GrapheneOS defends “duress” feature, discards decoy accounts idea
A border case could redefine the legality of phone privacy tools.

Image by Cybernews.
- GrapheneOS's duress password wipes phone data and appears as a factory reset, leaving minimal detection traces.
- A US border case prosecuting Samuel Tunick for data destruction may reshape privacy technology treatment nationwide.
- GrapheneOS developers say decoy accounts are easily identified by basic forensic software and laptops without exploits.
- The operating system's creators assert duress features are constitutionally protected under US law and need not weaken.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
With a new case in the US possibly determining the future of GrapheneOS users traveling to the country, the developers of the operating system claim that their duress password feature is "completely legal" and that decoy accounts wouldn't help.
"We have no obligation to weaken any of the security protections it provides. Creating and using GrapheneOS is strongly protected by the US constitution," the developers said, adding that laws attempting to make it illegal or require weakening the security "would be unconstitutional."
GrapheneOS entered the spotlight after reports in July revealed that US law enforcement prosecuted a man for wiping his phone clean during a border search. As reported by Cybernews, the US Department of Justice claims that Samuel Tunick, an Atlanta resident, provided the authorities with a passcode that destroyed the data on his smartphone.
The duress password is a special feature of the GrapheneOS operating system, which can be installed on Google Pixel phones. Instead of unlocking the phone, it wipes encrypted user data, returns the phone to a factory-reset state, and leaves little indication that the wipe was intentional.
Tunick pleaded not guilty and is seeking to suppress the evidence obtained during the stop.
Therefore, the ruling in this case might determine how privacy technology is treated at the US border, or how encrypted technology is treated more generally. While using encryption is generally lawful, prosecutors argue that intentionally destroying data after officials demand access is different.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Meanwhile, GrapheneOS was also forced to respond to suggestions that the operating system should use decoy accounts that would show up on a phone when a special password is entered. In theory, then, no one would know the real account a person uses. However, the developers claim this is not the case.
"The decoy profile concept many have suggested for years is far more flawed than this. It wouldn't hide the presence of other profiles and would be trivially identified," it said, adding that basic forensic software on a laptop would identify it without exploits.
Companies like Cellebrite and Magnet Forensics already document GrapheneOS capabilities in training and extraction tools, making decoy accounts less effective.