Slashdot Mirror


Ask Slashdot: How To Bequeath Sensitive Information?

New submitter UrsaMajor987 (3604759) writes I recently retired after a long career in IT. I am not ready to kick the bucket quite yet, but having seen the difficulty created by people dying without a will and documenting what they have and where it is, I am busy doing just that. At the end of it all, I will have documentation on financial accounts, passwords, etc., which I will want to share with a few people who are pretty far away. I can always print a copy and have it delivered to them, but is there any way to share this sort of information electronically? There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data. Does anyone have any suggestions? Is paper still the most secure way to go?

208 comments

  1. The Giver by Anonymous Coward · · Score: 5, Funny

    Find a young child to give all your memories to. Hopefully he doesn't run away after learning the horrible secrets of the IT world.

    1. Re:The Giver by cjestel · · Score: 3, Insightful

      Find a young child to give all your memories to. Hopefully he doesn't run away after learning the horrible secrets of the IT world.

      long time since I read that book.

      I use keepass to keep my passwords for various things encrypted on my systems. It works with windows, max, linux, android, and probably iphones. Then you just have one password to share and all of your information is unlocked. Send it to them in a secure fashion or come up with some sort of shared storage they can access (dropbox) so that you can update passwords as they need to change and then you can put your password for keepass in your will so they don't have access to anything until you die.

    2. Re:The Giver by Anonymous Coward · · Score: 0

      Yeah, same here... keepass2 with the database shared in Google Drive shared with different members of my family, the secret keyfiles distributed via scp to just the devices that use it, and the passphrases stored on paper in a big heavy firesafe.

    3. Re:The Giver by Anonymous Coward · · Score: 0

      So the people who know your secrets are you, your family members, Google, the NSA, and anyone else who runs to Google with a subpoena. Nice.

    4. Re:The Giver by Anonymous Coward · · Score: 0

      Only assuming the encryption done with keepass has a back door built into it, which I find unlikely.

    5. Re:The Giver by roc97007 · · Score: 1

      Same here. Used to use Secret (was a Palm Pilot user) but switched to Keepass.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    6. Re:The Giver by Anonymous Coward · · Score: 0

      Apparently you are too blind to see the part about the passphrases being stored on paper in a big heavy firesafe.

  2. Put it on a disc by techno-vampire · · Score: 1

    Put all of your files on a CD/DVD and mail it to them, with an explanation of what the files are. That way, the data's off-line until they need it and safe unless somebody breaks in who knows what to look for. And, if your friend's good at hiding things, it may still be safe. (As an example, put the disc in a DVD or Blu-ray case behind another one with a movie on it.)

    --
    Good, inexpensive web hosting
    1. Re:Put it on a disc by ed1023 · · Score: 2

      Yes but with the problems of archived CD/DVDs falling to pieces/ not being readable after 10 years this is not the best idea.

    2. Re:Put it on a disc by techno-vampire · · Score: 1

      It doesn't have to. Enough of the data will need occasional updating that you'll probably be sending a new copy every two or three years.

      --
      Good, inexpensive web hosting
    3. Re:Put it on a disc by Loether · · Score: 4, Funny

      (As an example, put the disc in a DVD or Blu-ray case behind another one with a movie on it.)

      It's funny, I do the exact opposite, I hide selected movies behind CD's labeled "Finance Data."

      --
      TODO create witty sig.
    4. Re:Put it on a disc by Anonymous Coward · · Score: 0

      Right. Until he goes senile and stops updating it. This is a very bad idea.

    5. Re:Put it on a disc by Anonymous Coward · · Score: 0

      Right. Until he goes senile and stops updating it.

      Right. Because for some reason, you won't be utilizing that disc if Grandpa Max becomes senile. You'll only need it when he kicks the bucket.

    6. Re:Put it on a disc by Anonymous Coward · · Score: 0

      >It's funny, I do the exact opposite, I hide selected movies behind CD's labeled "Finance Data."

      If you have to hide your porn, it's time to get the bunged up person or people out of your life. It's not normal to need to hide stuff.

    7. Re:Put it on a disc by ShanghaiBill · · Score: 1

      Here is what I do: I have a fireproof lock box bolted to the floor in my bedroom closet. My parents and siblings (all of whom live out of state) have the combination. If something happens to me, they can come and open the box, and have access to my will, trust documents, account information, passwords, etc., on paper and in digital format. The lock box also has backups of all the software I have written over my lifetime, decades of email archives, and thousands of photos, family movies, etc. The only information I have to give them is the six digit combination. It never changes, and it never goes out of date. I update the contents of the lock box with new backups at the end of every month.

    8. Re:Put it on a disc by roc97007 · · Score: 1

      I struggled with this for awhile, thought about the "pr0n pact" (good friends get together and decide that whomever dies first, the others will get on his machine and delete all his pr0n) but finally decided that anything I would need to hide from my family I probably shouldn't possess anyway. I think it was a good decision.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    9. Re:Put it on a disc by rjstanford · · Score: 2

      Even better - tell your lawyer. They have whole teams of people dedicated to solving this problem. Let them do the job that they're experts at and stop worrying about it.

      There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data.

      Yup. And when you give them money they may spend it on hookers and blow - or even donations to the Heritage Foundation or Greenpeace. You'll be dead. Once you've passed on the data and what it represents, its truly not your problem and no longer your concern.

      If it bothers you that much have your lawyers set up a trust instead. Again, let experts be experts.

      --
      You're special forces then? That's great! I just love your olympics!
    10. Re:Put it on a disc by L4t3r4lu5 · · Score: 1

      Why not just browse the adult web from an encrypted VM? Not only are you keeping your proclivities hidden, you're also protecting your system from the myriad of exploits pushed through these particular websites.

      --
      Finally had enough. Come see us over at https://soylentnews.org/
    11. Re:Put it on a disc by eggstasy · · Score: 1

      Or just use a Privacy Mode in your favorite browser.

      http://en.wikipedia.org/wiki/P...

    12. Re:Put it on a disc by Anonymous Coward · · Score: 0

      what about using the M-disc and M-disc Ready drive. They claim the discs last 1000 years.
      http://www.mdisc.com/

    13. Re:Put it on a disc by datavirtue · · Score: 1

      encrypt it and devlier the password over the phone

      --
      I object to power without constructive purpose. --Spock
  3. Time-tested by Anonymous Coward · · Score: 1

    Write a parable, and share it orally.

  4. Encryption by Anonymous Coward · · Score: 0

    There is this thing called encryption...

    1. Re:Encryption by roc97007 · · Score: 1

      I thought about that, but my daughter classically can't remember passwords she uses every day; there's no way she's going to remember a password she'll only need once.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    2. Re:Encryption by j-beda · · Score: 1

      I thought about that, but my daughter classically can't remember passwords she uses every day; there's no way she's going to remember a password she'll only need once.

      Then you WRITE IT DOWN. Then give her the piece of paper with it written down upon. Or give the encrypted files and/or paper with the password to one or more lawyer types to do the holding on for, if you want to really have it properly curated.

  5. Paper stored somewhere safe by Anonymous Coward · · Score: 0

    Even encrypted info isn't totally safe. From what I've been told, sensitive financial data like access codes, etc. should be stored somewhere disaster proof where your relatives know where to find it. You would think a safe deposit box might be the best way to go, but I've been advised not to do this. Apparently when the estate process begins, your associated safe deposit box access is frozen until the contents can be audited, before it's turned over to the executor. I guess this is a way to prevent people from stuffing $5M in cash in a bank vault somewhere.

