Live data from Hacker News

Cheat sheet for if I'm gone

thoughtscollected.tech

161–170 of 194 posts

Re: Cheat sheet for if I'm gone

#161
post #99

Keeping your money in the bank means the executor of your will can usually get it through a straightforward process. Keeping your money in crypto means that, by default, it dies with you, unless you take special effort to ensure otherwise, and are willing to trust a solution you can't possibly debug because you'll be dead.

Depending on how much you trust your government, bank, and judicial system, inability for them to access your money after your death is a feature, not a bug, because it means they also can't easily block or steal it during your life. As people in China who have had their bank accounts frozen for months, and now their health status flagged red when they were planning to protest, are finding out, https://www.cnn.com/20…

It's also illegal to transact (but seemingly not to hold?) cryptocurrency in China, which makes it risky to use. You'd have to trust your counterparty not to leak your location to the authorities. https://www.weforum.org/agenda/2022/01/what-s-behind-china-s...

(A conspiracy theory I have no evidence for but might believe is that the US has been very tolerant of cryptocurrency and stablecoins for the same reason as China bans them: enabling capital flight from China to the US.)

Re: Cheat sheet for if I'm gone

#162
post #28

I'm banking on the emergency access feature [1] of Bitwarden (available in self-hosted version too [2]). The "how it works" section has more information [3] but it essentially boils down to trusted individuals requesting access - which can be manually approved by account holder or they are automatically granted access after a pre-defined wait time. Bitwarden (paid version) also claims this - "If your premium features…

That sounds like a lot of work when you can just write down your password somewhere safe?

Re: Cheat sheet for if I'm gone

#164
post #142
post #132

Check out Get Your Shit Together [0]. It was started by a woman who lost her husband in an accident, suddenly becoming a widow and single mom to two young children. She has abridged [1] and long checklists [2] that everyone should complete. Most of us probably don't even think about these things: - will - power of attorney (in varying forms) - what happens to pets - what happens to kids - money - burial/funeral wishe…

Any competent estate attorney will do this for you.

Indeed. It's not cheap, but it's mostly a one-time cost* and the big binder we have that covers all sorts of scenarios and contingencies offers us considerable peace of mind. If you have enough assets that anyone would bother fighting over them**, it's worth doing.

* Not including divorces or if you change how you want to do things.

** If you haven't been involved in settling an estate, that bar is probably far lower than you'd expect.

Re: Cheat sheet for if I'm gone

#165
post #78
post #43

Earlier quoted context omitted.

Can't it be handled e.g by the spouse having "half" the key, bitwarden the other "half", which they only gives out after the timeout. Ok, bitwarden and your "trusted one" can collude to open it before, but they must both be in on it.

Cutting a key in half doesn't halve its security, but it reduces it exponentially. 256 bits = 2^256 possibilities for bruteforcing 255 bits = 2^255 possibilities for bruteforcing, or half the security of 256 bits 128 bits = 2^128 possibilities, or 1/(2^128) the security But you can have encryption schemes requiring N-of-M private keys to decrypt.

You can cut a key in half without literally cutting it in half. Like: generate random 256bit number, xor with the key, and hand the random number to one party, and the xor'd value to the other party.

Re: Cheat sheet for if I'm gone

#167
post #162
post #28

I'm banking on the emergency access feature [1] of Bitwarden (available in self-hosted version too [2]). The "how it works" section has more information [3] but it essentially boils down to trusted individuals requesting access - which can be manually approved by account holder or they are automatically granted access after a pre-defined wait time. Bitwarden (paid version) also claims this - "If your premium features…

That sounds like a lot of work when you can just write down your password somewhere safe?

Where? And how to stop your spouse from spying on you? I suppose notification of "Login from new device" would be a tell. But that would also be a shitty situation if you end up in a fight.

The Bitwarden access request seems cool since it has a "quarantine period" where the owner gets notified of the access request and can deny it, if still alive (against a malicious spouse request).

If you're sure you never face the "malicious spouse" scenario, then sure, but how many marriages end up in divorce again?

Re: Cheat sheet for if I'm gone

#168
post #36

Earlier quoted context omitted.

This means that the time delay could be theoretically bypassed by someone other than you (as time delay access is not a cryptographic construction), which means that someone else has access today (likely Bitwarden the company), which means the end-to-end encryption has been circumvented to enable this feature, which means they could be issued a search warrant to yield all of your passwords to law enforcement immediat…

This is the paradox. You want trusted parties to have access, only when you are unable to access it yourself, in cases such as your death, or Alzheimer. But you _don't_ want trusted parties to be able to access this in case you are incapable due to being arrested, or choosing to simply elope.

Yup. If I were to use it I'd set it to something like 4 weeks, to be sure to cover most scenarios where I'm still alive.

Re: Cheat sheet for if I'm gone

#169

Earlier quoted context omitted.

FYI: Bitwarden premium costs 10$ a year!

Oh? Do we like it better than last pass?

I can't speak for everyone, but I made the switch after there was some drama with LastPass not reporting security problems in a timely manner a while back (https://news.ycombinator.com/item?id=29737973)

I had used LastPass for a few years, and begrudgingly started paying when they went the "desktop or mobile only" option for free accounts - I need both for complicated reasons. The switch made me pretty bitter with them over the whole thing. It was like I was tricked into trusting them to deliver one thing, then they started to charge me for the "privilege", with no tangible improvement to the service they were providing.

After I saw the thread and started to read up a bit on their past issues (https://en.wikipedia.org/wiki/LastPass#Security_issues), I was motivated enough to make the switch.

Personally, I've had nothing but great things to say about Bitwarden since moving over. The import from one to the other was pretty painless.

I still have to interact with LastPass for certain job-related things, and the difference is really very noticeable. Much easier to generate usernames and passwords in the web extensions on BW. Things are laid out a bit more logically, in my opinion. It also feels like BW signs in/loads significantly faster in the browser extension (I might just be imagining things). It just feels less cumbersome than LP is.

The only negative I can think of is that LP is a bit prettier to look at.

Re: Cheat sheet for if I'm gone

#170
post #18

Earlier quoted context omitted.

How do you know this website will last longer than you?

In the spirit of the OP, and finding an enduring solution... something like the deadmans switch should be implemented in a de facto utility like browser password recovery but extended with a weighted audience tied to the time elapsed. Why not have that same function that keeps up with your authentications notify X audience in Y time - 30 minutes even or 30 years with an emphasis on how perpetual. Reasonably I say we…

In the very least, if you use google, setup the inactive account manager...

https://myaccount.google.com/inactive

Post reply on HN