I think this has been posted in response to this news story [1] to clarify that GrapheneOS has strong protection against data being extracted even without a duress PIN/password.
On a related note, a recent article [2] also describes how GrapheneOS helped a journalist protect his work and his confidential sources citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.
[1] A US man is being prosecuted after allegedly using a GrapheneOS duress PIN to wipe his Pixel during a border search – https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
[2] A Journalist had his mobile phone seized. Did using GrapheneOS protect his data? – https://www.computerweekly.com/feature/Journalist-Richard-Me...
citing the 18-hour auto-reboot feature that returns the device to Before First Unlock (BFU) mode, where keys cannot be extracted.
Also worth mentioning that you can set auto-reboot to a shorter period (down to 10 minutes). So if you anticipate situations where your phone can be seized (border crossings, demonstrations), it's worth temporarily setting this to a short time period (or rebooting your phone yourself to get to BFU).
The Guardian story discussed on HN: <https://news.ycombinator.com/item?id=49024436>.
(The Computer Weekly item was submitted but saw no significant discussion.)
In regards to your first link, the quote "'It’s concerning – and sends the message that [GrapheneOS] is criminal by default,' said Christophe Boutry, a cybersecurity and surveillance expert." really is leading language. It's stating that protection is criminal and that vulnerability is law-abiding.