10 ms·
Show HN: If you lose your memory, how to regain access to your computer?
Due to bike-induced concussions, I've been worried for a while about losing my memory and not being able to log back in.
I combined shamir secret sharing (hashicorp vault's implementation) with age-encryption, and packaged it using WASM for a neat in-browser offline UX.
The idea is that if something happens to me, my friends and family would help me get back access to the data that matters most to me. 5 out of 7 friends need to agree for the vault to unlock.
Try out the demo in the website, it runs entirely in your browser!
- moltymolt 8mo agoThat's an interesting idea. It's a good solution to the problem of sharing all your passwords with your loved ones posthumously. Typically that'd involve keeping everything in a vault which will automatically be released to your person of choice if you failed to reset it. The annoying part is having to reset it indefinitely. I like your idea where you share it with multiple people in advance but they would have to collectively decide to unlock it.
- eljojo 8mo agoexactly! my hope is to offload some trust to the collective of my friends
- ddtaylor 8mo agoI suffered a traumatic brain injury (TBI) related to an e-bike accident two years ago. I woke up in the ICU after a short coma-like thing and the nurses/doctors asking me questions and it was clear I was answering for the 10th time or more, like we had all done this before, but I couldn't remember anything. Thankfully my very long password I use for an encrypted Borgbackup I have was somewhere deep or untouched, but, otherwise I would have been fucked. Also, the backup codes Google told me they would always accept failed and it wasn't until I found a random unused Android device in a drawer that had been unused for a year was I able to get access back to my Google account of ~25 years.
- ericbarrett 8mo agoI also had old Google backup codes fail a few years ago. Anybody who hasn't regenerated them in a year or two, I recommend you do so.
- lucenet 8mo agoWell, this is disturbing news.
- Zambyte 8mo agoGoogle services are best treated as a liability.
- tencentshill 8mo agoMake Google Takeouts a part of your backup routine.
- bornfreddy 8mo agoI have (had?) a Google account tied to my email (which is on a domain I own). Not sure if I ever gave them my phone number, initially. Tried to login a few years back, correct password, but they insisted on me entering my phone. Finally I did - and they can't let me in because my "provider is not supported" and they can't send an SMS with the code, so I'm locked out. Tried every few months since then, no go. Fortunately I didn't lose much (except some family photos), but it is annoying as hell. I wouldn't trust Google with anything important. And yes, I tried with an brand new number on a new phone, unrelated provider. No dice. According to reddit I'm far from alone in this. So if you rely on a Google account for anything... Well, good luck!
- rektlessness 8mo agoLong-term access recovery typically requires rituals like annual check-ins, media rotation, and human drills. We already do this with annual fire-drills.
- 8mo ago
- modeless 8mo agoFor this purpose Google offers "Inactive Account Manager" AKA a dead man's switch.
- couchdive 8mo ago3 months of non-use is the lowest term available before it will enact. That's too long for most situations except maybe probate court
- eljojo 8mo agoI don't use Google :(
- bsza 8mo agoSet up a Github action to send out the secret if you don't commit to a repo every x days? You could even combine it with secret sharing to make sure your friends can't access it unless you're really in trouble.
- sowbug 8mo agoYou don't need to use Google day-to-day. Create a single-purpose Gmail account and set up Inactive Account Manager to provide Google Drive access to your trusted contacts at the designated time. Put a single document in the drive that contains whatever your recovery instructions are, and encrypt it with the secret that is unlocked with your M-of-N Shamir shares. Now you don't have to trust your M of N friends as much, because they can conspire to unlock the secret early, but they won't get access to the document that the secret unlocks until after your demise. There are non-fatal problems with this approach -- your N friends have to recognize the email they receive from a strange Gmail address 3 months after you're gone. You might lose the password to the Gmail account and be unable to get in there yourself, causing it to declare you dead when you're not. All these issues can be mitigated with extra care.
- deleted 8mo ago[deleted]
- bitexploder 8mo agoLow tech: I put my secret manager password in a physical journal that is locked in a fire proof, water proof vault and hidden somewhere only my partner and myself know where it is. I use a password manager. Everything else goes in the password manager.
- rcxdude 8mo agoIn general whatever kind of backup plan you have for when you die could also work in this scenario, you may just need to think harder about anything that you do not want have revealed when you die.
- munk-a 8mo agoAlternative - my partner and I (and also two other close contacts) have password managers that contain each of the other one's secret. This was less an effort to help with the memory loss scenario and more of an effort to deal with death and access to services (especially to cease subscriptions and the like). In a lower trust scenario you could probably use a lawyer as a broker of the secret (potentially even as part of a will).
