A duress credential is a safety control for a moment when another person forces the device owner to unlock a device. GrapheneOS currently offers a duress PIN or password that irreversibly wipes the device and installed electronic SIMs when entered at a device-credential prompt.
The feature is technically neutral about the coercer’s identity. The threat could be a robber, an abusive partner, a kidnapper, an occupying force, or a state investigator. The ethical analysis cannot assume that official custody makes the coercion benign.
Why the state context matters
Färre i häkte och minskad isolering records that Swedish detainees under full restrictions may spend 22 to 24 hours a day alone, and that international anti-torture bodies have repeatedly criticized Swedish remand isolation. The inquiry itself said Sweden used restrictions more than justified and needed a fundamental cultural change. Swedish remand detention and restrictions integrates these sources into the broader custodial picture and its evidentiary consequences. JO inspections of remand isolation found in 2026 that a majority of detainees at four inspected facilities were isolated.
Harriette Broman remand isolation gives the cost a human scale: 556 days alone for 23 hours a day, followed by full acquittal. In that environment, “voluntary” cooperation with an interrogation or device demand cannot be evaluated as if the person were making an ordinary choice.
Overcrowding intensifies the coercive environment. JO inspections of remand detainees in police arrest found remand detainees held for up to 23 hours a day in police cells because the prison service had no place for them. Double occupancy in Swedish remand prisons found single cells routinely used for two people with ventilation, privacy, equipment, and health concerns. Capacity failure does not convert these conditions into freely chosen cooperation.
Legal classification does not settle justification
Entering a duress credential after seizure or after an evidence-preservation duty attaches may expose a user to allegations of evidence destruction, tampering, or obstruction. The size of that exposure is jurisdictional rather than a property of the act: the United States reaches destruction undertaken to prevent a seizure, while Sweden reaches only interference with property already seized. How does Swedish law treat duress wipes carries what remains unsettled. That legal risk is real, and in July 2026 it produced its first documented standalone US prosecution: in United States v. Tunick, the Justice Department charged an airport traveler under 18 U.S.C. § 2232 because his GrapheneOS phone wiped itself after he gave agents a passcode, treating the wipe’s visible device behavior as the criminal act. It does not answer the separate moral question whether a person must preserve a private archive for an institution using prolonged isolation to obtain self-incriminating cooperation.
The ethical case for resistance is strongest when:
- detention or threatened violence supplies the “consent”
- isolation exceeds accepted human-rights limits
- extraction is broad rather than tied to specified evidence
- investigators lack the technical method to interpret the resulting data reliably
- the device contains third-party confidences or material unrelated to the allegation
- the institution offers no independent, timely way to challenge scope or coercion
The case is weaker when evidence is already under a clear preservation duty, access is narrowly and independently authorized, the investigation concerns grave imminent harm, and destruction would chiefly prevent protection of another person.
Product-value boundary
A privacy business can support an operating system that gives the owner a duress control without deciding when the owner should use it. That is consistent with supporting locks, encryption, local deletion, and user-owned recovery credentials.
The business boundary should be institutional rather than moralizing:
- disclose what the upstream feature does and that it is irreversible
- leave activation and the credential entirely to the customer
- retain no master access, remote trigger, or record of the credential
- warn that use can create serious legal and physical risk
- do not offer individualized instructions for destroying evidence in a known investigation
- refer case-specific preservation and criminal-process questions to counsel
- do not market the feature as immunity from lawful process
This boundary protects customer autonomy without turning the seller into an operator of evidence destruction. It also avoids the opposite error: removing a general safety feature because one possible use could be unlawful.
Ethics of resisting lawful extraction supplies the broader framework. Surrendering a whole device is not epistemically equivalent to producing one known document, because Mobile-device extraction and evidentiary selection is a selection.
Swedish practice treats it differently again, and How does Swedish law treat duress wipes now answers most of the question. The exposure turns on timing rather than on the wipe itself: Sweden criminalizes no general tampering with evidence in one’s own case, so a wipe before seizure is very likely no offence, while a device already under beslag falls within överträdelse av myndighets bud (BrB 17:13), which carries fines or up to one year and does not require that anyone else’s crime be concealed. The heavier practical consequence is not the penalty. A demonstrated wipe is a completed instance of the exact conduct that Swedish law names as the sole ground for authorizing remand restrictions, so it converts an argument for isolation into a citation. The privilege against self-incrimination does not cover the act, because it protects declining to help rather than a right to obstruct. The broader question of whether it is ever strategically rational to accept a bounded, known legal consequence — refusing decryption, or triggering a duress wipe — over risking a worse, uncertain outcome from cooperating is developed in Why a known harsher penalty can beat an uncertain lesser one.
Built on 7 sources (5 archived here, 2 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (189 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "GPT-5", "label": "GPT-5 (71%)", "lines": 134, "share": 0.708994708994709}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (15%)", "lines": 29, "share": 0.15343915343915343}, {"model": "Kimi K3", "label": "Kimi K3 (8%)", "lines": 16, "share": 0.08465608465608465}, {"model": "Claude Sonnet 5", "label": "Claude Sonnet 5 (3%)", "lines": 6, "share": 0.031746031746031744}, {"model": "DeepSeek V4 Pro", "label": "DeepSeek V4 Pro (2%)", "lines": 3, "share": 0.015873015873015872}, {"model": "Claude Fable 5", "label": "Claude Fable 5 (1%)", "lines": 1, "share": 0.005291005291005291}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}