    A will naming a *competent* executor is apparently very important. You need to pick someone who can make tough financial decisions and carry out exactly what the will says if the rest of your family starts fighting over your money.

    1. Re:Paper stored somewhere safe by roc97007 · · Score: 1

      I second the advice to NOT use a safe deposit box. In some states safe deposit boxes that have been untouched for a certain number of years (sometimes 15 but can be as low as 3) are declared "unclaimed items" and are confiscated by the state. There's been a few high profile cases recently. Burying a coffee can by the tree in the back yard may be a better idea. Or maybe a bus station locker. (At least, that's what they're always using in movies...)

      Banks are not safe places for long term storage.

      Regarding family fighting over my money after I'm dead. Bwaaaa hahaha. (wiping tears from my eyes) They'll be lucky if there's enough for cremation.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    2. Re:Paper stored somewhere safe by pnutjam · · Score: 1

      That depends on the state in some states a safe deposit box is the best place for a will and the law has special allowances to search for one. I think Pennsylvania is this way, maybe Indiana.

    3. Re:Paper stored somewhere safe by dcw3 · · Score: 1

      They'll be lucky if there's enough for cremation.

      Not saying that you haven't thought of this, but a lot of people don't...

      Most IT employees are covered under some type of insurance...Accidental Death & Dismemberment, and company covered life insurance. You've also likely got a 401k...I've met many people who don't know how much they have in theirs.

      --
      Just another day in Paradise
  6. Paper, and physical equivalents by Overzeetop · · Score: 1

    A paper record is good. So is a plaintext file well organized and placed on a USB flash drive. Both can be mailed and locked in a safety deposit box, which is about as secure as you can get. Both require physical access, which means any other encryption or security is more likely to confound your subjects than actually secure your data.

    --
    Is it just my observation, or are there way too many stupid people in the world?
    1. Re:Paper, and physical equivalents by almitydave · · Score: 1

      A paper record is good. So is a plaintext file well organized and placed on a USB flash drive. Both can be mailed and locked in a safety deposit box, which is about as secure as you can get. Both require physical access, which means any other encryption or security is more likely to confound your subjects than actually secure your data.

      In addition, you could encrypt the plaintext file with a well-known algorithm (you can even specify which one and the parameters) using a very strong password contained in your will, to prevent unwanted disclosure.

      You could then apply Base64 encoding to the encrypted plaintext file, and print the result in a large font to enable scanning and OCR to recreate the digital file and decrypt it. This should be reliable enough - I don't think any of these technologies are going to go away any time soon.

      --
      my, your, his/her/its, our, your, their
      I'm, you're, he's/she's/it's, we're, you're, they're
    2. Re: Paper, and physical equivalents by Anonymous Coward · · Score: 0

      Add some forward error correction and you will hate yourself less.

  7. Lawyer by Neruocomp · · Score: 2, Insightful

    Isn't that what lawyers are for?

    --
    Physics is like sex. Sure, it may give some practical results, but that's not why we do it
    1. Re:Lawyer by ColdWetDog · · Score: 2

      That's right. Use a professional for a professional job. Create a relationship with a decent lawyer (maybe the one who draws up your will), pay them some nominal fee. Use the system the way it was designed.

      If the world goes to hell in a handbasket such that the rule of law has gone by the wayside, you probably don't need all of those logins...

      --
      Faster! Faster! Faster would be better!
    2. Re:Lawyer by Jane+Q.+Public · · Score: 1

      Isn't that what lawyers are for?

      Yes, but... it depends on what your biggest concerns are. For example, are you more concerned about delivery, in the sense that you want to make absolutely sure the recipient eventually gets the information, or are you more concerned about "security", in the sense that you DON'T want it getting out prematurely?

      Here is a way to ensure both: strongly encrypt the data. Give your recipients at least two copies, to put in (separate) safe places. Then hire TWO attorneys, unknown to the recipients. Give each of them them a sealed package containing the names of the recipients, along with the encryption key and instructions for decrypting the data, to be delivered only after your demise. Put seals on the packages, and see that the recipients know what the seals are and how to tell if they're broken. But don't tell them who the attorneys are.

      It still requires that you put SOME trust in the attorneys. If you don't trust them as much as you'd like, then split the key in half and give half the information to each attorney. That way, if one of them is dishonest, maybe the other one won't be.

      There is no perfect way. But this one is pretty good.

    3. Re:Lawyer by L4t3r4lu5 · · Score: 1

      Encrypt and checksum the data you give to your attourney. Give your friend / recipient of the data the checksum to check for tampering, and the key to decrypt the data transfered to them by the attourneys. You now need only trust your friend.

      --
      Finally had enough. Come see us over at https://soylentnews.org/
    4. Re:Lawyer by quoob · · Score: 1

      But consider my recent situation: My mother entrusted her will and other important papers to her lawyer. After her death, I discovered the lawyer had died several years previously, and his widow sold the business, including my mother's documents, to another lawyer. After much investigation, I discovered the name of the second lawyer and managed to contact her. Once. For several months, I heard nothing and my calls were unanswered. Just as my own lawyer was about to begin a long and expensive process for settling the estate with a will gone missing (much harder than if there is no will at all!), I got a call out of the blue from the missing the second lawyer. She had taken sick and had been hospitalized in serious conditions for months. Within a few days she had located the documents and shipped them to me.

    5. Re:Lawyer by Kmatte81 · · Score: 1

      This sounds good in theory, but most law firms do not use any form of encryption for their email or data storage, so it is not that difficult for a hacker to get into your lawyers server and steal your information.

    6. Re:Lawyer by dcw3 · · Score: 1

      IANAL so this is just my $.02. Unless you have a complex plan for your will, or a significant (7digit+ size) estate, or expect that your will might be contested, an attorney is a waste of your time and money. Simple wills can be done, in nearly every state w/o legal assistance. It's no more difficult than formatting a hard drive in most cases.

      --
      Just another day in Paradise
    7. Re:Lawyer by nmr_andrew · · Score: 1

      I realize you're posting to the /. crowd, but do you realize how tremendously difficult formatting a hard drive is for most of the population?

    8. Re:Lawyer by Jane+Q.+Public · · Score: 1

      You don't need a checksum of what you're giving the attorney, because it's just the encryption key. If it's tampered with, it won't work. The recipients already have the encrypted data. And if THAT is tampered with, again it won't work.

      The only real issue here is keeping the attorneys apart from the recipients until your demise. For that, you can only trust that your attorney won't open the package and see who the recipients are. That's why I proposed splitting the key between two attorneys: you are doubling your chances of finding an honest attorney. (At the same time, however, you are at least theoretically reducing the odds of eventual successful delivery of the package.)

      But we've been trusting attorneys in this way for hundreds of years. I don't know a better way.

    9. Re:Lawyer by j-beda · · Score: 1

      This sounds good in theory, but most law firms do not use any form of encryption for their email or data storage, so it is not that difficult for a hacker to get into your lawyers server and steal your information.

      You would have the data on a drive unconnected to the network, and of course the password for the encryption is given to them on paper. If you are trying to guard against a dedicated group targeting you specifically, then of course more paranoia would be appropriate. The rest of us are not important enough to worry about that.

