Remix.run Logo
▲ delichon 6 hours ago

I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

▲WithinReason 6 hours ago | parent | next [-]

If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.

▲rdevsrex 5 hours ago | parent | next [-]

Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

▲DaveSchmindel 5 hours ago | parent | next [-]

That's been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...

https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a...

▲rtkwe 4 hours ago | parent | next [-]

That case has the specific, very important, wrinkle that he provided a _destructive_ duress code, he could have continued to refuse to provide the unlock code just fine legally. It's the use of the duress code that is likely going to be getting him in trouble and that falls outside of the existing defined protections about being compelled to unlock safes/computers etc containing possible evidence against yourself.

We'll have to see how that case goes but ultimately the reason he's getting in trouble is only tangentially related to his phone being encrypted. It's more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.

▲LoganDark an hour ago | parent [-]

He didn't smash the phone to pieces, he gave LE a hammer and they smashed the phone to pieces. It's entirely LE's own fault this happened -- they shouldn't have been trying to get into that phone, and it's their own fault it went wrong.

Though I would expect courts to consider that he knew LE planned to enter the provided PIN, and that the duress PIN would then result in the phone being wiped, and therefore accuse him of doing the wiping anyway.

But I don't think it's this guy's fault at all. LE is the one who asked him under duress, he easily could've feared for his life, and he did no direct harm. It was self-defense at worst.

▲someothherguyy 33 minutes ago | parent [-]

> He didn't smash the phone to pieces, he gave LE a hammer and they smashed the phone to pieces. It's entirely LE's own fault this happened -- they shouldn't have been trying to get into that phone, and it's their own fault it went wrong.

Setting a booby trap to destroy evidence that then gets destroyed when that trap is triggered is the same as destroying evidence. This is common sense, but also see https://en.wikipedia.org/wiki/Principal_(criminal_law)

▲delichon 5 hours ago | parent | prev | next [-]

Yeah, if you use it as a way to destroy data that gives them a whole new and powerful attack vector. 18 U.S.C. § 2232 is very broad.

▲Razengan 3 hours ago | parent [-]

What's more infuriating than laws like that is that there's a class of people completely immune to those laws.

▲simiones 5 hours ago | parent | prev | next [-]

That's completely different. Pleading the 5th and not testifying is completely different from giving false testimony - which is never protected. Even in a trial, if you are asked under oath if you handled the body, you are allowed to say that you invoke your 5th amendment rights not to respond; but you are not allowed to say "no, I didn't" if in fact you did (you can later be accused of perjury in addition to your conviction).

▲ 3 hours ago | parent | prev [-]
[deleted]
▲glitchc 5 hours ago | parent | prev | next [-]

> The Fifth Amendment protects against self-incrimination.

You can still be held in custody for obstruction of justice:

https://www.findlaw.com/legalblogs/third-circuit/man-held-in...

It took four years before he could secure his release:

https://www.sophos.com/en-us/blog/suspect-who-refused-to-dec...

▲midas89 3 hours ago | parent | prev | next [-]

you have the guy sitting in jail waiting for the courts to decide if his grapheneOS wiping his computer after wrong unlock codes is him obstructing.

keep in mind that the "obstruction" charge can be and is abused as a catchall charge.

▲MC995 3 hours ago | parent [-]

> courts to decide if his grapheneOS wiping his computer after wrong unlock codes is him obstructing

He didn't provide an incorrect code, or no code at all, he provided a duress code intended to destroy the device. There's a huge legal difference.

▲rdtsc 4 hours ago | parent | prev | next [-]

Can't they just hand it to you say "you enter your passphrase, but don't divulge it to us and then hand us the phone". In other words hinging the passphrase divulging to the 5th can backfire in that respect. It like saying we have a search warrant, you open the safe for us, it's fine if you keep the combination to yourself, we just need to get inside.

▲nater5000 3 hours ago | parent | next [-]

No, that's pretty absurd. It's not specifically about the act of speaking. It's the act of incriminating yourself.

But that's all beyond the point, anyways. If they did hand you your phone and said, "enter your passphrase," you can just say, "I don't remember it." They can throw a fit and put more heat on you in various ways, but until they resort to torturing you or they develop mind-reading technology, there's not much they can do at that point until the case reaches a judge.

That's not to say "I don't remember" is a sound, blanket defense. But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.

▲rdtsc 2 hours ago | parent [-]

If the search warrant and seizure wasn't a thing I'd agree with you. But I can easily see opening a phone interpreted not that differently than opening a safe or your reinforced front door.

> But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.

What happens if during serving a search warrant the door is impossible to open or they find a super reinforced safe. Owner can even say "I don't remember the combination"?

▲kadoban 2 hours ago | parent | prev [-]

The act of unlocking it can incriminate you. It's ~proof that you have control of the device beyond what they already knew.

