GrapheneOS duress password case draws legal pushback
GrapheneOS says its privacy software is legal and protected as the first U.S. case involving one of its security features moves through court.
By Theo Nakamura · Staff Writer
· 3 min read
The GrapheneOS duress password case has put a privacy-focused smartphone operating system in the middle of a live fight over device security and law enforcement access. GrapheneOS said on X that its software is legal and protected by the U.S. Constitution after what 404 Media described as the first U.S. prosecution involving one of its features.
The project wrote on July 27 that GrapheneOS is “completely legal” and said it has no duty to reduce the security protections built into its operating system. It also argued that any law forcing it to weaken those protections would be unconstitutional.
For users, the practical issue is straightforward: strong device security can make data inaccessible, including to the company that created the tool. GrapheneOS said that if key material has been wiped, it cannot help recover access, adding that bypassing encryption is not possible by design. Encryption is the process of scrambling data so it can be read only with the right key.
What is the GrapheneOS duress password case?
The case involves Atlanta activist Samuel Tunick, who spoke with 404 Media about the charges against him. A duress password generally refers to a security feature meant for situations where a person is pressured to unlock a device; GrapheneOS’s public comments focused on what happens once key material is wiped.
Tunick told 404 Media that he believes the prosecution is meant to discourage people from protecting their data. His public defender told 404 Media that agents could have sought a warrant and did not, and that the statute involved has been used only once before.
GrapheneOS’s comments came after an X user asked whether the project was refusing to cooperate with Homeland Security. GrapheneOS responded that it could not provide the requested assistance if the relevant key material no longer exists. That distinction matters: the project framed the issue as a technical limit, not a choice to withhold a working backdoor.
A backdoor is a built-in way to bypass normal security controls. Privacy software makers often reject backdoors because a weakness available to one party can become a weakness available to others if discovered or abused. GrapheneOS’s position, as stated on X, is that its system is designed so the project itself cannot bypass encryption after certain security steps occur.
The court case is still proceeding, according to 404 Media. No outcome has been reported in the material cited by GrapheneOS, and the legal question now sits at the intersection of criminal procedure, constitutional protections and the technical design of modern phone security.
GrapheneOS’s public defense does not resolve the case against Tunick. It does clarify the project’s stance: creating and using its operating system is lawful, in its view, and the developers say they cannot undo security protections once the system has destroyed the material needed to access protected data.
This story draws on original reporting from Decrypt.