Hi everyone,
This week on Shared Security, we discuss a federal case involving a GrapheneOS phone wipe during an airport search.
The case is about one person and one device, but the bigger question affects anyone who cares about privacy: when does using strong security tooling become framed as suspicious behavior?
GrapheneOS is a legitimate privacy and security-focused mobile operating system. Duress-code and wipe features can be useful for high-risk users, but this case shows how those same features may create legal and practical risk in border/search scenarios.
The takeaway is not “privacy tools are bad.” It is that threat models matter, especially when travel, law enforcement, and device searches collide.
Links from the episode
TechSpot — US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search: https://www.techspot.com/news/113236-us-prosecutors-charge-atlanta-man-after-grapheneos-phone.html
GrapheneOS project: https://grapheneos.org/
EFF — Border searches: https://www.eff.org/issues/border-searches
Quote from this week’s episode
GrapheneOS is a mobile operating system that is more private and secure… it doesn't mean that you are a criminal because you're using this.
— Tom Eston
Tom’s take
Privacy tools should not be treated as guilt by default. But if you travel with sensitive data, especially across borders or through airports, you need to understand that the legal and practical risk model can be very different from everyday phone use..
Help Review The Digital Legacy Tree
(upcoming book by co-host Scott Wright)
Scott Wright is looking for a small group of volunteer beta readers to review the nearly finished manuscript of his upcoming book, The Digital Legacy Tree.
The book is a practical guide to helping your loved ones find, access, and understand the digital accounts, devices, documents, and information they may need when you're no longer able to manage them yourself. The manuscript is about 30,000 words and is planned for publication in September.
You don't need to be a cybersecurity expert. In fact, Scott is especially interested in feedback from ordinary people with real digital lives. If you've ever wondered whether your family could locate the information they would need during an emergency, illness, incapacity, or after your death, your perspective would be valuable.
Reviewing the manuscript is designed to be quick and easy using a simple online tool that allows you to highlight passages and record your reactions, thoughts, and comments as you read. A couple of hours of your time could help make the book significantly more useful for future readers.
Beta reviewers who provide meaningful feedback will:
• Be eligible for acknowledgement in the book's beta reviewer section
• Receive early access to companion resources, templates, and worksheets
• Receive a complimentary PDF copy of the finished book upon publication
Scott is hoping to recruit approximately 5–10 reviewers for this final round of feedback.
To volunteer, share your story, or suggest ideas that may help others facing digital legacy challenges, visit:
https://securityperspectives.com/digital-legacy-tools
Also worth your attention this week
Passkey-protected accounts can still be hijacked by malware — Passkeys reduce phishing risk, but malware and session theft can still take over accounts from an already-compromised endpoint. Source: https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/
EDPB calls for review of EU-U.S. Data Privacy Framework — A useful privacy-law watch item as transatlantic data-transfer rules face renewed scrutiny. Source: https://www.hunton.com/privacy-and-cybersecurity-law-blog/edpb-calls-for-review-of-eu-u-s-data-privacy-framework-after-u-s-supreme-court-decision-on-ftc-independence
Snowflake hacker pleads guilty — A breach-accountability reminder that identity, session, and third-party access failures keep showing up in major incidents. Source: https://cyberscoop.com/connor-moucka-guilty-snowflake-attack-spree/
Listen / Watch
🎧 Audio Podcast: https://sharedsecurity.net/2026/08/10/grapheneos-phone-wipe-case-when-privacy-tools-become-evidence/
▶️ YouTube Version: https://youtu.be/Cch3pG2EO-g
We’d love your feedback
Do you think privacy-focused tools like GrapheneOS should ever be considered suspicious by default? Reply and let us know what you think.
Thank you to our sponsors!
Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.
🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT! Visit: https://slnt.com and use discount code "sharedsecurity" at checkout.
Closing
If you found this episode useful, subscribe to Shared Security, share it with someone that’s concerned about digital privacy, and consider supporting the show through YouTube channel membership or by following us wherever you get your podcasts.
Stay safe, stay secure, and stay private.
Tom Eston
Founder and Host, Shared Security Podcast

