Live data from Hacker News

Show HN: If you lose your memory, how to regain access to your computer?

eljojo.github.io

91–100 of 243 posts

Re: Show HN: If you lose your memory, how to regain access to your computer?

#91
post #16

This kind of thing, widely implemented, would be a game-changer for dealing with assets after someone's death! I maintain my family's IT infrastructure (Google Enterprise admin, webserver etc) and I've been tempted to write down 1/4 of my password manager root password and give it to each of my family members - but then we run into the problem where if any one of them loses their shard, it's unrecoverable. Some kind…

Don't worry even if your heirs have the password, it's extremely likely that Google will find the login attempts "suspicious" and try to verify your identity by sending SMS codes to a phone number you last had in 2005, despite your best attempts to prevent it.

Re: Show HN: If you lose your memory, how to regain access to your computer?

#92
post #29

I like it. Perhaps you can use a weird idea of mine. You can discard/modify part of a password before sending it to your backend. Then, when you log in the server has to brute force the missing part. One could extend this with security questions like how many children pets and cars you own. What color was your car in 2024. Use that data to aid brute forcing. The goal would be to be able to decrypt with fewer than 5 s…

That sounds like a roundabout way of doing security questions... https://security.stackexchange.com/questions/186297/do-secur...

Re: Show HN: If you lose your memory, how to regain access to your computer?

#93
post #16

This kind of thing, widely implemented, would be a game-changer for dealing with assets after someone's death! I maintain my family's IT infrastructure (Google Enterprise admin, webserver etc) and I've been tempted to write down 1/4 of my password manager root password and give it to each of my family members - but then we run into the problem where if any one of them loses their shard, it's unrecoverable. Some kind…

A quarter of your password manager's password means it needs to be really long for it to not be bruteforceable if one or two quarters are recovered (on the order of at least 24 completely random alphanumeric characters)

Shamir's secret sharing scheme does not allow anyone to bruteforce it, no matter if they have 99 out of the 100 required pieces that unlock a 10-character password. If you want to do this sort of thing, I would recommend using a secret sharing scheme instead

Re: Show HN: If you lose your memory, how to regain access to your computer?

#94
post #53

Earlier quoted context omitted.

do you store stuff in a bank? could you tell me more about it? my account gives me access to one for free and been meaning to put a yubikey there for a while but never have

Safe deposit boxes are not safe. There are many stories of peoples stuff going missing. ex: https://www.cbc.ca/news/safety-deposit-box-protection-1.7338... https://archive.is/www.nytimes.com/2019/07/19/business/safe-...

Maybe not safe for valuables. What about stuff that has no value to anyone else? I'm not a villain from Ocean's Eleven, no one is stealing my passwords to break into my elaborate safe.

Re: Show HN: If you lose your memory, how to regain access to your computer?

#95
post #29

I like it. Perhaps you can use a weird idea of mine. You can discard/modify part of a password before sending it to your backend. Then, when you log in the server has to brute force the missing part. One could extend this with security questions like how many children pets and cars you own. What color was your car in 2024. Use that data to aid brute forcing. The goal would be to be able to decrypt with fewer than 5 s…

This makes little sense, IMO. Information is information. There is no difference between this and just having a short/simple passphrase with the PKBDF iterations turned very high. You might as well shard secrets using Shamir and encode it via a modified version of BIP32 words.

Re: Show HN: If you lose your memory, how to regain access to your computer?

#96

We use Vaultwarden and Bitwarden to share passwords with the family. My wife has my master password and I have hers. The bigger issue if I drop dead is all the nontrivial tech crap I have set up (self hosted Vaultwarden included…).

Honest question: what is the benefit of such a specialized service compared to just an encrypted file with all your passwords that you share via some common file sharing service (hosted or self-hosted)

Re: Show HN: If you lose your memory, how to regain access to your computer?

#97
post #3

I suffered a traumatic brain injury (TBI) related to an e-bike accident two years ago. I woke up in the ICU after a short coma-like thing and the nurses/doctors asking me questions and it was clear I was answering for the 10th time or more, like we had all done this before, but I couldn't remember anything. Thankfully my very long password I use for an encrypted Borgbackup I have was somewhere deep or untouched, but,…

Wow, it both surprises me but also makes me feel justified in that I keep telling people to make backups of things they care about including something like a Spotify account (if your song lists are dear to them, at least the titles and other metadata that they could rebuild from) and other "cloud" or SaaS services. Anything one cares about, back it up! (Not to you but as a PSA)

Still, it's weird that Google doesn't accept a recovery code. Then again, I had a similar issue where I had nothing set up but a recovery email address and password (back when 2FA was rare), and after confirming both, Google said "well, we still think it's suspicious, why don't you use a device where you're already logged in" (my account had no active sessions that I knew of, besides that I was traveling). Luckily I didn't need it for anything as I had my email moved away already at that time. I still can't access that account today and I switched to throwaway accounts for things like youtube comments or app downloads from the play store (need to download that government authentication software somehow...)

Did Google specifically reject the recovery code as invalid, or did it accept all entries and then their algorithm rejected the login outright?

Re: Show HN: If you lose your memory, how to regain access to your computer?

#98

Earlier quoted context omitted.

I also had old Google backup codes fail a few years ago. Anybody who hasn't regenerated them in a year or two, I recommend you do so.

Long-term access recovery typically requires rituals like annual check-ins, media rotation, and human drills. We already do this with annual fire-drills.

My password manager has, *checks*, precisely 900 entries. Say that I care about maybe ten percent, that's still doing a "drill" on every single weekend day of the year

Security aspects of software should just work properly. Google should test this and, imo, people should make backups of data they care about. Google might ban you for any reason, no matter if the recovery drill worked 2 hours ago it might not work anymore now. Seems like a fool's errand to keep chasing it instead of making routine (or automated) backups of data when you update it

Re: Show HN: If you lose your memory, how to regain access to your computer?

#99
post #70

I like that more people are thinking solving some of the problems of digital inheritance we face. These are problems that are so important now that so much of our lives are digital and tapping into ones actual social circle seems the best way to do this. Also, kudos for packaging it as a static web app. That's the one platform I'm willing to bet will still function in 10 years.

As someone who still plays Windows games from 30 years ago and Flash games from ~20 years ago, I'd not be so pessimistic about other platforms, at least when there is no negative sentiment towards it and a good track record of stability. Not to say that the web is not among the best choices

Re: Show HN: If you lose your memory, how to regain access to your computer?

#100
post #83

i thought 3M had already invented the best password safe ;)

lol i'm so neurodivergent i had to read this 5 times to understand 3M didn't just get into the encryption business

Want to clue a brother in?

Edit: wait, sticky notes maybe? I thought they were a tape company (I'm not sure they're active in my country) but it just occurred to me that maybe they sell other office supplies as well

Post reply on HN