I have to admit… I’m a little jealous of the guy currently being charged by the U.S. government for allegedly obstructing a border search.
Not because of the felony charge (I’ll happily pass on that part), but because his phone had one absolutely brilliant feature: GrapheneOS’ Duress PIN.
For anyone unfamiliar with it, GrapheneOS lets you configure a secondary PIN or password. If you’re ever forced to unlock your phone under duress, entering that code doesn’t unlock the device—it immediately and irreversibly destroys the encryption keys, rendering the data inaccessible. It’s the digital equivalent of a silent panic button, and it’s exactly the kind of security feature I’d love to see become mainstream.
Ironically, my home alarm system has had a similar concept for years. Enter the duress code, and everything appears normal to whoever is watching—but behind the scenes, it silently sends an emergency signal. Smart security isn’t always about making noise; sometimes it’s about saying nothing at all.
This whole story also highlights why I find GrapheneOS so fascinating. It isn’t just about privacy—it’s about giving the device owner meaningful security controls that simply don’t exist on stock Android. Features like PIN scrambling, configurable auto-reboot back into Before First Unlock (BFU), USB protection while locked, and the Duress PIN are examples of security engineering that deserves far more attention.
One feature still on my personal wish list would be an option to automatically return the phone to the BFU state after a configurable period of inactivity—without requiring a reboot. (Yes, I know GrapheneOS already offers auto-reboot, which achieves BFU after the reboot, but I’d still love even more flexibility.)
Until then, I recently found an Android app that can manually force the phone back into BFU on demand. It’s not quite the same, but it means I can proactively place my phone into its most secure state before travelling or entering a situation where I want maximum protection.
Love it or hate it, this recent case has accidentally become one of the best advertisements GrapheneOS has ever received. When your operating system ends up in court because its security features actually worked… that’s certainly one way to demonstrate they aren’t just marketing bullet points.
https://readmydamnblog.com/wp-content/uploads/2026/07/2026-07-30-GrapheneOS-case.jpg.png628428Mikehttps://readmydamnblog.com/wp-content/uploads/2015/02/toplogo4.pngMike2026-07-30 15:10:012026-07-30 15:12:58Under duress – GrapheneOS to the rescue🫡
After watching this fascinating video about Operation Rubicon (also known as Operation Thesaurus), I was saddened to discover that Denmark apparently also were among the customers of Hagelin Crypto.
To be fair, I am not sure Denmark used these exact models. Still, it is unsettling to learn that cryptographic devices trusted by governments around the world may have been secretly compromised by the CIA and German intelligence agencies for decades.
The story behind Operation Rubicon is both fascinating and deeply sobering. It serves as a reminder that in intelligence, cybersecurity, and geopolitics, trust is often the most valuable — and vulnerable — component of all.
Which ultimately leaves us with the timeless question: who can you really trust?
Under duress – GrapheneOS to the rescue🫡
Mobile, Mobile Phone, NewsI have to admit… I’m a little jealous of the guy currently being charged by the U.S. government for allegedly obstructing a border search.
Not because of the felony charge (I’ll happily pass on that part), but because his phone had one absolutely brilliant feature: GrapheneOS’ Duress PIN.
For anyone unfamiliar with it, GrapheneOS lets you configure a secondary PIN or password. If you’re ever forced to unlock your phone under duress, entering that code doesn’t unlock the device—it immediately and irreversibly destroys the encryption keys, rendering the data inaccessible. It’s the digital equivalent of a silent panic button, and it’s exactly the kind of security feature I’d love to see become mainstream.
Ironically, my home alarm system has had a similar concept for years. Enter the duress code, and everything appears normal to whoever is watching—but behind the scenes, it silently sends an emergency signal. Smart security isn’t always about making noise; sometimes it’s about saying nothing at all.
This whole story also highlights why I find GrapheneOS so fascinating. It isn’t just about privacy—it’s about giving the device owner meaningful security controls that simply don’t exist on stock Android. Features like PIN scrambling, configurable auto-reboot back into Before First Unlock (BFU), USB protection while locked, and the Duress PIN are examples of security engineering that deserves far more attention.
One feature still on my personal wish list would be an option to automatically return the phone to the BFU state after a configurable period of inactivity—without requiring a reboot. (Yes, I know GrapheneOS already offers auto-reboot, which achieves BFU after the reboot, but I’d still love even more flexibility.)
Until then, I recently found an Android app that can manually force the phone back into BFU on demand. It’s not quite the same, but it means I can proactively place my phone into its most secure state before travelling or entering a situation where I want maximum protection.
Love it or hate it, this recent case has accidentally become one of the best advertisements GrapheneOS has ever received. When your operating system ends up in court because its security features actually worked… that’s certainly one way to demonstrate they aren’t just marketing bullet points.
Further reading:
https://www.pcmag.com/news/grapheneos-defends-data-wiping-function-that-blocked-us-border-search
https://arstechnica.com/gadgets/2026/07/activist-charged-with-felony-after-giving-border-agent-duress-code-that-wiped-his-phone/
Operation Rubicon
Military, SecurityOperation Rubicon
After watching this fascinating video about Operation Rubicon (also known as Operation Thesaurus), I was saddened to discover that Denmark apparently also were among the customers of Hagelin Crypto.
To be fair, I am not sure Denmark used these exact models. Still, it is unsettling to learn that cryptographic devices trusted by governments around the world may have been secretly compromised by the CIA and German intelligence agencies for decades.
The story behind Operation Rubicon is both fascinating and deeply sobering. It serves as a reminder that in intelligence, cybersecurity, and geopolitics, trust is often the most valuable — and vulnerable — component of all.
Which ultimately leaves us with the timeless question: who can you really trust?
Also read;
https://www.dr.dk/nyheder/indland/forsvaret-har-koebt-krypteringsudstyr-millioner-hos-hemmeligt-cia-firma
The Linux Kill Switch
Deployment, OS, Security