4 ms·
When I'm dead, how will my loved ones break my password?
- mynameishere 17y agoJust make a program that takes a password, and then (if correct) sends two emails: One to your box, and then (a day later) one to whomever you're leaving your data to. Tell them the password and then if they use it before you're dead, you have a day to change everything.
- deleted 17y ago[deleted]
- ComputerGuru 17y agoAnd every day until you die, the person has to receive an email reminder from you? :P
- tlrobinson 17y agoIt should include a way for you to cancel the request, so if the person does use it before you die you don't have to reset all your passwords. Basically a dead man's switch. I thought there were already similar services but only found this casualty of the first dotcom bubble: http://www.sfgate.com/cgi-bin/article.cgi?file=/chronicle/archive/1999/11/29/BU82176.DTL http://www.sfgate.com/cgi-bin/article.cgi?file=/chronicle/ar...
- dkokelley 17y agoThere are similar services but the author questions the integrity and security of those services.
- Jebdm 17y agoBetter yet, don't require "changing everything". Write a program that takes a password, and upon validation sends you an email. If you don't reply within a certain period of time (say, a week), then it will send your info to whoever you want to leave it to. And make sure you can change the waiting period, in case you go on vacation or something.
- frossie 17y agoPersonally, I enjoyed most this comment from the bottom of that article: So let's get this straight; you don't trust your wife, you think your daughter will grow up to be a nut job, and you're worried that your close friends will turn against you. Man, I'd just hand it all over now. It sounds like you have nothing to live for anyway. Maybe this should be a unit test for whether you are ready to marry somebody. If you can't bring yourself to trust them with your password - and trust them not to use it - you have commitment issues. :-)
- TallGuyShort 17y agoI also liked his "liberation" speech. "I never have to worry about being mugged for my laptop". Actually, they're just as likely to mug you. They just won't get your data. Even then, all they have to do is beat you over the head with a hammer until you give them the password... and even then, all they have to do is put in a LiveCD to format your hard drive and they have a new computer. Not so liberating...
- RiderOfGiraffes 17y agoYour entire comment is predicated on him being concerned about losing the laptop. Clearly he isn't. Clearly he's only concerned about losing the data. After all, a laptop can be replaced. With that point of view your comment becomes rather less relevant.
- anigbrowl 17y agoDoctorow is a professional writer. Is it too much to expect he write what he actually means?
- visitor4rmindia 17y agoTo be honest, who mugs people for their data!?! "Your bytes or your life!" just doesn't have the same ring to it.
- RiderOfGiraffes 17y ago
- jf 17y agoInteresting, this seems to be the result of this post on BoingBoing: http://boingboing.net/2009/05/27/what-will-happen-to.html http://boingboing.net/2009/05/27/what-will-happen-to.html I liked Jacob Appelbaum's reply best: http://boingboing.net/2009/05/27/what-will-happen-to.html#comment-504039 http://boingboing.net/2009/05/27/what-will-happen-to.html#co...
- dryicerx 17y agoI've always wondered about this, and one of the ideas I've been playing with my head is the distributing the keys between a few people, and if something were to happen, they can combine them to unlock my secret (all the keys must be present) SECRET xor KEY_A xor KEY_B xor KEY_C xor KEY_D = PUBLIC This is kind of lame, but the same principle...
- mcav 17y agoInteresting, but then if one person loses it, you're out of luck.
- paulgb 17y agoIf you want to get sophisticated you could use Reed-Solomon encoding to avoid this problem. http://en.wikipedia.org/wiki/Reed-Solomon_error_correction http://en.wikipedia.org/wiki/Reed-Solomon_error_correction
- jf 17y agoWhat you are looking for is Shamir's Secret Sharing algorithm. http://en.wikipedia.org/wiki/Shamirs_Secret_Sharing http://en.wikipedia.org/wiki/Shamirs_Secret_Sharing
- hvs 17y agoInteresting analysis of a problem that I don't have. Either I'm not nearly as paranoid as I should be, or I just don't feel like anything of value that I will be handing over to my heirs (whoever they turn out to be) will be digital in form. They'll get a chunk of cash and a bunch of computers with open source software on it.
- pyre 17y agoMaybe not files, but things like email account passwords and such would be good. Also passwords to accounts that get charged on a regular basis (hosting or something) would be easier to deactivate in the event of your death if you heirs had your password (vs. needing to prove to the company that you're dead or something). At the very least, maybe an encrypted file or something with bank accounts, passwords, etc in it would help them out. And it would be easier to update than a will.
- byrneseyeview 17y agoGosh, why go to all this trouble? Just have an unnecessary heart valve transplant, and have the doctor inscribe your password on the new valve. Then develop a serious booze-and-sodium problem (I guess margaritas are the most efficient way to do this) until you absolutely cannot live without that last remaining valve. At that point, nobody can access your password until you're dead. Or, at least, once someone can access your password, you're definitely dead, which is more or less the same thing.
- Evgeny 17y agoWait a second, there's still one thing missing ... you would then have to kill the doctor who inscribed the password.
- gcheong 17y agoI've thought about this and wondered if it would be possible to create an escrow service that would only give over the key when say an official death certificate is presented or something like that.
- pyre 17y agoProblem being government intervention can force them to hand it over. Unless the company is in a place with laws that prevent that sort of outside interference.
- aristus 17y agoThis is such a non-issue I really don't understand why it keeps coming up. Write your passwords down and store them with your other vitally important documents like your checks, bank account records, passport, etc. Why make it so complicated?
- wmeredith 17y agoThis. Why wouldn't you just put a password section in your will?
- pyre 17y agoThe problem with having it in a will is that there is a 'single point of failure' to someone obtaining it. He also mentions moving it out of jurisdiction of the UK, so I'm assuming he's trying to prevent court orders from trying to force the contents to be revealed. If that's the case, then it's possible that having a will stored/signed with a lawyer in Toronto, Canada (or just 'another country from where he currently lives') is not 'legal' or provides issues with the execution of the will in the event of death. If that's true, then he has to have his will in the UK with a lawyer somewhere. I assume that a court could order his will revealed/unsealed if they thought that his password was there and they were trying access the contents of his laptop... If it's possible to have foreign-country wills, then that issue doesn't exist, but I suspect that a will in a foreign country presents legal problems if it isn't outright declared 'invalid.' Of course, if he put it on his will and didn't tell anyone that he did; it's possible that authorities wouldn't even think to go after it (or maybe a judge wouldn't allow them access to it unless they had some sort of evidence that the password was stored there).
- Locke1689 17y agoSeriously. Jesus christ, write your private key file to a USB flash drive and give it to the lawyer/firm in charge of executing your will. Done. Oh, and he really knows nothing about cryptography if he thinks "splitting up the key" is a cryptographically secure way to encrypt your data. Having even part of a private key can hurt.
- deleted 17y ago[deleted]
- grinich 17y agoIt seems to me that the kinds of people who have data requiring this amount of security usually have a lot of other people working for them on just that task.
- drhodes 17y agoI'll just get my passwords surgically implanted. sounds easier, and cheaper than dealing with all the lawyers. sheesh.
- pchristensen 17y agohttp://legacylocker.com/ http://legacylocker.com/
- dejan 17y agoHmm.. I see he missed on something BIG time. How will his data persist if he is not paying the bills for hosting, Amazon S3 and so on. His legacy might not live up a few months after death. I think this is a serious issue. What you blog and write today wont exists after you unless you are a company. Soon I'll post an idea soon on aleveo.com for this, be sure I'll post back on HN. Securing the data is the easy part given it is persisted.