A GrapheneOS phone-wipe prosecution raises concerns that privacy and security tools could be treated as suspicious by default during border/device searches.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Welcome to the Shared Security podcast, the longest running cybersecurity and privacy
show for actual humans.
No jargon, no hype, just honest analysis from industry veterans who've seen everything
and survived it.
Each week we break down the stories that matter, expose the nonsense that doesn't, and give
you the tools to stay safe in a world where everything is connected and nothing
is guaranteed.
This is Shared Security.
Today on Shared Security, we're talking about a federal case that turns a privacy feature
into the center of a criminal prosecution.
Prosecutors charged an Atlanta man after agents says his Graphene OS phone wiped itself during
an airport search.
The legal question is bigger than one phone, though.
When does using strong privacy tooling become treated as suspicious or even as evidence or
wrongdoing?
And joining me to discuss this timely topic is my co-host, Mr. Scott Wright.
Yep, I'm here again.
Here you are.
Here you are.
Can't get rid of me.
No, I can't.
We keep trying, but you keep coming back.
What's happening here?
So yeah, no good topic for today.
It is.
Hopefully we get some good viewer feedback, too.
That'd be fun.
Yeah, definitely.
It reminded me of, and we'll actually right up here on the YouTube video, we will link
another episode that we did a while back on Border Searches, which actually was one
of our most popular episodes.
So this is somewhat related to that topic, but this is a little bit different.
So Scott, would you want to talk a little bit about why this came up as a story to talk
about?
Yeah, I mean, I just grabbed my attention that first of all, it was talked about a person
with a phone that had the ability to just wipe itself when you use what's called a
duress password, which is interesting.
I've learned about that doing some work in high security organizations, and they have
that situation sometimes where if you're at gunpoint to your head and they ask you to
open the safe or unlock a door, you can put in a code and in some systems, the
code will actually work, but it alerts people with a silent alarm and a response
can be initiated.
But in this case, the duress code in the phone is sort of highly integrated
with the OS, and I didn't know that.
So I thought that was really interesting that you can have this
mobile operating system that takes a password and says, oh, this is a password
that tells me not to let the person in, just wipe the whole device.
Yeah, that was pretty cool.
Yeah, exactly.
And for our listeners that may not know about this story.
So this gentleman, Sam Turnick, was apparently under federal investigation
or still is by the FBI for apparent terrorism, something to do with a group
that he's part of in his hometown, something that, you know, he was him
and some other protesters or something were going against some type of center
for police, I'm not really sure exactly what exactly it is.
But it was outside the U.S.
So I somewhere in he was returning from somewhere outside the U.S.
Well, he was coming from Dominican Republic back into the United States,
into Atlanta, which was not where he's from, but it was like the first airport
that probably had a connection or what have you.
And the FBI actually sent the airport an alert that this gentleman was going
to be landing there.
And so they essentially started questioning him, took him into a room.
He had asked for a lawyer like four times and was denied a lawyer.
And, you know, maybe before we get into more of the details, you and I have
talked about this before that airports are kind of this gray area in terms
of what rights do you actually have?
And this is not just a U.S. thing.
This is an international thing, right?
Like, you don't have all the rights that you do as a citizen of your country
when you are in an airport because it's this it's just this gray area
because you're you're at the border.
They can do certain things.
And so there are debates of do you actually have all of your rights?
Yeah, I guess it comes down to where the laws have jurisdiction, right?
And the territory inside an airport security space could have a different
legal status, right?
Yeah, yeah.
So so more about the story.
So obviously he was asked that if they could search his phone, he said no at
first and then he it looked like he was putting in his passcode or I think he
gave his passcode a passcode to the law enforcement people at the airport.
And it was actually that duress code that you mentioned, Scott.
And so it started wiping the device.
Thank you.
Restarted the device and that gave them the first clue.
Hey, it's not letting us in.
Right.
And I guess it showed a screenshot or it showed Graphene OS when it rebooted.
And for those of you that don't know, Graphene OS is a mobile operating
system that will replace your Android operating system with this operating
system that is more private and secure.
So this operating system has certain things that can lock down your data.
It can only use certain types of wireless networks or, you know, for
example, two G networks are famously infamous.
Let's say they're infamous for being insecure, right?
So the phone basically disables that.
So it only uses, you know, more modern wireless technology.
So that's one of many things that this operating system can do.
And so the big debate is because this person was using Graphene OS from
a privacy perspective, the government is considering this evidence.
And because he gave the duress code to wipe the device, this person
is essentially destroying evidence.
And I think that's what they are prosecuting him with, which is
pretty unprecedented that this has happened.
Mobile apps are just part of everyday life now.
Banking, healthcare, shopping, entertainment, you name it.
And with that comes a lot of trust because users are putting
their personal data directly into your app.
But here's the reality.
Mobile apps are a growing target.
A recent survey found that 72% of organizations experienced
a mobile app security incident last year and 92% say threats
are only increasing.
And the way attackers are going after apps is pretty sophisticated.
They're reverse engineering them, modifying them and redistributing
fake versions through phishing campaigns, side loading and even
third party app stores.
So from a user's perspective, everything can look completely legitimate.
That's why taking a proactive approach to mobile app security
really matters.
You want to stay ahead of these threats, not react after the damage is done.
This is where Guard Square comes in.
They provide advanced protection for both Android and iOS apps along
with automated security testing to catch vulnerabilities early and
real-time threat monitoring.
So you can actually see what's happening out there.
If your mobile app is critical to your business, and it probably is,
this is something worth paying attention to.
You can learn more at GuardSquare.com.
That's GuardSquare.com.
Yeah, yeah.
I guess in my mind, I'm questioning like, did he actually
have some, was he charged with anything before that?
Maybe they were investigating him.
But I guess the question is, if you wipe your browser history,
is that destroying evidence?
Right.
Yeah, how far do you take this?
Exactly, because you're right.
You're right, Scott.
I mean, you could think of all the things that is considered
destroying evidence.
You know, I think in a traffic stop, I always think of the most
simple things, right?
Or your house is being raided and you see in the movies,
like the drug dealer, you know, putting all the drugs down
the toilet, right?
Like that is technically destroying evidence because,
but in those cases, the police are raiding the house because
they have a warrant and they have evidence that this person
is a drug dealer, right?
So hence, they're most likely going to find drugs in the house.
So how do you apply that to this?
Yeah, it is certainly based on the information we have in the
story. It's probably unclear as to whether it was a privacy
issue or not, because if they had already had an extensive
investigation, they had a whole bunch of probable cause for,
you know, looking at his stuff, then maybe I guess it could
be potentially valid to say that it's destroying evidence to
do what he did.
But there was no warrants issued.
Right, right.
There was no warrant for his arrest either.
This was a, you know, they just wanted to question him.
But then questioning led to, let's see your device.
He said, no, and that's where this kind of got a little worse.
Yep, yep, yep.
I'm curious as to like what percentage of people use the
Graphene OS and and of those people, how many use it for
this purpose or this kind of situation?
It's a good question.
I think I always look at this as people that install these
operating systems, these privacy focused operating systems.
I don't say they don't have anything to hide, right?
So they're, you know, these are people that I would say are
more on the extreme side of protecting their privacy for
whatever reason, right?
Yeah, there are lots of valid reasons.
I mean, you know, there can be reporters trying to
protect their sources, et cetera.
Right.
Yeah, all those things.
And so I think there is this with law enforcement,
probably because of previous cases where drug dealers and
known criminals have used things like Graphene OS and
there's, you know, there's actually, I was listening
to the 404 media podcast that kind of went into this
a little bit more in a little more detail.
And they talked about there are phones that criminals
buy that are preloaded with things similar to
Graphene OS or they copy Graphene OS onto these
phones.
And then, of course, law enforcement knows that
these phones are used by drug dealers and criminals.
So there is a underlying, oh, if you're using Graphene
OS, you must be, therefore, you must be a criminal.
And that is the dangerous slippery slope that I
think we want to talk about on this show is
because that's not always the case, right?
You may just want more privacy for whatever reason.
Like you said, Scott, a journalist, a human
rights activist or a politician or, I mean, it goes on
and on and on or you just really care about your privacy.
It doesn't mean that you are a criminal because
you're using this.
So yeah, it's it's a great example of situations
where people need to think a little more, because
clearly now that this has become a big story, there
will be more attention from authorities on this kind
of situation, right?
They'll be looking for it more.
Yeah, and I think it's a reminder about, you know, when
you cross a border or you're at an airport, you're
flying back or you're flying into a country, just be
aware that the normal laws and the normal rules don't
necessarily apply.
And if your threat model says, you know, that you
are in a high risk position, like I mentioned,
journalist or politician or someone that is being
actively targeted by either the government or a
nation state or some type of threat actor, you need
to be aware of these situations.
And it might be a good idea, right?
For you to use something like Graphene OS, depending
on your situation, but I think be aware that this
is a risk of working in that mode too, right?
It definitely is.
It definitely is.
So this court case doesn't happen until October.
So we won't know until then what happens to
this gentleman or if he's going to be prosecuted
is his lawyers, I think, have a good case because,
by the way, this is an American citizen we're talking
about too.
So, you know, Americans do have certain rights,
whether those rights are allowed or not, because
he was at an airport, I think is also one of the
big debates, because he did ask for a lawyer several
times and was denied.
Yeah.
And so I think that's the big thing that his
lawyers are probably going to be betting on.
So, so, yeah, so let us know if you're
listening or watching this podcast.
We'd love to hear your feedback.
Is this is this something that is concerning to you
when you cross the border?
Do you feel that people running something like
Graphene OS have something to hide or is this just
yet another privacy tool that people can just
install and it's not necessarily something that
shows guilt, right?
Yeah, yeah, absolutely.
And Scott, I think you had an update about
your digital legacy tree.
Yeah.
So I've reached the stage now where the
digital legacy tree book is in its final stages
as a manuscript, almost ready for publication,
which is exciting, and I'm looking for a small
group of thoughtful reviewers who are interested
in this idea of ensuring that your loved
ones can have access to the digital accounts
that you may want to have them take over if
you die, kind of a sad situation, but a lot
of people don't think about it that much.
And as I mentioned in the past, I've been
working on this for a little while.
My goal is actually to release the book in
around September and, you know, it's not a long
book. It's actually quite full of value, I think
through every chapter, just in terms of doing
little exercises or things that you can record,
create your own digital legacy file, I call it.
And so just like to get people's viewpoints,
you don't have to be a security or privacy
expert just to get your own real life
experience and concerns around this issue of
what happens to your accounts when you die.
So if you actually are able to do a review
and provide me with feedback, I'm looking
at, you know, doing an acknowledgement section
in the book to name the people who've
helped out and also give early access to
people to the published book and the working
materials that come with it.
As I mentioned, there is quite a few
little work worksheets and things that will
help you create a record that you can save.
So it's not huge, but 30,000 words.
So you should be able to get through it in a
couple of hours.
So really excited to get people's feedback.
And I think Tom is going to put a link to
it in the show notes.
So looking forward to getting more of that done.
We'll be linking that in the show notes
for everybody if you're interested.
And if you want to connect with Scott on that,
it's super, super important topic.
And I think, like we've always said, right,
Scott, the two things are inevitable in
life, death and taxes.
So very important topic for everybody.
All right.
Well, I think that's all we have time for today.
So thank you all for listening.
And until next time, stay safe, stay secure
and stay private.
Thank you for listening or watching.
If you liked this episode, hit subscribe,
share it with your friends and colleagues
or jump into our community at shared
security dot net slash supporter to keep the
conversation going.
Thanks again, and we'll see you next week for
another episode of shared security.