GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

Source: pcmag.com
131 points by pseudolus 5 hours ago on hackernews | 145 comments

The developer of an ultra-secure version of Android, Graphene OS, is defending its approach after an activist used the operating system’s data-wiping feature to erase his phone and block federal agents from searching the device. 

“GrapheneOS is completely legal. We have no obligation to weaken any of the security protections it provides,” the software developer tweeted on Monday. “Laws attempting to make it illegal or require weakening the security would be unconstitutional.”

At issue is an Atlanta-based environmental activist named Sam Tunick, who had the free GrapheneOS software installed on his Pixel phone. In January 2025, US Customs agents demanded the device's password during a search at the airport. Tunick’s lawyers claim the agents “never read him his Miranda rights,” and ignored his request to speak with a lawyer. When Tunick provided a password for his phone, it was actually a “duress password” that irreversibly wipes a device when entered.

“When the CBP officers entered the password on his cell phone, ‘the screen went black, flashed several times and the phone appeared to restart,’” a court document says. 

The US filed a criminal indictment against Tunick in November, claiming he violated a US law against “knowingly” destroying or impairing the government’s authority to seize property under its lawful control. The Guardian also reports the case might be the first targeting GrapheneOS, which has been around for a decade.

In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the “auto-reboot timer” that’ll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted. 

The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. “People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device,” the nonprofit wrote. “GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device.”

Recommended by Our Editors

On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick’s phone. “Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it,” the group wrote. “Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it.”

The case arrives amid a years-long debate about privacy versus US investigatory powers, which has been a long flash point with Apple iPhones and end-to-end encryption. In the past, the FBI has called on tech companies to build a lawful backdoor to bypass encryption, but the industry has argued that doing so risks undermining encryption for all and creating a way for hackers and foreign governments to exploit the weakness. 

For now, the case might be a PR win for GrapheneOS, which features official production support for unlocked Google Pixel 6-10 devices. In the meantime, Tunick could face up to five years in prison if found guilty. But in March, his lawyers urged the US district court to suppress all evidence taken from his interrogation, arguing that his constitutional rights had been violated.

About Our Expert