4 ms·
Show HN: Seal – Letters and passwords that open for your family after you die
I'm a CS undergrad who has developed an interest in hardware keys ever since I used them for a school project a few years ago. I made a little chat app that only allows users to chat if they registered a key, nothing else.
The backstory of how I came to work on Seal (this project): was that I was generating ideas with Claude to come up with an idea that only hardware keys could make into software. I was thinking about physical house keys and what you could do with those, but in software. I was already making iOS apps with Claude, and I came up with this idea and it sounded good. I had already worked on a few projects involving hardware keys and I already loved them.
Today I submitted my latest app, Seal, for review in the app store. Seal is an iOS app for iPhone and iPad that lets you write an Envelope (an encrypted bundle of passwords, photos, voice memos, etc...) for all of your loved ones when you're gone.
You can register hardware keys and assign identities for each person. Then you can create Envelopes and assign them to the key that you want to distribute. They plug in the key to their phone and are ready to receive an Envelope from you.
If you don't log into the app for months, one of your designated key holders can start the process of opening the Sealed Envelope. You, as the writer of the letters, get weeks of warnings to check in at least once before the letters open.
After 90 days of countdown, 21 days of warnings, and 14 days of grace, the envelope opens for each person they met IRL and exchange keys with.
No one else can read the envelope or see the photos (even the key holders, Apple, or me) unless that envelope was designated for that person.
What's different from a password manager like 1Password: emergency access there hands one person your whole vault through the company's server, so it needs that company to still exist and be honest on the day it matters. Seal gives each person their own envelope nobody else can open, and there's no company in the middle.
There's also no server at all besides a free Cloudflare static site. The encrypted bundles of passwords and photos are in Cloud Kit. Sign-in/identity is a passkey Face ID/Touch ID or a Hardware Key. It's all Crypto Kit, so there's no dependencies required.
Currently, it's just me and Claude working on this. It hasn't been independently audited by anyone, and it's iPhone only for now. Please do not put a live seed phrase in it yet. If anyone has advice for me as the lead developer for this project, I'm all ears! You can help contribute on the github source code repository page if you'd like. My mom likes this app especially because she's into crypto and she needed a way to pass down or give away the seed phrases for her wallets to all 3 kids without any question about who gets what and when. In the end, there's no confusion or hurt feelings after the fact with just crypto. Thank you for reading and let me know if you have any questions or concerns for me or the project!
Source: https://github.com/jasonepage/Seal https://github.com/jasonepage/Seal
Site with limits and objections pages: https://sealmessenger.com https://sealmessenger.com
Free on TestFlight while the App Store version is in review: https://testflight.apple.com/join/cYp9JRCG https://testflight.apple.com/join/cYp9JRCG
- itake 13d ago> the keys never leave the phones, and the record of who did what can be checked with a script that has no Seal in it. What happens if someone loses their phone or buys a new phone? What happens if they forget to tell you that they need a new key?
- jpage2 11d agoThank you for these questions!! In an example, my mom holds a piece of my key. She upgrades her iPhone. She signs into iCloud, Face ID works, she opens Seal and it knows exactly who she is. Everything looks normal. But her piece of my key is dead, because that piece was locked to the old phone. She has no reason to suspect anything is wrong, which is why I need to fix this in the app ASAP I think. She needs to Seal her Envelopes again with the new phone's key. She can also have a backup hardware key to restore the credential but she has to re-seal again as well in this scenario if she is logged out of her Apple account or broke her main hardware key.
- sebmellen 13d ago> What is not done Rewrite this Readme without Claude? Also > There's also no server at all besides a free Cloudflare static site. The encrypted bundles of passwords and photos are in Cloud Kit. Sign-in/identity is a passkey Face ID/Touch ID or a Hardware Key. It's all Crypto Kit, so there's no dependencies required. To me, this clearly implies that there’s a server involved… Apple’s server. Am I wrong?
- jpage2 11d agoNgl this is humbling I need to hit the textbooks or something because you're definitely right lol there has to be a server... It's just not Seal's server or decryptable by Apple, us, or anyone without the designated keys. It's Apple's Cloud Kit container so they can delete or deny access to any of it... which is a real fault. Also, the database is readable so counts, timing, account IDs and your rule(s) are visible. Also, Apple could decide to terminate my developer account with the container associated with it which would be devastating.
- 13d ago