  8. Why complicate things? by Anonymous Coward · · Score: 0

    Hire a professional to write your will (and create a trust, if desired), and leave a copy with him and take a copy home. Leave a copy of the other information with your designated executor, as well as a copy at home (and maybe another copy in a bank safety deposit box, although it may be difficult for others to access after your death/incapacitation).

    1. Re:Why complicate things? by Em+Adespoton · · Score: 4, Informative

      This is the way to do it -- I've added one more step. My safety deposit box also includes a master password and a 1TB encrypted USB backup drive. Since the professional who wrote my will also advised leaving a copy in the box and registering that this is where the "official" notarized original is located, my executor will, by local laws, just have to provide proof of death and the copy of the will indicating they are the executor to access my box. Having the key (which they likely would) would help too.

    2. Re:Why complicate things? by Anonymous Coward · · Score: 0

      You just have to hope that the USB interface hasn't gone away in twenty or thirty years. Twenty years ago the equivalent was the (nominally) 3" floppy drive. As you are reading this, do you know where a floppy drive is that you could use, now? In twenty years, the USB standard will probably still be around in some form, but I'm confident your tablet, or phone or whatever your everyday computing device will be will not have today's common USB port. You'll have trouble finding a machine to read that old USB drive. Paper is still more durable and requires less hardware.

    3. Re:Why complicate things? by richy+freeway · · Score: 1

      You're assuming he's never going to update the storage before he dies. If he dies tomorrow, then it won't take twenty or thirty years for the will to be executed and the drive fired up.

      If he lives for another 10 years and another popular interface and storage format comes along then I'd assume (based upon the effort put in so far) that he'd replace the USB hard drive with whatever the next big thing is.

      So what was your point again?

    4. Re:Why complicate things? by Em+Adespoton · · Score: 1

      Exactly -- I've come to realize that storage format doesn't really matter -- what matters is keeping it current. In my case, that 1TB drive doubles as my offsite backup; it gets swapped out about every 3 months. I've already changed actual medium used 3 times since I started this; at the start, it was only essential files on a thumb drive, as hard disks weren't small enough back then to fit in the box.

      Another benefit of this is that even if my home computer gets scrubbed/sold/stolen/etc, all my passwords are stored on my keychain on that fully bootable drive. So the drive just needs a hardware-compatible computer to connect to and the appropriate password in order to access anything.

      Sure, some TLA could force the bank to open my box, retrieve the drive, and have access to my entire life plus full identity theft privileges... but then most TLAs can already do that without the hassle of involving a bank.

    5. Re:Why complicate things? by Em+Adespoton · · Score: 1

      Oh, for that matter: if you don't update your Will and associated documentation within 20 years, the contents are probably void anyway. Things change over time, and you need to keep that stuff current.

      Otherwise, your wife and kids may be a bit upset that you left everything to your mother and some non-profit that doesn't even exist anymore.

    6. Re:Why complicate things? by pnutjam · · Score: 1

      I am spinning up an offsite backup/archive company. I plan to offer annual data backup plans. I'll bill you and send you a flash device for your data, which will be loaded to a server that hashes it and uses some other processes to protect the data integrity.

      I am considering offering an escrow service where data can be released to a third party when certain criteria are met. The site is empty now, but check back to find out more, http://www.o2ark.com./

    7. Re:Why complicate things? by Em+Adespoton · · Score: 1

      I am spinning up an offsite backup/archive company. I plan to offer annual data backup plans. I'll bill you and send you a flash device for your data, which will be loaded to a server that hashes it and uses some other processes to protect the data integrity.

      I am considering offering an escrow service where data can be released to a third party when certain criteria are met. The site is empty now, but check back to find out more, http://www.o2ark.com./

      First off: sounds like a good idea.
      Second: It's going to need a LOT of work. I'm not going to send some random person a flash device with my data on it, even in encrypted form. The service is going to require not just escrow but a pretty heavy bond; basically, you're going to have to set yourself up like a bank. Then there's the issue of jurisdiction. If you're in the US, there's no way I'm going to trust my data to your server, when it's been shown that government WILL step in and look at things just because they can. Other countries aren't much better; they just don't have a Snowden leak. to back things up. Compared to this, fully offline safety deposit boxes have a ton of legal precedent to prevent third party snoopers.
      Third: You're going to be competing with data protection behemoth Iron Mountain. Are you up for that?

    8. Re:Why complicate things? by pnutjam · · Score: 1

      Yes, I'm targeting more of the low bandwidth households that can't back up to the cloud and those smart enough not to trust the crowd, but not educated enough to roll their own solution. I don't see an offering from Iron Mountain that caters to the new mom with 10GB of baby photos.

      Data security is something I will have to deal with. I think offline encrypted volumes will be pretty tough to snoop.

  9. No paper! by Anonymous Coward · · Score: 0

    You can do your part to keep things secure. However, it is the recipient's responsibility to ensure that it is safe on their end.

    Perhaps the one thing you can do is let your recipients know how important this stuff is to you, and likely for them. If the message comes across, they'll do their best to keep things secure.

    I happen to be great at these things, so if you'd like, I'd be happy to tell your recipients!!

  10. Possible... by retech · · Score: 5, Insightful

    You could send them an encrypted file (#1) now with all the info you wish to share with them. Along with a password for a file that will arrive when you die. Then set up a service like deathswitch.com and have another encrypted file sent to them (#2). The password they already possess unlocks #2 and that contains the password(s) for #1.

    1. Re:Possible... by Anonymous Coward · · Score: 1

      TrueCrypt

    2. Re:Possible... by dotancohen · · Score: 1

      Your sig is apt for the context.

      --
      It is dangerous to be right when the government is wrong.
    3. Re:Possible... by ZeroPly · · Score: 1

      You're reinventing the wheel. Public key cryptography allows a key to be split up, so that you need a minimum of X out of Y pieces to recover the key. Split the key into 5 pieces where 3 are enough to unlock it, and hand it out to lawyer, friends, co-workers, etc.

      --
      Support microSD: in a post 9/11 world, it is unwise to carry your data on media that you cannot comfortably swallow.
    4. Re:Possible... by Anonymous Coward · · Score: 1

      Not unreasonable, but too complex. Just give the data in a plain-text document to your attorney to be delivered upon your demise.

    5. Re:Possible... by Anonymous Coward · · Score: 0

      This is the only real answer here.

    6. Re:Possible... by retech · · Score: 1

      It works for anything.

    7. Re:Possible... by retech · · Score: 1

      Cheers. Just a thought, what if 3 of the 5 got together prior to death?

    8. Re:Possible... by theshowmecanuck · · Score: 1

      Hire Johnny Mnemonic.

      --
      -- I ignore anonymous replies to my comments and postings.
    9. Re: Possible... by Anonymous Coward · · Score: 0

      It seems the same as sending one password and deliver encrypted file after the death. Or other way around.

    10. Re:Possible... by ZeroPly · · Score: 1

      The idea is to separate the five, so that it would be impractical for all five to know each other or to break your trust. So for example, your dentist that you've gone to for 20 years, your lawyer, a trusted coworker, your wife, and your brother in China.

      Of course, the 3 and 5 are not magic numbers. You could make it 12 out of 13 if you're really paranoid. You could make it 5 out of 25 if you want very low possibility of your data being lost (for example a large earthquake).

