21 ms·
Show HN: Passbox – Give access to your data only after you're dead
- mrdazm 7y agoHi all, original poster here. I created Passbox after buying my first motorcycle and thinking that if anything happened to me on it I'd like for my devices/accounts/photos and such to not be walled off forever. I'd love to hear your thoughts on the app, approach and any feedback in general! Thanks!
- cloudking 7y agoCool idea but your pricing structure seems high. You should consider a one-time lifetime fee, it aligns with your business model.
- mrdazm 7y agoThank you for checking it out and for your feedback! An initial thought I had was to look at it as being akin to an insurance policy of sorts and that's what sort of led me down the recurring revenue path. Definitely will consider one-time fees for the future! Thanks again!
- jaysh 7y agoThose types of insurance polices payout on an event, so a monthly premium makes sense as nobody can afford to pay it upfront. I'd say your service is the internet version of someone creating their will, and leaving it with a friend or family member, which are all one-off costs.
- mrdazm 7y agoDefinitely. It'll be interesting for me to balance my recurring costs while matching with consumer ideals. To be continued...
- giancarlostoro 7y agoI would suggest a mix of both. The issue with lifetime fees is eventually someone will start to cost you money. I had a friend who sold some lifetime subscriptions to a VPN service, it's just not entirely feasible. On the other hand, this is what I use BitWarden for, so my wife has access to important accounts and vice-versa. BitWarden does provide free shared passwords for 2 users.
- jaysh 7y agoI don't think that's a fair comparison. VPN services have significant ongoing technical costs: bandwidth, servers, labour (upgrades, support, security, incident resolution) etc which you must pay monthly but are never recovered when charging a one-off price. If you're finding that the users you're sharing your passbox with are requesting your passwords every day, that's probably signal enough to remove them so they automatically use the service less. I'd expect the lifetime marginal cost of an additional user here to be a very small percentage of the revenue for that client.
- mrdazm 7y ago> If you're finding that the users you're sharing your passbox with are requesting your passwords every day This is an interesting scenario I've thought about. Thanks for sharing! It could be the case that once the "death trigger" happens there's a countdown for the requesting user to download the data and then I (Passbox) locks everything down or deletes the original data or something. To be determined...
- fennecfoxen 7y agoGiven cloud pricing structures and some basic actuarial tables, it shouldn't be too hard to put a reasonable limit on your resource costs. The real question is whether the cloud will last, or if you'll need to migrate everything off of AWS and onto something incompatible some time in the next 40 years.
- mrdazm 7y agoAnd with lifetime pricing I don't like the idea of just keeping that money if someone churns. Maybe I'm just not enough of a hardened business person haha. In your case with Bitwarden you're sharing access to your credentials and such with your wife right now, today, right? With Passbox I'm looking to defer that access for data that makes sense. In my case I'm currently single and no one else has access to my iPhone but if I passed then maybe my mom or best friend should have that - as a hypothetical.
- epanchin 7y agoI would be nervous with the one time fee the developer would give up on maintenance before I kicked the bucket. A monthly fee seems reassuring.
- exhilaration 7y agoBut what happens when your credit cards are cancelled after you die? That's a Catch-22 right there.
- mrdazm 7y agoI've thought about this. Not a final decision per se (and I haven't coded anything for the scenario) but I imagine I'd maybe have the third party accessing the data pay (up to a cap) to reconcile the account to make it "current" before giving them access - something like that. It avoids folks signing up, canceling the card and then riding for free.
- dageshi 7y agoMy 2cents, ditch the monthly plan, price it yearly instead. Monthly plans are for things you will actually use day to day like netflix, yearly are more like "insurance" products which is what this is, I think displaying the yearly option will be a better value proposition for people looking at it. Second, I don't know what payment you're using, but seriously consider paypal if you're not already, because I'm pretty sure you can setup yearly recurring "subscriptions" on paypal and people are much more likely to keep their paypal funding sources up to date. So you're not going to have to nag them to update credit card info every couple years and they're less likely to have occasion to think "do I really want to pay for this", it'll just be pay automatically.
- giancarlostoro 7y agoThis also moves the point of cancellation to once a year and not monthly, or one month after.
- 7y ago
- bristleworm 7y agoHi. While I like the general idea, I do have mixed feelings storing so much valuable data online, on servers of a company I don't know, that operates in the US.
- mrdazm 7y agoThanks for checking it out! Do your feelings change at all with knowing that the data is completely encrypted at rest and inaccessible by me/the company even though I have access to the database?
- bshep 7y agoWhat prevents a 3letter agency from instructing you to: 1- give access to one of you trusted contact accounts 2- disable sending notifications to the account holders email 3- 3letter agency clicks on request data 4- data gets released ( as it will not get denied if the account holder does not receive a notification)
- mrdazm 7y agoThanks for this! 1 - Even with access to the trusted contact's account a passphrase/access key (specific to the main account and not stored by the service) is required 2 - Interesting scenario but still requires the above-mentioned access key 3 - Same as above two points even after being approved 4 - Won't get released without the key
- luckylion 7y ago> 1 - Even with access to the trusted contact's account a passphrase/access key (specific to the main account and not stored by the service) is required I understand that your service is encrypting the data before saving it (vs that happening completely on the client and only encrypted data being sent to you), so there's nothing stopping you from logging it to a plain text file (even accidentally). Given that these passwords will likely hold the keys to that person's identity, that's a huge amount of trust that they need to have in you, your technical abilities and future decisions.
- snowwrestler 7y agoHow do I know you're still going to be in business when I die?
- mrdazm 7y agoIf this actually goes anywhere I personally wouldn't shut the company down silently. I'd have contact information for everyone involved to help them prep for its sunsetting.
- madamelic 7y agoWhat happens if you die in a server-related explosion? That's a pretty easy way to shut down this service with no notice. Absurdist, sure. But that is the stakes with this kind of service.
- mpnordland 7y agoYour feature list for Freemium includes both "Fixed 1-Day Access Wait Period" and "Set Your Own Access Wait Period."
- mrdazm 7y agoI have _no_ idea what you're talking about. :) (Read: Thanks a ton!)
- antjanus 7y agoHey! One of my best friends died in a motorcycle accident -- he was a developer as well (got me in the field!). After his passing, no one knew how to get on his server and/or his domain registrar's account so as a result, someone else snatched up his personal site as soon as it expired, and pretended to be him for several years. I really love hearing about projects like yours cause I'd definitely want to avoid stuff like that!
- mrdazm 7y agoWow. This hits way too close to home. Thanks for sharing!
- deleted 7y ago[deleted]
- MrLeap 7y agoInteresting! This was kind of my software engineering II project back in college a decade ago. I wrote it in PHP. You configured all sorts of different actions that would occur if you failed to check in every once in a while (there were lots of ways to kick the deadman switch down the road. A simple phone app, you could text message a number with anything, you could send an email..) The idea was that you could configure "I loved you and never told you!" emails to out, cancel your electricity / gas, ask people to return your videotapes, send your top secret dossier to journalists, and give access to sekret treasure maps if you get eaten by a bear while on a hike. I never had the moxy to make it public, but I always liked the idea. I wish you the best of luck!
- mrdazm 7y agoThank you so much!! The version you built (dead man's switch + triggered workflows) is what I envision for a phase 2 if this goes anywhere. :)
- Dolores12 7y agoWouldn't it be nice to leave 60$/year to those you really care instead?
- chacha2 7y ago$60 is a lot for something a notepad in your desk could achieve. Never mind any additional security risks caused by this.
- yellowsir 7y agoi rather die, then giving a 3.american company my PWs.
- mrdazm 7y agoYou'd really be giving the company garbled (read: encrypted) data and allowing folks you care about access to your actual data/passwords/notes/whatever.
- deleted 7y ago[deleted]
- latchkey 7y agoI use https://www.deadmansswitch.net/ https://www.deadmansswitch.net/ Saved a PGP encrypted message to some friends. One time fee of $20, but the free tier is more than enough. Super simple UX. I click a link in an email once a month.
- bronco21016 7y agoI’ve given a lot of thought to this problem lately after becoming a parent. However, I just can’t picture trusting this to a third party. Ideally I’d store my master password to my password manager and give instructions on what accounts exist and what to do with them. By storing this on someone else’s server I’m at risk of that data being leaked which is effectively the ‘keys to the kingdom’. You can talk about encryption all you want but without knowing what’s actually happening with that extremely sensitive data behind the scenes I cannot trust your product. Perhaps a Bitwarden style model where the source is provided could be a solution? Because Bitwarden is open source, self-host able, and audited I can have some degree of comfort that my data is actually encrypted client side and stored safely. Speaking of the problem space, what non-tech techniques do people use for this scenario? The best I’ve been able to come up with is storing the information in two safes and leaving instructions on how to open the safe in a will or with trusted persons. Other thoughts?
- edoo 7y agoI bet someone makes a product with this someday https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing. You could in theory have a digital safe that you yourself can open with one key, and a quorum set of 2 keys that require both. You distribute 1/2 combination keys to your kids and keep one yourself. When you die your 1/2 key is passed to the kids who can now open the data. The keys themselves are useless without the other keys so anyone in the chain of custody of the key until it reaches your kids wouldn't be able to open the data. No one would have to have your singular key.
- troymc 7y agoThis service (Passbox) seems to be equivalent to LastPass's "Emergency Access" feature. See: https://support.logmeininc.com/lastpass/help/set-up-and-manage-emergency-access-lp030013 https://support.logmeininc.com/lastpass/help/set-up-and-mana...
- mrdazm 7y agoDefinitely but with more of a focus on the assigning/sharing of data primarily than being a pw manager.
- ropiwqefjnpoa 7y agoLastPass is cheaper too. Or if you're really cheap, leave your lastpass login written down somewhere where friends and family will find it.
- mrdazm 7y agoThanks for this. LP is cheaper depending on how many users you have. My current model allows for unlimited trusted users (people who can request access to your account) for the same price. LP charges per user.
- wheelerwj 7y agoThere's another on, key2lyf.com which is really similar. I love these kind of ideas.
- mrdazm 7y agoThanks for the head's up!
- chadash 7y agoA few comments: - I think the pricing structure is way too high. $60/year is quite a bit for what you are offering. At that price, I would rather rent a safety deposit box with a bank and just tell my friends and family about it. That way, I can store passwords as well as physical valuables there. - This seems a lot less useful than Lastpass's Emergency Access feature. Once i'm trusting a third party with my secrets, I might as well keep it to just one third party. Again, if the service was cheap enough, then maybe I wouldn't care, but $60/year is a lot. - It also seems like a hassle to update my passwords in passbox every time I change them. I'm going to forget. I need it to sync automatically.
- bwanab 7y agoAre you sure you want to keep valuables in a safe deposit box? https://www.nytimes.com/2019/07/19/business/safe-deposit-box-theft.html https://www.nytimes.com/2019/07/19/business/safe-deposit-box...
- stevekemp 7y agoIt is actually really hard to rent a safe-deposit box nowadays, because banks just don't offer them.
- mrdazm 7y agoThanks for your reply! I’m not tied to pricing at all and had to start somewhere. There’s been pretty good discussion on it throughout this post. I’ll consider everything while also taking into account this being the HN crowd. I personally don’t think an actual safety deposit box compares both in terms of ease of updating its contents for digital-related items (which you also mention about Passbox in your last point) and for modifying access to it - physical key distribution and revocation. How is it less useful than emergency access (assuming it’s not just the price which is a work in progress)? Also, I’ve built it to allow for you to segment who can get what so there’s the idea that you can have multiple trusted parties getting access to varying groups of data (or all of them equally). I’m with you in the updating aspect. Currently one could update with csv exports but it’s not the most ideal scenario. I’ve got thoughts on this but nothing ready for public discussion as yet. Thank you again for checking it out and commenting!
- kemiller2002 7y agoSerious question. Why wouldn't I just use a safety deposit box? Outside of the convenience of being electronic what benefit does this add over a physical storage space? The deposit box can store non-electronic stuff as well. When I die, I can pass the key over to the executor and that person can go through the contents etc.
- mrdazm 7y agoTo me I think that'd definitely work with static content/data and of course physical items. Things like passwords, accounts, devices and any special notes you may want to leave can change pretty often and presumably could become a chore to replace in the box and get neglected. It could also be a hassle handling physical keys and also re-assigning who gets what. The barrier to having multiple and also changing accessors goes down. Overall I'm not knocking the deposit box approach but it could be a little more work to maintain.
- ken 7y ago3 months ago: https://news.ycombinator.com/item?id=20545276 https://news.ycombinator.com/item?id=20545276 TLDR: it's not unheard of for banks to be downright incompetent at maintaining safety deposit boxes.
- option_greek 7y agoI thought about doing this several times but backed off because of dark connotations with death :)
- mrdazm 7y agoIt took me a while to even mention death in my copy but I know I have to embrace it - it's part of life!
- teuobk 7y agoFree alternative: use one of several tools that implement Shamir's Secret Sharing Scheme to split your master password into chunks. You can create a bunch of chunks and require that at least a certain subset of them be used to recover the password. For example, you could encode your password into 10 chunks and require that at least 5 chunks be presented together to recover the secret. Any 5 chunks of the 10 (in this example) could be used, but it is mathematically impossible to recover the secret with just 4 or fewer of the chunks (in this example). Thus, you could spread those 10 chunks among 10 trusted friends, the idea being that they would recombine the chunks only in the event of your death. Moreover, if you are not yet dead, at least five of your trusted friends (again, in this example) would need to betray you for your secret to be stolen.
- mrdazm 7y agoWhat are some such tools that you know about/recommend? I've also considered this for Passbox but needed to start simply.
- npalmer 7y agoTake a look at Hashicorp's Vault. https://www.vaultproject.io/docs/concepts/seal.html https://www.vaultproject.io/docs/concepts/seal.html
- peterwwillis 7y agoNot the same, but you can use two-man crypto verification to make sure a file was signed/encrypted by multiple parties. Example: https://github.com/psypete/public-bin/blob/public-bin/src/security/twoman.sh https://github.com/psypete/public-bin/blob/public-bin/src/se...
- achikin 7y agoWhy not print all that data out and give it to someone you trust or keep it in a deposit box which can be legally passed to your family?
- mrdazm 7y agoThanks for this. In my opinion that's not ideal because: 1. They'd have access right then and there 2. You could use a traditional password manager for that 3. Data changes could become more of a hassle to keep up-to-date
- bobbonew 7y agoI’m surprised there wasn’t a lifetime plan for $5.99. The cost to store that amount of minimal data is moot. I would never pay monthly for something like this - but would likely jump in a second for my aforementioned plan. Good idea thinking out of the box with your SaaS. Good luck!
- mrdazm 7y agoThanks for your feedback and compliment! As you can imagine I had to pick an approach and run with it. Nothing’s set in stone and I’m considering the exceptional feedback throughout to see what changes I should make that are mutually beneficial. Taking pricing off the table would you be game to give the app a test drive and email me your feedback/thoughts? Thanks again!
- beshrkayali 7y agoAsking users to trust a random web service with their most sensitive data almost feels like a prank.
- mrdazm 7y agoI'm with you. That's one of the big challenges I (and anyone in the space, I presume) would have from outset. On the bright side Passbox would only be random until it's not. The right news article, partnership or some other form of validation would inspire trust. It's not there yet but any company has to start somewhere and build up.
- beshrkayali 7y agoMaybe. "random" wasn't intended to be the focus of my comment. But even if, I can't see how something like this is feasible. Even with the best of intentions, services get hacked and they break. A tiny mistake (maybe some extra logging, now or down the line) could expose user's data. All services dealing with personal data claim being secure, until users receive that dreaded "we're sorry" email. Maybe if you allow uploading files (that would be gpg encrypted by users, locally) with some mechanism to have their keys physically sent to their relatives in a way that you don't store it or even have access to it, it'd be something worth paying for. But at this point, one can just get a safety deposit box, and they can give their loved ones the encrypted file(s) even before death.
- ken 7y agoYou should line up the free and paid features, perhaps in a table. I can't glance at a list of 8 items and a list of 10 items and distinguish what changed between them, so I'm not sure what I'd be paying for.
- mrdazm 7y agoThanks for this comment!
- kylekelly 7y agoMy solution is to doubly encrypt a 7zip file with 2 separate passwords and send each password to a different individual so that they need to cooperate in order to access the information. I wrote about it a while ago on my blog here: https://kylekelly.com/posts/share-your-passwords/ https://kylekelly.com/posts/share-your-passwords/ I'm wondering if I missed an obvious security issue with this solution?
- gjs278 7y agothey cooperate and steal from you
- ken 7y agoThe "How does Passbox work?" isn't clear to me. Is it encrypted at rest? Who has the password (or passwords), and is it just one secret key to unlock everything? Do my Trusted friends have to remember how to access Passbox, and a Passbox password? Am I notified if they do? How many of them do I need to select, and what if they die before I do, or move out of my life, or otherwise cease to be Trusted? This all feels like it's trying to apply the web-SAAS model to a domain where it really doesn't fit. I'd rather have a simple system where I could take any data, easily encrypt it on the client-side, and put it somewhere that's going to stay around for a long time (S3? thumb drive?). Then I give my lawyer the password and instructions on how to use it, on a sheet of paper. At any point, I can upload new data, replacing the old data. Digital security isn't as important because it's always encrypted before it leaves my desk. I don't need to maintain Trusted Friends because the only person with the password is my lawyer, who keeps it with my will. Dealing with my possessions after my death is a solved problem. It's possible to simplify parts of it, but we shouldn't try to replace it entirely with another model that discards the good parts of what we have.
- timharding 7y agoThis is more or less what my lawyer suggested when I set up my will with her. Apparently very few people have ever asked her about this. I don’t think it has yet become part of the checklist for arranging one’s affairs.
- WorldMaker 7y agoAt one point I was considering a Shamir's Secret Sharing based idea with the thought of especially targeting lawyers as a key part of "digital estate planning". The trouble happened that the more I talked off hand with various lawyers about the idea, the more it sounded what I really needed to make was a political lobby first (and that's not something I'd enjoy). We have a lot of estate laws for arranging physical goods. We have almost no digital asset rights that survive our passing. Most of our accounts are explicitly locked to our lifetimes in Terms of Services agreements (generally, they are between me and only me and the service). There's likely going to be some big political battles over the next decade or two as folks with big Steam collections or Movies Anywhere accounts or Dropbox file stores pass on and try to pass those digital "assets" to surviving family members. So my "simple" idea of "I want to build a tool for lawyers to securely write down and file people's passwords in their wills/trusts" became a giant rabbit hole of "securing the will/trust may not be the hard part, making sure those passwords are useful to survivors is a very hard problem that currently everyone is kicking the can on".
- LinuxBender 7y agoMy method is to give half of a passphrase for a keypass file to family members. My attorney will hand over the other half.
- madamelic 7y agoGet rid of $5.99 / mo, charge a flat $99 lifetime. Monthly doesn't make sense at all for this kind of service. I have no plan on dying anytime soon.
- pheug 7y agoMonthly can actually make perfect sense for this kind of service as a signal that the user's still alive. But yeah, $6/month is way too high.
- bananocurrency 7y ago...what? >Monthly can actually make perfect sense for this kind of service as a signal that the user's still alive ...and so when they stop paying for the service...?
- mcast 7y agoI agree this is too high, but a better question is, will this service even be solvent in 50+ years? I don't even expect my Gmail account to last to my death. Maybe at that point, maintenance and support engineers will be entirely automated.
