A story moving through privacy circles right now has a clean, alarming shape: federal agents forced a man to unlock his phone at the border, it self-destructed using a privacy feature, and now the government is prosecuting him for destroying evidence. Mostly right. The version circulating on social platforms, though, including an AI-generated summary card I was handed that got half the timeline wrong, buries the two things that carry the case. One is a constitutional question the courts have not settled. The other is a forensic-procedure failure that may sink the charge on its own terms, before the constitutional question is ever reached.
I taught mobile forensics and digital evidence for years. What follows walks the case in order: what happened, what the law requires, and where the government’s own seizure protocol undercuts its indictment.
What happened
On January 24, 2025, Samuel Tunick, an Atlanta resident associated with the movement opposing the police training facility known as “Cop City,” flew back into Hartsfield-Jackson Atlanta International Airport after a trip abroad. Customs and Border Protection pulled him into secondary inspection. His attorneys later stated in court filings that agents had already circulated his name and photo internally, describing him as under investigation for suspected terrorism activity tied to his associations, and that the stated pretext for demanding his phone was a search for child exploitation imagery for which they offered no supporting evidence.
The phone was a Google Pixel running GrapheneOS, a privacy-hardened Android fork. GrapheneOS includes a duress feature: the owner can set a passcode that, when entered instead of the real one, triggers an immediate wipe. Agents demanded a passcode. Tunick provided one. Per the reporting drawn from his motion to suppress, the screen went blank, flashed several times, and the phone restarted. The agents then seized the device, told him he was free to go, and admitted him to the country.
Months later he was indicted under 18 U.S.C. 2232 for knowingly destroying the digital contents of the phone to prevent a lawful seizure. The docket tells the sequence cleanly. A grand jury returned the indictment on November 13, 2025. It was sealed at first, then unsealed on December 4, 2025, and the arrest warrant was executed on December 3. The case is United States v. Tunick, No. 1:25-cr-00499, in the Northern District of Georgia, before District Judge Eleanor L. Ross. Tunick pleaded not guilty.
The suppression hearing was held earlier in July 2026, and the judge left it open for additional testimony rather than ruling from the bench. The defense brief is due September 18, the government’s response October 9, and the defense reply October 23. A ruling is not expected before the end of October.
One note on sourcing, because this case has attracted a lot of secondhand retelling. 404 Media first broke the story in December 2025 and later published an interview with Tunick and his federal public defender. TechCrunch’s Zack Whittaker reported the indictment and motion in detail on July 24, 2026, and noted that the indictment itself contains a typo, “Untied States Code,” which tells you something about the care with which it was assembled. Where you see confident claims about a “December 2025 traffic-stop arrest” or a suppression hearing that “concluded” in July, treat them with suspicion. The real December event was the arrest on the indictment warrant, not a traffic stop, and the hearing was continued, not concluded. Nothing has been decided.
What the law requires
The charge rests on a single statute. Here is the operative text of 18 U.S.C. 2232(a), from the Government Publishing Office edition:
Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action … for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control … shall be fined under this title or imprisoned not more than 5 years, or both.
Break that into what the government must prove. First, a person authorized to search or seize was engaged in searching for or seizing the property. Second, the defendant knowingly took action to destroy or impair the property. Third, he did so for the purpose of preventing a lawful seizure. And fourth, folded into “lawful authority,” the seizure the defendant impaired had to be one the government was lawfully entitled to make.
Every credible source on this statute, including the federal public defender on Tunick’s own team, describes the charge as extraordinarily rare. His attorney found only one other application of the law, in a drug-trafficking case. Security experts at the Electronic Frontier Foundation and independent digital-security specialists said they had never seen the statute used against a duress password. Prosecutors are reaching well past the tool’s normal use, and a reach like that gets tested at the elements.
Intent is the soft spot, for a specific reason. The government has to prove Tunick entered that passcode meaning to destroy data and defeat a seizure, not that he simply gave a code when agents demanded one while denying him access to a lawyer. A grand jury indicted him, which means it found probable cause on the government’s untested say-so. Probable cause to indict is a floor. The old line that a prosecutor can indict a ham sandwich exists because the grand jury hears only one side. Proving guilt beyond a reasonable doubt to a trial jury is a different mountain.
Where the constitution comes in, and where it does not settle anything
The loudest claim online is that the Fourth Amendment does not apply at the border and there is no protection against search and seizure. That is wrong as stated, and the real doctrine underneath it is more contested than either side admits.
