When defending your privacy becomes suspicious: the arrest, GrapheneOS, and Apple warning you about spyware

There is a contradiction at the heart of how Western democracies are treating digital privacy, and it is time to call it by its name.
On one side, technology companies keep telling us to protect our devices ever better: strong passwords, two factor authentication, encryption, isolation modes, defenses against spyware. On the other side, when those protections actually work against someone who wants to get into our data, that same protection can turn into a criminal charge.
This is not a hypothesis. It has already happened, in a United States federal court, to a person with a first and a last name.
And the question this case leaves on the table is the one the coming years will make impossible to avoid: to what extent are we still the owners of the data held on our devices? And above all: when does the desire to prevent access stop being considered privacy and start being considered suspicious?
Apple warns users in 110 countries: someone is trying to get into their phones

The starting point seems disconnected, but it is not.
On August 13, 2026, Apple sent a new wave of notifications to users it believes are targeted by mercenary spyware: extremely sophisticated commercial software, used in targeted attacks. This time the warnings reached users in 110 countries. Since 2021, Apple states it has sent notifications of this kind in more than 150 countries.
We are not talking about malware fired at random into thousands of phishing emails. Apple describes these attacks as operations that cost millions of dollars, aimed at a few selected people, and historically associated with state actors or with private companies that develop spyware on their behalf. Apple itself cites NSO Group's Pegasus as an example. The typical targets: journalists, activists, politicians, diplomats.
The wave was so extensive that John Scott-Railton of Citizen Lab described the quantity and geographical spread of the public reports as unprecedented. A Bahraini human rights defender reported having received a record number of requests for help after the notifications were sent.
Apple has even changed the way it shows the alert. Since 2026, the notification appears directly on the iPhone lock screen, in Settings, by email, and on the account page. The message is blunt: Apple believes, with high confidence, that this person has been targeted.
The advice? Protect yourself. Update the phone, use strong passwords, turn on two factor authentication, enable the isolation mode, what Apple calls Lockdown Mode. In other words, build a higher wall around your digital life.
And this is exactly where the paradox begins.
Protect your phone. But not too much?
On January 24, 2025, Sam Tunick was returning to the United States from the Dominican Republic when he was stopped at Hartsfield-Jackson Atlanta International Airport and subjected to a secondary inspection by the border authorities.
Tunick is linked to the Defend the Atlanta Forest movement, which opposed the construction of the contested Atlanta police training center, the one its opponents call Cop City.
According to his lawyers, during the questioning the agents repeatedly insisted on getting access to the phone. The defense argues that Tunick had asked to speak with a lawyer, that the agents did not inform him of his rights, and that the search had no real customs purpose but served to target his environmental activism. The agents, the defense reports, allegedly justified the absence of a warrant by saying that Tunick had not yet entered United States territory. The government argues instead that they were legitimately exercising their powers.
The phone was a Google Pixel on which, according to journalistic reconstructions and the defense, GrapheneOS was installed, an open source operating system meant to increase privacy and security.
GrapheneOS has a particular feature: the duress PIN. It is not just any wrong PIN. It is a credential that the owner sets up on purpose for situations of coercion: if it is entered instead of the normal password, the device wipes itself irreversibly, including the eSIMs. The process does not require a reboot and cannot be interrupted.
According to the prosecution, Tunick gave the agents a code. When one of them entered it, the screen went black, flashed several times, and the device seemed to reboot. The data was gone.
The phone was his. But was the data still his?
In November 2025 a federal grand jury indicted Tunick on the basis of 18 U.S.C. § 2232, the rule that punishes anyone who destroys or damages property with the intent to prevent or hinder a lawful seizure by the government. The penalty can reach five years in prison.
It must be said precisely: Tunick has not been convicted. He pleaded not guilty. The prosecution argues that he deliberately destroyed data to prevent a lawful seizure. The defense argues that the detention and the search were unlawful, and asks that the evidence stemming from the episode be excluded. Who is right will be decided by the trial.
But the political and technological problem already exists now. Because for the first time we know of an American federal case in which the use of a security feature designed to react to coercion sits at the center of a criminal indictment. Security experts point to it as the first of its kind.
And this changes the very nature of the discussion.
A phone is not a suitcase. It is a copy of our life
One of the most stubborn errors of surveillance law is to keep treating smartphones and computers as modern versions of a suitcase. They are not.
A suitcase contains what we have decided to take on a trip. A smartphone potentially contains years of our life. Private conversations, photographs, relationships, contacts, location history, financial data, work documents, political opinions, online searches, health data, notes. The people we talk to, and those we have stopped talking to. And above all it contains information that concerns not only us, but hundreds of other people who never consented to being searched.
This is what makes digital checks at the border so delicate. In the United States there is the so called border search exception, which at the border grants the authorities search powers far broader than those they can exercise inside the country.
The border agency itself distinguishes between a basic search, the manual examination of a device's content, and an advanced search, in which an external device is connected to copy and analyze the data. The latter, according to the agency's policy, requires reasonable suspicion or a national security concern and the approval of a manager. The basic search does not.
