An encrypted disk image stays unlocked on a Mac: make it lock itself
· 6 min read
An encrypted disk image is locked only while it is ejected. Once you type the password it stays open through sleep, the screen saver and the screen lock, until you eject it, log out or restart. macOS has no setting that changes this, so the choices are a faster way to eject, a habit of logging out, or a tool that locks again by itself.
If you have not made an image yet, Encrypt a folder on a Mac with Disk Utility walks through it.
Why it stays open
Opening an encrypted image mounts it as a disk. macOS reads the password once, keeps the key in memory and decrypts files as they are read. From then on the system treats the image like an external drive you plugged in: it stays connected until something disconnects it. Sleep does not. Closing the lid does not. Locking the screen does not.
That is a sensible design for a drive and a poor one for a secret. The password on the image protects it from someone who has the file. Once it is mounted, the only thing protecting it is your login session. Anyone who can use your unlocked Mac, or who knows your login password, can open the mounted volume in Finder without being asked for anything. Keep files private from someone who knows your Mac password is about exactly that gap.
The Remember password in my keychain checkbox on the password prompt widens it further. With that ticked, even an ejected image opens with a double-click while you are logged in.
See what is open right now
Look in the Finder sidebar under Locations. A mounted image appears there with an eject button beside it. For a complete list, including images whose windows you closed hours ago, use Terminal:
hdiutil info
Each attached image is listed with the path of its file and, on a line ending in /Volumes/ and a name, the place it is mounted. If the list is longer than you expected, you have found the problem.
While an image is mounted, Spotlight can also find what is inside it. Keep private files out of Spotlight search covers that side.
Eject it by hand
Any of these locks the image again:
- Click the eject button beside it in the Finder sidebar.
- Select it on the desktop or in the sidebar and press Command-E.
- In Terminal, run
hdiutil detach "/Volumes/Private"with your own volume’s name.
If macOS says the disk was not ejected because a program is using it, a file from the image is still open somewhere. Close the document or quit the app, then try again. To find out what is holding it:
lsof | grep "/Volumes/Private"
The first column names the process. Finder offers a Force Eject button, and hdiutil detach -force does the same from Terminal. Either can lose unsaved changes in whatever was open, so use them only when you are sure nothing is being edited.
Make ejecting a single key
The Shortcuts app can turn that Terminal command into a keystroke and a menu bar item.
- Open Shortcuts, choose Settings, Advanced, and turn on Allow Running Scripts.
- Create a new shortcut and add the Run Shell Script action.
- Enter
hdiutil detach "/Volumes/Private", using the name your image shows in Finder when it is open. For more than one image, put each on its own line. - Open the shortcut’s details (the i button), tick Pin in Menu Bar, and click Add Keyboard Shortcut to assign a key combination.
Now one keystroke locks everything on the list. The command refuses instead of forcing when a file is still open, and that is the behavior you want: an error message, not a damaged document.
What macOS can do automatically
There is no checkbox in Disk Utility or System Settings for ejecting an image when the screen locks. With built-in behavior alone, you have three options:
- Log out instead of locking. Logging out ejects every disk image. Use the Apple menu, Log Out, or Shift-Command-Q. It costs you your open windows, which is why few people keep it up.
- Shut down at the end of the day. Same effect. The image needs its password after the next startup, unless you saved it in the keychain.
- Tighten the screen lock, so the session at least is not left open: Require a password immediately after a Mac sleeps. This ejects nothing. It only shortens the time the Mac sits unlocked with the image open behind it.
That is the Apple route: free, and dependent on you remembering every time.
A lock that closes itself
Hushbox exists for this gap. You right-click a file or folder in Finder and choose Lock with Hushbox, and what it creates is the same kind of AES-256 encrypted disk image Disk Utility makes. The difference is what happens after you open it:
- It locks again by itself when the screen locks, when the Mac sleeps, or after 5, 15, 30 or 60 minutes idle, whichever you pick.
- Lock Now is in the menu bar icon and in the right-click menu.
- If an app has unsaved work inside, Hushbox asks first. It never force-closes anything.
- Unlocking takes Touch ID or the Hushbox password, so locking often does not cost you much typing.
While an item is unlocked, its contents open in a private encrypted space that Spotlight never indexes.
To bring an existing image across, open it, copy the contents into an ordinary folder, lock that folder with Hushbox, confirm it opens, and then delete the old image.
Know the limits before you rely on it. The name of a locked item still shows in Finder; Hushbox hides contents, not names. Each locked item uses about 33 MB of extra space, so lock a folder instead of many separate files. There is no password recovery. Copies made before you locked something, such as Time Machine backups, are not changed. And it is not a replacement for FileVault, which protects the whole disk when the Mac is off.
It runs on macOS 13 or later and costs $9 once for two Macs after 24 free hours. Unlocking stays free after the trial, so your files are never held hostage. Because the format is Apple’s, a locked item renamed to end in .sparsebundle opens in macOS with the password and without Hushbox.
Questions
Does closing the image’s Finder window lock it?
No. The window is only a view. The volume is still mounted, and it is still listed in the sidebar and in hdiutil info.
Is a mounted image still encrypted on the disk? Yes. The file stays encrypted the whole time, and macOS decrypts in memory as files are read. What changes when you mount it is who can ask for those files: anyone using your login session.
Should I tick Remember password in my keychain? Not for anything you are keeping from people who use your Mac. It swaps the image’s own password for your login session, which is the weaker of the two in this situation.