The Fourth Amendment applies at the border. What changes is the standard. Courts have long recognized a border-search exception under which routine searches need no warrant and no probable cause, because the government’s interest in controlling what enters is at its peak. That much is settled. What is not settled is whether searching a modern phone, which holds the digital sum of a person’s life, counts as routine. The circuits disagree, and the disagreement is real rather than cosmetic. In United States v. Cano (2019), the Ninth Circuit held that a forensic phone search at the border requires reasonable suspicion, and it narrowed that suspicion to a search for digital contraband specifically, not general evidence gathering. Other circuits have gone further toward the government, some requiring no suspicion even for forensic searches, and a recent Fourth Circuit ruling permits suspicionless manual searches outright. The Supreme Court held in Riley v. California that police need a warrant to search a phone incident to a domestic arrest, and it has never squarely applied that logic to the border. So the honest description is reduced protection, an unsettled standard for phones, and a patchwork the Court has not resolved. Tunick’s case sits in the Eleventh Circuit, which has leaned government-friendly on device searches, and well outside the Ninth Circuit rule that would most help him.
There is a sharper wrinkle the coverage mostly misses. Agents reportedly justified the warrantless demand by arguing Tunick had not yet crossed the border, invoking the government’s long-standing position that a person is not on U.S. soil until admitted. Against a visa holder or foreign national that argument carries weight. Against a U.S. citizen who cannot be refused reentry, it mostly collapses. Tunick’s leverage is not the geography of the inspection area but his citizenship. The “not yet admitted” theory is the government’s sword, and it does not cut a citizen the way it cuts a traveler who can simply be turned away.
The part almost no one is discussing: the seizure happened after the wipe
Here is where my forensics background changes the reading, and where the government’s case has a structural problem independent of the constitutional fight.
Standard practice for seizing a phone as evidence runs in a fixed order, and the order is not arbitrary. You take custody of the device. You place it in a Faraday bag or equivalent RF isolation, so it cannot be remotely wiped, locked, or altered while in your possession. You receipt it, documenting that the government now holds this specific item as evidence. Only after all of that do you deal with the passcode. The isolation step exists because a networked phone is volatile evidence. Anyone trained in mobile acquisition knows to cage it before interacting with it, because the entire threat you are guarding against is the one that materialized here.
Now line that protocol up against the reported facts. Agents demanded the passcode. Tunick entered it. The phone wiped. Then they seized it. The seizure, the isolation, the receipt, all of the acts that mark a device as legally seized property in government custody, came after the interaction that destroyed the data. At the moment of destruction, by the government’s own procedural definition of what a seizure is, no seizure had occurred. There was a search in progress and a demand to unlock a phone the owner was still holding in his hand.
The distinction carries the whole charge, because 2232 protects a seizure, not a search. The statute is keyed to defeating the government’s authority to take property into custody. Read the reported chronology carefully and the seizure was reactive, triggered by the wipe and formalized afterward, not interrupted by it. You cannot form the purpose of preventing a seizure that has not been announced, attempted, or made imminent through any act you would recognize as the start of a seizure. No notice of seizure, no assertion of custody, no isolation, nothing that signals a seizure is underway, until after the phone went blank.
The statute’s own structure reinforces this. Subsection (a) reaches conduct “before, during, or after” a search or seizure, which the government will lean on to argue that anticipatory destruction counts. But Congress wrote a separate offense, subsection (c), specifically criminalizing giving advance notice of an impending search or seizure. When the drafters wanted to capture purely anticipatory conduct, they said so in dedicated language. That cuts against reading (a)’s “before” as a catch-all for anything a person does in expectation that a seizure might follow. The government’s best answer is a constructive-seizure theory, that pulling Tunick into secondary inspection placed everything on his person, phone included, under constructive custody from that moment. Whether that holds for a specific device the agents had not taken in hand is unsettled, and it is where the case will be fought.
The irony is hard to miss. The government’s procedural failure is what produced the outcome it is now prosecuting. Had agents followed standard protocol, seized and isolated the phone before demanding a code, the duress wipe would have accomplished far less. They would have possessed the device and could have preserved its state. The wipe worked only because they interacted before they isolated. A failure to secure the evidence is being recast as the defendant’s crime.
