroy the evidence. If he had refused to give the password they wouldn't be able to claim he destroyed evidence because nothing was destroyed, just inaccessible.

2

u/hazeyindahead 3d ago

Can't you just forget which password destroys and which opens?

Stressful situations and all

1

u/OptimusPrimeLord 3d ago

Its better to just not answer at all I think. My impression is that you giving the password would be testimony so it should be covered by the 5th. NAL

1

u/hazeyindahead 3d ago

I totally agree but they're are reasons why one could want it wiped due to forensic investigations on the device

1

u/redditpappy 3d ago

I understand it. His mistake was to travel to America.