I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.
As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.
>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513
If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.
It seems foolhardy to carry your life savings around everywhere, encrypted or not.
If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.
> I keep all of my most sensitive personal documents on my phone
Why...?
If I had anything I didn't want the authorities to get, I'd remove it from my phone before travel (e.g. put in cloud, etc).
If you travel abroad you must unlock. No 4th amendment for you.
It seems to me you are taking a big risk. Some considerations:
> Cryptomator
Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.
And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.
Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.
Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.
> or legal access
Ask a lawyer.
Oh my god, get out of crypto. Put your money into a bank instead of trying to one-man-army yourself into being Fort Knox.
If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.