This points at something larger than one botched stop. Having line officers perform live searches of high-tech devices at the border has a short shelf life, and I am surprised anyone is still attempting it. You cannot train every officer at every port of entry to do forensic work correctly. The skill is specialized, the devices change constantly, and the failure modes are the kind on display here. The scalable answer is the boring one that also happens to be the lawful one: seize the device, isolate it, receipt it, and route it to people trained to handle it, under whatever legal authority actually applies. What happened to Tunick looks less like competent investigation than a fishing expedition run by officers improvising with a device they were not equipped to handle. Courts friendly to law enforcement have started backing away from exactly that. The pro-enforcement move and the pro-rights move land in the same place. Stop asking line officers to freelance forensic acquisition in an inspection booth.
Some of the coverage has circled the edge of this. A few outlets noted that CBP agents themselves entered the code that triggered the wipe, and that this complicates the government’s destruction theory. Correct as far as it goes, though it does less work than the chronology point. Whether Tunick or an agent physically entered the code goes to intent and causation, and the government can answer it by arguing he supplied the code knowing what it would do. The seizure-timing point is harder to answer, because it does not turn on whose finger pressed the key. It turns on whether the legal event the statute protects had begun at all. Of the two arguments, the one about when the seizure started is the sturdier.
The argument is not really about the Fourth Amendment at all. It goes to whether the indictment states an offense, and it turns on custody chronology, which is a forensics question before it is a legal one. Grant the government every border-search power it claims, and the statute still does not fit if no seizure had legally commenced when the phone wiped.
It is worth being clear that the public motion to suppress does not appear to make this argument. The defense attacks on Fourth, Fifth, and Sixth Amendment grounds, the warrantless search and seizure, the denial of counsel, the absence of Miranda warnings, and asks the court to suppress everything including the fact of the wipe. That is a suppression strategy. The seizure-timing point is a different lever, aimed at the elements rather than the admissibility of evidence, and on the public record it is sitting unused.
Why the doctrine is a decade behind the device
One reason a case like this can even be brought is that the authoritative government guidance on mobile forensics has not kept pace with the technology.
The foundational document is NIST Special Publication 800-101 Revision 1, “Guidelines on Mobile Device Forensics,” published in 2014. That is still the current revision. It predates GrapheneOS, predates the modern Pixel hardware security model, and predates the duress-wipe threat entirely. On the National Institute of Justice side the picture is the same vintage: the “Digital Evidence Policies and Procedures Manual” dates to 2020, and the older “Forensic Examination of Digital Evidence” guide traces back to 2004. There is no current federal methodology addressing a hardened AOSP fork with a user-triggered wipe, which is precisely the scenario CBP walked into. The doctrine is a decade behind the threat.
I will make an offer on that point, because complaining about stale standards without volunteering to fix them is cheap. If NIST does not have people on hand with current expertise in hardened mobile operating systems and their acquisition, I will rewrite the mobile device forensics standard myself and bring it to a review panel to verify it aligns with sound practice and existing law. I have taught this material. Updating a decade-old guideline to match how these devices behave now is finite work. The obstacle is institutional will, not technical difficulty.
The mechanism that does stay somewhat current is the Computer Forensics Tool Testing program, a joint effort of the Department of Homeland Security, NIJ, and NIST that validates whether commercial forensic tools actually perform as claimed. Notably, CBP is a named participating agency in that program, which is directly relevant here given that CBP conducted the seizure.
The academic literature has only just arrived at this device. In March 2026, Katharina De Rentiis and colleagues published “The Investigator’s Friend and Foe: A Forensic Analysis of GrapheneOS” in Forensic Science International: Digital Investigation, the journal affiliated with the Digital Forensics Research Conference (DFRWS). The paper calls itself the first forensic analysis of the operating system, and it surveys tool support across the major commercial suites, Cellebrite, Magnet GrayKey, MSAB XRY, Belkasoft, Oxygen, and others. As a capabilities survey it earns its keep. Its framing is another matter. The paper opens on a law-enforcement sting and casts the operating system throughout through the lens of criminal use, with one cited source headlining GrapheneOS as the secret weapon of narcotraffickers. The subject in this literature is almost always a criminal, rarely a journalist, a dissident, a domestic-violence survivor, or a citizen at a border who has not been charged with anything.
