Connect with us

Tech

US accuses American of allegedly wiping his phone using a ‘duress’ password during border search

The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports. 

This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a “duress” password built into a phone’s software.

According to The Guardian, which covered the story earlier this week following the court’s first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick’s attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year and that any evidence — including the alleged wiping of his phone — should be thrown out.

The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone.

The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode.

Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.

The government’s indictment, which contains a typo (“Untied States Code”), accuses Tunick of allegedly providing a passcode to border agents that caused the phone to “delete the digital contents,” prior to the device being seized.

Tunick’s attorneys filed a motion to suppress the evidence, claiming that the detention and the seizure were unlawful. The motion said U.S. border authorities took Tunick into a secondary inspection at Atlanta’s Hartsfield-Jackson airport as he returned from overseas on January 24, 2025, but that he was repeatedly denied access to an attorney and was not informed of his legal rights.

Tunick’s attorneys accused the government of demanding access to his phone under the pretext of searching for child exploitation imagery, but without providing evidence to justify its suspicion. His motion to suppress argued that the government was instead investigating him over his association with a long-running environmental movement called Defend the Atlanta Forest, which opposes the development of a sprawling training campus for law enforcement in Atlanta dubbed “Cop City.”

The motion said that the border agents claimed they did not need a warrant to search Tunick’s phone because he had not yet crossed the U.S. border. The U.S. government has long claimed it can search and seize people’s devices without a search warrant or court order until they are permitted entry to the United States.

When Tunick provided his passcode and the authorities entered it, “the screen went blank, flashed several times and the phone appeared to restart.” The authorities seized his phone anyway, before telling him that he was free to go and could enter the United States.

Prosecutors later charged Tunick under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it. Tunick has pleaded not guilty.

Matthew Dodge, an assistant federal public defender on Tunick’s legal team, told TechCrunch that it was incredibly rare to see the federal statute used in an indictment.

Security experts also said they had not seen charges brought in this way before.

Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords.

“I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” 

“With a little planning ahead of time, you can always download the data you need once you get to where you’re going,” said Sandvik. 

The Electronic Frontier Foundation has guides on how to protect your data and security at the U.S. border, and explains what rights you have.

The Atlanta federal court overseeing the case is expected to rule on Tunick’s motion to suppress later this year. A Justice Department spokesperson declined to comment when reached by TechCrunch.

Updated to correct the spelling of a surname in the fifteenth paragraph.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Sam Altman’s biometric startup World raises $52.5M via crypto sale

World, the online verification startup co-founded by OpenAI’s Sam Altman, has raised $52.5 million through a crypto token sale to strategic investors.

Participating investors joined a 12-month lockup sale of World’s token, WLD. Lockup periods prevent asset buyers from selling or trading their tokens for a set period of time. The yearlong lockup demonstrates investors’ “long-term commitment to World’s continued growth and utility,” the company said Friday in a press release.

The money will go to the World Foundation, an exempted limited guarantee foundation based in the Cayman Islands, created to steward the expansion of World’s network.

The sale’s lead buyer is Pantera Capital, a venture capital firm focused on digital assets. Other companies involved in the sale included Eightco Holdings, Bain Capital Crypto, Susquehanna Crypto, and Selini Capital, among others.

The World project is operated by Tools for Humanity (TFH), a startup based in San Francisco and led by CEO and co-founder Alex Blania. Altman is the company’s other co-founder.

World is an unusual business that revolves around online verification and sells access to what it calls “proof of human” tools. The idea is that, as bots and AI generate much of the content online, it will become increasingly important to know who is really human and who isn’t. World’s mission is to popularize its World ID, an anonymous digital marker that verifies whether a human — not a bot or an AI agent — is behind a particular account.

To get a verified World ID (the highest level of verification within World’s system), users must have their eyes scanned by an Orb, a metallic ball that converts a user’s iris into a distinct cryptographic identifier. World’s Orbs are located at its offices and have also been deployed at partner stores around the world.

The project began as a more overtly crypto-based experiment under the name “Worldcoin” — the same name of the crypto asset involved in the recent sale. Users can trade or hold the token through World’s app, which also serves as a custodial wallet. The company later rebranded to World amidst a broader backlash against the crypto industry.

In April, the project launched a new version of its app and announced partnerships with companies, including Tinder, Zoom, and Docusign. Yet, despite its global ambitions, World has struggled to scale its business or convince consumers to care much about its mission. In June, TFH conducted a round of layoffs.

Correction July 24: An earlier version of this story incorrectly stated that World has a partnership with Ticketmaster. It does not. We regret the error.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

OpenAI’s own model went rogue before Kimi had Wall Street sweating

Chinese AI lab Moonshot’s open model Kimi went viral this week for reasons that had less to do with the model itself and more to do with how the U.S. AI industry reacted to it. Meanwhile, an unreleased OpenAI model wandered outside its test environment and ended up connected to a real security breach at Hugging Face — a reminder that “China risk” isn’t the only kind of AI risk worth worrying about. 

