Earlier quoted context omitted.
I share your fears about its longevity. What company would you trust to launch and maintain this kind of service? I feel like WordPress.org or Wikipedia Foundation would be two companies with the right moral compass, funding and longevity who would be great backers of something like this.
The Internet Archive.
Show HN: DeathSwitch
21–30 of 51 posts
Re: Show HN: DeathSwitch
#22Despite the policy difficulties of running a site like this (when is someone dead?, how long until release of secrets?, how to deal with lack of access to emails? etc), This site is completely insecure.
https://www.deathswitch.com/members/myaccount.php is vulnerable to a CSRF hijack through the update email page. This literally took 20 seconds to find...who knows what would happen if I dedicated an entire minute.
In fact, there are no CSRF tokens on the entire site at all. There are big problems in these services and the policies that run them. Technical solutions might not be the best to use here. Perhaps a legal solution is the best route...
edit: I gave it 20 more seconds. Stored XSS. If I paid the money for premium service which allows file upload I'll bet I can RCE too. This is just not the type of person I want protecting my secrets.
Re: Show HN: DeathSwitch
#23Posted this in another thread but what company would you trust to launch and maintain this kind of service? You need to know that when you kick the bucket in 10, 20, 30, 40, 50 years etc that the switch is actually going to work. You need a company with the right moral compass; funding to pay for hosting, maintenance etc; and the longevity to keep going for the next 100 years. Companies on the "maybe" list for me inc…
Again the problem is who will pay your aws when you are dead. But is supposed that you have been paying the latest invoices with your credit card. To be honest I haven't digg enough in the legal terms of these cloud providers.
Re: Show HN: DeathSwitch
#24I think it's an interesting view into how we think about our lives that the first scenario listed is about work data and coworkers, not loved ones or personal data: "Imagine that you die with computer passwords in your head, leaving coworkers without access to critical files." I enjoy my job, and my coworkers are great people, but when thinking about things as serious as planning for post-mortem, I'll admit that thin…
I can't really think of much of anything work-related that should be a secret known by only one person and released upon death. I feel like part of my job is ensuring that at least one other person knows how to access our accounts. We actually use an encrypted password manager to which at least two of us have access.
Re: Show HN: DeathSwitch
#25while the idea has merits, i would not trust you with my most sensitive data (especially if it is reversibly encrypted or plaintext), i would feel like i was paying for an added secuirty risk, of which there are too many already. also it doesnt seem like there are assurances against you abusing my data like there would be if you were a lawyer i had entrusted to execute my will. there's no personal relationship there,…
The secrets they store should be offline and require manual intervention to retrieve.
Also, what's to stop a false triggering? It should require confirmation from m of n sources you specify. If I had some serious life secrets, I'd want to be very sure they don't get sent out just because I'm in a coma for a month.
Re: Show HN: DeathSwitch
#26The answer is it needs to be tied to some infrastructure that's reliable and already has access to this data.
And yes, paying $2/mo for this is nonsensical for someone relatively young. This is a problem without a solution, but this is also not a solution. To be frank, the odds that this domain even resolves this time in 2015 are pretty low.
This alone does not warrant a service. This should be a piece in a bigger puzzle - a small part of a bigger suite of life contingency services.
Re: Show HN: DeathSwitch
#27Posted this in another thread but what company would you trust to launch and maintain this kind of service? You need to know that when you kick the bucket in 10, 20, 30, 40, 50 years etc that the switch is actually going to work. You need a company with the right moral compass; funding to pay for hosting, maintenance etc; and the longevity to keep going for the next 100 years. Companies on the "maybe" list for me inc…
A law firm. That is the "correct" answer to this problem and is what people actually use.
Re: Show HN: DeathSwitch
#28Re: Show HN: DeathSwitch
#29Does the blockchain support something like this?
Re: Show HN: DeathSwitch
#30(If a critical password changes - e.g. Dropbox, which actually contains my 1Password file - that password is encrypted, sent via email, I tell him the password via some other means (usually involving some sort of puzzle just to keep life interesting), he decrypts it and writes it on the envelope.)
And yes, suffice to say I trust my friend absolutely.