The US Department of Justice’s recent case against GrapheneOS user Sam Tunick has renewed discussions about mobile privacy, digital security and the limits of law enforcement access to personal devices. The GrapheneOS Foundation has responded by defending its open-source operating system and clarifying how its security mechanisms handle deleted information.
The Toronto-based non-profit organization said GrapheneOS is a lawful operating system and rejected any suggestion that the software itself is connected to illegal activity. The foundation emphasized that it has no responsibility to weaken features intended to protect users and their data.
Based on Android and currently designed for Google Pixel devices, GrapheneOS incorporates several security and privacy protections. The foundation argues that developing, distributing or using the operating system is protected under US constitutional principles and that legislation specifically targeting its security capabilities could face constitutional challenges.
One of the features at the centre of the case is GrapheneOS’s "duress password." Tunick reportedly provided the password to a US Customs and Border Protection officer. The feature is designed to trigger an immediate wipe of a device when a specific password or PIN is entered under coercion.
When activated, the process removes the phone’s stored information, including eSIM data. According to the foundation, the wipe occurs immediately, cannot be interrupted and cannot subsequently be reversed. As a result, data erased through the feature cannot be recovered from the device.
Despite the attention surrounding the duress password, the GrapheneOS Foundation has stressed that it represents only one small component of the operating system’s broader security architecture. The organization also cautioned that using such a feature could potentially have physical or legal consequences, meaning users need to consider the risks before relying on it during encounters with authorities or other coercive situations.
The legal dispute is also focused on Tunick’s treatment during the encounter. His attorney has alleged that the border officer did not provide Miranda warnings and disregarded Tunick’s requests to consult a lawyer.
Tunick’s legal team is seeking the exclusion of evidence obtained during the incident. The attorney has argued that the evidence should be dismissed because the authorities allegedly violated Tunick’s constitutional rights.
The case has consequently raised broader questions about the balance between individual privacy, device security and government authority, while putting renewed attention on how privacy-focused operating systems handle data deletion and compelled device access.
Players of indie game Meccha Chameleon have been advised to install the latest update and avoid the game's original Discord community after malicious Steam Workshop maps were found to contain malware capable of compromising users' computers.
The security issue was initially investigated by independent researcher Feint after players reported unusual black windows appearing briefly while custom maps were being loaded. According to a report by Dexerto, Feint identified one of the problematic maps as "Laser Tag Neon." Loading the map caused a hidden file to be placed on the user's computer.
The hidden file was reportedly designed to connect to the internet and retrieve additional malware. Although "Laser Tag Neon" was eventually removed, another map called "Chroma Grid Arena" was reportedly found carrying similar malicious content.
Feint's investigation suggested that the second-stage malware could provide attackers with persistent remote access to affected machines. However, players were not compromised merely by downloading the maps. They needed to actually load and play the malicious content for the infection to take place.
Meccha Chameleon co-developer Haganeiro said the vulnerability was addressed in update 3.1.0. The developers also took steps to deactivate the malicious code within affected maps, including for users who had not yet installed the update.
The incident nevertheless escalated when a systems engineer helping the developers investigate the malware reportedly had a backup computer compromised. According to Dexerto, attackers subsequently used the infected machine to gain access to the engineer's Discord account.
Per Developer LEMORION, the attackers then changed permissions on the game's official Discord server and banned members of the development team. The server has approximately 100,000 members.
The developers said the compromised computer did not have access to Meccha Chameleon's source code, game files or Steam developer accounts. Reports suggesting that attackers had used the Discord takeover to compromise the game's official build were also disputed.
A new community Discord server has since been created as the developers wait for Discord's support team to respond to the incident.