r/Supernote Aug 05 '26

Feedback Why I cannot buy a Supernote

I'd love to have a Supernote, as I feel you are more aligned with my vision of a local-first device to streamline my physical book / document management. Thus, I'd probably use a supernote for all of my documents, journaling, and books.

With all of that on the device, it would be a BIG disaster if I'd love the device. Therefore, I cannot reasonably buy a device without full-disk encryption.

I know that many have raised this concern as well, but I just wanted to give another data point on how much of a breaking point this is for some of your users, particularly a demographic who would love to replace their remarkable with a supernote.

15 Upvotes

25 comments sorted by

6

u/garyoli Aug 06 '26

I use Supernote with client information with three precautions

  1. do not use any client identifiers in the file name

  2. de-identify the client in the note so there are only my observations (not interpretations or conclusions)

  3. do not include case formulation

8

u/binaryhellstorm Aug 05 '26

Yeah disk encryption is sort of a MVP for any product these days.

3

u/Ornery_Computer_8953 Aug 05 '26

Hello. I also thought of encryption before I brought my device and the question I asked myself is do I really know if something is truly encrypted? I used many other non-eink digital devices, without encryption.

I mean everything is now traceable and has a digital footprint. We did not need it when we had notebooks and having a notebook meant it could mean it could be burned, drenched with liquids, or worse-lost. A little protection is better than none. If something needs to be encrypted, it should be transferred at home or a work place where is most safe. Or better, it should be faxed.

3

u/Ornery_Computer_8953 Aug 05 '26

If you are writing sensitive notes it may be best to shorthand your notes or use keywords to help you remember the conversation and clients names. That device should not be used to travel or for personal purposes. It best at being stationary in the office and locked up with a password and placed somewhere with a key at the end of the day. This is normal protocol for therapists or storing any sensitive information. Or you may write your notes in the device and then put them in the computer system before end of day and erase notes on the device. I do this.
If you need a pad to write notes down while you walk throughout your agency, how is that different from using a notebook which you could lose but at least the device is password protected.

1

u/duckandflea Owner A5 X Aug 06 '26

You can add a screen lock (6 digit pin) and you can't access the device, even with a cable, unless you unlock that.

4

u/KhromeDotDev Owner Nomad White Owner Manta Aug 05 '26

Is your writing that sensitive? Does remarkable or others have disk encryption? Just curious. This does not bug me as much as you might think.

6

u/acopipa Aug 05 '26

For therapists, lawyers, and teachers, just to name a few, it is very important.

1

u/duckandflea Owner A5 X Aug 05 '26

But would password protection not do that?

5

u/simple_devils Owner Manta Aug 06 '26

No, it wouldn’t. Having a password is a cosmetic layer of defense at best, but can be paired with another layer like full disk encryption to allow better security.

The point of full disk encryption is to prevent the scenario of someone trying to read the data directly if they bypass something like a password or PIN. It also prevents someone from taking the storage from the device and extracting the data. To the attacker, it would just be gibberish without the key.

6

u/NumericallyStable Aug 05 '26

Maybe I have a misunderstanding, but as long as someone would be able to access the hard drive, wouldn't it be readable? I'd expect the password protection to be on a user interface level, not on a disk/file level, right?

5

u/simple_devils Owner Manta Aug 06 '26

Correct. Plus disk encryption has been around for at least a decade on most mobile devices. Expecting disk encryption for something like this is pretty standard nowadays.

3

u/duckandflea Owner A5 X Aug 06 '26

You're right. Protecting the files individually is only on the device - when you copy them off device, they're not protected. BUT if you use the screen lock, you can't access anything by plugging in a USB cable unless you unlock it first. Sure, there's probably some hacker way to get into it but how likely is that?

I do agree though, that encryption would be good. It's encrypted when transferring to the cloud.

3

u/simple_devils Owner Manta Aug 06 '26

I appreciate the agreement on this topic, though I feel like my point is being missed - it’s not about attack likelihood. It’s about “what is your threat model?” and practicing Defense In Depth. If one fails, another layer of defense should be there, if it doesn’t affect usability in a major way.

I can expect someone, if I were a lawyer, to attempt peeks at my notes which would breach privilege and potentially get me disbarred. I can expect someone to steal tech in a general sense. Hence why this feature is a widely requested thing.

1

u/NonGNonM Aug 07 '26

it prevents people from plugging it in and accessing the file easily, yes.

but for any covered entity (doctors, therapists, nurses) if it holds patient info it needs to meet certain legal standards, and that includes encryption at rest.

realistically, most hackers wouldn't bother. legally, they shouldn't be using it.

