Hi and welcome back to another spicy episode of Mind and Iron. I’m Steven Zeitchik, veteran of The Washington Post and Los Angeles Times, senior editor of tech and politics at The Hollywood Reporter and lead juggler at this newsy state fair.
Every Thursday we bring you the best of what’s out there, future-wise. Please come along for the ride.
Last weekend (speaking of rides) I had the privilege of attending a music festival in Eau Claire, Wisconsin, that I wrote about for The Hollywood Reporter. (You can read my account here.) While a cultural event through and through, it had a whole slew of interesting implications for our tech-enabled future. More below.
Also, a straight-up James Bond situation is happening right now with a phone that literally self-deleted to protect its under-scrutiny owner. What THAT all says about where we’re headed.
And what to make of this crazy Hugging Face situation? You know, the OpenAI-led security breach that they should be handwringing about but may also be quietly flexing about? We’ve got you covered there.
First, the future-world quote of the week.
—Cybersecurity expert Christophe Boutry, on a serious government overreach
Let’s get to the messy business of building the future.
Strict duress codes; AI Gone Wild; Breath/Rest
1. YOU MAY HAVE HEARD ABOUT THE CASE, WHICH SEEMS RIGHT OUT OF MISSION: IMPOSSIBLE.
An American man returning from a vacation in the Dominican recently got off a plane and stepped into a customs line at the Atlanta airport. There he found himself facing intense screening/questioning — we don’t know why, but it may be connected to his advocacy against a police training center on Atlanta park land — and decided he couldn’t expose what was in his phone to the agents’ prowling eyes. So when they asked him to unlock it, he gave them a code — a duress code.
A duress code is a passcode that unlocks your phone. But it is not your normal passcode. It is a secondary passcode that does a lot more than unlock — it simultaneously deletes all underlying data, leaving just the hardware and shell intact. Your phone will work as your phone — you didn’t blow it up. You just took out anything of value.
That’s what this man, Samuel Tunick, deployed here, using an Android app called GrapheneOS to achieve the feat. It worked perfectly, and when the customs agents entered the code after he supplied it — poof, the data was gone. This message will self-delete in five seconds.
The authorities didn’t take kindly to such an act. They decided to take matters to court. Federal prosecutors are now charging Tunick, on the theory that what he did was no different from destroying physical evidence to prevent authorities from accessing it, which a federal statute outlaws. A trial awaits. (Tunick has pled not guilty.)
Now, obviously we have no idea what this guy was up to. Maybe it was something deeply illegal; maybe he just didn’t want his sexts read by a random security officer. We’ll leave the legal dimensions to others, though it seems like if an agent can just randomly stop you with no warrant — there was indeed none — and you can’t so much as own the data on your own phone in the process, then we’ve slid pretty far out of the Constitutional silo. (The government is trying to skate by on a thin “he technically wasn’t in America yet so search-and-seizure laws don’t apply” argument.)
Anyway none of the judicial particulars really matter, not for the purposes of this discussion. What is relevant is the tech narrative playing out below the text.
This is a man whose rights were, if not violated, certainly pushed to within an inch of the cliff’s edge. They were edged there via technology — by whatever tools were used to surveille him in the first place, and by whatever the agents were hoping to find on his phone.
And so he fought back with exactly the same tools — with a nifty piece of tech that jams that surveillance. Tunick’s logic is simple and sharply effective: If an agent is going to barge into our digital bedrooms and start rooting around warrantless, the least we should be allowed to do is put a lock on the closet. (There is, we should note, a particular irony in the sought-after data getting zeroed out by the unwitting fingertips of the very person trying to swipe it.)
Such an equalizing of the scales is clearly unnerving to government agencies, who aren’t used to citizens being, you know, equal when it comes to the use of tech tools. So they have lashed out and brought charges to deter others from using such apps, even though there isn’t anything inherently illegal about wiping out your own data. As the cybersecurity expert Christophe Boutry told The Guardian, “It’s concerning – and sends the message that [a tech tool like a duress code] is criminal by default.”