- rcxdude 8mo agoPassword managers like bitwarden also have emergency access features which can do this, with the caveat of trusting them to enforce the requirement of access only being granted after a notification to the account holder is not denied in some time period (but unlike the lawyer you're not trusting them with the secret directly)
- spockz 8mo agoApple has this thing called Legacy Contact which allows the same but then built in to the whole Apple account. This includes devices as well as the iCloud ~~and attached keychains. Granted, it is another hoop to jump through compared to presharing keys with each other.~~ It would be nice if your Apple account could be unlocked with some other keys as well apart from the primary one, but I guess that is what Apple calls the “Legacy Contact Key”. Edit: okay so the keychain is excluded from this. So back to storing each others passwords in eachothers keychain…
- lucenet 8mo agoWrite down the password, print out recovery codes. Store them in separate buildings. Tell someone you trust about where you left these pieces of paper.
- notepad0x90 8mo agoa safe-deposit box at a bank works ok too.
- deleted 8mo ago[deleted]
- registeredcorn 8mo agoI explicitly make it so I cannot regain access to my computer in the event that my memory becomes faulty. I would be in an impaired state, and cannot function in way that would be conducive to either work or pleasure in terms of computer use. That is to say, the entire reason why I have password security at all is to keep out people who do not know the password. If someone does not know the password, they should not be able to access the system. That obviously and clearly applies to myself as much as any other person. "If you do not know it, then you do not need it."
- esafak 8mo agoNo family, eh?
- seb1204 8mo agoMaybe but does not want to share the pics or tax return.
- catlifeonmars 8mo agoWhat if you forgot your password but retained all other memories?
- eljojo 8mo agoasking the real questions here
- wavemode 8mo agoWell see, that's why I keep my "password" memory stored snugly next to "breathing" and other such. If I'm walking around conscious, then I must still know my password.
- fragmede 8mo agoI must have missed that option in the character creation part of being born (along with choosing my parents). For the record, human memory doesn't actually work in practice. It's unbelievably uncommon, but TBI have weird effects.
- BoredPositron 8mo agoYubikey
- nippoo 8mo agoThis kind of thing, widely implemented, would be a game-changer for dealing with assets after someone's death! I maintain my family's IT infrastructure (Google Enterprise admin, webserver etc) and I've been tempted to write down 1/4 of my password manager root password and give it to each of my family members - but then we run into the problem where if any one of them loses their shard, it's unrecoverable. Some kind of ECC would be great - ideally where I could print it out onto various bits of paper with a user-definable redundancy, or better still, some kind of reciprocal system where (say) 8/10 members of a trusted friend group/family ring could unlock any other member's password...
- rcxdude 8mo agoShamir secret sharing is the cryptographic thing that you want. You can can configure any M of N to be needed to recover the underlying secret. (If you have a trusted third party, you can also enforce a cooling off period: e.g. that any attempt to access results in a notification to the account holder that if not denied within some time period, access is granted)
- nandomrumber 8mo agoYou can give your password, or part of it, to your estate lawyer to attach to your will. This is obviously more cumbersome, and probably costly, if you intend on changing your password. I guess you could change the part of it you don’t store with them.
- eljojo 8mo agoyes! I am starting to do some planning on that myself, that's why I'm in that kind of mindset. If you know more people in this space, please share this with them! would love to get feedback
- cyphar 8mo agoI wrote a project to do this a few years ago[1], it's mainly missing an automated mechanism to scan the PDFs and a GUI. Maybe you'll find it interesting. [1]: https://github.com/cyphar/paperback https://github.com/cyphar/paperback
- JTbane 8mo agomaster password on paper hard copy
- eljojo 8mo agothat's so scary though! what if someone has access to it? or it gets lost when you need it?
- seb1204 8mo agoI think this is when you need to evaluate your thread scenario. A) self-made crypto accessible through web or browser that any cracker can find through www and use machine clusters to run on or AI to work on etc. B) physical home invasion that are interested in one of your A4 papers with some random words that have only meaning to you and few trustees.
- eljojo 8mo agoi didn't roll this crypto, using hashicorp and age
- 9x39 8mo agoWell, there's power of attorney, which centralizes massive authority over your life with someone else, and yet people do so because when you pick right, it's a useful system. I'm trying to think of how this survives friends (who come and go in your life) having to coordinate. Then again, some people really did have PGP key signing parties...
- rawgabbit 8mo agoFor my personal passwords, I use Apple's password manager. It lets me share passwords with my family. I also created a folder on Apple's iCloud that I share. https://support.apple.com/guide/iphone/share-passwords-iphe6b2b7043 https://support.apple.com/guide/iphone/share-passwords-iphe6... https://support.apple.com/guide/icloud/share-files-and-folders-mm708256356b/icloud https://support.apple.com/guide/icloud/share-files-and-folde...
