SUMMARYGrapheneOS defended its duress-password and auto-reboot features after an environmental activist used them to wipe a Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The Canadian nonprofit said the operating system is legal, cannot recover erased data, and should not be weakened with encryption backdoors. The activist faces up to five years in prison if convicted.

GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal," cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports: In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that'll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted.

The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. "People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device," the nonprofit wrote. "GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device."

On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick's phone. "Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it," the group wrote. "Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it."