      --
      Support microSD: in a post 9/11 world, it is unwise to carry your data on media that you cannot comfortably swallow.
    11. Re:Possible... by retech · · Score: 1

      Cool. I really didn't know that was out there. Very cool to know. Any recommendations on tutorials? Applications? etc...?

      Thank you.

  11. Safety Deposit Box by Anonymous Coward · · Score: 3, Insightful

    you can do what my grandfather did

    wrote up the entire list on paper form and electronic on a flash drive. He laced them in a safety deposit box and shared the key with his executor who in turn had a copy of his will.

    When he did pass away it was a pretty smooth process getting all of the information needed to close accounts, collect on policies, etc. The only thing that had a hiccup was property in a state with different probate laws but that too worked itself out.

    1. Re:Safety Deposit Box by selectspec · · Score: 2

      This is by far the best approach out of all of the recommendations. Obviously, sending paper documents (or USB drives) via overnight delivery is relatively immune to intercept, but what if you relatives leave the documents out in an unsafe area? The best place is a safe deposit box, along with any portable valuables (nice watch, jewelry, etc). You can arrange in your will to have your estate trustee then disseminate the contents.

      --

      Someone you trust is one of us.

    2. Re:Safety Deposit Box by azadrozny · · Score: 4, Informative

      Safe deposit boxes can get funny depending on state law. First don't ever put the will in the box. The executor will need that access the box later. Furthermore, it could take several day or weeks to get the authority to open the box after the person has died, so don't put anything in there that is time critical.

    3. Re:Safety Deposit Box by Anonymous Coward · · Score: 0

      Just be sure that the will is not in the box. Without the will you cannot prove you are entitled to open the box.

    4. Re:Safety Deposit Box by plopez · · Score: 1

      Give he the will and your executor a key to the safety deposit box with the will in it. In my area they cost about $10/yr, so having 2 or more is an easy option. One for the will and one or more for other purposes, e.g. one for the component which when combined with its 6 mates will open the portals of hell.

      --
      putting the 'B' in LGBTQ+
    5. Re:Safety Deposit Box by Anonymous Coward · · Score: 0

      I think you mean, "just be sure that the only copy of the will is not in the box." Give a paper copy to your lawyer, one to a trusted friend, and put one in the box. Tell each person about one of the other two, so that they can verify the other copies with their own. For added measure, you can put a file copy and hash of the text on a USB drive and repeat the previous step.

  12. Updated info periodically by dbarron · · Score: 1

    And...how are you going to handle updating information as you are forced to change your password for whatever reasons?

    I don't have a good solution...I wish I did. There's no reason you can't change your email password today and die before you can document it (which if you're like most people might be a week later).

    1. Re:Updated info periodically by Anonymous Coward · · Score: 0

      There's no reason you can't change your email password today and die before you can document it (which if you're like most people might be a week later).

      You could solve that by having the next password documented.
      Then once you change the password, you'd need to update the document: next password becomes current password, generate new next password.

    2. Re:Updated info periodically by fermion · · Score: 1
      Here is how this was kind of handled in an automatic case with me. I knew the password to the computer where all the credentials were stored, and access to the file cabinet where all the paper stuff was. All the passwords and information was stored in one of those two places.

      For an individual person that may not work, as there may be sensitive sensitive information that you don't want anyone to see. In that case consider a separate account on your computer with the information that everyone will need in an eventuality, and a separate account on your computer. where you can do stuff you don't want people to see.

      Here is my take on this. There is a lot of stuff that I don't care if no one every gets to close it. Most of my online forum acounts like /.. I expect everything on my computer to go with me. Creating data sets that are going to expire in a few months seems a bit over the top to me. The solution to this problem is to think about what people need, and assume they are going to have physical access to your stuff when you are no longer here.

      --
      "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
  13. stone tablets by ThatsDrDangerToYou · · Score: 2

    .. worked for me.

    1. Re:stone tablets by rastos1 · · Score: 1

      Moses ..., is that you??

    2. Re:stone tablets by Anonymous Coward · · Score: 0

      Moses was the reader...

  14. Analog degrades gracefully by Gothmolly · · Score: 1

    Ink may fade, paper may yellow, but should still be readable. Put it on a CD or USB drive, flip 1 bit, and you lose everything.

    --
    I want to delete my account but Slashdot doesn't allow it.
    1. Re:Analog degrades gracefully by RabidReindeer · · Score: 1

      Ink may fade, paper may yellow, but should still be readable. Put it on a CD or USB drive, flip 1 bit, and you lose everything.

      This is this concept known as Error Checking and Correcting code. The ECC encoding on disks can easily repair all single-bit errors and many multi-bit errors.

      ECC will not guarantee that if you make regular replications of your data that nothing will get lost. But it will make it mathematically very difficult for the copy process to introduce undetected errors. And if you catch the errors early enough, you should be better able to pull out a spare copy and repair the data manually before it propagates and expands.

      I'm for stone tablets myself. Problem is, paper or stone, it takes an awful lot of space to store a Terabyte's worth of data. And few of the ancients thought to add ECC to their writings.

    2. Re:Analog degrades gracefully by Kaenneth · · Score: 1

      Each letter in an english word only stores one bit worth of data on average.

      see: http://www.maximumcompression....

      And moist anjone can eaiily correc simxle errors automaxically while reeding in there heads.

      I'm sure mistakes were made while carving stone tablets, and they just said 'Fuck it, it's fine.'

      I was at a Pho shop the other day, with etched glass windows reading 'NODDLE SOUP' (in Comic Sans...)

    3. Re:Analog degrades gracefully by nctritech · · Score: 1

      "Moist anjone" accurately describes my emotions right now.

    4. Re:Analog degrades gracefully by Anonymous Coward · · Score: 0

      Using something like dvdisaster, you can burn a CD/DVD/BD with extra recovery information (either on the disk, or as a separate file)

  15. Document escrow is not new. by Anonymous Coward · · Score: 3, Informative

    Put the passwords, etc on a piece of paper. Put that paper in a large envelope. Give that envelope to a firm that does document escrow (many law firms will do this) with instructions on who should be given a copy after your death. Let your friends and relatives know who has your escrowed docs. They provide proof of your death, and everyone gets a copy.

    Why exactly are we reinventing the wheel here? This is old hat stuff. You don't need to trust anyone not to open their present early. Firms that do document escrow have better theft prevention techniques than anything you're likely to cobble together.

    If you want to go super fancy, use USB keys encrypted with a pre-shared password instead of paper. Then you don't really have to trust the escrow folks.

    1. Re:Document escrow is not new. by mlts · · Score: 1

      I do a similar version of this. I have a few document escrow services and a couple friends that have pieces of my master keys. It is a system that requires "x out of y" pieces to re-assemble the keys, so if one person is out, the key can still be recovered.

      I have a couple symmetric keys and a private key. That way, if RSA or ECC get broken, the core data is still protected until all the escrow places plop down their segment of the keys.

      To be safe, the key part and the SSSS (Shamir's Secret Sharing Scheme) utility is not just stored on an archival grade DVD and a USB flash drive, but also UUencoded and printed out (with a QuickPAR recovery record just in case.)

    2. Re:Document escrow is not new. by sexconker · · Score: 1

      Why exactly are we reinventing the wheel here? This is old hat stuff.