The orientation deserves naming, though not overstating. The venues where digital-forensics methodology gets built and blessed, the conferences and the tool-validation programs, are dominated by tool vendors and law-enforcement laboratories. Vendor nondisclosure agreements and law-enforcement-sensitive sessions gatekeep what gets examined and who gets to examine it. The result is a body of methodology optimized around the state’s needs as the investigating party, with the defense and the non-criminal user treated as edge cases. Structural bias, not conspiracy, and it shapes which questions get asked. When a duress feature legitimately defeats an unlawful or improperly executed seizure is not a question this literature is built to ask.
I have argued this in a lot of rooms. Forensics is about finding fact, not convicting criminals. Those are not the same goal, and the gap between them shows up in real cases. A forensic laboratory that reports to a police chief or a prosecutor sits inside an institution with a stake in the outcome, which is the wrong home for a function whose whole value depends on indifference to the outcome. The medical examiner model points at the better arrangement. We accept that a coroner should be independent of the agencies whose cases they touch, so the finding carries weight no matter which side it helps. Digital forensics belongs in the same category, housed in an independent body rather than an arm of the prosecution. I do not expect that soon. The institutional inertia is enormous and the budgets flow the other way. But the misuse cases keep piling up, and accumulation is how arrangements everyone tolerated become untenable.
The vendor secrecy layered on top makes the structure more fragile, not more secure. The dominant extraction tools are sold under agreements that bind agencies to confidentiality, and the companies instruct their own users to conceal the tools’ existence and capabilities. A leaked training video from the largest vendor told law enforcement users to keep the technology as quiet as possible, and the company confirmed as policy that it does not disclose what its tools can do, framing the secrecy as denying criminals an advantage. Access runs one direction. Cellebrite’s own sales terms restrict its advanced unlocking and extraction services to law enforcement with legal authority to unlock phones, and its licensing limits the products to approved government and security customers, backed by the ability to disable a noncompliant customer’s equipment remotely. So the side that produces the evidence can buy the capability while the side that must challenge it cannot. A methodology whose limits and error modes are shielded from adversarial testing, by contract and by the fact that the challenger is not an eligible customer, sits inside the one process built to test them. Legal scholars have made the obvious point back at the companies: a defendant cannot meaningfully challenge evidence produced by a method he is not allowed to understand, let alone examine.
Call it a house of cards. No single dramatic flaw, just a validated-in-secret toolchain resting on the assumption that no one will ever force the methods into open court and break them. Someday a case will. When it does, every conviction that leaned on a concealed method becomes vulnerable at once, which serves law enforcement’s own goals poorly. The discipline that would protect those convictions is the discipline the secrecy regime avoids: open methods, independent labs, validation that survives a competent cross-examination. A profession confident in its methods does not need to hide them.
What to actually take from this
The alarming headline is real. The government is prosecuting a citizen under a rarely-used statute for the alleged destruction of data via a privacy feature, and the case could influence how much protection travelers retain at the border. But the case is weaker and stranger than the headline suggests.
Strip away the noise and a few things stand out. The constitutional question is contested, not settled, and Tunick’s citizenship is a stronger lever than the commentary credits. The intent element is hard for the government to prove, because an indictment is an accusation, not a finding. And the seizure the statute is supposed to protect appears, on the reported facts, to have happened after the destruction it is prosecuting, a problem the government created through its own inverted procedure.
The suppression motion is the near-term hinge. If the search is ruled unlawful, the “lawful authority” element weakens and the prosecution may collapse. A ruling is not expected before the end of October, after the briefing runs its course. But the deeper point does not even require winning on the Fourth Amendment. It requires only asking a question the doctrine and the literature are poorly equipped to ask: at the moment the phone wiped, had a seizure legally begun? On the facts as reported, the answer looks like no.
A word on where I come from, because a piece like this reads as anti-police if you squint, and it is the reverse. I have worn the badge, taught the people who wear it, and had both junior officers and very senior ones in my classrooms. I believe in an ordered society. Procedure and the protection of a suspect’s rights are not obstacles that get in the way of the job. They are the job. A professional can hold two ideas at once: that a person may be guilty as sin, and that officers who cut corners can hand that person a lawful path out the door. Miranda is the whole lesson, and its namesake was by most accounts not a sympathetic man. The rule was never meant to protect the sympathetic. It keeps the state disciplined.
