U.S. Charges Man for Using Duress Password on Encrypted Phone

The government is prosecuting someone for using a built-in security feature—a duress password that wipes a GrapheneOS device—rather than charging them with any underlying crime. By criminalizing the act of triggering the device's self-destruct mechanism, prosecutors are attempting to establish that technical countermeasures to forced data extraction constitute obstruction. If successful, this precedent would effectively criminalize privacy-by-design across all encrypted devices. The case tests whether owning and using privacy technology can itself become illegal in the U.S., with implications far beyond smartphones.