The editorial argues this is the first case where the act of wiping — not the contents — is the alleged crime, effectively placing devices under a preservation obligation the moment a traveler enters the inspection lane. This upends a decade of standard guidance from EFF, ACLU, and corporate security teams that recommended wiping devices before travel as the only reliable defense against the broad border-search exception to the Fourth Amendment.
Federal prosecutors are applying obstruction and destruction-of-records statutes — the same laws used against defendants who shred documents ahead of a subpoena — arguing that once a CBP officer indicated intent to search the phone, clearing it constituted destruction of evidence in a federal proceeding. The government's theory does not depend on the underlying data being illegal; the act of deletion itself is the crime.
Samuel Tunick, a US citizen re-entering the country, was indicted after Customs and Border Protection officers noticed he had wiped data from his phone during secondary inspection. According to the filing reported by the New York Times on August 21, Tunick is charged under federal obstruction and destruction-of-records statutes — the same family of laws used against defendants who shred documents ahead of a subpoena. The government's theory is not that the underlying data was illegal. It is that deleting it, once a CBP officer had signaled intent to search the device, constituted destruction of evidence in a federal proceeding.
This is the first widely reported case in which the act of wiping a phone at the border — not the contents of the phone — is itself the alleged crime. Previous headline cases involved travelers refused entry, detained for hours, or having devices seized for forensic imaging. Tunick's indictment moves the line: the government is arguing that once you're in the inspection lane, your device is functionally under a preservation obligation, and clearing it can put you in front of a grand jury.
CBP's own policy, updated in 2018, distinguishes between a "basic" search (an officer scrolling through your phone) and an "advanced" search (connecting the device to forensic equipment like Cellebrite). Basic searches require no suspicion. Advanced searches require reasonable suspicion of a border-related offense — a bar that appellate courts have set very low. Neither policy, until now, was paired with a criminal charge for pre-emptive deletion.
For the last decade, the standard advice from EFF, ACLU, and every corporate travel-security team has been some version of: travel with a burner, or wipe your device before you fly. The reasoning was that the border-search exception to the Fourth Amendment is broad enough that fighting a search in the moment is a losing move — better to have nothing to search. That advice was built on the assumption that the act of minimizing what you carry is legally neutral. Tunick's case says it may not be.
The legal theory here is worth pulling apart. Obstruction statutes typically require intent to impede a specific proceeding. The government's read appears to be that a CBP inspection is a "proceeding" the moment an officer directs you to unlock the device, and that any deletion after that instruction constitutes obstruction. That's a live legal question — the defense will almost certainly argue that ordinary phone hygiene, including auto-deletion of messages, is not the same as shredding subpoenaed documents. But the mere fact that DOJ is willing to charge on this theory changes the calculus for every developer, journalist, lawyer, and executive who crosses a US border with a working device.
Community reaction on Hacker News (863 points and climbing) has centered on two threads. The first is procedural: what counts as "during" the inspection? If your device auto-purges Signal messages every 24 hours and that purge runs while you're standing in the CBP lane, are you obstructing? The second is technical: full-disk encryption plus a strong passphrase gives you a Fifth Amendment argument at the border that a post-hoc wipe does not. The perverse incentive the Tunick charge creates is to *never* touch your device once you're in line — which pushes the entire security burden back to pre-travel preparation.
Compare this to how other jurisdictions handle the same fact pattern. The UK's Schedule 7 powers already treat refusal to provide a passcode as a criminal offense, and Canadian border officers can compel decryption under CBSA policy, though the Supreme Court of Canada has not yet ruled on whether that violates Section 8. What's novel about the US posture in Tunick is the retroactive framing: it's not about compelling access, it's about criminalizing the removal of what would have been accessible.
If you carry a laptop or phone across a US border for work, your operational security model needs an update — and it needs to happen before you get to the airport, not at the kiosk. The safe posture is now to arrive at the border with a device whose state is already what you want it to be, and to touch nothing between the jet bridge and secondary inspection.
Concrete moves worth considering:
- Physically separate travel devices from working devices. A cheap Chromebook or a factory-reset iPad that syncs from cloud sources after you clear customs is legally cleaner than a wiped-in-transit primary laptop. There's nothing to delete because there was never anything on it. - Move secrets out of local dotfiles. SSH keys, cloud credentials, `.env` files, and signed commits sitting on a work laptop are exactly the material a forensic search will surface. Push them to a hardware token or a cloud secrets manager and re-provision at destination. - Audit auto-deletion behavior. If Signal, Session, or a self-destructing email client runs a scheduled purge while you're in inspection, you've now got a factual argument to have. Disable timed deletion for the duration of the trip, or don't have the app installed. - Log out, don't wipe. Signing out of cloud services at home before you fly is not the same act as clearing local data mid-inspection. The former is normal account management; the latter is what Tunick is charged with. - Rethink corporate travel policy. Legal and IT teams that mandate "wipe before border crossing" as blanket policy are effectively instructing employees to take on personal criminal exposure. That policy needs a lawyer's second look this quarter.
For open-source maintainers, journalists working with sources, and anyone under a protective order or an NDA, the exposure is sharper. The government does not need to prove your data was incriminating — under the obstruction theory, they only need to prove you deleted it after being told a search was coming.
Tunick's case will almost certainly be litigated on First and Fourth Amendment grounds, and the outcome will shape border-device policy for the next decade. But the practitioner takeaway does not depend on how the case resolves. The mere existence of the charge is the deterrent — DOJ has now shown it will indict on this theory, and the legal fees to fight it will bankrupt most defendants long before any appellate court weighs in. Treat border crossings the way you would treat handing your device to a forensic examiner with a warrant, because functionally, that's now the regime. Prepare the device beforehand. Don't touch it in line. And if your work depends on carrying secrets across borders, the question you should be asking your security team this week is not "how do we wipe faster" — it's "why are we carrying anything at all."
And this is why companies in the EU have a business travel rule to take a freshly wiped laptop on international trips, not just a locked one with a "distress code".
For exactly the border search scenario, I wish smartphones could be imaged and restored as easily as PCs. Imagine booting the phone from a flash drive, making an encrypted image of the phone on said drive, and writing a fresh OS before reaching the border.There's no deception required to protec
I read a pretty compelling argument by a lawyer that we're looking at this the wrong way. (I Am Not A Lawyer)Their point was that if the law is knocking on your door to legally search your house, and you have records of your criminal empire printed out in boxes in your attic, or just non-illega
The decoy passcode feature should boot into a separate partition that looks like a normal phone setup, and during that time quietly erase the user's actual data. They would never have known if it worked like this.
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
From Universal Declaration of Human Rights (UDHR) accepted by the United Nations General Assembly on 10 December 1948-------- Article 12No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has th