
GrapheneOS has published a detailed explanation of its security architecture after The Guardian reported on a US criminal case in which federal prosecutors are attempting to use a privacy-focused operating system as part of their case against an Atlanta activist linked to the Stop Cop City movement.
The case involves Atlanta resident Sam Tunick, who was stopped by Customs and Border Protection (CBP) officers at Hartsfield-Jackson International Airport in January 2024 after returning from the Dominican Republic. According to court filings, Tunick had been placed on a terrorism watchlist because of his alleged association with protests against Atlanta's $109 million police training center, commonly known as Cop City.
During the airport inspection, agents repeatedly asked Tunick to unlock his Google Pixel phone. Court filings cited by The Guardian state that after he entered his passcode, the device's screen went blank, restarted, and its contents were no longer accessible. Federal prosecutors are now attempting to charge him under a federal law that prohibits destroying property to prevent it from being seized by authorities.
GrapheneOS is an open-source, security-hardened operating system based on Android that currently supports Google Pixel devices because they provide the hardware-backed security features the project requires. It is widely used by journalists, activists, security researchers, and privacy-conscious users seeking stronger protections than those offered by standard Android.
Following The Guardian's reporting, GrapheneOS published a lengthy thread explaining that its security model is designed to prevent unauthorized data extraction rather than rely on features that erase user data.
The project said modern Android devices use hardware-backed disk encryption that cannot realistically be broken directly. Instead, attackers generally need to exploit the operating system while the device is already in an unlocked state or successfully guess the user's PIN or password.
GrapheneOS also highlighted several protections available on supported Pixel devices, including secure element-enforced rate limiting that progressively delays failed unlock attempts, hardware protections against firmware tampering, support for passwords up to 128 characters, hardened exploit mitigations such as Memory Tagging Extension (MTE), blocking new USB connections while the device is locked, and an automatic reboot feature that returns the phone to its most secure “Before First Unlock” state after a configurable period.
The project also addressed its optional duress PIN/password feature, which securely wipes a device when entered. GrapheneOS stressed that this feature is only one component of its broader security model and is not required to protect user data from extraction. According to the project, the primary defenses are hardware-backed encryption, secure authentication, exploit mitigations, and physical attack protections, with the duress feature simply providing an additional option for users who determine it is appropriate for their own threat model.
The latest case follows another Stop Cop City-related investigation reported earlier this year. Court records showed that Proton Mail, acting under a Swiss legal order, supplied payment-related subscriber information that was later shared with the FBI through a Mutual Legal Assistance Treaty (MLAT) request. The records helped investigators identify the alleged operator of an anonymous protest-related email account, illustrating how account metadata can remain accessible even when message contents are encrypted.







Leave a Reply