▲BeetleB an hour ago | parent | prev | next [-]

He said "jail", not "prison".

There's a difference.

▲throw0101c 36 minutes ago | parent | prev | next [-]

> Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

SCOTUS: Hold my beer…

:)

▲nikanj 3 hours ago | parent | prev | next [-]

The fifth amendment doesn't do jack shit if they haul you away. After a few years of trials and appeals you might regain your freedom.

▲wslh 2 hours ago | parent | prev | next [-]

I think that the issue is that the law enforcement personnel could make you pass a bad time even if it's covered by the Fifth Amendment. The enforcement could be later than the arbitrary decision.

▲izacus 5 hours ago | parent | prev [-]

Self-incrimination yes, but not for cases when the person compelled has evidence to incriminate another process in a case.

▲roncesvalles 2 hours ago | parent [-]

That being said, overlap protects you still. So if answering a question about another person might incriminate you, you don't have to answer.

▲spl757 2 hours ago | parent | prev | next [-]

Precisely, unless there is plausible deniability that a blob of data is indeed an encrypted file they can just hold you in jail until you comply. There are encryption schemes that provide plausible deniability, but implementing would probably not be trivial.

▲ChrisMarshallNY 6 hours ago | parent | prev | next [-]

Classic $5 wrench.

Having thugs on speed dial opens a lot of doors.

▲gonzalohm 5 hours ago | parent | prev [-]

So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not

▲wahern 5 hours ago | parent [-]

They can't know, they infer. AFAIU, normally they just detain you at the airport and harass you to try to break you. To jail you they're technically supposed to be confident enough about you knowing the password to be able to charge you with a crime (presumably something like obstruction, possibly specific to immigration law, otherwise right against self-incrimination might prevent a conviction on failure to disclose alone), or have other evidence of some other crime. Then you end up in the legal system, where courts handle due process and a judge, preliminarily, and then a judge or jury decides if you knew the password.

Note that the recent high-profile case of a man being jailed involved him refusing to decrypt, rather than claiming he didn't know. He was deliberately trying to test the law regarding the permissible scope of inspection of digital data, to force the matter into the courts so the issues could be litigated in a controlled context untainted by other potential crimes; being arrested and charged was part of his plan.

▲Cider9986 5 hours ago | parent | prev | next [-]

It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513

If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

[1] https://www.privacyguides.org/en/cloud/

▲0x262d 3 hours ago | parent [-]

Yeah, getting all your sensitive stuff off your phone onto a secure cloud service seems like the obvious approach here right? They can still escalate what they try to coerce you to do, but they don't have physical access to your data just by taking your phone, and you can also leave the phone with them and only lose the device if needed. In my likely scenario - innocent traveler, they aren't looking for anything specific, but I still don't want them to look through my files and photos just because I happen to travel internationally - that seems like it puts it out of reach (and out of obvious view) for now.

▲BeetleB an hour ago | parent | prev | next [-]

> I keep all of my most sensitive personal documents on my phone

Why...?

If I had anything I didn't want the authorities to get, I'd remove it from my phone before travel (e.g. put in cloud, etc).

▲jstanley 6 hours ago | parent | prev | next [-]

It seems foolhardy to carry your life savings around everywhere, encrypted or not.

If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

▲ryandrake 4 hours ago | parent | next [-]

Exactly. Don't keep your life on your phone. We shouldn't have to take these precautions but unfortunately we do.

▲Razengan 3 hours ago | parent [-]

What if everyone at the airport or border stood together and refused to comply?

▲devin 5 hours ago | parent | prev [-]

or a separate hard drive in a fireproof safe or something.

▲fragmede 2 hours ago | parent | prev | next [-]

Oh my god, get out of crypto. Put your money into a bank instead of trying to one-man-army yourself into being Fort Knox.

▲tenacious_tuna 2 hours ago | parent [-]

Cryptomator appears to be a file encryption tool, not a cryptocoin anything. What're you reacting to?

▲fragmede 2 hours ago | parent [-]

I made the leap based on

> could cost me my home and life savings

but it's entirely fair to point out that Cryptomator itself is not a crypto wallet. I just know too many people irl that have lost thousands of dollars because they lost crypto private keys.

▲pieter_mj 6 hours ago | parent | prev | next [-]

If you travel abroad you must unlock. No 4th amendment for you.

▲eli 3 hours ago | parent | next [-]

That’s not the full story and not really correct.

https://www.aclu.org/news/privacy-technology/can-border-agen...

▲skinfaxi 6 hours ago | parent | prev | next [-]

You can decline but then they can seize is that right?

▲alistairSH 4 hours ago | parent | next [-]

In the US, that is generally true. They cannot prevent entry (by citizens), but can keep the phone for a period.