- politelemon 8mo agoDespite the convenience factor, it isn't great to use a manager tied into your own ecosystem. It should exist outside, with the minor factor of lesser convenience.
- eljojo 8mo agoI've been so tempted to try out the apple password manager, I'm fully vested in their ecosystem, but the lock in is too big for me to feel comfortable with. This is the sort of stuff that terrifies me https://hey.paris/posts/appleid/ https://hey.paris/posts/appleid/
- rawgabbit 8mo agoIt also terrifies me. The best solution I can come up is to export out my passwords to a thumb drive every few months.
- croisillon 8mo agoi thought 3M had already invented the best password safe ;)
- ddtaylor 8mo agoI think 3M also sells a $5 wrench.
- eljojo 8mo agolol i'm so neurodivergent i had to read this 5 times to understand 3M didn't just get into the encryption business
- lucb1e 8mo agoWant to clue a brother in? Edit: wait, sticky notes maybe? I thought they were a tape company (I'm not sure they're active in my country) but it just occurred to me that maybe they sell other office supplies as well
- croisillon 8mo agoYes, Post-It™, where people famously write passwords down
- cbabraham 8mo agoaw, friend of mine built this way back in the day https://michael-solomon.net/keybearer https://michael-solomon.net/keybearer https://github.com/msolomon/keybearer https://github.com/msolomon/keybearer
- eljojo 8mo agono way!!!! I searched for a long time for a solution like this, many could encrypt using shamir but none took an actual file with browser upload and easy UX. and like, 14 years ago? my hats down to you my friend. my zip bundles are 1-2 megabytes due to all the wasm, and you achieved this on so little. impressive job! I'd love to hear what you think about mine, one of the differences is that it creates a ZIP file containing the recovery app in it, as well as a PDF with instructions for non-technical friends. Overall trying to make the recovery experience as smooth as possible. but cheers, your version is the only one that I found that does basically what mine does, all the others fall short one way or another!
- thephyber 8mo agoI wonder how many thousands or millions of useful projects are so well hidden that they are effectively nonexistent.
- eljojo 8mo agoyou know, I've always thought that "If I know I have something... somewhere, but I don't know where that thing is is, I have effectively lost it"
- mohn 8mo agoI agree with the sentiment, and the specific wording of your comment made me want to link to the classic bash.org quote[0] which has consistently been in the top 5 for a long time, but I just learned that we lost bash.org... :( [0] https://web.archive.org/web/20230610235249/http://bash.org/?5273 https://web.archive.org/web/20230610235249/http://bash.org/?...
- econ 8mo agoI like it. Perhaps you can use a weird idea of mine. You can discard/modify part of a password before sending it to your backend. Then, when you log in the server has to brute force the missing part. One could extend this with security questions like how many children pets and cars you own. What color was your car in 2024. Use that data to aid brute forcing. The goal would be to be able to decrypt with fewer than 5 shards but make it as computation heavy as you like. If no one remembers the pink car it will take x hours longer.
- eljojo 8mo agoohhhh that's brutal haha! for context my app runs entirely clientside, but I get it, it's an interesting idea...
- econ 8mo agoI wonder if they even need a file. They could pick some question and type their secret into the app, something like the name of their first date etc If you are to hand out files maybe it is wonderful to write them a letter that serves as their shard? They might actually store it some place safe and it wouldn't scream I'M A SECRET!
- ImPostingOnHN 8mo agoThat is a neat take on "key strengthening", or "peppering": https://crypto.stackexchange.com/questions/20578/definition-of-pepper-in-hash-functions/20583#20583 https://crypto.stackexchange.com/questions/20578/definition-...
- lucb1e 8mo agoThat sounds like a roundabout way of doing security questions... https://security.stackexchange.com/questions/186297/do-security-questions-make-sense https://security.stackexchange.com/questions/186297/do-secur...
- digiown 8mo agoThis makes little sense, IMO. Information is information. There is no difference between this and just having a short/simple passphrase with the PKBDF iterations turned very high. You might as well shard secrets using Shamir and encode it via a modified version of BIP32 words.
- cedws 8mo agoI also gave this problem some thought: https://github.com/cedws/amnesia https://github.com/cedws/amnesia
- eljojo 8mo agooh hey, nice timing! good name too, I see we're both on the same wavelength there. I'll link you from my readme!
- gingerlime 8mo agoOther than passwords though, I also have stuff installed at home on a Synology NAS, a mail server, a VPS running some websites (my own, family, my wife's), Home Assistant, Family photos with backups etc etc. I wonder who would not only have the passwords, but the know-how to manage the whole thing, at least to transition it to more managed services...
