Shared Security Podcast

A GrapheneOS phone-wipe prosecution raises concerns that privacy and security tools could be treated as suspicious by default during border/device searches.

Show Notes

A federal case involving a GrapheneOS phone wipe during an airport search raises a bigger question for privacy-minded users: can using strong mobile security features be treated as evidence of criminal intent? Tom and Scott break down what happened, why border searches are different, and what this could mean for secure phones and everyday privacy.

Tom and Scott also discuss duress codes, realistic travel threat models, and Scott’s Digital Legacy Tree update.

** Links mentioned on the show **

TechSpot — US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search https://www.techspot.com/news/113236-us-prosecutors-charge-atlanta-man-after-grapheneos-phone.html

GrapheneOS project https://grapheneos.org/

EFF — Border searches https://www.eff.org/issues/border-searches

Help Review The Digital Legacy Tree (upcoming book by Scott Wright)
To volunteer, share your story, or suggest ideas that may help others facing digital legacy challenges, visit:
https://securityperspectives.com/digital-legacy-tools

** Watch this episode on YouTube **

https://youtu.be/Cch3pG2EO-g

** Become a Shared Security Supporter **

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

** Thank you to our sponsors! **

Guardsquare

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

SLNT

Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

** Subscribe and follow the podcast **

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

What is Shared Security Podcast?

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Welcome to the Shared Security podcast, the longest running cybersecurity and privacy

show for actual humans.

No jargon, no hype, just honest analysis from industry veterans who've seen everything

and survived it.

Each week we break down the stories that matter, expose the nonsense that doesn't, and give

you the tools to stay safe in a world where everything is connected and nothing

is guaranteed.

This is Shared Security.

Today on Shared Security, we're talking about a federal case that turns a privacy feature

into the center of a criminal prosecution.

Prosecutors charged an Atlanta man after agents says his Graphene OS phone wiped itself during

an airport search.

The legal question is bigger than one phone, though.

When does using strong privacy tooling become treated as suspicious or even as evidence or

wrongdoing?

And joining me to discuss this timely topic is my co-host, Mr. Scott Wright.

Yep, I'm here again.

Here you are.

Here you are.

Can't get rid of me.

No, I can't.

We keep trying, but you keep coming back.

What's happening here?

So yeah, no good topic for today.

It is.

Hopefully we get some good viewer feedback, too.

That'd be fun.

Yeah, definitely.

It reminded me of, and we'll actually right up here on the YouTube video, we will link

another episode that we did a while back on Border Searches, which actually was one

of our most popular episodes.

So this is somewhat related to that topic, but this is a little bit different.

So Scott, would you want to talk a little bit about why this came up as a story to talk

about?

Yeah, I mean, I just grabbed my attention that first of all, it was talked about a person

with a phone that had the ability to just wipe itself when you use what's called a

duress password, which is interesting.

I've learned about that doing some work in high security organizations, and they have

that situation sometimes where if you're at gunpoint to your head and they ask you to

open the safe or unlock a door, you can put in a code and in some systems, the

code will actually work, but it alerts people with a silent alarm and a response

can be initiated.

But in this case, the duress code in the phone is sort of highly integrated

with the OS, and I didn't know that.

So I thought that was really interesting that you can have this

mobile operating system that takes a password and says, oh, this is a password

that tells me not to let the person in, just wipe the whole device.

Yeah, that was pretty cool.

Yeah, exactly.

And for our listeners that may not know about this story.

So this gentleman, Sam Turnick, was apparently under federal investigation

or still is by the FBI for apparent terrorism, something to do with a group

that he's part of in his hometown, something that, you know, he was him

and some other protesters or something were going against some type of center

for police, I'm not really sure exactly what exactly it is.

But it was outside the U.S.

So I somewhere in he was returning from somewhere outside the U.S.

Well, he was coming from Dominican Republic back into the United States,

into Atlanta, which was not where he's from, but it was like the first airport

that probably had a connection or what have you.

And the FBI actually sent the airport an alert that this gentleman was going

to be landing there.

And so they essentially started questioning him, took him into a room.

He had asked for a lawyer like four times and was denied a lawyer.

And, you know, maybe before we get into more of the details, you and I have

talked about this before that airports are kind of this gray area in terms

of what rights do you actually have?

And this is not just a U.S. thing.

This is an international thing, right?

