GrapheneOS - Profiles, Credentials, Duress PIN, and Practical Privacy Setup
GrapheneOS is a hardened, privacy-focused mobile operating system based on the Android Open Source Project. It runs exclusively on Google Pixel devices and prioritizes real security and privacy improvements over marketing features. Among its strongest tools for compartmentalization and coercion resistance are multi-user profiles, flexible lock-screen credentials, and the duress PIN.
Lock-Screen Credentials and Authentication Options
Each user profile on GrapheneOS can have its own independent lock-screen credential (PIN, password, or pattern). Biometrics (fingerprints) can be added as a secondary unlock method.
A particularly useful configuration is the two-factor fingerprint unlock. You set a strong primary passphrase or long PIN for full protection, then enable fingerprint plus a shorter secondary PIN for convenient daily unlocking. The secondary PIN is only usable for a limited window after the last primary unlock (typically 48 hours), after which the strong credential is required again. This combines strong cryptographic protection with practical usability.
PIN scrambling is also available, randomizing the number pad layout on each unlock attempt to reduce shoulder-surfing risk.
The Duress Feature
GrapheneOS includes a dedicated duress PIN (and optional duress password). When this secondary credential is entered anywhere the system requests authentication (lock screen or other OS prompts), the device immediately and irreversibly wipes all encryption keys and installed eSIMs. The wipe cannot be interrupted and leaves the phone in a factory-reset state. There is no confirmation dialog and no obvious visual indication that a wipe is occurring rather than a failed unlock.
This feature has recently entered the legal spotlight. In January 2025, Atlanta resident Samuel Tunick was stopped at Hartsfield-Jackson Atlanta International Airport while returning from the Dominican Republic. Border agents demanded access to his GrapheneOS Pixel. According to court filings, a passcode was entered and the phone appeared to wipe itself. Federal prosecutors later charged him under a statute prohibiting the destruction of property to prevent government seizure. This is the first known U.S. case centered on the use of a GrapheneOS duress credential. The case is ongoing as of mid-2026, with the defense challenging the legality of the search and detention.
Reboot and Profile State
After a full reboot (or when the device is in the Before First Unlock, or BFU, state), the Owner profile must be unlocked first. Only then can secondary profiles be accessed. This is a technical requirement because sensitive system-wide data resides in the Owner profile.
Once the Owner has been unlocked at least once after boot (the After First Unlock, or AFU, state), you can switch between profiles freely by selecting them from the lock screen or quick settings and entering the appropriate profile credential. Ending a secondary profile session returns its data to an encrypted-at-rest state.
User Profiles
GrapheneOS supports multiple fully isolated user profiles. Each profile has its own encryption keys, separate apps and app data, and independent lock-screen credentials. Profiles also have an optional ability to run in the background or forward notifications.
The Owner profile is special. It must be unlocked after every reboot before other profiles can be used, and it can manage secondary profiles (including installing apps into them). Secondary profiles cannot access the Owner data, and vice versa.
Recommended Privacy-Oriented Setup
A widely recommended configuration among experienced users follows a three-layer approach.
Owner profile: Keep it essentially empty. Use a very strong passphrase. This profile exists mainly to unlock the device after reboot and to manage secondary profiles or install apps.
Daily-driver secondary profile: This is where you live day to day. Install your normal apps here. Use a strong but practical credential (or the two-factor fingerprint plus PIN setup).
Duress credential: Configure it, but treat it as a last-resort tool.
Important practical advice on duress: In situations of physical constraint or when dealing with authorities (especially at borders), many experienced users recommend against using the duress wipe. Entering it can itself become evidence of intent to destroy data, as the Atlanta case illustrates. In many jurisdictions it may carry legal risk. Prefer other strategies: travel with a clean secondary profile, keep sensitive data offline or in end-to-end encrypted services that require additional authentication, or simply refuse to unlock when legally permissible.
Bottom line
This combination of an empty Owner profile, a daily secondary profile with strong credentials, and cautious use of duress gives you strong compartmentalization and cryptographic protection while remaining usable for everyday life. The right setup depends on your specific threat model, but GrapheneOS gives you the tools to build it.