Excellent way to make money :) Just run this service for a few years without actually encrypting the data, then charge $20/month to NOT release the information.
Dead Man's Switch
41–50 of 101 posts
Re: Dead Man's Switch
#4230 days seems long, but I guess if I am in a hurry I could set up 10 of them with 3 days in between so that it is always 72 hours out...
Re: Dead Man's Switch
#43This is something I've thought about, and as I see it a lot of the problems common to crypto software are manifest in this space as well. Specifically with regard to security vs useability/ease-of-adoption issues. This particular implementation transmits sensitive data in the clear and does the encryption server-side, so it's hard to take it seriously except as a remote (and unsecure) notification service. Aside from…
That party could be the dead man's switch service, but do you want to trust them? I wouldn't. (Nothing against the operators of this site. It's just inherently risky to trust a website operator in this type of situation.)
Alternatively, the key can be given in advance to the files' intended recipients via some secure channel. For example, suppose Alice wants Bob to receive the files upon Alice's death. Alice can deliver the decryption key(s) to Bob in person, electronically with PGP, or in some other sufficiently secure manner. But in this scenario, Bob has to know about Alice's deadman's switch in advance.
So I'm wondering: Is there any way to do this a) with encryption, b) without entrusting the keys to the operator of the service, and c) without informing the recipients in advance?
Re: Dead Man's Switch
#44Re: Dead Man's Switch
#45I wish there was a better way of determining whether you were alive or not. There's an endless number of possibilities as to what could happen in order for me to not be able to go online and verify with that link. Why would I put myself through the stress of potentially forgetting and now I have to worry about the secrets of my dying breathe being released to the public while I'm still around. If I wanted anything to…
Consequently anything that relies on a reply to determine if someone is still alive (even with notifying relatives) simply isn't going to end up solving the problem.
Re: Dead Man's Switch
#46This seems like a good option if I am ever in an action movie and I need to tell the bad guy that all of the information will be released to CNN and the NYT if anything happens to me. If I come up with something I can't tell my wife while I am alive, I will probably just put it in my will.
Re: Dead Man's Switch
#47This is something I've thought about, and as I see it a lot of the problems common to crypto software are manifest in this space as well. Specifically with regard to security vs useability/ease-of-adoption issues. This particular implementation transmits sensitive data in the clear and does the encryption server-side, so it's hard to take it seriously except as a remote (and unsecure) notification service. Aside from…
In any protocol, how would you manage the decryption keys? If the file's owner is dead, s/he can't provide the keys. So that means the keys must be transmitted to some trusted party before the owner's death. That party could be the dead man's switch service, but do you want to trust them? I wouldn't. (Nothing against the operators of this site. It's just inherently risky to trust a website operator in this type of si…
DMS #1 and #2 (Assuming there are several 'providers' in the 'market') would need to collude or both get hacked in order to compromise the secret.
If there are more DMS services, the key can also be split between them. And I believe there are some key-splitting algorithms that even help this process further.
Re: Dead Man's Switch
#48This is something I've thought about, and as I see it a lot of the problems common to crypto software are manifest in this space as well. Specifically with regard to security vs useability/ease-of-adoption issues. This particular implementation transmits sensitive data in the clear and does the encryption server-side, so it's hard to take it seriously except as a remote (and unsecure) notification service. Aside from…
In any protocol, how would you manage the decryption keys? If the file's owner is dead, s/he can't provide the keys. So that means the keys must be transmitted to some trusted party before the owner's death. That party could be the dead man's switch service, but do you want to trust them? I wouldn't. (Nothing against the operators of this site. It's just inherently risky to trust a website operator in this type of si…
Re: Dead Man's Switch
#49This is something I've thought about, and as I see it a lot of the problems common to crypto software are manifest in this space as well. Specifically with regard to security vs useability/ease-of-adoption issues. This particular implementation transmits sensitive data in the clear and does the encryption server-side, so it's hard to take it seriously except as a remote (and unsecure) notification service. Aside from…
One may say this is too complicated and the layman wouldn't know how to do this, but laymen wouldn't have the need for this. Anyone who is not satisfied with the given service, must have the power and will to change it to their needs.
Re: Dead Man's Switch
#50I wish there was a better way of determining whether you were alive or not. There's an endless number of possibilities as to what could happen in order for me to not be able to go online and verify with that link. Why would I put myself through the stress of potentially forgetting and now I have to worry about the secrets of my dying breathe being released to the public while I'm still around. If I wanted anything to…
A week seems like a short amount of time. If you're dead, we're not talking about safety here—urgency is less important. I think even a mail every month would be sufficient.