Assume your devices are compromised
101–110 of 197 posts
Re: Assume your devices are compromised
#102Earlier quoted context omitted.
I don't think it's so much "ugly truths people try and sweep under the rug" as "we do not yet appear to have a practical way to actually do anything about it without vastly reducing the usefulness of the system". There are ways to improve things a bit with your choice of sandboxing tech, but those are frequently either ineffective (oh good, an attacker who compromises can only get to my bank account, but not my SSH k…
> flatpak portals are cool so long as you don't mind manually approving all file access And by “manually approving all file access” you mean “opening the file in the file picker like normal”, right? There are some apps where using a file picker at all is awkward, but I’d argue in most applications it’s basically what you’d do anyway. Certainly most applications that non-developers would use. The bigger problem is tha…
Re: Assume your devices are compromised
#103Earlier quoted context omitted.
Just send four trusted family members half of the passphrase in a sealed envelope and tell them what it's for. If your family has a lawyer or safe deposit box trusting that instead is a 1000x better option.
Lawyer yes, safe deposit hell no. Three reasons: - Banks fubar safe deposit boxes all of the time, in a variety of ways. - Once the bank figures out that you’re dead, it’s sealed without a court order. - As you get older it’s more likely that you’ll screw up payments, lose keys or codes, etc. Also, the attorney will advise your loved ones on what they can do. For example, you need a power of attorney for many things.
https://www.nytimes.com/2019/07/19/business/safe-deposit-box...
Re: Assume your devices are compromised
#104Earlier quoted context omitted.
Yes but lastpass contains your password to something like your bank account. You don’t need your password for your bank account if you have a death certificate is what the poster is saying.
It can contain passwords to much more and other information
Re: Assume your devices are compromised
#105These are fun thought experiments, but I think having a personal Disaster Recovery plan is a far more applicable security exercise. What would you do if you lost your phone? If you were locked out of your google account? If you forgot your password manager master password? If your home was destroyed in a fire? Having a secure plan for quickly recovering from these scenarios is more important than trying to keep state…
Re: Assume your devices are compromised
#106These are fun thought experiments, but I think having a personal Disaster Recovery plan is a far more applicable security exercise. What would you do if you lost your phone? If you were locked out of your google account? If you forgot your password manager master password? If your home was destroyed in a fire? Having a secure plan for quickly recovering from these scenarios is more important than trying to keep state…
I just wrote up instructions for accessing my backups for my wife and friend, and my critical accounts have dead-man switches to give my wife access to everything she would need. Assuming what she needs is access to my email (yes) and gigabyte of photos from my drunk college days (no).
Re: Assume your devices are compromised
#107These are fun thought experiments, but I think having a personal Disaster Recovery plan is a far more applicable security exercise. What would you do if you lost your phone? If you were locked out of your google account? If you forgot your password manager master password? If your home was destroyed in a fire? Having a secure plan for quickly recovering from these scenarios is more important than trying to keep state…
yeah, I've been thinking a lot about it... Shamir Secret Sharing and splitting the shares in a way that makes sense to me have me piece of mind. I even wrote a trivial console app to let my wife restore my secrets if I were to drop dead tonight.
Re: Assume your devices are compromised
#108Earlier quoted context omitted.
All of my passwords are in the "pass" command line utility, where they're encrypted with gpg. I added my brother's gpg key as an encryption target, and his ssh key onto the sever where the git repo is stored, locked down to the git shell command. In the event of my untimely demise, my wife tells him the url of the git repo.
I personally wouldn’t go to the extent of using CLI tools, as my next of kins and family members aren’t at all technical. A printout of my 1Password emergency kit in a safe deposit box is probably doable, but then what - 598 passwords to projects on an old git repo on an ancient Synology NAS, or a throwaway account for some random website? There is probably a lot to be said to curate your accounts to assist those sif…
Things that need to stay secret. That's why they are secrets. If my passing means that these things are no longer accessible to anyone ever again? Perfect. Works as intended.
Re: Assume your devices are compromised
#109Earlier quoted context omitted.
It can contain passwords to much more and other information
Can you offer some examples, besides financial accounts, of things that a person would prevent others from accessing while alive and grant access upon death? In sifting through the list of things in my password manager, none of them (besides finances) seem to have this quality. Seems like anything that should be seen by family after death could be seen by them before death as well.
Re: Assume your devices are compromised
#110These are fun thought experiments, but I think having a personal Disaster Recovery plan is a far more applicable security exercise. What would you do if you lost your phone? If you were locked out of your google account? If you forgot your password manager master password? If your home was destroyed in a fire? Having a secure plan for quickly recovering from these scenarios is more important than trying to keep state…
I wish Google would sell me a letter mail with my Gmail recovery passwords on a nice durable laminated card.