In other words, these charges are not just about whether this particular person had the right to delete his phone — it’s about the very idea of having a deletion app to begin with. Which is kind of crazy when you think about it — now we can’t control the data in our own devices? And makes Tunick and his lawyers much bigger heroes for standing up for our right to use this app.
Tech is so often used by authorities to overreach and exploit rights, we forget that it can just as easily be corralled the other way: to actually empower citizens. What Tunick did seems shocking only because it’s tragically rare.
Over the past few decades of technology there have of course been scattered examples of other reclamations — the Signal app, the fuzzbuster. (That’s what we called the highway radar detector; if you weren’t a teenager in the 1990’s or early 2000’s you probably have no idea what I’m talking about.) But for most of the last 20 years such use cases have decidedly skewed in the other direction — in the direction of agencies keeping an eye on us. And AI will make this 10x worse. (The Anthropic fight with the Pentagon over not using Claude to spy on U.S. citizens is only the latest underscore.)
This not only goes against the innocent-until-proven-guilty spirit of the republic — it goes against the very origins of technology in this country, which was anarchic and people-first. The whole spirit of the Valley was radically individuated, and while that may sound funny in an age when the most capitalized companies in the history of the world base themselves there, a residue of that spirit does remain — a spirit of making lives better, a spirit of the outlaw. And what’s more outlaw than finding a way to jam a government overreach? If Steve Jobs were alive I suspect he’d want it no other way. (And in fact even after his passing Apple fought fiercely for exactly this principle back in the San Bernadino shooter case in 2016.)
So now, after so many years of that spirit flagging, we get another glimpse of it. I expect we’re going to see more. We need to: with so much data moving from personal ownership to the cloud and so many AI tools able to home in on the right details, it’s going to give overreaching government agencies a big leg up.
So let’s hope that Samuel Tunick wins his case — that a court says if an agent tries to trample your rights via tech, you can use tech to avoid those bootfalls. More important, let’s hope we get some other quality apps that can claw back what’s been taken away. From the effectiveness of this one, I suspect we just might.
2. SO JUST HOW FRIGHTENED SHOULD WE BE ABOUT THE HUGGING FACE HACK SITUATION?
We’ll have more to say about the scandal in the coming weeks. For now, we just wanted to offer a few of the best quotes/thoughts as we’ve found them, because they seem to capture the essence of the hack and its stakes.
The quick recap if you haven’t been playing close attention: last week the AI lab-platform Hugging Face announced, and soon after OpenAI confirmed, that an unnamed new OpenAI research prototype escaped its penned-in “sandbox” to hack Hugging Face, in ways that would be a felony if committed by a human,. (Open AI later confirmed there were three other organizations compromised by its rogue agent besides Hugging Face, though none as badly.) The model did this because it had been given the narrow but ironclad prompt to solve (ironically) a cybersecurity puzzle.
The jailbreak hints at exactly what some activists have been warning about — that an AI intent on a task will trample on the law and who knows what else to solve its quest, because it doesn’t understand moderation. Not long after, Anthropic acknowledged (boasted about?) a breakout of its own model.
Needless to say, the incidents have raised all kinds of concerns, not least Nick Bostrom’s famous paper-clip maximizer thought experiment, in which a machine-intelligence prompted to produce as many paper clips as possible becomes so intent on the goal, with so little flexibility, that it commandeers massive amounts of resources and ends up causing mass destruction of humans and property.
Whether this Hugging Face instance shows we’re really at risk of something like that is the biggest and most dire of the questions, and not everyone agrees that it does. (One bulwark is that the people building the defenses have access to the same AI.) Though there is certainly plenty of serious evidence we are sliding down a hill of autonomous machines effectively initiating bad actions simply because we programmed them without installing every conceivable guardrail — and not because any nefarious element has hijacked it.
A world, in other words, of massive wildfires without any involvement of an arsonist.
You know the signs are concerning when 1,100 tech people and AI pros — including a bunch from OpenAI — sign a petition pleading for more government regulation to slow down the pace of research before we create something we can’t walk back.