- thephyber 8mo agoDon’t assume that anyone can. If you want someone to be able to access it after you’re gone, either put 1000 BTC in it or leave instructions. Paper instructions in a physical fireproof safe is way easier to deal with than any digital encryption with no hints.
- eljojo 8mo agoyou're completely right! the app actually guides you on some of that, it generates a readme that gives you advise on what to document, but I agree you can't be too careful here, the passwords IS NOT ENOUGH. You need to give people "a map" of where things are: https://github.com/eljojo/rememory/blob/main/internal/project/templates/manifest-readme.md#tier-3--the-map-where-stuff-lives https://github.com/eljojo/rememory/blob/main/internal/projec...
- reddalo 8mo agoMe too. I'm starting to self-host more and more services for both me and my family, and I wonder what would happen should I meet a bus in a front-facing way.
- Terr_ 8mo agoI think that boils down to having a checklist addendum to go with your will, an outline of accounts and data to rescue.
- rkagerer 8mo agoNice! Good to see some tooling in this space explicitly designed for simplicity and user-friendliness. One practical problem to consider is the risk of those distributed bundles all ending up on one or two major cloud provider's infra because your friends happened to store them someplace that got scooped up by OneDrive, GDrive, etc. Then instead of the assumed <threshold> friends being required for recovery, your posture is subtley degraded to some smaller number of hacked cloud providers. Someone using your tool can obviously mitigate by distributing on fixed media like USB keys (possibly multiple keys to each individual as consumer-grade units are notorious for becoming corrupted or failing after a time) along with custodial instructions. Some thought into longevity is helpful here - eg. rotating media out over the years as technology migrates (when USB drives become the new floppy disks) and testing new browsers still load up and correctly run your tool (WASM is still relatively new). Some protocol for confirming from time to time that your friends haven't lost their shares is also prudent. I always advise any disaster recovery plan that doesn't include semi-regular drills isn't a plan it's just hope. There's a reason militaries, first responders, disaster response agencies, etc. are always doing drills. I once designed something like this using sealed paper cards in identified sequence - think something like the nuclear codes you see in movies. Annually you call each custodian and get them to break open the next one and read out the code, which attests their share hasn't been lost or damaged. The routine also keeps them tuned in so they don't just stuff your stuff in an attic and forget about it, unable to find their piece when the time comes. In this context, it also happens to be a great way to dedicate some time once a year to catch up (eg. take the opportunity to really focus on your friend in an intentioned way, ask about what's going on in their life, etc). The rest of my comments are overkill but maybe fun to discuss from an academic perspective. Another edge case risk is of a flawed Shamir implementation. i.e. Some years from now, a bug or exploit is discovered affecting the library you're using to provide that algorithm. More sophisticated users who want to mitigate against that risk can further silo their sensitive info - eg. only include a master password and instructions in the Shamir-protected content. Put the data those gain access to somewhere else (obviously with redundancy) protected by different safeguards. Comes at the cost of added complexity (both for maintenance and recovery). Auditing to detect collusion is also something to think about in schemes like these (eg. somehow watermark the decrypted output to indicate which friends' shares were utilized for a particular recovery - but probably only useful if the watermarked stuff is likely to be conveyed outside the group of colluders). And timelocks to make wrench attacks less practical (likely requires some external process). Finally, who conducted your Security Audit? It looks to me as if someone internal (possibly with the help of AI?) basically put together a bunch of checks you can run on the source code using command line tools. There's definitely a ton of benefit to that (often the individuals closest to a system are best positioned to find weaknesses if given the time to do so) and it's nice that the commands are constructed in a way other developers are likely to understand if they want to perform their own review. But might be a little misleading to call it an "audit", a term typically taken to mean some outside professional agency is conducting an independent and thorough review and formally signing off on their findings. Also those audit steps look pretty Linux-centric (eg. Verify Share Permissions / 0600, symlink handling). Is it intended development only take place on that platform? Again, thanks for sharing and best of luck with your project!
- 2color 8mo agoI like that more people are thinking solving some of the problems of digital inheritance we face. These are problems that are so important now that so much of our lives are digital and tapping into ones actual social circle seems the best way to do this. Also, kudos for packaging it as a static web app. That's the one platform I'm willing to bet will still function in 10 years.
- lucb1e 8mo agoAs someone who still plays Windows games from 30 years ago and Flash games from ~20 years ago, I'd not be so pessimistic about other platforms, at least when there is no negative sentiment towards it and a good track record of stability. Not to say that the web is not among the best choices
- mikkupikku 8mo agoI'm a firm believer in passwords on sticky notes. (At home of course, people get pissy if you do this at work!)
- Yodel0914 8mo agoWe use Vaultwarden and Bitwarden to share passwords with the family. My wife has my master password and I have hers. The bigger issue if I drop dead is all the nontrivial tech crap I have set up (self hosted Vaultwarden included…).