      Because self-important nerdulons think they're special or that things being done on computers or online somehow constitutes a separate reality.

    3. Re:Document escrow is not new. by bobbied · · Score: 1

      How about you just give the document escrow folks a one time use pad cypher and simply keep your "secure" documents encrypted using that pad. You can then "update" everybody electronically with an encrypted document that they cannot decrypt until they can obtain the one time pad from escrow.

      While you are alive, you need to protect your copy of the pad, but its not hard to invent some classy way to do that given that the pad has absolutely no useful information in it...Like using a your favorite MP3 or something...

      --
      "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
    4. Re:Document escrow is not new. by Anonymous Coward · · Score: 0

      Bruh, his porn collection, comixology account, and shitty short stories are gonna be worth their weight in GOLD when he dies.

      You don't just put those things out there where anybody with lax document security standards can photocopy them!

      Besides... the internet NSA PRISM DMCA Snowden Wikileaks Assange, and stuff.

    5. Re:Document escrow is not new. by j-beda · · Score: 1

      How about you just give the document escrow folks a one time use pad cypher and simply keep your "secure" documents encrypted using that pad. You can then "update" everybody electronically with an encrypted document that they cannot decrypt until they can obtain the one time pad from escrow.

      While you are alive, you need to protect your copy of the pad, but its not hard to invent some classy way to do that given that the pad has absolutely no useful information in it...Like using a your favorite MP3 or something...

      I think that using the one-time-pad to encrypt multiple items ends up leaking information if someone gets their hands on those multiple updates. Since you are sending out those updates to "everyone", that doesn't sound optimal. I don't know that this "attack" is particularly feasible however.

  16. yes by Charliemopps · · Score: 1

    Is paper still the most secure way to go?

    Yes.

    Specifically, paper, in a safe deposit box, and the key with a lawyer.

    1. Re:yes by Anonymous Coward · · Score: 0

      You mean like a will?

  17. 90 Days by Anonymous Coward · · Score: 0

    Won't all of your password information be obsolete after you change all of your passwords in 90 days?

  18. Yes, Paper by Anonymous Coward · · Score: 0

    I have tried to get my wife to use my Keepass database; she won't do it. She wants it all on a piece of paper. Most other people will too.

    1. Re:Yes, Paper by TheCarp · · Score: 1

      I tried to get my wife to use keepass too, she did do it.....changed all her passwords then.... forgot to save the file and her computer rebooted with windows updates. She called me at work rather upset and spent the rest of the day resetting her passwords.

      5 years later I am just now getting her warmed up to trying again.

      --
      "I opened my eyes, and everything went dark again"
    2. Re:Yes, Paper by Anonymous Coward · · Score: 0

      She changed all her passwords at once and forgot to hit save? That's pretty insane. LastPass might be a better solution for you/her then since you get prompted to update passwords and save passwords but don't have to remember to hit Save. Yes, it can also be used to store passwords that aren't used for websites, but that is its main strength. I probably isn't NSA proof, but neither is your home or office.

    3. Re:Yes, Paper by TheCarp · · Score: 1

      Total rookie mistake but, also a very common one. I have burned myself more than once not saving a document. Usually, it isn't all of my passwords.

      Actually keepass has an option to save after every change, it just isn't turned on by default.

      --
      "I opened my eyes, and everything went dark again"
  19. You can always read paper by Anonymous Coward · · Score: 0

    You can always read paper

    Print account information, passwords, secret question/answers and seal in an envelope. Keep copy with will in fire safe. Send copy to relative

  20. Skip technology by netsavior · · Score: 1

    Use Acid-free paper and just print it out. If you want to be more clandestine and secure, then print out the information about the accounts and the credentials in two separate places. Like for instance:
    Fed-ex the unlabeled passwords
    USPS the un-passworded accounts list

    The truth is, if you put it on a thumb drive, it might fail. If you put it on a CD it might fail (or 3 years from now, your grandma's iBookPro won't be able to read a CD).

    As humans, we read paper documents that were created 100 years ago. It is a reliable data mechanism that is predictable and will out-live you for sure.

    Plus it doesn't require that your executor be a cryptography nerd in order to make sure your wishes are followed.

    1. Re:Skip technology by eth1 · · Score: 1

      Fed-ex the unlabeled passwords

      USPS the un-passworded accounts list

      Actually, if you're mailing passwords, send the FUTURE passwords. Then once you've verified that the copies have reached the recipients unmolested, change the passwords to what you sent.

    2. Re:Skip technology by Anonymous Coward · · Score: 0

      If you want to be more clandestine and secure, then print out the information about the accounts and the credentials in two separate places.

      And if you want ultra-sekrit supar-sekur clandestine storage, write all the important information in homemade invisible ink: that's right, acid free paper + urine. Then just tell your executor, "bring a blow dryer to the reading of these documents."

      I heard this was way more secret than a simple fucking document escrow service that just about every estate lawyer on earth offers.

  21. Paper, lock, and key by ZahrGnosis · · Score: 1

    Write down everything in paper, then lock it away in a fireproof box or a safety deposit box (or both).

    I'm a fan of the phrase "we know how to secure a piece of paper". Not the sticky note taped to your desk that anyone can read and put back without your knowledge, but something really secure. You will know if your lock box has been stolen or broken in to; I would have no idea if someone broke into my e-mail or stole a file off of my computer or backup due to some weird exploit. If you want off-site safety, a deposit box is about as good as it gets with some assurance that no-one will go peeking. Let your close relatives and friends know where everything is so that when it is needed they can get to it, but they don't need access in the mean time if you have things you don't want them to know (or, you can give a copy of the key to someone if you want to... you have options, but you're still relatively safe in who accesses what).

    1. Re:Paper, lock, and key by Anonymous Coward · · Score: 0

      You will know if your lock box has been stolen or broken in to;

      Except by the Feds. And they'll forbid the bank from letting you know.

    2. Re:Paper, lock, and key by ZahrGnosis · · Score: 1

      That's the deposit box. The lock-box under your bed is going to be tough even for the feds.

  22. Do this (My solution) by cbelt3 · · Score: 3, Interesting

    I keep an encrypted online database of my passwords. Sort of. I use a 'modular' password. One word is different, the other is always the same. So in my will I have the same word (and it's l33t combinations) written down, along with the address of the database. So anyone dealing after my death will know ALL my codes. My wife of 30+ years also keeps a copy of it, and knows the super secret codes.

    I started this after being in a coma, and my wife having to deal with my PDA bleeping about meetings to her until the battery died. Which made her cry even more.

  23. Its *all* at risk by nurb432 · · Score: 1

    Once it hits the other side..

    --
    ---- Booth was a patriot ----
  24. Ask a Lawyer by Rob+the+Bold · · Score: 4, Insightful

    Even though the "ask a lawyer, not Slashdot" answer gets trotted out all the time, I think it's appropriate here. Lawyers do this sort of thing for a living. Probably cheaper in the long run to ask one.

    --
    I am not a crackpot.
    1. Re:Ask a Lawyer by azadrozny · · Score: 1

      Second this. There are a lot of state and federal laws to navigate here. It may not be necessary or appropriate for someone to use your passwords to access your financial information. You could land yourself in a heap of trouble if you access someones account after they die, even if you are entitled to the money.