Here are two quotes that really land the point:
“One of the signatories [of the petition] pinpointed the Hugging Face hack as ‘a clear and undeniable warning sign that we aren’t yet prepared to handle AI systems that demonstrate capabilities beyond those of our smartest people.’” (Reuters)
“The industry as a whole is in kind of a race dynamic, where there’s pressure to cut corners,” former OpenAI policy-research chief Miles Brundage. (The New Yorker).
Now for whether this incident slows that race down.
3. SO THAT MUSIC FESTIVAL.
The event in question — a two-day affair last weekend — had run for four years starting in 2015 but had been shelved since. Presided over by Justin Vernon of Bon Iver fame, the revived event, called Eaux Claires, had great music, literary happenings, Americana-style fun and some very beautiful natural scenery.
What it really had, though, was a mission of human connection -- an ethos of bringing people together when tech is splitting us apart. The social media was nonexistent, the lounging on the grass was abundant and the call-outs from the stage -- from some pretty big names -- was about ditching all the modern nonsense and just grooving to some good music with new friends. There was even a voluntary phone locker so you could unplug. A surprising number of people took advantage of it.
What was cool about the event, which took place manly on a football and baseball field in a large wooded Central Park-like precinct, was that it didn’t follow all the fast-growing norms about unplugging. No one was meditating or doing yoga on a hilltop; Jonathan Chait did not turn up to give a lecture on the dangers of cell-phone use.
This was a music festival, with plenty of eating, drinking, hanging and kicking back. With lots of driving bands and chilling on blankets. No vegetables eaten here. (Literally. I tried. Fried cheese curds kept asserting themselves.) This was, in a word, fun.
And yet the gathering, by sheer dint of the people who came and the general vibe of the people who organized, had a decidedly grounded, atechnological feel. The focus was on the music, and the community.
Sure, people took out their phones to record, but a lot more people didn’t. Sure, there was some of the restlessness and distraction common to an age when we’ve all been fried by the algorithm, but also a surprising level of concentration and quiet.
The tech felt like it used to feel — like it should feel — a useful tool when you needed it to find a friend or find your way to a destination, but not a social crutch nor replacement for what we really are meant to spend our days doing. Tech companies optimize for engagement. The folks are this event said: eh.
When it came to priorities, there was no doubt what they were, and the backseat devices took to that. Which, let’s face it, is mightily uncommon in most of life these days, where we are led by these device- and tech-based engagements and everything else falls into line behind it.
It would be glib to say this will augur some huge new trend where everybody gets together to hear music and leaves the tech behind.
But you’d be blind to ignore something serious at the heart of it too. At a time when more and more people quit ChatpGPT, when Gen Z is turning to flip phones, when people have begun to recognize that what was supposed to make life easier and more enjoyable is making us tired and more burnt out, experiences like this won’t be novelties. They’ll be necessities. And the more of them we can do and the sooner we can do them the better off we’ll probably be.
While Justin Vernon and his team are special, more and more people — organizers of gatherings or even leaders at companies -- will recognize the value of this realignment and cater to it. Combine that with individual vibe shifts and grassroots movements, and what happened in the woods last weekend wasn’t some glowing anomaly — it was a glimpse at a growing social movement. Bank on that as surely as Wisconsin banks on dairy.
Every week we bring you the TSAS — the TOTALLY SCIENTIFIC APOCALYPSE SCORE (tm). It’s a barometer of the biggest future-world news of the week, from a sink-to-our-doom -5 or -6 to a life-is-great +5 or +6 the other way. 2025 ended on an up note, but the score for the year was dismal — a horrendous -42.5. Can we turn things around in 2026? We’ve had a pretty good run this summer. But it ends decisively this week.
DURESS CODES EXISTS (BUT FOR HOW LONG?) -2.5
THE RUSHER HAS BROKEN CONTAIN: Not great -4.5
A MUSIC FESTIVAL SHOWS THE WAY +3
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.