- karussell 8mo agoHonest question: what is the benefit of such a specialized service compared to just an encrypted file with all your passwords that you share via some common file sharing service (hosted or self-hosted)
- mawax 8mo agoA few years ago I switched from KeePass, with the database stored in Dropbox, to a SaaS password manager. My primary reasons where: - No more sync conflicts when using multiple devices - Backups are taken care off - It's harder to steal the database - Slightly better browser and mobile extensions for auto-filling passwords
- Yodel0914 8mo agoWell, we already use password managers for all their benefits: autofill, syncing, password generation, passkey storage etc. For a while we’re using `pass` which doesn’t have an easy way to share passwords, so my wife and I had duplicates of a handful of passwords, which was annoying when they changed, or when we needed to share a new one. Moving to Bitwarden meant that we can have a set of passwords that are shared, and we can update or add to it. As the kids have gotten older, I’ve get them using it too, so we can share a small set of passwords with them (wifi, streaming services etc).
- rektlessness 8mo agoAs our identities get more fragmented across devices, clouds, and cranial volatility, I expect digital wills that withstand real-world decay to become the norm.
- kzalesak 8mo agoThank you for this tool. We have been looking at shamir schemes in our org for encrypting backup, and decided against it for the reasons of being too complicated. Maybe it is time to revisit it again.
- Terr_ 8mo agoThe "lost my memory" scenario differs a bit from death/succession planning in that you can use biometrics... but IMO it's better to jump straight to the latter and concuss two birds with one stone.
- octoberfranklin 8mo agoShamir Secret Sharing is notoriously difficult to implement correctly, and even the smallest most subtle bugs result in total compromise. Consider whether you really need this. Doing 7-choose-5 separate multiparty encryptions is way harder to screw up. Is having to produce 42 ciphertexts really a dealbreaker?
- kortex 8mo agoThey are using the Hashicorp Vault implementation, and it's been around for years. I think we can safely say they know what they are doing.
- octoberfranklin 8mo agoCan we? Hashicorp is a devops company, not a cryptography company. The "hash" in their name bears no reference to cryptographic hashing. If the implementation came from DJB, or RSA corporation, or the OpenSSH developers that would be one thing.
- aforwardslash 8mo ago5 out of 7 means you cannot be in an eg. car accident with more than 2 of them at a time, if there is the possibility of all of them present in the car not surviving. Im also quite more practical - there are responsabilities that may go beyond a simple memory loss - eg. If one is in a coma or just hospitalized for a long period of time; trusted third parties may require access to your accounts even for simple stuff like paying bills/rent/cloud services.
- Joel_Mckay 8mo agoDead man's switch doesn't necessarily mean the operator has expired https://en.wikipedia.org/wiki/Dead_man's_switch https://en.wikipedia.org/wiki/Dead_man's_switch They are an important feature in autonomous systems, critical equipment, and deterrents. =3
- mhb 8mo agoStep 1. Get 7 friends
- ShrootBuck 8mo agoI have to say, this is a very cool project, and I love how everything you need is packaged up nicely for distribution
- crazygringo 8mo agoTouchID is a good starting point... though it does confirm your password weekly. Somewhat tongue-in-cheek, but if I lose my memory, how am I supposed to remember the 7 (or 5) friends who have my password...? Somewhat less tongue-in-cheek, if you really wanted to be serious about your friends not being able to produce your password now for the lolz, then you'd actually want to ensure they were merely acquaintances who didn't know each other and couldn't find each other, e.g. not all Facebook friends. In which case the list of friends becomes essentially as important as the password, and then how do you remember where you've stored that list? In reality, hopefully you can just entrust your master password with your closest family (spouse, parent, adult children), assuming they're not going to drain your bank account or read your private digital journal.
- unbad505 8mo agoI just keep my password manager password hidden in a journal
- deleted 8mo ago[deleted]
- 0gs 8mo agosorry if i missed this question. how do you remember you have this vault?
- eljojo 8mo agoi tell my friends about it, so they remind me in case I lose my memory
- 0gs 8mo agosorry if i missed this elsewhere: how do you remind yourself this vault exists? do you have to explain the whole thing to your 7 lifelines?