    2. Re:Ask a Lawyer by bobbied · · Score: 1

      I'm with you on this one... Come up with $100 or so and pay a lawyer. After all, they got to eat too.

      --
      "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
    3. Re:Ask a Lawyer by Anonymous Coward · · Score: 0

      Lawyer I spoke to about a will wanted $3K, and she was cheap.

      Depends on what you're bequeathing, if you are of median means, or less, lawyers are a heavy tax.

    4. Re:Ask a Lawyer by Anonymous Coward · · Score: 0

      Arrange for them to meet the person in a lightning storm and say, 'Hey, you Marty McFly? I got something for you...a letter.'

    5. Re:Ask a Lawyer by Rambo+Tribble · · Score: 1

      Of course, you'd first need to find a lawyer you could trust. That's a task Sisyphus might quail at.

    6. Re:Ask a Lawyer by Anonymous Coward · · Score: 0

      >Of course, you'd first need to find a lawyer you could trust. That's a task Sisyphus might quail at.

      I've heard good things about 1-800-ASK-SAUL

  25. Lastpass by Allasard · · Score: 1
    http://lastpass.com/

    Put it in secure notes. Give them all the login/password.

    If they test it regularly, then have a locally cached copy if Lastpass goes belly up, which can be opened with Lastpass Pocket or whatever it's called now.

  26. Safety Deposit Box by richtopia · · Score: 2

    You still control it, yet it is remote and will be properly searched when you die. You can put a usb key in or some paper documents with the relevant information.

  27. How long? by jchoyt · · Score: 1

    How long do you expect this to last before it's needed? DVDs and USB drives are common, but I see DVDs heading out at this point. Paper has the advantage that in 40 years it'll still be readable. Of course if your passwords change you'll have to update this information anyway. Assuming you update passwords occasionally because of a) good practice or b) some company gets hacked, I'd send it electronically and encrypted, so the person needs to actually enter a password to get to the data. Unless the recipient gets a keylogger installed, you should be safe. A text file encrypted with pgp is good for the knowledgeable recipient. For someone less savvy, I'd send them an encrypted tiddlywiki. Obviously give them the password over the phone, in person, or via snail mail.

    --
    Sometimes the truth is arrived at by adding all the little lies together and deducting them from all that is known.
  28. I go old school by the_skywise · · Score: 1

    All of my financial info is with Quicken on my PC. Everything else related to teh intertube world is recorded on a textfile on my PC with the passwords being represented as a cypher. The cypher is a one or two word comment relating to the password phrase I use (which I, in turn, munge to be first letter of each word or some other pattern, yadda) I've got the username/password cypherlist stored on my smartphone as well (Because I can't keep up anymore) and the cypher key is kept only as a hardcopy along with a hard copy of the textfile stored in a fireproof lockbox in my home. (The textfile points out the key is in the lockbox too).

    I should probably just put the cypher key list in a separate lockbox (without any other username/account info) and geocache it to make it more fun for my heirs...

    1. Re:I go old school by RabidReindeer · · Score: 1

      You're in trouble, then. Quicken's file format is proprietary and unpublished. Your financial data is only as retrievable as Intuit allows it to be.

      Assuming Intuit is still around when your heirs need it and not gone the way of Ashton-Tate or other software institutions of yore.

      But, hey, what are your heirs going to do with your financial data anyway? Use it to settle your estate?

    2. Re:I go old school by Rob+the+Bold · · Score: 1

      But, hey, what are your heirs going to do with your financial data anyway? Use it to settle your estate?

      A surviving spouse might still want to pay the bills and track the investments.

      --
      I am not a crackpot.
    3. Re:I go old school by Oligonicella · · Score: 1

      If a surviving spouse needs that to know what the bills are, they haven't been very intelligent about things in the first place. Same for investments. For that matter, same for passwords.

    4. Re:I go old school by alexander_686 · · Score: 1

      I would tend to doubt that.

      Quicken, and things like this, are good at handling internal flow data. How much am I spending on overpriced coffee drinks? What is my internal rate of return on investments? Etc. This data is most helpful for a continuous, ongoing business. The wife continues to run the personal finances; the business partner continues to run the business. However, this kind of implies that these people had access, and were using, Quicken prior to the death. So no change there.

      On the other hand, I feel that the situation we are talking about represent "breaks" instead of "continuous" business. A new person enters the picture and inherits the assets. Normally they don't care what the deceased spent on coffee or what their old investments returns were. They might need prior knowledge of what is going on, but the normal course of action is for the new person to load the inhered data into their own accounting systems.

    5. Re:I go old school by Anonymous Coward · · Score: 1

      > Quicken on my PC.

      That's a terrible idea. Intuit constantly makes incompatible changes to the file format. It's such a hack that they are embarrassed to publish the format. When my father passed away, we were unable to open his files with newer versions of Quicken. The copy he had lost its activation so it was no longer usable. Intuit refused to sell us a copy of Version 6 for Windows which is what he used or version 2000 or older which they claimed would open the file. I had to buy an old PC on Craiglist to open it. That took me about three months of posting ads looking for old PCs that had Quicken installed, and I had to drive about four hours roundtrip to pick it up. Don't put your data in a dead-end, undocumented, and intentionally made obsolete file format. Unless you constantly upgrade, your files will probably not be able to be used. According to the Wiki page, Intuit has dropped support for 24(!!) different versions of Quicken in just the past decade.

    6. Re:I go old school by RabidReindeer · · Score: 1

      A lot of spouses aren't "intelligent". They don't know what the bills are and I happen to have one who doesn't even know where all my investment accounts are despite being required to sign off on the annual tax return.

      I don't use Quicken. I gave up on it because it didn't have the power to do things like handle non-ESOP stock antics. I use an open-source equivalent and the file format for it is well-documented. Plus it keeps multiple generations of backups automatically.

      I expect that should the need arise that still isn't going to help my spouse, but it won't be because the data isn't accessible or readable.

    7. Re:I go old school by alexander_686 · · Score: 1

      Which kind of speaks to my point. From my personal experience, the spouse (usually the wife) is going to adopt a new accounting system that they are more comfortable with. And my definition of accounting systems run from custom enterprise jobbies to the shoe box variety. All they need at that point are the last statements to update their accounts. Rarely is there a strong need to have access to the old accounting system.

    8. Re:I go old school by RabidReindeer · · Score: 1

      Tax audit?

    9. Re:I go old school by alexander_686 · · Score: 1

      For a tax audit, Quicken et. al. only helps you a little. It is just a program with imputed numbers. Who is to say that the inputted numbers are valid? Normally you want original documentation.

      There are expectations if you are running a business. Mileage forms, etc. Expect that if it is a ongoing business then the spouse / business partner would normally have access to the accounting system prior to death or would have access to the printed (or al least PDFed) year end documents that were generated. I mean you should not be preparing new tax reports for a tax audit - Those should be generated from the base data when the taxes and done.

  29. "long career in IT" by Anonymous Coward · · Score: 0

    Yet you ask if there is any way to share this electronically? If I didn't know better this smells like yet another made-up headline filler by Timothy without much thought put into it.