▲mmooss 5 hours ago | parent | prev [-]

It would depend on the country.

▲jstanley 6 hours ago | parent | prev [-]

This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.

▲bryceacc 5 hours ago | parent | next [-]

https://arstechnica.com/tech-policy/2026/09/immigration-advo...

>CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.

would suck to be one of those 55 thousand people. I've never been bitten by a shark but I sure care about people that have?

▲Havoc 4 hours ago | parent | prev | next [-]

Dismissing something as false just because you haven’t personally experienced it is quite something

▲jstanley 3 hours ago | parent [-]

"If you travel abroad you must unlock" is hardly the central experience. It is FUD.

▲Havoc 3 hours ago | parent [-]

No, it's just incredibly bad reasoning. I've not been in a car crash yet, but I don't conclude that therefore talk of road safety is FUD.

▲serf 5 hours ago | parent | prev | next [-]

I get asked to unlock my dev laptop every single time I go from the US to Montreal. The TSA person sits there and waits for my WM to boot before waving me past.

It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.

▲dylan604 5 hours ago | parent | next [-]

That's been my experience as well. I've visited Sydney twice, and both times I've been asked to light up my devices. Granted, I was on work trips requiring three separate laptops which does probably look suspect, but once they were booted they did not request to browse anything and were satisfied to see them working.

▲0cf8612b2e1e 4 hours ago | parent [-]

All the more reason to dual boot into a decoy OS. Does not stop a targeted investigation, but lets you pass a cursory examination where some thug might want to rifle through your data.

Edit: now I am gleefully thinking about how I would craft my decoy desktop persona. What gives me the most effective non interesting profile.

▲folmar 2 hours ago | parent | prev | next [-]

In EU normally BIOS startup screen is the point at which they wave it as ok.

▲matheusmoreira 3 hours ago | parent | prev [-]

Now I'm wondering what exactly they're looking for... What else could those devices have been?

▲wildzzz an hour ago | parent | next [-]

They are looking to see if you've gutted a laptop and filled it with explosives or drugs. Although tbh, a computer that can launch a desktop doesn't need much physical space and the battery just has to last long enough for a cursory glance.

▲0cf8612b2e1e 2 hours ago | parent | prev [-]

Maybe the agent gets lucky and you have a folder full of nudes on the desktop.

▲dana-s 6 hours ago | parent | prev | next [-]

I believe the parent comment is talking about leaving US, coming back to the US and then having US's border patrol do so. If that is also what you understood, are you an activist or anyone whom would be of interest to the feds to be asked so? Otherwise saying "I've never been asked" sounds like a common thing for most people.

▲jstanley 5 hours ago | parent | next [-]

Reading this kind of stuff online made me afraid of international travel for many years. When I finally did it literally nothing happened to me.

Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.

▲simiones 4 hours ago | parent | next [-]

It's important to separate what can happen from what will happen.

The majority of people walking in the worse neighborhoods of LA or Chicago never have a single crime happen to them. But that doesn't mean that it's safe to go in a bad neighborhood - and it really doesn't mean it's safe to go there wearing designer clothing, gold watches, diamond rings and wearing your Apple VR device.

The same is true for travel. It's perfectly safe for the vast majority - but it's very important to be aware what may make you a target and what can happen to you if you are. Tens of millions of people visit the UK or China every year with no incident. But if you're a public active supporter of Palestine Action, or an active demonstrator against the CCCP respectively, be aware that you personally face a real risk from this travel, and your devices are actually very likely to be searched at those borders. Vice versa though (anti-CCCP activist traveling to UK, PA activist traveling to China) is perfectly safe, though.

▲Liftyee 4 hours ago | parent [-]

Last time I checked, the Soviet Union was dissolved.

(CCCP = Union of Soviet Socialist Republics...)

▲bryceacc 2 hours ago | parent | prev | next [-]

this sounds exactly like the chilling effect and fear the US government wants to instill on people these days. They want us to know big brother is watching, they have the power to stop and search you, and you can't do anything about it

▲UpsideDownRide 5 hours ago | parent | prev [-]

It's even worse for your mental to never think about It.

▲jimt1234 5 hours ago | parent | prev [-]

What's the BFD? I have nothing to hide! (I hear that shit all the time. So annoying.)

▲ 5 hours ago | parent | prev | next [-]
[deleted]
▲ 6 hours ago | parent | prev | next [-]
[deleted]
▲FireBeyond 3 hours ago | parent | prev [-]

TSA thought it odd that I had two MBPs (work and personal) and an iPad in my carry on, and asked me to power up all three.

▲mmooss 5 hours ago | parent | prev [-]

It seems to me you are taking a big risk. Some considerations:

> Cryptomator

Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.

And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.

Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.

Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.

> or legal access

Ask a lawyer.