- Brajeshwar 8mo agoStart treating the Future-You like a Stranger. Write for that stranger, your Future-You will thank you. We think we will remember, but we won’t. So, don’t be too harsh on yourself and make it easier for your future-you. If that stranger finds it easier, it will also be for others; your relatives, kids, etc. Unless your work and life need to be very secretive, or involve matters of national or international importance, I personally think a simpler printed/written format that works without electronics/Internet would be a better option. Of course, the printed details can have simple encryption, which your family/friends can break using day-to-day quirks you shared, such as the family secret codes, the name of that pet in the town you grew up in, or the middle name from the story of your great-grandfather, etc. Some time ago, my mother-in-law (erstwhile teacher) and my godmother-aunty (businesswoman) began to forget many things. Their kids have tried quite a few phone apps and whatnot with electronics. Finally, I have suggested enforcing just two things: a lot of Valet bowls around the house (at common places in all the rooms) and pocket notebooks with pens attached. They just write anything and everything, from money to kitchen items to anything they want. If they forgot something, refer to the notebooks. If a key is lost, try the Valet Bowl. Now, my plan is to train their muscle memory to drop/pick from the bowl (don’t try to remember) and write things down. The idea of Valet Bowls comes from something someone mentioned on Hacker News.
- cyode 8mo agoThis comment right? https://news.ycombinator.com/item?id=41220059 https://news.ycombinator.com/item?id=41220059 (Funny how I can remember this comment from many months ago after never implementing the bowls, but I currently can’t remember where my car keys are. Should have implemented the bowls…)
- Brajeshwar 8mo agoOh God, Yes. Now, in my favorited posts and comments. For keys, there is only one place: the Keyholder wall-mounted near the main door, while still visible from the main Hall. Not easy to pick and go by “guests” without being seen by someone, but easy for residents to just walk out with one. I got the exact same ones from Amazon and wall-mounted them in all the homes where I serve as Printer-Repair Guy. 10+ years, I kinda have trained every family member’s muscle memory, “Keys go there and only there.” ;-) Add/Edit: I also have a sticker I printed stuck to the Keyholder, in Monica’s words from Friends, “Got the Keys?”
- seized 8mo agoLook at Bitwardens Emergency Access: https://bitwarden.com/help/emergency-access/ https://bitwarden.com/help/emergency-access/ Would also cover banking details or whatever else you want to put in there.
- csullivannet 8mo ago> Trusted emergency contacts must be existing Bitwarden users While the motivation is similar this basically kills the feature. It requires that your friends not only use but continue to maintain their accounts. From my understanding of OP's implementation, being completely offline they can basically just keep the key on a USB or file store of any kind. Personally I think the most robust solution is single key access (a la emergency kit), distributed in one or more secure bank vaults for redundancy (many still do offer these for free or cheaply for small boxes). Put instructions in your (living) will and done.
- hypeatei 8mo ago> just keep the key on a USB or file store of any kind Similar arguments could be made against this too: trusted contacts need to make sure the USB isn't damaged or lost and that the files haven't been corrupted. At the end of the day, these types of recovery flows require some level of engagement which in itself is an issue since human beings are very flawed.
- KevinChasse 8mo agoInteresting approach. I like that this is explicit about human recovery rather than pretending crypto alone solves catastrophe. That said, this design and fully stateless systems like mine (deterministic derivation, no escrow) are solving opposite failure modes. Shamir-based social recovery assumes: trusted third parties remain reachable, they are willing and able to cooperate, and that recovery is an exceptional event. Stateless systems assume the inverse: no one can be relied on, recovery is impossible by design, and the primary threat is silent compromise rather than lockout. Neither is “better” universally; they’re value judgments. What I appreciate here is that the tradeoffs are made explicit instead of buried behind UX. One open question I’d be curious about: how you reason about coercion risk over time (friends change, incentives change), and whether you see this as something users should periodically re-shard as relationships evolve.
- eljojo 8mo agothanks for your thorough review and congrats on your launch! for my personal use case, I'm not worried about coercion, but many have highlighted it as a real risk. my answer to that is to do what you suggest: update my contact list yearly, send new ZIP files with bundles, and ask them to delete the previous ones.
- joeframbach 8mo agoSee also: Horcrux. https://github.com/jefdaj/horcrux https://github.com/jefdaj/horcrux
- Waterluvian 8mo agoI still remember regions! https://www.folklore.org/I_Still_Remember_Regions.html https://www.folklore.org/I_Still_Remember_Regions.html
- eljojo 8mo agogreat story :')
- utopiah 8mo agoAh, I actually did something similar years ago. I basically hashed individual pages of my wiki and I think I published the hash of hashes on the Blockchain. Anyway I didn't need it and stop maintaining that system but definitely interesting explorations. To clarify the hashing was to verify that the pages were indeed modified by me, to prevent tempering. Damn, found it back, was in 2011! in English https://fabien.benetou.fr/Slideshows/MemoryLoss https://fabien.benetou.fr/Slideshows/MemoryLoss in French https://fabien.benetou.fr/Slideshows/MemoryLossPES https://fabien.benetou.fr/Slideshows/MemoryLossPES
- utopiah 8mo agoFWIW as I commented just earlier if you have to verify without relying on memory nor a public note (e.g. sticker on screen) that others could use to pollute your data then use a biometric mechanism, e.g. YubiKey Bio.