    1. Re:"long career in IT" by JazzLad · · Score: 1

      I call BS on the whole thing, "long career in IT" =/= UID over 3.5M

      --
      "If you have nothing to hide, you have nothing to fear." - Every fascist, ever
    2. Re:"long career in IT" by alen · · Score: 1

      long career of inserting punch cards into computers

  30. Throw it out by Anonymous Coward · · Score: 0

    I know you spent a lot of time on it and have a lot of great memories but nobody wants your porn stash.

  31. Bare-bones, secure laptop by da6s · · Score: 0

    Invest in a durable, compact laptop preloaded with Linux and only the necessary software to view the data. This should be fairly cheap because you won't need a WiFi card or ethernet port, nor a high-end graphics card. The bulk of the cost should be spent on a reliable hard drive. Once you have everything documented, encrypt the drive and stick it in a safe-deposit box next to your will. This way the data never has to be transported anywhere.

  32. Shamir's Secret Sharing and Encryption. by grnbrg · · Score: 2

    Pick a nice, long, secure passphrase. Use it to secure a GPG keypair. Back up this keypair in multiple locations, and with multiple people who know "This is the key that encrypts all of my digital stuff. My family will need it when I die.".

    Use that keypair to encrypt all of your important passwords and data. Back up the encrypted files in multiple locations. Make sure your family knows where these locations are, and why thy and the files they contain are important.

    Download a copy of http://passguardian.com/ . Load the saved copy (preferably in an offline PC) in a browser, and use it to convert your passphrase into several N of M parts. ie: Create 10 parts, and require at least 6 to reconstruct the passphrase.

    Use something like http://goqr.me/ (or any other generator) to create QR codes for the 10 secret shares. Laser print the text share, QR code and some instructions onto a business card sized piece of paper, and have them laminated.

    You now have 10 waterproof, hard to damage cards, any 6 of which will unlock your digital data. Distribute them to trusted parties and locations with instructions to use the shares once they hear and confirm your death. These parties don't have to be literate enough to merge and decrypt the data themselves, they just need to know that it is possible with their share. On your death, they will arrange to bring the shares and data together, and even if they have to hire a nerd to help them, they will unlock what they need.

    1. Re:Shamir's Secret Sharing and Encryption. by Mike+Van+Pelt · · Score: 1

      This. I've idly thought about this every now and then, and passguardian.com is exactly the tool I was thinking of.

      In my case, what I'll be distriubting is parts of my LastPass login and password, with the actual data stored there.

  33. Print it to microfilm... by Narcocide · · Score: 1

    ... then roll it up, stick it in a tiny airtight canister and cram it faaar up your ass.

  34. Weird questions... by carlhaagen · · Score: 2

    You state that you have a long career in IT, and at the same time you ask how to electronically hand over information generated within IT. Among those things, you even claim that you have passwords, meaning that they have been stored insecurly. This has "IT Janitor" written all over it, or possibly a concocted story.

    1. Re:Weird questions... by UrsaMajor987 · · Score: 2

      Nope, not a concocted story. A long career in IT; the last 19 years with a major international bank that took great pains to secure sensitive data both within the data center and in transit between data centers. The problem I am trying to solve is different. With the bank, we were sending sensitive data from one secured facility to another; what I need to do is send sensitive data from my (reasonably secure) home system to a location where I can not be sure of the security. How do I keep sensitive data secure in a remote location that is not necessarily well protected? At first I thought it would be easy; just use a password protected zip file and put it on DVD or USB. Send the media and password through different channels. But then I thought, what if someone gets curious and unzips onto their hard disk and leaves the files unprotected? The more I thought about all the possible scenarios for compromise, I realized plain old paper was the best solution. I was hoping there was some way of doing it electronically since there will be updates in the future but I could not think of any safe way of doing it via computer. The best solution suggested so far is to print everything out on paper and keep in a safe deposit box in the local bank. I can send the branch location and deposit box number to the siblings and since the paper is kept locally, updates should require nothing more than a trip to the bank. Kind of ironic that after all those years in IT and worrying about securing systems and data; I am reduced to using paper. Maybe I will seal the documents with wax and a ring :-)

    2. Re:Weird questions... by Anonymous Coward · · Score: 0

      What you want is DRM.
      What the recipient wants is not.

    3. Re:Weird questions... by Anonymous Coward · · Score: 0

      The solution to the transportation problem ("Byzantine generals problem") is encryption, with public key encryption solving the pre-sharing of keys difficulty. The remaining problem is twofold:

      Second, as you're aware, you can't be sure what the recipient will be doing with it. There really is no fix for this other than thorough training and earning your trust they won't do stupid things. Personally, I count "using windows" as a thing high up on the stupid list. Do you know what they're using? How well are they versed in avoiding malware and password stealers and such?

      First, though, is the general inability of people to deal with encryption software. It doesn't help that the interface to something like gpg is something only cryptonerds could love, even non-crypto nerds have trouble with it. So while the software can do what you'd like when used correctly, good luck getting a public key out of your recipients, as opposed to, say, their private key. See _Why Johnny Can't Encrypt_ for some insight in the matter.

      You can, however, delay the problem until after your death by withholding the key until then. Just hope they don't delete the encrypted data beforehand on the grounds they can't read it. I might use a public key and encrypt toward it, send updates encrypted to these people under an agreement that they'll be able to unlock the secrets upon your death, with the key as part of the will (say on paper, try "paperkey", or if that's too difficult perhaps just a really long password on paper as part of the will, key included in the updates, instructions in both) or perhaps spread out under some m-of-n scheme. Something like that. Sending out multiple copies to multiple parties is a good idea anyway. The upshot of using a public key is that you don't need to keep the private key to encrypt toward. Reasons why this is important left as an exercise.

      Though I have to say that your grounding in security isn't that impressive for someone with a long career with banking IT. Zip passwords are easily broken, and before that the archives already leak information. There are much better options available for free. You don't appear to be much good working with the relevant IT tools. Oh, and sealing wax doesn't protect against peeking. It can only show evidence of tampering, and that doesn't do you much good once you're dead. But it sure does look impressive. Is that what you're after, security by impressiveness?

  35. crypto! by Anonymous Coward · · Score: 0

    Archive and encrypt using a symmetric algorithm and a suitable passphrase. Take the passphrase and run it through a threshold system, also known as information dispersal algorithm, secret sharing, whatever. With this you can split the passphrase into five shares that require any three to reconstruct it. Then give the archive and a share of the passphrase to five trusted folks (friends, relatives, lawyers, whatever) with instructions not to give out the share until you are dead. Presto, as long as you trust three of the five folks to keep their shares a secret nobody can get your stuff.

  36. Encryption! by Mini-Geek · · Score: 1

    Encrypt the file with a secure password or key, maybe using AESCrypt. Email the encrypted file to the relevant parties. Put the password to the file in your will (keep it under appropriate trusted guard, to be released only on your death). As long as the will and the encrypted file are kept apart until after your death, the file will remain secure until then. You can also modify the encrypted file as things change, encrypt with the same password, and resend the file.

    There's still the possibility that their computer is compromised after you die and they decrypt the file. They could reduce this risk by opening it only on a known-secure system (e.g. an Ubuntu LiveCD boot), if it really matters. In any case, this greatly reduces the security exposure by not have this file sitting around for years for anyone to read.

