GrapheneOS - Did Tunick Provide a Duress Password?

The GrapheneOS. Duress passwords. It's all over the news. 

This is the case of Samuel Tunick, who was detained by CBP when he returned to the United States via the Atlanta airport. The Government alleges he provided a password to agents that would wipe his phone. It's been reported that his phone had GrapheneOS installed on it. 

According to the article from The Guardian (https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone), "Agent Findley and several others repeatedly asked Tunick to open his phone during the interrogation, telling him they would seize it if he did not. When he finally provided a passcode, “the screen went blank, flashed several times and the phone appeared to restart”, according to the motion."

Here's the direct quote from the motion regarding the phone password "Mr. Tunick provided a password to his cell phone and e-reader. According to the government, when the CBP officers entered the password on Case 1:25-cr-00499-ELR-CCB Document 21 Filed 03/17/26 Page 4 of 13 5 his cell phone, “the screen went blank, flashed several times and the phone appeared to restart.” (Tunick_07)." 


The motion did NOT state that Mr. Tunick provided a duress password. It only states Mr. Tunick provided a password.

But what will the artifacts on the phone reveal when examined through the eyes, training, and experience of a digital forensics examiner?

First, you need to know that GrapheneOS is based on version 16 of the Android Open Source Project. So it's going to be slightly different than some of the mainstream flavors of Android you've seen. It's really no different than the Android OS running on Google Pixel vs a Samsung vs a Motorola. They're all a little different. Speaking of Pixel phones, if you want to use GrapheneOS you have to have a Pixel.

Yes, Graphene does provide users with the ability to enter a duress password that will wipe the phone immediately.  There are a couple of different options available when setting this up. Upon the entry of the duress password, it will "wipe" the phone by destroying the encryption keys. This makes for a fast "wipe." According to Graphene documentation, it does NOT require a restart as part of the wiping process. To be clear, when it states it doesn't require a reboot to wipe, it means it doesn't start rebooting and then go into some sort of wiping process. It deletes your encryption keys and then the phone reboots. If it did require a reboot to start the wiping process, you might be able to stop the reboot to avoid wiping.

Graphene can also be set to reboot automatically after a certain amount, and this time can be as short as 10 minutes. The reboot would enter the phone into Before First Unlock (BFU) status, which limits the amount of data that can be available during the extraction process.

I was unable to clearly determine the number of invalid attempts for password settings for GrapheneOS. But it is certainly a possibility that the agents were already guessing the password in an attempt to gain access to the phone. Once they had the password provided by Mr. Tunick, did they fat-finger the password, causing the phone to follow a standard procedure for too many failed password attempts?

From what I've seen (not my own testing) if a duress password is entered the phone says wrong password entered, the phone goes blank, starts rebooting, and then a message says a new operating system is loading. Once it's done rebooting a message says it can't load the Android Operating System and asks you to select a factory reset or to try again. There is no trying again from a user perspective because the keys have been deleted. The data is there, but it's encrypted. So, unless you can break this encryption, you aren't getting anything off the phone. Selecting factory data reset will reset your phone, and allow you to set it up again from scratch.



Here's what's displayed if you enter the password wrong too many times:



According to the motion, Mr. Tunick's electronic devices were seized. It's logical to assume that after his devices were seized, an extraction of his phone should have been completed. What will an examination and analysis reveal?

What, if any, artifacts will be present on the phone to support what was observed with the eyes? Did someone take a picture of the phone in this GraphenOS recovery state? Or a picture of the phone stating how long before they could try again? I searched for the transcript from the hearing on July 20, 2026, and I couldn't find it; it might just be too soon. I did find that the Government produced 5 exhibits, but no idea what those exhibits contained or depicted.

The examiner should consider what actions could cause the actions observed by the eyes. Then the examiner needs to determine what evidence is left behind when those actions occur. If the phone isn't stuck at either one of the screens shown above, it will likely take a considerable amount of testing to determine what may have happened on that phone.

It will be interesting to see what the facts reveal in this case. 

So, back to the question, did Tunick provide the agent with a duress password? Without seeing the evidence the answer is... maybe or maybe not. A duress password is certainly a possible explanation for what the agent said he visually observed. But there are other possible explanations that include the agent entering the password incorrectly and a timed/planned reboot.

We won't know more until more information is released from the courts.

Have you worked a case when someone wiped their Google Pixel Phone running the GrapheneOS? If so reach out to me and we can discuss it on the podcast Parsing the Truth: One Byte at a Time.


Connect with me on LinkedIn




Comments

Popular posts from this blog

Epstein's Missing Minute Found

Casey Anthony: The State's Evidence

Casey Anthony: John Bradley's Testimony