- procaryote 8mo agoA lower tech version would be to pick a very long recovery passphrase, cut it in two or three and give it to two or three friends. It doesn't give you N out of M, but it will be good enough for a lot of real world scenarios
- konha 8mo agoI don’t know. Depending on how much time passes between now and the moment you try to recover the key I bet at least one of your friends will have misplaced or lost that piece of paper.
- sjducb 8mo agoThis could be a useful tool for putting self hosted Bitcoin in a will. If you self host then die no one can access your coins. Lawyers don’t want to be trusted with copies of secret phrases because of liability if the bitcoin gets stolen. If you encrypt the bitcoin recovery info across several files you can give part to the lawyer and part to different beneficiaries.
- nesk_ 8mo agoI've been searching for a solution to let my wife have access to my master password if I die someday. This is definitely something that could work, thank you!
- trueismywork 8mo agoVery cool, but I must say the best way is still a paper with master password in a bank locker. May be distributed it if needed gor additional security.
- yieldcrv 8mo ago> 5 out of 7 too high
- mjanx123 8mo agoA sticker with your password to the monitor, like everybody else
- fragmede 8mo agoThat's stupid! I put mine under the keyboard. Way more secure :p
- ninalanyon 8mo agoI know that you and the person you are responding to are joking (probably) but this does in fact seem like a much simpler way of solving the problem and really not much less secure if we are talking about a home computer.
- utopiah 8mo agoAt least if you go that route use a biometric authentication mechanism, e.g. YubiKey Bio.
- generic92034 8mo agoI personally do not really care if my relatives are able to access everything I was able to access once I am dead or forget everything. But they should be able to access anything of monetary worth. So, without any crypto my belongings are either real estate or depots and accounts at banks. Both can easily be discovered in case of my death. I think there is a similar discovery process if I am subject to guardianship (permanently).
- scaradim 8mo agogoal for the rest of your life: prepare and leave after your death more that real estate and bank accounts to your relatives and friends.
- generic92034 8mo agoI am already doing this with our shared experiences and memories. But why do I need to add my online activities to that? I see no good reason.
- kunley 8mo agoThe idea is very noble. In am just thinking about the number of 5, who these times has really five trustable friends not just acquaintances or people bound by some specific activity perishing over time. I am afraid, for most people in the digital era this number is much lower (and I am certainly not speaking for myself now).
- eljojo 8mo ago"who has five friends?" has been the number one comment I've received on this, by far. a bubble just popped for me
- kortex 8mo agoYou should add a feature where you can select the shares/threshold, with 3/5 being the default. edit: d'oh! you do, I didn't get that far into using it yet cause I was on mobile.
- fruitworks 8mo agoWhat technique did you use for the timelock encryption?
- eljojo 8mo agoI don't have timelock encryption, but have been looking into integrating https://docs.drand.love/docs/timelock-encryption/#use-cases https://docs.drand.love/docs/timelock-encryption/#use-cases
- Alice4788 8mo ago[flagged]
- commandersaki 8mo agoWe need a standard or reference for an SSS combined encryption mechanism. It definitely has value, but I don't think anyone will trust a single lonesome implementation no matter how good it is.
- meander_water 8mo agoSeems similar to a Show HN from 5 years ago: https://news.ycombinator.com/item?id=26256726 https://news.ycombinator.com/item?id=26256726 I gotta say Horcrux is a catchier name ;)
- nmstoker 8mo agoDefinitely catchier name!
- kortex 8mo agoUntil you get sued by JK Rowling. Unlikely? sure, but I wanted to decouple for other reasons. That's why i went with PassCrux for mine. Can't argue that it's too close, since "crux" is just latin for cross, as in "crux of the matter" (JK likely invented horcrux as a portmanteau of horror + crux). https://github.com/xkortex/passcrux https://github.com/xkortex/passcrux
- nubinetwork 8mo agoIf you're not encrypting your hard drive, cracking a local Windows password is easy... Linux is even easier, but you just need a livecd to get back in either way... Online accounts on the other hand... I hope you used something like lastpass. :) Honestly, anything more than this is completely overkill.
- graemep 8mo agoThat is why you should be encrypting your hard drive. You do not want it to be that easy.
- mdavid626 8mo agoSticky notes?
- vladde 8mo agothen your friends conspire together against you and gain access to your system on their own /j
- giantfrog 8mo agoThis system introduces a fun question: What’s more likely, that you suffer total spontaneous memory loss or your best friends betray you?