Like, you don't have all the rights that you do as a citizen of your country

when you are in an airport because it's this it's just this gray area

because you're you're at the border.

They can do certain things.

And so there are debates of do you actually have all of your rights?

Yeah, I guess it comes down to where the laws have jurisdiction, right?

And the territory inside an airport security space could have a different

legal status, right?

Yeah, yeah.

So so more about the story.

So obviously he was asked that if they could search his phone, he said no at

first and then he it looked like he was putting in his passcode or I think he

gave his passcode a passcode to the law enforcement people at the airport.

And it was actually that duress code that you mentioned, Scott.

And so it started wiping the device.

Thank you.

Restarted the device and that gave them the first clue.

Hey, it's not letting us in.

Right.

And I guess it showed a screenshot or it showed Graphene OS when it rebooted.

And for those of you that don't know, Graphene OS is a mobile operating

system that will replace your Android operating system with this operating

system that is more private and secure.

So this operating system has certain things that can lock down your data.

It can only use certain types of wireless networks or, you know, for

example, two G networks are famously infamous.

Let's say they're infamous for being insecure, right?

So the phone basically disables that.

So it only uses, you know, more modern wireless technology.

So that's one of many things that this operating system can do.

And so the big debate is because this person was using Graphene OS from

a privacy perspective, the government is considering this evidence.

And because he gave the duress code to wipe the device, this person

is essentially destroying evidence.

And I think that's what they are prosecuting him with, which is

pretty unprecedented that this has happened.

Mobile apps are just part of everyday life now.

Banking, healthcare, shopping, entertainment, you name it.

And with that comes a lot of trust because users are putting

their personal data directly into your app.

But here's the reality.

Mobile apps are a growing target.

A recent survey found that 72% of organizations experienced

a mobile app security incident last year and 92% say threats

are only increasing.

And the way attackers are going after apps is pretty sophisticated.

They're reverse engineering them, modifying them and redistributing

fake versions through phishing campaigns, side loading and even

third party app stores.

So from a user's perspective, everything can look completely legitimate.

That's why taking a proactive approach to mobile app security

really matters.

You want to stay ahead of these threats, not react after the damage is done.

This is where Guard Square comes in.

They provide advanced protection for both Android and iOS apps along

with automated security testing to catch vulnerabilities early and

real-time threat monitoring.

So you can actually see what's happening out there.

If your mobile app is critical to your business, and it probably is,

this is something worth paying attention to.

You can learn more at GuardSquare.com.

That's GuardSquare.com.

Yeah, yeah.

I guess in my mind, I'm questioning like, did he actually

have some, was he charged with anything before that?

Maybe they were investigating him.

But I guess the question is, if you wipe your browser history,

is that destroying evidence?

Right.

Yeah, how far do you take this?

Exactly, because you're right.

You're right, Scott.

I mean, you could think of all the things that is considered

destroying evidence.

You know, I think in a traffic stop, I always think of the most

simple things, right?

Or your house is being raided and you see in the movies,

like the drug dealer, you know, putting all the drugs down

the toilet, right?

Like that is technically destroying evidence because,

but in those cases, the police are raiding the house because

they have a warrant and they have evidence that this person

is a drug dealer, right?

So hence, they're most likely going to find drugs in the house.

So how do you apply that to this?

Yeah, it is certainly based on the information we have in the

story. It's probably unclear as to whether it was a privacy

issue or not, because if they had already had an extensive

investigation, they had a whole bunch of probable cause for,

you know, looking at his stuff, then maybe I guess it could

be potentially valid to say that it's destroying evidence to

do what he did.

But there was no warrants issued.

Right, right.

There was no warrant for his arrest either.

This was a, you know, they just wanted to question him.

But then questioning led to, let's see your device.

He said, no, and that's where this kind of got a little worse.

Yep, yep, yep.

I'm curious as to like what percentage of people use the

Graphene OS and and of those people, how many use it for

this purpose or this kind of situation?

It's a good question.

I think I always look at this as people that install these

operating systems, these privacy focused operating systems.

I don't say they don't have anything to hide, right?

So they're, you know, these are people that I would say are

more on the extreme side of protecting their privacy for

whatever reason, right?

Yeah, there are lots of valid reasons.

I mean, you know, there can be reporters trying to

protect their sources, et cetera.

Right.

Yeah, all those things.

