Eg: http://www.bbc.co.uk/news/technology-26448158
Ask HN: Should I put our passwords in our wills?
1–10 of 15 posts
Re: Ask HN: Should I put our passwords in our wills?
#2You would need to make clear that they would need your phone as well for MFA codes, so if you have a phone password (you should) make sure to put that in the deposit box or notes section of 1password/LastPass.
Re: Ask HN: Should I put our passwords in our wills?
#3Safe Deposit box with emergency unlock codes for 1password or Last Pass maybe? That should be pretty straight-forward. You would need to make clear that they would need your phone as well for MFA codes, so if you have a phone password (you should) make sure to put that in the deposit box or notes section of 1password/LastPass.
Re: Ask HN: Should I put our passwords in our wills?
#4Safe Deposit box with emergency unlock codes for 1password or Last Pass maybe? That should be pretty straight-forward. You would need to make clear that they would need your phone as well for MFA codes, so if you have a phone password (you should) make sure to put that in the deposit box or notes section of 1password/LastPass.
Nice story here about this topic: https://www.buzzfeed.com/nicolenguyen/digital-death-plan-pas...
Re: Ask HN: Should I put our passwords in our wills?
#5Re: Ask HN: Should I put our passwords in our wills?
#6Re: Ask HN: Should I put our passwords in our wills?
#7Re: Ask HN: Should I put our passwords in our wills?
#8Safe Deposit box with emergency unlock codes for 1password or Last Pass maybe? That should be pretty straight-forward. You would need to make clear that they would need your phone as well for MFA codes, so if you have a phone password (you should) make sure to put that in the deposit box or notes section of 1password/LastPass.
Re: Ask HN: Should I put our passwords in our wills?
#9I am using the emergency contacts feature in lastpass, this contact can ask for access, lastpass will contact and allow it if you don't respond in a configurable amount of time (i.e 24h, 1 week, etc). I have 2 emergency contacts, one with a long period and my wife with a shorter one. I also use secure notes to include information about important things that only I might be aware.
Re: Ask HN: Should I put our passwords in our wills?
#10I am using the emergency contacts feature in lastpass, this contact can ask for access, lastpass will contact and allow it if you don't respond in a configurable amount of time (i.e 24h, 1 week, etc). I have 2 emergency contacts, one with a long period and my wife with a shorter one. I also use secure notes to include information about important things that only I might be aware.
So does that mean they store your passwords in some other way as opposed to only storing those encrypted with your master password? I’ve only used 1pass, so maybe it’s different, but that seems sketchy that they can just access your data without your master password to decrypt things. Or is this recovery system all handled locally on a machine you own?
From the documention:
LastPass uses public-private key cryptography with RSA-2048 to allow users to share the key to their vault with trusted parties, without ever passing that information in an unencrypted format to LastPass. When Emergency Access is activated, each user has a pair of cryptographic keys – a public key to allow others to encrypt data for the user, and a private key that allows the user to decrypt the data that others have encrypted for them.
The key used to encrypt and decrypt your vault data is encrypted with the Emergency Access contact’s public key, and can be decrypted only with their corresponding private key. When setting up Emergency Access, you are using the recipient’s public key, encrypting your vault key with that public key, and then LastPass stores that RSA-2048 encrypted data until it’s released after the waiting period you specify. Only the recipient can decrypt the data, so no one else can decrypt it without access to the private key of the recipient you’re sharing it with, which is encrypted with their master password key. This process is completely automated, with no action required by the end user, and ensures that the data is inaccessible by LastPass or outside parties.