In fiscal year 2024 alone, the agency states it checked the devices of 47,047 travelers, out of more than 420 million people who passed through. As a percentage it is a tiny fraction, well below 0.01 percent. In absolute terms, they are still tens of thousands of digital lives opened up in front of an agent.
And the legal picture is anything but uniform. The Supreme Court has not yet set a general rule for searches of electronic devices at the border. Federal courts apply different standards. And in Atlanta a very heavy precedent weighs: in the 2018 case United States v. Touset, the Eleventh Circuit ruled that the Fourth Amendment does not even require reasonable suspicion for a forensic search of electronic devices at the border. No suspicion. No threshold. It is on this ground that the Tunick case falls.
Privacy is becoming something you have to explain
Here is the cultural shift that matters more than any technicality.
For decades we considered it normal to close a door. Normal to put documents in a safe. Normal to seal a letter in an envelope. Normal not to let a stranger read our diary. Nobody asked you why.
Technology has progressively turned privacy into something that has to be actively built, and to every layer of protection a question has attached itself. You use Signal? Why? Your disk is encrypted? Why? You use GrapheneOS? Why? You set up a system that wipes the data if someone forces you to unlock the phone? So then, what do you have to hide?
It is a subtle and profound reversal. The question is no longer: why should someone have the right to access my data? It is becoming: why should I have the right to prevent it?
Privacy should not be the proof of suspicious behavior. It should be a normal condition of existence.
Democracies are doing what they used to reproach dictatorships for
Here the uncomfortable part has to be said, the one usually left between the lines.
For years the West built part of its identity on the distance from autocracies. It was they who spied on journalists. It was they who bought spyware to surveil their opponents. It was they who demanded access to the phones of dissidents at the border, who criminalized encryption, who treated confidentiality as a privilege to grant and revoke. We were different. We had fundamental rights.
Let us look at today's photograph, with no discount.
The mercenary spyware Apple denounces is not born in a vacuum: it is an industry that sells intrusion capabilities to governments, and among the documented clients there are not only authoritarian regimes. The Atlanta precedent establishes that at the border you can rummage through a device forensically without even a suspicion. And a citizen faces five years in prison for using a security feature, in a proceeding that his defense links directly to his political activity.
These are exactly the practices that, seen elsewhere, we would have called by their name: surveillance of activists, pressure on journalists, punishment of those who protect their communications. The difference is that when a democracy carries them out they arrive well dressed, wrapped in a law, motivated by a procedure, justified by a purpose that sounds reasonable.
But a fundamental right does not stop being violated just because the one violating it is an elected institution. On the contrary. When it is a democracy that compresses the confidentiality of its own citizens, the damage is more serious, because it betrays the promise on which that democracy rests. And it takes away from the West the one thing that allowed it to criticize others with a clean face: consistency.
The real knot is the word lawful
There is a serious objection, and it must be taken seriously, not sidestepped.
A functioning society cannot grant anyone the absolute right to destroy evidence at the moment when a lawful search or seizure is already under way. If a court issues a valid warrant and a person deliberately deletes the material to withhold it, the matter is not settled by invoking privacy.
But the word that decides everything is precisely lawful.
The Tunick case turns on this. The law used against him speaks expressly of the government's lawful authority to take that property into custody. The defense contests precisely the lawfulness of the search, and argues that the border check was the instrument of a broader political investigation.
If the line between protecting privacy and destroying evidence depends on the lawfulness of the state power exercised at that moment, then that power must be subjected to rigorous controls. Otherwise the reasoning becomes circular, and poisonous: the government has a right to the data because it is looking for it, and the act of preventing it becomes the proof that you should not have prevented it. It is exactly the logic that, in another country, we would define without hesitation as authoritarian.
The future of privacy could be this
Digital privacy is not simply disappearing. Something more insidious is happening: it is becoming exceptional.
Technologically we have more powerful tools than ever: hardware encryption, hardened operating systems, end-to-end messaging, passkeys, secure enclaves, automatic reboot, isolation modes, duress PINs. At the same time the capabilities of those who want to breach it are growing: commercial spyware, zero-click exploits, biometrics, forensic extraction tools, ever more automated surveillance infrastructures.
In the middle there is the user. They are told to defend themselves. But they are not always granted an equally strong right to decide who to defend themselves from.
The true meaning of the GrapheneOS case is not a PIN that wipes a smartphone. It is a much bigger question: must a computer system obey the owner of the device, or those who have the power to demand access to it?
For years the battle over privacy has focused on encryption. The next one will be about something more radical: the user's right to keep final control over their own data.
Because a society in which protecting your own information is automatically read as suspicious behavior is a society that has already changed the very definition of privacy. It is no longer a right. It has become a concession.
And concessions, unlike rights, can always be withdrawn.
Sources
- US accuses American of allegedly wiping his phone using a 'duress' password during border search · TechCrunch
- Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware · The Hacker News
- Apple sends fresh wave of mercenary spyware warnings worldwide · 9to5Mac
- Device Searches at the Border, CBP FY2024 data and United States v. Touset · NACDL
- GrapheneOS: Duress PIN/Password, official documentation