Everything above sits inside that frame. The myth that people have no rights at the border is exactly the kind of shortcut that produces a case like this one. Good officers do good procedure. They seize the device, isolate it, receipt it, then deal with the passcode, in that order, every time, because the order is what protects the evidence and the case. The agents here appear to have inverted it, and the wipe is the consequence. Should the prosecution falter, a privacy feature will not have beaten the government. The government will have beaten itself. The remedy is not more latitude at the border but better training, and a professional culture that treats the sequence as sacred rather than optional. The good ones already hold themselves to that standard. This case is an argument for holding the rest to it.
Sources and citations
The notes below map each significant factual claim in the piece to the source that supports it, with URLs. Court records and primary documents are listed first, then the statute and case law, then the reporting, then the forensics and vendor material. Where a claim rests on the author’s own professional judgment rather than a source, the text says so and it is not cited here.
Court records and primary documents
Docket, procedural history, judge, and briefing schedule. United States v. Tunick, No. 1:25-cr-00499 (N.D. Ga.). The docket shows the indictment returned November 13, 2025, initially sealed, unsealed December 4, 2025, the arrest warrant executed December 3, 2025, and the case assigned to District Judge Eleanor L. Ross. CourtListener: https://www.courtlistener.com/docket/72009158/united-states-v-tunick/
Suppression hearing continued, and the fall briefing schedule (defense September 18, government October 9, defense reply October 23, no ruling before end of October). It’s FOSS, “A GrapheneOS Privacy Feature Just Became the Basis for a Federal Indictment,” reporting from the docket: https://itsfoss.com/news/grapheneos-duress-password-indictment/
Indictment text and the “Untied States Code” typo. The indictment charges that Tunick, “before and during the search for and seizure of property” by a CBP Tactical Terrorism Response Team supervisory officer, knowingly acted to delete the digital contents of a Google Pixel phone. Posted to DocumentCloud: https://www.documentcloud.org/documents/28513012-samuel-tunick-indictment/ Full indictment language quoted in Cybernews: https://cybernews.com/privacy/atlanta-man-border-search-prosecuted-grapheneos/
Motion to suppress, and the grounds the defense actually raised (Fourth, Fifth, and Sixth Amendment: warrantless search and seizure, denial of counsel, no Miranda). Posted to DocumentCloud: https://www.documentcloud.org/documents/28513064-tunicks-motion-to-suppress/ Note: the DocumentCloud viewer blocks automated retrieval, so the characterization here relies on detailed press summaries of the filing rather than a line-by-line read of all thirteen pages. The grounds are summarized in Windows Forum: https://windowsforum.com/windows-news.4/grapheneos-duress-password-in-first-u-s-border-wipe-prosecution.440531/ and MediaNama: https://www.medianama.com/2026/07/223-us-grapheneos-duress-password-case/
Statute and case law
18 U.S.C. 2232, full text of the operative language, including subsection (a) on destruction to prevent seizure and the separate subsection (c) on giving advance notice of a search or seizure. United States Code, Government Publishing Office edition: https://www.govinfo.gov/content/pkg/USCODE-2021-title18/html/USCODE-2021-title18-partI-chap109-sec2232.htm
Elements of a 2232 charge, and confirmation that intent is the contested element. Summaries by criminal-defense practitioners: https://www.blacklawseattle.com/federal-law-on-the-destruction-of-property-to-avoid-seizure/
Riley v. California, holding that police generally need a warrant to search a cell phone seized incident to arrest, and the opinion’s own discussion of Faraday isolation and remote wiping. Riley v. California, 573 U.S. 373 (2014). Official reporter via Justia: https://supreme.justia.com/cases/federal/us/573/373/ Cornell LII case page: https://www.law.cornell.edu/supct/cert/13-132
United States v. Cano, the Ninth Circuit rule that forensic border phone searches require reasonable suspicion limited to digital contraband. United States v. Cano, 934 F.3d 1002 (9th Cir. 2019). Ninth Circuit published opinion: https://cdn.ca9.uscourts.gov/datastore/opinions/2019/08/16/17-50151.pdf Justia case page: https://law.justia.com/cases/federal/appellate-courts/ca9/17-50151/17-50151-2019-08-16.html
The circuit patchwork, including the recent Fourth Circuit ruling allowing suspicionless manual searches and the varying standards across the First, Eighth, and other circuits. TechTimes, “CBP Can Rifle Through Your Phone by Hand at the Border”: https://www.techtimes.com/articles/321338/20260723/cbp-can-rifle-through-your-phone-hand-border-no-suspicion-required.htm
Reporting on the case
Primary account of the border stop, the passcode demand, the “screen went blank” description, the seizure occurring after the wipe, the “not yet crossed the border” justification, and the Cop City connection. Zack Whittaker, “US accuses American of allegedly wiping his phone using a ‘duress’ password during border search,” TechCrunch, July 24, 2026: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/
Expert commentary that the statute’s use here is extraordinarily rare, from the federal public defender and from EFF and independent security specialists. Same TechCrunch report above.
