
Pressing down on you.
GrapheneOS is an Android-based operating system for seriously privacy- and security-minded users.
It’s pretty great.
It only runs on Google Pixel phones that are still within their support lifetime, which is not great, but it’s not really Graphene’s fault that no other phone makers are selling phones with that level of security hardware in them.
Among the many (seriously, many) security features that GrapheneOS offers that almost no one else does is a thing called a “duress password” (or “duress PIN” or “duress code”).
This is an alternative password the user can set that, instead of unlocking the device, can wipe it instead; it’s intended for use when someone is threatening you to get you to give them access to the device.
I know; pretty neat feature, right?
Of course, criminals that might want to threaten users to get access to their devices don’t like duress passwords being a thing. It kinda gets in the way of doing all those crimes that they want to do.
They’re pretty great for everyone else, though.
Especially if they’re implemented carefully so it’s not obvious when they’ve been used.
Anyway, the United States government …
The U.S. government has long maintained that the border (and any place within 100 miles of the actual border line) is a Constitution-free zone, where even the long-corrupted rules restricting State behavior do not apply.
So they’ve had a longstanding policy that border agents get to examine the contents of computers whenever they want, and can demand that the user unlock devices for inspection.
Like you do, if you’re an abusive police State.
You can probably see where this is going.
The U.S. government is prosecuting a fellow named Sam Tunick for using his GrapheneOS duress password during a warrantless search.
First, good on Tunick for even being aware of GrapheneOS; it’s a really niche system. And serious kudos for actually using it and having the duress password set. This is deep into actual security professional territory here (though really this feature should be everywhere and not just limited to the pros).
And serious shame on the government for putting him in a position where using the duress password was necessary.
Warrantless border searches like this are blatantly unconstitutional; there is no “unless you’re within 100 miles of the border” clause in the 4th Amendment.
It does sound like GrapheneOS’ implementation of the duress feature leaves something to be desired, and that something is called “deniability”. Ideally, a duress feature would be built carefully to minimize the chance that anyone can tell that it’s been used. They should probably look at fixing their duress implementation.
Like we should look into fixing our country so we don’t need a duress password when crossing the border.
- As Designed: Duress Passwords Are Not A Crime - 2026-07-30
- Electoral Dysfunction: Third Time, No Charm - 2026-07-29
- Unlawful Assembly: Not A Real Thing In The U.S. - 2026-07-27