On this episode of TechCrunch’s Equity podcast, hosts Kirsten Korosec, Anthony Ha, and Sean O’Kane dig into why Kimi K3 set off a fresh round of AI panic, the industry’s response to an OpenAI staffer’s “regulatory FUD” post, and what that OpenAI breach means for AI security more broadly. 

Subscribe to Equity on YouTube, Apple Podcasts, Overcast, Spotify and all the casts. You also can follow Equity on X and Threads, at @EquityPod. 


source

Continue Reading

Tech

India’s move against Jack Dorsey’s Bitchat sparks legal debate

An apparent Indian government effort to remove GitHub repositories for Jack Dorsey’s offline Bluetooth-powered messaging app Bitchat has raised questions about the legal basis for targeting open source software because of how it works.

The issue with Bitchat came to light after Dorsey posted on X on Friday what he said was a notice from India’s Ministry of Home Affairs directing GitHub to restrict access to three Bitchat repositories within three hours. The notice argues that the app’s anonymous, decentralized architecture could facilitate unlawful activity and allow users to communicate during internet shutdowns while making lawful interception more difficult.

The move comes as Indian authorities tighten internet restrictions after weeks of student-led protests in New Delhi over alleged examination paper leaks.

The demonstrations, known as the “cockroach” movement, have drawn thousands of young people demanding the resignation of Indian Education Minister Dharmendra Pradhan, with authorities also imposing restrictions on marches toward the parliament. Local media reported that some protesters downloaded offline messaging apps, including Bitchat and Briar, after internet services were suspended.

The order represents a new approach for the Indian government, which, before 2021, typically relied on Section 69A of the IT Act and the 2009 Blocking Rules when it wanted content removed nationwide, according to Mishi Choudhary, founder of SFLC.in, an Indian digital rights legal advocacy group.

She told TechCrunch that the document resembled the format of recent government takedown notices, but the legal provisions it cites do not clearly authorize authorities to seek the removal of an entire software project because of how it works rather than any specific illegal content.

Bitchat app on iOS.Image Credits:Apple App Store (screenshot)

Unlike many government takedown requests, the document Dorsey shared does not identify specific posts, messages, or repositories containing unlawful material. Instead, it argues that Bitchat’s ability to function during internet shutdowns and without central servers could facilitate unlawful activity.

The notice, dated July 23 and apparently issued by the Indian Cybercrime Coordination Centre (I4C), which operates under India’s Home Ministry, said Bitchat enables users to communicate “even during network restrictions” and “internet shutdowns,” making it possible to “circumvent lawful restrictions” while hampering “lawful interception, attribution, and traceability.”

In recent days, Bitchat has seen a sharp rise in popularity in India. Market intelligence provider Sensor Tower shared data with TechCrunch that showed that India accounted for about 85% of the app’s global downloads between July 17 and July 23, compared with about 1% over the previous 30 days. Bitchat was downloaded more than 91,000 times in India over the past five days, after downloads jumped thirty-two-fold on July 19 from the previous day. The app’s daily active users in India also reached more than 330,000 on Thursday, the highest level recorded for the app in the country.

Request raises questions about open source software

The Internet Freedom Foundation (IFF), a New Delhi-based digital rights advocacy group, questioned the effectiveness of the apparent takedown request.

“The order also fails on its own terms as deleting a repository does not delete the application from any phone that carries it, and the mesh keeps functioning without servers. What the takedown actually prevents is scrutiny of the underlying code,” the group said on X.

Raman Chima, global program director at the Association for Progressive Communications, a global digital rights network, told TechCrunch the apparent notice went beyond targeting the messaging service itself by seeking to remove its open source code from GitHub.

“They’re [the Indian government] not just targeting the designated service provider, but they’re trying to say that open source development of this type of product … should not occur,” he said.

Bitchat’s primary GitHub repository remained accessible in India on Friday.Image Credits:Jagmeet Singh / TechCrunch

GitHub did not confirm whether it had received the document. The repositories remained accessible from India on Friday. Asked about the apparent notice, the company shared a link to its public repository of government takedown requests, which did not contain any recent requests related to Bitchat.

Namrata Maheshwari, Asia Pacific policy manager and encryption policy lead at digital rights group Access Now, told TechCrunch that blocking an offline messaging platform during internet restrictions risked turning shutdowns into “a communication blackout” that violated fundamental rights. Protesters in any democracy have the right to communicate privately and coordinate peacefully, she said.

“When we receive a complete government takedown request, we notify the affected account owners and give them an opportunity to appeal,” Rose Coogan, the company’s principal online safety counsel, said in a statement emailed to TechCrunch. “We share every government takedown request we take action on publicly.”

India’s Home Ministry did not respond to a request for comment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading