// blog · Privacy

GrapheneOS duress wipe at Atlanta airport

The case

The Justice Department is asking a federal court in Atlanta to treat a man's erasure of his own phone as destruction of property, the first known US prosecution built on a phone's duress password. Samuel Tunich faces one count under Title 18, Section 2232A, a statute covering the destruction of property to stop the government from taking it.

Prosecutors say he handed Customs and Border Protection officers a passcode that deleted the contents of his Google Pixel instead of unlocking it. His lawyers appeared before the court arguing that officers ran a custodial interrogation without Miranda warnings, denied him a lawyer, and searched him unlawfully. They want everything obtained from the encounter suppressed.

CBP pulled Tunich into secondary inspection at Hartsfield-Jackson as he returned from the Dominican Republic. An FBI special agent had coordinated with CBP in advance to question and search him on arrival. Officers never read his Miranda rights. He repeatedly asked for a lawyer. Questioning continued.

Tunich eventually provided a password for his phone. The screen went blank, flashed several times, and the phone appeared to restart. Officers seized the devices and told him they would return after 30 days. The phone was, by then, a paperweight. The data was irretrievable.

The duress password

GrapheneOS has a feature called a duress password. You set up your regular PIN, the one you type every day to unlock your phone. Then you set up a second PIN. If you're stopped by TSA, the police, border agents, or anyone else who demands your phone, you enter the duress PIN instead. The phone wipes everything. It deletes the encryption keys so that even with forensic analysis, it's next to impossible to recover any data from the device.

The beauty of this is that it's the authorities' only window into GrapheneOS. They have to ask you for your PIN because they can't get in any other way. They'll threaten you with arrest, with charges, with whatever they think will work. But if you give them the duress PIN, the phone wipes, and they're left holding a brick. There's nothing they can do with it.

Cellebrite and the forensic matrix

A couple of years ago, a security researcher managed to get into a Zoom call for a company called Cellebrite. Cellebrite makes the tool that governments, airports, and police forces use to extract data from phones, the little desktop machine with a USB cable that officers plug into your device. It's developed by an Israeli company, and it's already loaded with malware and hacking tools designed to pull everything off a stock phone: stock Android, stock iOS, stock Windows. Plug in, press go, and it pulls your Signal messages, your WhatsApp chats, everything.

The researcher took screenshots of an internal Cellebrite presentation, a matrix showing how effective their tool was at pulling data from various operating systems. The results were telling.

Stock Android: everything, every time. Before first unlock, after first unlock, even when the screen is locked. Cellebrite pulls it all. iOS sits in the middle: vulnerable in several states, especially after first unlock. But GrapheneOS, on any device from 2022 onwards, is impossible. They can't get anything from a locked GrapheneOS phone. The hardware security on Pixel phones, which is ironic given it's Google's hardware, combined with GrapheneOS's hardening, makes forensic extraction effectively impossible.

Before First Unlock

There's an important detail here for anyone on iOS or stock Android. Your phone has two primary states. When you reboot and the phone turns on but you haven't unlocked it yet, that's called BFU, Before First Unlock. That's the most secure state your phone can be in while powered. Once you put your code in the first time, that authentication stays in RAM and can be re-accessed. Your phone is less secure after that first unlock than before it.

On GrapheneOS, even after first unlock, Cellebrite can't extract data. On stock Android and iOS, once you've unlocked it once, the door is open.

What this case means

This case is the first of its kind, and it matters because it tests whether wiping your own device, your own property, to protect your privacy counts as destroying evidence. If the DOJ succeeds, it sets a precedent: the act of protecting your data becomes a crime in itself.

GrapheneOS built the duress feature deliberately, knowing this day might come. They went out of their way to build features that mean when bad actors, be they state actors or hackers, attempt to access your phone, it is technically impossible for them to do it. That's not a bug. It's the point.

If you're on stock Android or iOS and you're worried about privacy, look into GrapheneOS. There's a step-by-step guide on their website. My partner installed it on her own, and she's not a computer person. It's doable. And the only way to fight the encroachment on digital privacy is to make good decisions with your own data, one device at a time.

GrapheneOS Privacy Legal Cellebrite
← Back to blog