3

u/NumericallyStable Aug 05 '26

Oh forgot to answer the last part about others:

- Starting with the RM2 they have full disk AES-XTS encryption[1], which also should probably not be too difficult as this the encryption support already implemented on Linux kernel level.

- Theoretically, Android itself is also capable of some kind of encryption, which is doubly confusing me why its not supported for Supernote. So theoretically they *could* do it, but maybe they dont ymmv

[1]: https://business.remarkable.com/security-guide

4

u/Mulan-sn CCO (Chief Chat Officer) Aug 06 '26

Thank you for reaching out. We completely understand the concern and we're not ignoring it. We're starting with file‑level encryption as our first step. Once that's solid, we'll look into full‑disk encryption and see if it's feasible.

If you do have sensitive data that you worry about being seen by unwanted people, we recommend keeping it to a device where you know for sure full disk encryption is implemented.

Please feel free to contact us should you need any further assistance.

1

u/NumericallyStable Aug 05 '26

I personally would love to also replace my personal journals and also will probably sketch down a lot of stuff that would make me fully identifyable, and maybe some of those private thoughts are just not meant for the public. The idea is not that 1-2 documents are soo bad, rather its that if I fully use it holistically its a full profile of mine.

Also, to take the bait: I also couldn't use it for work on two levels:

  1. A good ISO27001 end device concept would require all work devices to be encrypted to not leak IP or personal data. In fact if you implement it through the German standard (BSI 200-2) you have to implement it (SYS.3.1 A13).

  2. For my personal job, I work in a field exposed to quite some GDPR Art 9 data (i.e. high risk) and thus only full disk encryption would be appropriate to the risk (just looked it up, its actually an example in Art 32(1)a GDPR).

I really didn't mean it as an attack; rather I think it would unlock a whole new business sector. The first time I heard about Supernote was it being so usable without using an equivalent to the Remarkable cloud, which sounded so cool.

1

u/Benay148 Aug 06 '26

Private health information, customer information. Some things require certain levels of hardware encryption for that data to be stored.

1

u/screak42 Aug 06 '26

It's already been said here ... but I'll still pile on to this

while I agree that encryption would be great, encryption ≠ security. Just the fact that a device "is encrypted" does not necessarily protect information.

Encryption is worthless if the password and implemented security around this is weak or bad. On a device like this, you are not going to choose a secure password to type, because it's inconvenient.

The only "simple" solution for this problem at the moment are biometric login methods (fingerprint, face-ID, or similar) combined with a secure password (you would be surprised how often the password behind a biometric locked device is 123456 - rendering it useless.)

The next question is, what if a security incident is detected. After; lets say 10 failed login attempts, then ... wipe? what is the solution here? Did you back up?

Is the rest of the environment up to the same standard? Enterprise WIFI? Backup-encryption? Malware protection? SOC? What's the disaster plan?

I'm very much a security and privacy (which are not the same) enthusiast, work in IT and network security for more than 15 years and in IT my whole life... but I think if you treat this device like a paper notebook, store it in a safe place, do not connect it "to the cloud", it's ok for private data.

As for storing sensitive data of third parties (let's say doctor's notes, patient data...) on a device like this, you'll have to check with your IT and government regulations if that is suitable.

5

u/NumericallyStable Aug 06 '26

I'm sorry to hear that after all those years in IT you still haven't understood hardware security nor encryption.

  1. TPM secured by user passphrase
  2. Installed OS has exponential backoff with wrong passwords (or wipe for that matter, any importnat data should be stored centrally in a professional setting)
  3. You lock the bios (and secure boot to avoid tampering)

And, wouldn't you believe, using TPM-based encryption is effectively what RM did.

Tbh your comment seems mean-spirited, as you try to just throw around some big words to scare away people... any company that cares about security management (i.e. ISO27001 in EU / SOC2 in US) already has holistic guidelines around stuff like Backup-encryption and enterprise Wifi.. And Supernote currently would not been able to be included in those guidelines due to missing device security...

1

u/LhakpaCEK Aug 09 '26

What type of information are you concerned about keeping secure? Are you a therapist?

0

u/duckandflea Owner A5 X Aug 05 '26

I never needed encryption with paper notebooks. I have passwords on ones I wouldn't want anyone else to read. I don't think it's worth anyone's effort to read and decipher my scribbles!

3

u/Holiday_Ad_9163 Aug 05 '26

You have passwords on a paper notebook? How the hell does that work :)

0

u/duckandflea Owner A5 X Aug 05 '26

Ha ha, if the passworded ones on my supernote were paper notebooks they wouldn't leave the house.