4 ms·
When my brother died suddenly, recovering his passwords was a nightmare. Especially for accounts he managed for his wife’s dental business. Fortunately his son
by Tagbert 3y ago
When my brother died suddenly, recovering his passwords was a nightmare. Especially for accounts he managed for his wife’s dental business. Fortunately his son and I were able to guess his main password and a few others. We also found that he was reusing a small set of passwords. We finally were able to get into all of the relevant accounts and then wrote everything down and gave it to his wife. Not a fun process. We should all think about what happens after our deaths and how other people will deal with our messes.
- Terr_ 3y agoWhen it comes to a Stash of Secrets to be only posthumously available, two approaches come to mind: 1. Some arrangement with a law-firm so that your Stash of Secrets will be delivered to your executor in the event of your death, where you trust they won't peek because of financial/legal relationships. 2. A way to unlock your Stash of Secrets that requires a certain portion of keys to be brought together, and you give out keys to different people. (People you trust enough not to all conspire together, but who also are unlikely to pass away the same time you do.) The latter, secret sharing[0], is obviously more algorithmically-interesting. The simplest approach would be two keys that XOR together to reveal the key needed to decrypt the Stash of Secrets. That said, don't let perfect be the enemy of good! At the very least proactively set up other people as "beneficiaries" at major institutions in the event of your death, and at least provide them a list of what institutions or accounts exist even if they don't have the credentials to control them now. [0] https://en.wikipedia.org/wiki/Secret_sharing https://en.wikipedia.org/wiki/Secret_sharing
- zlg_codes 3y agoHow does your model account for the lack of trustworthiness of the establishment wrt citizen privacy? What guarantee do we have that the bank won't just yeet your lockbox? I'm not sure trusting social institutions is a good idea. History shows it will be used against you, before you die.
- Terr_ 3y agoYou could encrypt the Stash of Secrets given to the legal-firm, with not-so-secret key known only to potential recipients. (Who you trust not to conspire with the firm prior to your death, etc.) However in a way that's just another form of option #2, where different parts must be brought together.
- zlg_codes 3y agoAh, I hadn't thought of pulling a two-layer version of that... clever, and you can share keys only with people who are in the will or testament. I wonder if law firms or banks feel more safe holding onto things for people if they don't know their contents. I imagine it would reduce liability.
- Terr_ 3y agoAside from the 80/20 conventional measures I mentioned (beneficiaries, institution checklist) I'd probably go for: 1. Hire a law firm with instructions to deliver an envelope in the event if your death to your executor/SO/whatever. Or even just a trusted friend. 2. Proactively tell your family who that contact is, so that they can promptly request the letter if something happens. 3. In the letter, put a semi-permanent password you don't use for another purpose. Maybe toss in a copy of your will too. 4. Periodically upload a copy of your secret-stuff which was encrypted by that password onto something like a shared Google Drive folder or something just your family members already have access to. (As with all backups, don't assume your house outlives you.) This way you don't need to update the death-letter every time you change a password, and the law-firm/friend will have a key without a lock.
- zlg_codes 3y agoI went through something similar when my SO's dad passed. Her mom is not tech savvy by any means and my SO is only somewhat savvy, so it was up to me to break into the Windows machine, check for any spare files that might contain passwords, etc. I got lucky, because the man kept a .rtf or .doc file with them written down. Bad format, some were out of date, etc, but I was able to get into the e-mail, which led to the rest of it. After that whole ordeal, it put things into perspective for me. I use FDE and you need a hardware token to even boot my machine. I will need to share a minimum of 3 master passwords for my SO to unlock my digital life. Should I die before any of this is written down and secured, I strongly doubt she'd even attempt. That saddens me because there are a lot of pictures and whatnot, so I need to put together a posthumous security protocol.
- rstuart4133 3y agoBitwarden has a solution for this: https://bitwarden.com/help/emergency-access/ https://bitwarden.com/help/emergency-access/ The solution is you give third parties access to your vault, but it's on a time lock. To see what's in the vault they first have to request access. You will be notified if they do, and access is only granted after a delay and during that delay you can block them.
- JohnFen 3y ago> We should all think about what happens after our deaths and how other people will deal with our messes. I have a package prepared for after my death that includes the master password for my password manager, just for this reason. The rest of my passwords can be obtained from the password manager. It also contains a list of all important accounts I have and official copies of important documents. And a description of my various servers and what they do. And a personal letter to my loved ones.