And so I think there is this with law enforcement,

probably because of previous cases where drug dealers and

known criminals have used things like Graphene OS and

there's, you know, there's actually, I was listening

to the 404 media podcast that kind of went into this

a little bit more in a little more detail.

And they talked about there are phones that criminals

buy that are preloaded with things similar to

Graphene OS or they copy Graphene OS onto these

phones.

And then, of course, law enforcement knows that

these phones are used by drug dealers and criminals.

So there is a underlying, oh, if you're using Graphene

OS, you must be, therefore, you must be a criminal.

And that is the dangerous slippery slope that I

think we want to talk about on this show is

because that's not always the case, right?

You may just want more privacy for whatever reason.

Like you said, Scott, a journalist, a human

rights activist or a politician or, I mean, it goes on

and on and on or you just really care about your privacy.

It doesn't mean that you are a criminal because

you're using this.

So yeah, it's it's a great example of situations

where people need to think a little more, because

clearly now that this has become a big story, there

will be more attention from authorities on this kind

of situation, right?

They'll be looking for it more.

Yeah, and I think it's a reminder about, you know, when

you cross a border or you're at an airport, you're

flying back or you're flying into a country, just be

aware that the normal laws and the normal rules don't

necessarily apply.

And if your threat model says, you know, that you

are in a high risk position, like I mentioned,

journalist or politician or someone that is being

actively targeted by either the government or a

nation state or some type of threat actor, you need

to be aware of these situations.

And it might be a good idea, right?

For you to use something like Graphene OS, depending

on your situation, but I think be aware that this

is a risk of working in that mode too, right?

It definitely is.

It definitely is.

So this court case doesn't happen until October.

So we won't know until then what happens to

this gentleman or if he's going to be prosecuted

is his lawyers, I think, have a good case because,

by the way, this is an American citizen we're talking

about too.

So, you know, Americans do have certain rights,

whether those rights are allowed or not, because

he was at an airport, I think is also one of the

big debates, because he did ask for a lawyer several

times and was denied.

Yeah.

And so I think that's the big thing that his

lawyers are probably going to be betting on.

So, so, yeah, so let us know if you're

listening or watching this podcast.

We'd love to hear your feedback.

Is this is this something that is concerning to you

when you cross the border?

Do you feel that people running something like

Graphene OS have something to hide or is this just

yet another privacy tool that people can just

install and it's not necessarily something that

shows guilt, right?

Yeah, yeah, absolutely.

And Scott, I think you had an update about

your digital legacy tree.

Yeah.

So I've reached the stage now where the

digital legacy tree book is in its final stages

as a manuscript, almost ready for publication,

which is exciting, and I'm looking for a small

group of thoughtful reviewers who are interested

in this idea of ensuring that your loved

ones can have access to the digital accounts

that you may want to have them take over if

you die, kind of a sad situation, but a lot

of people don't think about it that much.

And as I mentioned in the past, I've been

working on this for a little while.

My goal is actually to release the book in

around September and, you know, it's not a long

book. It's actually quite full of value, I think

through every chapter, just in terms of doing

little exercises or things that you can record,

create your own digital legacy file, I call it.

And so just like to get people's viewpoints,

you don't have to be a security or privacy

expert just to get your own real life

experience and concerns around this issue of

what happens to your accounts when you die.

So if you actually are able to do a review

and provide me with feedback, I'm looking

at, you know, doing an acknowledgement section

in the book to name the people who've

helped out and also give early access to

people to the published book and the working

materials that come with it.

As I mentioned, there is quite a few

little work worksheets and things that will

help you create a record that you can save.

So it's not huge, but 30,000 words.

So you should be able to get through it in a

couple of hours.

So really excited to get people's feedback.

And I think Tom is going to put a link to

it in the show notes.

So looking forward to getting more of that done.

We'll be linking that in the show notes

for everybody if you're interested.

And if you want to connect with Scott on that,

it's super, super important topic.

And I think, like we've always said, right,

Scott, the two things are inevitable in

life, death and taxes.

So very important topic for everybody.

All right.

Well, I think that's all we have time for today.

So thank you all for listening.

And until next time, stay safe, stay secure

and stay private.

Thank you for listening or watching.

If you liked this episode, hit subscribe,

share it with your friends and colleagues

or jump into our community at shared

security dot net slash supporter to keep the

conversation going.

Thanks again, and we'll see you next week for

another episode of shared security.