The developer of an ultra-secure version of Android, Graphene OS, is defending its approach after an activist used the operating system’s data-wiping feature to erase his phone and block federal agents from searching the device.
“GrapheneOS is completely legal. We have no obligation to weaken any of the security protections it provides,” the software developer tweeted on Monday. “Laws attempting to make it illegal or require weakening the security would be unconstitutional.”
At issue is an Atlanta-based environmental activist named Sam Tunick, who had the free GrapheneOS software installed on his Pixel phone. In January 2025, US Customs agents demanded the device's password during a search at the airport. Tunick’s lawyers claim the agents “never read him his Miranda rights,” and ignored his request to speak with a lawyer. When Tunick provided a password for his phone, it was actually a “duress password” that irreversibly wipes a device when entered.
“When the CBP officers entered the password on his cell phone, ‘the screen went black, flashed several times and the phone appeared to restart,’” a court document says.
The US filed a criminal indictment against Tunick in November, claiming he violated a US law against “knowingly” destroying or impairing the government’s authority to seize property under its lawful control. The Guardian also reports the case might be the first targeting GrapheneOS, which has been around for a decade.
In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the “auto-reboot timer” that’ll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted.
The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. “People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device,” the nonprofit wrote. “GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device.”
On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick’s phone. “Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it,” the group wrote. “Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it.”
The case arrives amid a years-long debate about privacy versus US investigatory powers, which has been a long flash point with Apple iPhones and end-to-end encryption. In the past, the FBI has called on tech companies to build a lawful backdoor to bypass encryption, but the industry has argued that doing so risks undermining encryption for all and creating a way for hackers and foreign governments to exploit the weakness.
For now, the case might be a PR win for GrapheneOS, which features official production support for unlocked Google Pixel 6-10 devices. In the meantime, Tunick could face up to five years in prison if found guilty. But in March, his lawyers urged the US district court to suppress all evidence taken from his interrogation, arguing that his constitutional rights had been violated.
About Our Expert
I've been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I'm currently based in San Francisco, but previously spent over five years in China, covering the country's technology sector.
Since 2020, I've covered the launch and explosive growth of SpaceX's Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I've combed through FCC filings for the latest news and driven to remote corners of California to test Starlink's cellular service.
I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.
I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I'm now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I'm always eager to learn more, so please jump in the comments with feedback and send me tips.
- Starlink Exempted From FCC's Foreign-Made Wi-Fi Router Ban
- Claude Chats Popped Up in Google Search Results. Who's to Blame?
- Coca-Cola's Fairlife Milk Production Resumes as Hackers Tout 1TB Data Theft
- Amazon Plans to Launch 5,000 New Satellites to Beam Data to iPhones
- In Face of US Crackdown, Microsoft, Nvidia CEOs Back Open-Weight AI Models
- More from Michael Kan