SIGNAL OF THE DAY: A phone wipe may become a courtroom test of digital self-defense
As phones become searchable borders, privacy features may become the next legal battleground.
An Atlanta activist is facing a federal case after authorities alleged he used a GrapheneOS duress passcode that wiped his phone during a border search. The case appears to be unusual; Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.
GrapheneOS has since defended the legality of its security features. The developer tweeted: “GrapheneOS is completely legal. We have no obligation to weaken any of the security protections it provides.” The organization also said it cannot help law enforcement recover wiped data, because once the key material is erased, recovery is not possible.
Frame a privacy tool as evidence destruction, and cryptography starts to look like contraband
That raises a bigger question: could a tool designed to protect private data be framed as inherently suspicious — or even criminal? Here’s what Miguel Fornes, our cybersecurity expert and Information Security Manager at Incogni has to say:
“The surveillance ecosystem is expanding at a rapidly terrifying pace. Prosecutors routinely subpoena Tesla telemetry, and in some cases vehicles can be seized or towed so investigators can extract camera footage and sensor data collected from the surrounding street. Together, these cases show how privately owned devices are increasingly being converted into public evidence infrastructure.
Parked cars, phones, and home cameras are quietly turning private homes and residential streets into evidence-gathering infrastructure, helping build dragnet evidence files in ways that can sidestep the limits people associate with traditional warrants.
This may now be escalating from passive tracking to the possible criminalization of digital self-defense. The concern is not only that federal officers sought access to a phone during a border search, but that the alleged use of a legitimate security feature could be framed as evidence destruction.
Now, as a security engineer, I should stress that GrapheneOS is widely regarded as one of the strongest mobile security platforms available. It is purpose-built to resist spyware, forensic extraction, and unauthorized access, leaving forensic tools like Cellebrite completely in the dark. So, when a legitimate privacy tool is framed as an instrument of evidence destruction, the government is effectively treating cryptography as contraband.
That reveals a disturbing double standard. In an environment where our personal data is constantly scraped, leaked, breached, demanded, and sold by opaque corporations, taking steps to defend our digital sovereignty should not be treated as an admission of guilt. The message is chilling: lock your own digital door, and the state may treat the lock itself as suspicious.
Still, public pressure can change the course of surveillance technology. After public backlash over the weaponization of home-security cameras, Amazon reportedly ended its Ring partnership with Flock Safety. The same principle applies here: privacy tools should not be criminalized simply because they are effective.”
A record year for border phone searches raises the stakes for digital privacy
The broader context is the fact that border phone searches are rising. CBP searched around 55,424 electronic devices in FY2025, a record high and up from around 47,000 in FY2024. A decade earlier, in 2015, the figure was 8,503.
Signal insights:
- Record high: CBP searched 55,424 electronic devices in FY2025.
- Sharp rise: Searches are up more than 6x since 2015.
- Legal test: A phone-wipe privacy feature may soon be tested in court.
- Privacy stakes: One search can expose far more than what’s stored in a bag.
Sources
CBP: Border Search of Electronic Devices at Ports of Entry
The Guardian, Timothy Pratt: US government targets Cop City protester over phone operating system