logoalt Hacker News

delichon • today at 3:20 PM • 7 replies • view on HN

I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.


Replies

WithinReason • today at 3:29 PM

If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.

➕ show 4 replies
Cider9986 • today at 3:50 PM

It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513

If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

[1] https://www.privacyguides.org/en/cloud/

➕ show 1 reply
jstanley • today at 3:29 PM

It seems foolhardy to carry your life savings around everywhere, encrypted or not.

If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

➕ show 2 replies
BeetleB • today at 8:08 PM

> I keep all of my most sensitive personal documents on my phone

Why...?

If I had anything I didn't want the authorities to get, I'd remove it from my phone before travel (e.g. put in cloud, etc).

pieter_mj • today at 3:23 PM

If you travel abroad you must unlock. No 4th amendment for you.

➕ show 3 replies
mmooss • today at 4:18 PM

It seems to me you are taking a big risk. Some considerations:

> Cryptomator

Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.

And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.

Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.

Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.

> or legal access

Ask a lawyer.

fragmede • today at 7:26 PM

Oh my god, get out of crypto. Put your money into a bank instead of trying to one-man-army yourself into being Fort Knox.

➕ show 1 reply