- mrdazm 7y agoAre you presuming a scenario where the company would go dark with no notice?
- deleted 7y ago[deleted]
- ghostbrainalpha 7y agoWhile I agree that your pricing makes more sense to the customer, consider that $99 is only 17 months. Someone who signs up with this service and sort of forgets about it or thinks about it like life insurance (just another small monthly bill), could be a paying customer for 20 years and ultimately be worth $1,200 to the company. Couple that with the monthly fee model is much easier to pari with a "3 months free" offer, and the current pricing may be optimal for the company even if it results in significantly less signups or a less common sense pricing strategy.
- GaryNumanVevo 7y agoWhat if Passbox dies before I do?
- mrdazm 7y agohttps://news.ycombinator.com/item?id=21344639 https://news.ycombinator.com/item?id=21344639
- miguelmota 7y agoTwo concerns: 1. I don't think I can trust a new 3rd party with private data 2. I don't think this service will live long enough to be around for another 50+ years This service makes sense for people who are highly likely to die or become in a vegetable state someday soon like stuntmen or intense sport athletes
- mrdazm 7y agoI’m with you on number 1. It’s going to be an interesting challenge to overcome but I’m mindful that even the biggest of names today started from scratch. Understood on your second point but should it be wound down it’s easy to contact everyone, provide a suitable sunset notice and allow off-boarding. Thanks for your comments!
- mayneack 7y ago> Bank-Level Security (using AES Encryption) I know what they're trying to do, but "bank level" doesn't inspire confidence. Financial institutions have regularly clunky rules like max password sizes, and I've gotten a plain text password emailed to me by a bank before. I also feel like they're over represented in the Troy Hunt security shaming (https://twitter.com/troyhunt https://twitter.com/troyhunt).
- mrdazm 7y agoThanks!
- adam_ellsworth 7y agoFor those (with gmail accounts) looking for other alternatives, Google provides something like a "Dead-man's Switch": https://publicpolicy.googleblog.com/2013/04/plan-your-digital-afterlife-with.html https://publicpolicy.googleblog.com/2013/04/plan-your-digita...
- offmycloud 7y agoIf a person dies and their payment card stops working, does the account get suspended for non-payment?
- deleted 7y ago[deleted]
- mrdazm 7y agoI haven’t coded anything for that yet but my thinking is to possibly have the third party user pay the balance of what’s owed (probably up to a cap) to access the account owners data. Reason being that without that anyone could ride for free by using a card that is then canceled Thanks for your question!
- quickthrower2 7y agoAnother solution is to share the data with friends and family why you are living. Most services and passwords can go with you to the grave no dramas. Bank accounts etc. would be covered by a will. Access to domains etc.: Personal blog, who cares (just author in Github then someone can grab the source if they want) anything valuable domain wise should be owned by a company. That company should have procedures if you die and probably will share passwords between trusted owners or employees.
- mrdazm 7y agoI don't disagree with you here. I just aim to offer a one-stop shop to get that access. The ideal scenario too is for credentials, data, etc that's not currently shared between people when alive. So I, for example, as a single dude don't have anyone else with access to me iPhone, email, or Facebook. That's not something I'd just hand over to anyone just in case. In a Passbox scenario though then by all means!
- kangnkodos 7y agoMy trusted friend decides to try to access all my online accounts, and requests access to my Passbox. Passbox sends me an email informing me of the request. Oops. The email from Passbox ends up in my junk email folder by mistake. I never see it. After the waiting period, my trusted friend gets the information from Passbox and proceeds to wreak havoc with all my online accounts. No thanks.
- mrdazm 7y agoThanks for your comment! Email is the current approach I decided to _start_ with but isn't the only way to go about it. Voice calls, text messages and maybe even push notifications (if a mobile app materializes) are feasible approaches too.
- Deadswitch 7y agohttps://deadswitch.com https://deadswitch.com
- mrdazm 7y ago500 error here