The observation that CBP agents themselves entered the code, and that this complicates the destruction theory. Gadget Review: https://www.gadgetreview.com/the-government-just-charged-a-man-for-using-a-phone-privacy-feature
The Dominican Republic as point of origin, and federal circulation of Tunick’s name and photo as a suspected-terrorism matter. TechSpot: https://www.techspot.com/news/113236-us-prosecutors-charge-atlanta-man-after-grapheneos-phone.html
Initial break of the story and the interview with Tunick and his public defender. 404 Media, “The Government Hopes To Set a Precedent”: https://www.404media.co/the-government-hopes-to-set-a-precedent-an-interview-with-the-man-charged-for-allegedly-wiping-his-grapheneos-phone/
GrapheneOS duress-feature description and its June 2024 introduction. Cryptonomist: https://en.cryptonomist.ch/2026/07/27/duress-password-grapheneos-case/
Forensics doctrine and standards
NIST SP 800-101 Revision 1 as the current (2014) federal guidance on mobile device forensics, predating the devices and threats at issue. NIST: https://csrc.nist.gov/pubs/sp/800/101/r1/final
NIJ “Digital Evidence Policies and Procedures Manual” (2020) and the older “Forensic Examination of Digital Evidence” guide. NIJ: https://nij.ojp.gov/library/publications/digital-evidence-policies-and-procedures-manual
CFTT as the joint DHS/NIJ/NIST tool-validation program, with CBP among participating agencies. IACP Cyber Center overview: https://www.iacpcybercenter.org/officers/mobile-forensics/
First academic forensic analysis of GrapheneOS, its tool-support survey, and its criminality framing. Katharina De Rentiis et al., “The Investigator’s Friend and Foe: A Forensic Analysis of GrapheneOS,” Forensic Science International: Digital Investigation, March 2026. DFRWS presentation page: https://dfrws.org/presentation/the-investigators-friend-and-foe-a-forensic-analysis-of-grapheneos/ ScienceDirect: https://www.sciencedirect.com/science/article/pii/S2666281726000053
Vendor tooling, secrecy, and access
Cellebrite instructing law enforcement users to keep the technology secret (leaked training video), and the transparency concerns that raises for defendants. AppleInsider coverage of the TechCrunch report: https://appleinsider.com/articles/23/08/19/cellebrite-trains-law-enforcement-to-maintain-iphone-hacking-secrets Inside Telecom: https://insidetelecom.com/leaked-cellebrite-training-video-puts-tech-company-in-hot-seat/
Cellebrite’s stated policy of not disclosing tool capabilities, and the accidentally-published military contract exposing them. Reason, “How the military exposed the tools that let authorities break into phones,” October 16, 2025: https://reason.com/2025/10/16/how-the-military-exposed-the-tools-that-let-authorities-break-into-phones/
Access restriction: Cellebrite Advanced Services available only to law enforcement with legal authority to unlock phones. Cellebrite Advanced Unlocking & Extraction sales inquiry page: https://cellebrite.com/en/cas-sales-inquiry/
Licensing restricted to approved government and security customers, with remote-disable enforcement. Cellebrite Ethics & Integrity page: https://cellebrite.com/en/about/ethics-integrity/
Corroboration that Cellebrite products are sold only to law enforcement, intelligence, military, and similar bodies. Robson Crim (University of Manitoba legal analysis): https://www.robsoncrim.com/single-post/signal-vs-cellebrite-restricting-expanding-search-powers-anonymous
A note on what is not citedTwo threads in this piece are the author’s own argument, not reported fact, and are presented as such in the text: first, that the seizure the statute protects had not legally commenced when the phone wiped, which turns on custody chronology and does not appear to be raised in the public motion to suppress; and second, that digital-forensics laboratories should be independent of law enforcement and prosecution, on the medical