Live data from Hacker News

Dead Man's Switch

deadmansswitch.org

61–70 of 101 posts

Re: Dead Man's Switch

#61

This is an idea that has been around in various forms for a number of years. A number of other sites have popped up but like a number of people have already said, I don't trust random third parties with the keys to my online life.

Two keys, you put one on memory sticks which you give to friends/family you trust. In the event anything happens to you the other key is sent to those people allowing them to decrypt it. Service can't access your data as it only has one and same for trusted person. I'm sure something like this already exists (and tbh the level of effort required to set it up pretty much makes it unlikely to catch on) but it is theore…

For those of us who run FreeBSD, there's gshsec(8):

http://www.freebsd.org/cgi/man.cgi?gshsec

Want to set up a "2 of 3" (or similar) scheme? You could use, for example, a three-disk RAID5 using USB flash drives.

Re: Dead Man's Switch

#62
I like it. There should also be a "delete" feature in addition to notification. Sort of a self-destruct dropbox (in the generic sense) to contain your most private and personal data -- bits you want to "take to the grave" with you, so to speak. They only exist there for as long as you respond to the ping, otherwise they're deleted. Maybe it's already thought about by the creators, but it's not apparent in the description. My $0.02

Re: Dead Man's Switch

#63

I too have thought about this. How am I going to pass on my account information/bitcoins and other secret detective work? My idea was to open a security box in a bank that contained hand written keys to open an encrypted password store in some publicly accessible location. If I died, that security box should go to the next family members who would be the only ones that can get access to it. I fear there are loop-hole…

ever heard of geocaching? The idea is that you leave things hidden around the world with GPD coordinates and hints of the location and other geocachers will grab their GPD devices (or smartphones) and hunt down your cache based on the location provided and your hints. It's like a big scavenger hunt.

What if you looked up caching 'best practices' for how to safely store items for in the weather, then stashed your valuable information somewhere nobody would find it. Keep track of the location the same way you would a geocache, but obviously don't publish it publicly. Then all you need to do is leave the cache-retrieving information in your legal will and the right people will have access to it at the right time, and it's as safe from prying eyes as you're ever going to get in the meantime :)

Re: Dead Man's Switch

#64
post #28

Earlier quoted context omitted.

The form action for login appears to be https, but not the code... I don't know why people bother not just httpsing everything if they have the cert. It avoids these types of worries and appearance.

The form action for registration is not https. Also, they have nothing to prevent a MITM from changing where the form action goes. Why would anyone use this...

I see this:

						
							Email:
							
							Password:
							
							
							Create an account
						

Also, what does/can anyone do to prevent a MITM attack? Even if thy sent a HSTS header or a redirect, they're still subject to that.

Re: Dead Man's Switch

#65
post #11

Earlier quoted context omitted.

The form action for login appears to be https, but not the code... I don't know why people bother not just httpsing everything if they have the cert. It avoids these types of worries and appearance.

The cert is expired anyway.

I didn't even check. It expired in Jan 2013....wow I'm betting the project isn't maintained anymore?

Re: Dead Man's Switch

#66

Earlier quoted context omitted.

Wow! I had no idea. According to http://www.idanalytics.com/news-and-events/news-releases/201... > More than 15 percent of SSNs are associated with two or more people. More than 140,000 SSNs are associated with five or more people. Significantly, more than 27,000 SSNs are associated with 10 or more people.

Yup. It was stated over and over again that SSNs were not supposed to be a form of ID, but nobody pays attention...

I've always wondered how the SS administration deals with this. SSN _should_ be unique, but in practice they're not, so how do these people deal with taxes and _gasp_, social security?

Re: Dead Man's Switch

#67
post #27

I've thought about that service a lot and this solution is not working because : * I have to constantly check my mails to prove I'm not dead * The other person's mail will without any doubt change if I die in 10+ years * Can this service live up to 50+ years? I'm really doubting that as well.

At least the time limit is too long to use for Suicide-note-as-a-Service. If it were shorter, I would worry about that being the primary use case for something like this.

Re: Dead Man's Switch

#68
post #22

Earlier quoted context omitted.

Obviously the solution is a DeadManSwitchCoin.

I proposed this in an earlier thread and got some push back on the utility of the concept https://news.ycombinator.com/item?id=6509824

I think your sarcasm-meter failed you.

Re: Dead Man's Switch

#69

This seems like a good option if I am ever in an action movie and I need to tell the bad guy that all of the information will be released to CNN and the NYT if anything happens to me. If I come up with something I can't tell my wife while I am alive, I will probably just put it in my will.

What prevents the bad guy from torturing you until you disable the DMS, then kill you?

Any good DMS of that calibre can't be disabled. The operator must take upfront payment and not care if you die or not, only fulfilling a contract you can't go back on. Sounds like something a Swiss bank could do for you, if stereotype is to be believed.

Re: Dead Man's Switch

#70

Earlier quoted context omitted.

Two keys, you put one on memory sticks which you give to friends/family you trust. In the event anything happens to you the other key is sent to those people allowing them to decrypt it. Service can't access your data as it only has one and same for trusted person. I'm sure something like this already exists (and tbh the level of effort required to set it up pretty much makes it unlikely to catch on) but it is theore…

You don't need any keys. Just say "I wrote how to log into my email on a piece of paper in the safe deposit box. You may have found it already."

But that doesn't have enough points of failure!
Post reply on HN