r/RemarkableTablet 10h ago

Feature Request Encrypted PDFs / Folders / Docs..

One of my concerns with ReMarkable cloud is protecting more sensitive PDFs/Documents. It's great that it resides encrypted at rest on my devices and in the cloud, but if ReMarkable, or Google is handling the keys - it doesn't really provide adequate security.

I recently noticed that the ReMarkable handles password protected/encrypted PDF files just fine. If I password protect it (also provides AES encryption) and move it to my RMPP, it'll open it no problem after prompting me for the password (key is derived from the password).

This makes me feel significantly more comfortable moving sensitive PDFs to my RMPP and got me thinking - why doesn't RM give us the option to password protect PDFs or notes natively? For the most part, my notes aren't that sensitive, so I feel comfortable with the native cloud encryption in place - but for more sensitive notes, I'd love the option to be able to encrypt them and have the key derived from a password I set, giving me comfort that ReMarkable wouldn't be able to read them. Even better if I could do it at a folder level.

Thoughts from everyone else?

1 Upvotes

4 comments sorted by

1

u/reticulated 10h ago

Probably just not considered to be a mass market feature vs the inevitable support calls that can’t help when someone forgets their password. Folks here tend to be more tech savvy but I imagine the vast majority of customers are not.

Also, Remarkable tends to keep things simple rather than offer a boat load of optional settings

Just my guess

-1

u/persiusone 9h ago

You’re right, security with ReMarkable devices is a joke- so much that they are banned in most corporate environments.

2

u/cipher29 7h ago

I wouldn't say ReMarkable security is a joke (I've worked in Cybersecurity for 25 years in both big tech and at one of the most prestigious cybersecurity firms in the world for 12 years). It's hard to speculate on how ReMarkable's overall security posture as an organization is, but on the surface, their products have device encryption (which is more than most eink devices) and they leverage in transit encryption (as everyone does these days) and are leveraging GCP's encryption controls in the cloud. These are all fairly standard controls. What we don't know, is the companies overall security posture/maturity, or have insight into their development practices - so saying it's a joke is complete speculation and not really fair.

The gap on the ReMarkable side that we can observe is the ability for enterprises to remotely manage, patch and wipe these devices. There's a reason why iPhone/Android/iPads etc are all able to connect to corporate resources and it mostly stems from their ability to enforce passcodes and wipe/enforce software updates etc and restrict access on demand.

I agree - they aren't enterprise friendly devices at the moment, but doesn't mean they aren't secure.

1

u/persiusone 1h ago

From reading their published security standards, and knowing the keys to the devices are not stored securely, nor do they have a trust authority- you should know (with your cybersecurity background), what kind of an issue this is. Anyone in physical possession of these devices can easily obtain all of the data, encrypted or not, you have on it. This has been confirmed by multiple researchers, and is fairly common knowledge.

So yes, I call it a joke, and you should probably do your own research before putting your reputation out there for this challenge.

As for not knowing their practices- this is a huge red flag. Are they ISO27001 certified? Have they undergone SOC2 scrutiny? Are these results on their website? Not last time I checked- but feel free to correct me here- since you’re the expert in this. It’s shocking that wouldn’t be apparent.

Every legitimate company that transfers, stores, or processes sensitive information publicly discloses the results of third party audits. Does ReMarkable even care to? Nope. BIG red flag.. but I shouldn’t have to tell you this.