- Schmerika 8mo agoI think you'd have to plot a curve based on the potential reward of betrayal... I suspect that many Americans* would have their 5th closest friends committed or worse for low 6 figures. If in ~dire straits, as about half all Americans are, that number could get much lower. * If my use of the word 'Americans' above is triggering, feel free to substitute it with 'people'.
- whycombinetor 8mo agoYea, this project gives less "my contract partners will benevolently read my diary after I die" than "enabling and incentivizing my closest friends to hold a vote to redistribute all my assets amongst themselves"
- ck2 8mo agonot just illness but age too will "bitrot" your brain fifteen years ago I decided to fiddle around one winter and learn a newfangled thing called "bitcoin" and setup my computer to run 24/7 and heat my apartment as a benefit after mining a dozen coins which were worth next to nothing then, I gave up and took apart the PC and put it away fast-forward to 2020 and covid/long-covid has now rotted my brain, swiss-cheesed my mind to the point I cannot remember the password for the life of me I was too clever then for future me, and used a long passphrase that made funny sense then but beyond me now (they are worth over a million dollars at times now) In hindsight: go find a book in your library and pick a random page and write the password or a significant hint to the password on that page and then put it away (don't put any other indication on that paper)
- vulcan01 8mo agoLibraries get rid of books in poor condition and loan books to other libraries, and patrons regularly fail to return books.
- knifeinhead 8mo agoUnfortunately, for this to work, you need friends...
- tonetheman 8mo ago[dead]
- notesinthefield 8mo agoThings like biometrics and hardware keys make this an easy fix - were they a consideration?
- kube-system 8mo agoIf you are preparing for accidents where memory loss might be an issue you might also want to consider that you could quickly be in a situation where: * you forget that you have a clever password scheme * you forget that you have data to decrypt * your mental capacities are deteriorated enough that someone else takes over decisions making for you. This person may not know you or your data protection scheme. * you are physically injured where biometrics are non functional. Or a biometric system with a limit on tries may have been tripped by those trying to help you. * you were in an incident that your friends/family were also affected by In my opinion, the best way to protect against these is simply write stuff down in plaintext somewhere that relies on physical security, like with documents in your home. Also notate what they are and why someone would need to access them and how.
- kortex 8mo agoThat's why you have a public-ish recovery guide for all the other steps.
- kube-system 8mo agoJust because something is on a blog or a github page doesn't mean that they are discoverable to everyone who might need to know, e.g. a conservator. You're better off physically putting it with obvious locations for your financial documents, like in your home with your tax returns or valuables.
- rodolphoarruda 8mo agoMy family members know of my physical "red notebook" and its location. It has instructions on how to access my digital life on detail.
- kortex 8mo agoGlad to see this idea getting traction! Had the same idea years ago (same hashicorp lib too) but lost motivation to polish it to the point I felt confident enough to Show HN. https://github.com/xkortex/passcrux https://github.com/xkortex/passcrux But given recent events, I want to restart work on it. My use-case revolved more around preserving a master password e.g. to a password manager. I also wanted to support self-hosted backup, like hiding shares and giving directions to the parts to trusted friends. The shamir sharing part was straightforward but i really want to add forward error-correction to protect against partial data loss.
- xtiansimon 8mo agoInteresting. Very useful _in the event of my untimely demise_. Specifically for my own memory problem I use a printed "random number pad" that is a 10x10 grid of characters. I keep a copy in the house and in the cloud. I have a strong visual memory. I can remember shapes and images much better than words or strings. To reveal the password I need only recall the visual pattern and collect the characters underneath.
- Barry987 8mo agoI Invested $50,000 and reinvested it for 3 days and the money got up to $102,213. I told them that i wanted to withdraw. They told me i have to Pay 20% of my money before I can withdraw, I paid it and the following day, i wanted to withdraw and they told me i have to pay additional $40,000 . I told them i will not pay any money again, and that was how it ended. I taught they had gone with my money until I came across COIN HACK RECOVERY whom many had reviewed how they helped them recovered their stolen bitcoin and funds, I contact them on coinhackrecovery (at) gmail dot com I gave them a try and the outcome was epic! They helped me recover all my stolen bitcoins within 48 hours.
- kfn 8mo agoI think my FDE password is muscle memory at this point, which is harder to lose. There's also a copy of it printed out stuck in my filing cabinet which I may or may not ever find, since I won't know to look for it.
- s_u_d_o 8mo agoHey cool one. Fingerprints, FaceID, EyePrint would be a plus to add to it, what do you think? Stay safe
- bombashell 8mo agoI like this because it treats memory loss as a realistic threat model instead of an edge case. Most security setups assume the user stays cognitively stable forever which is a pretty wild assumption if you think about it… This feels more like desgining for humans over decades instead of just for today’s convenience.
- Alice4788 8mo ago[dead]