    --
    do {print "Mini-Geek Rules!\n";}
    until ($TheEndOfTheWorld);
  37. gnupg by Anonymous Coward · · Score: 0

    In this way only the people for which you have signed the "document", for instance a archived/compressed file, can un-encrypted it using their private keys; it could not be simpler. Mind you however no matter how secure is the transmission of this data and its subsequent un-encryption it does not guarantee the parties you'll share your data with will not leave the un-encrypted document(s) in a non-secure system but i guess that is not what you have asked.

  38. Yes, paper. by ShaunC · · Score: 1

    Forget doing it digital. Your beneficiaries may have no idea how to decrypt something, or how to access whatever's become of some dead man's switch. Really, if I got hit by a bus tomorrow, even if I had things stored in quadruplicate across various flash drives, I'm not so confident anyone would know what to do with them.

    Type the important stuff up, and seal it in an envelope (or several, if you're dividing things up amongst likely heirs). Present those things to an attorney and have him draw up a will. The attorney will retain those envelopes and ensure that things are done properly once you're gone. If your very important passwords change, revise the documents and stop by the lawyer's office with new copies in new envelopes. They might not even charge you anything for that.

    I know we generally hate lawyers here, but this is one really worthy function that many of them can perform, and the courts know full well how to deal with written and physically signed documents. In the event that you outlive your lawyer, his or her office will retain custody of your will and your envelopes, or you can find a different lawyer.

    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
  39. Really? by Anonymous Coward · · Score: 0

    After being in IT for a "long career" you can't figure out how to encrypt a file and email it to people or better yet use a shared cloud storage that you can put your heavy encrypted file on that you can easily update at your own whim and they all get that copy instantly.

    If you do not want them to have the decryption key, put that tidbit in your will to be handed out at the reading.

    Where did you work in IT, Best Buy?

  40. I got it by necro81 · · Score: 2

    Take pictures of all the documents and send them via snapchat. Isn't this the kind of application it was made for (restrictred permission viewing)? It's, like, toooootally secure.

  41. ive used a time tested solution. by nimbius · · Score: 1

    Many of the 'knowledge share' sessions ive taken part in have requested my notes and musings on the technologies ive handled. Cryptography is the most logical means of securing this data as we all know, but the method by which one achieves this should be carefully followed.

    1. Choose a cypher whos strength is measured in the number of heat deaths of a cruel gods distant universe. Many will suggest a 256 bit cypher, but dont let that stop you from pursuing the correct size, a 256 megabyte cypher.

    2. passwords for archives and files should be sized accordingly as the md5 sum of the number of office parking spaces multiplied by the number of empty toilet paper rolls in the nearest bathroom to the largest conference room. the password must only contain characters whos hexadecimal value falls between the number of chairs warmed by the morning sun in the main lobby, and the number of lights in the break room that flicker when first turned on.

    3. You can never be too careful with USB drives. potting has long been a method of deterrence for unauthorized reverse engineering, but many dont know that a far more economical means of securing your USB data is to plunge it into an identical reproduction of a fifteenth century hessian crucible on the first blood moon of Rajab, the holy month of Allah.

    4. your paper trail should be auditable, and the business should know to whom you've shared information in order to determine future knowledge owners and process managers of your data. a CMS like system (similar to sharepoint) can easily be constructed by liberally dredging your paper documents and binders in a mixture of polychlorinated dibenzodioxins and low-yield fissile byproducts. the checked out or viewed copies will then be easy to track using simple FEMA disaster response processes.

    and congratulations on your retirement! give yourself a pat on the back because you deserve it. I hope my tips help you achieve a smooth and manageable transition.

    Regards,
    BOFH

    --
    Good people go to bed earlier.
  42. Few options by tyggna · · Score: 1

    So, what I would do is pick a few passphrases that are long and cryptographically secure. Print these out and store them in a safety deposit box, bequeathing said box to whomever you want to give this information to.

    From there, the linux command-line utility gpg will work nicely.

    gpg -c filename

    Will prompt for a passphrase twice (use one on your sheet), and output "filename.gpg" leaving filename still in tact.

    From there, you can do whatever you want with the encrypted file--store it on a USB and put it in the safety deposit, email it, whatever. No one will be able to do anything with it until they have the passphrase.

    The other way I'd do that, which is more of the day-to-day stuff, is create two bitmessage accounts and just send it via that.

    PGP encrypted email is also a good way to go, so long as the recipient has their private key properly protected.

    1. Re:Few options by Overzeetop · · Score: 1

      Simpler version: put the data in the safety deposit box.

      No need for linux, or command lines, or encryption, or anything else. The only advantage to the encrypted file is that you don't have to get off your ass to make changes (i.e. put the updated data in the SDB).

      Because, let's face it, as soon as the SDB is compromised, your entire security system is compromised. It's just a matter of time and computational effort at that point. And the risk is that the person who needs the information will not be able to access your information due to an error, or simple inability to work the technology. Anyone who is "after" your precious data will have the wherewithal to decode your stuff, but Aunt Matilda or cousin Jeb may end up just stuck.

      --
      Is it just my observation, or are there way too many stupid people in the world?
  43. private key? by Anonymous Coward · · Score: 0

    why not send them just the private key for something that you keep in your possession? it sounds backwards, but you can change the contents anytime, and they can't access it until the file is taken from your cold, dead hands.

    also, make sure no one steals the file. ; )

  44. BETA IS STILL THERE? by Anonymous Coward · · Score: 0

    Unbelievable, and when you click "goto classic" you go to the homepage instead of the story link you clicked.
    Dice has a total disrespect to their users, fire everyone who is in charge of this mess.

    1. Re:BETA IS STILL THERE? by Anonymous Coward · · Score: 0

      I wish to place my fetid pregnancy rod into your rancid, worm-infested Bayer aspirin hole. What say you? What say you?

      What say you? What say you? What say you? What say you? What say you? What say you? What say you? What say you? What say you? What say you?

  45. The old fashioned way by jeffmeden · · Score: 1

    You will die exactly once (barring a zombie apocalypse, in the event of which I am going to disavow any credit for this post) so why reinvent the wheel if it's only going to get one turn anyway? Hire a reputable family lawyer, set up a will detailing your important documents (and whatever else you are giving away), name an executor, choose a safe place (in meatspace) for the documents to live in the meantime, and then enjoy your retirement.

  46. You have no control by DerekLyons · · Score: 1

    There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data. Does anyone have any suggestions? Is paper still the most secure way to go?

    You have no control of what happens once the data leaves your control - whether the data is held and transmitted electronically or held and transmitted physically.

    That being said, though IANAL*, it seems that it's your executor who needs the data rather than people "pretty far away".

    * And really, when it comes to drawing up a will, there should be one involved. It'll save everyone involved a whole ton grief in the long run if you set things up right in the first place.

  47. Would be honored to serve your needs by Anonymous Coward · · Score: 0

    Dearest Sir:
    My name is William Saweto and I represent the First Security Bank of Nigeria. My employer and I would be honored to handle your business. We guarantee secure handling of private data in our protected cloud environment. I would be honored to discuss this matter further with you. Please feel free to contact me at any time at nota419@gmail.com.
    Yours truly,
    William Saweto, MBA, MSc, PhDBanking, KoC Fellow

  48. encrypted file on flash drive by Anonymous Coward · · Score: 0

    I carry my financial information and rarely used passwords on a file on a USB flash drive. I then use Winzip to encrypt it.

    1. Re: encrypted file on flash drive by Anonymous Coward · · Score: 0

      My approach is basically similar: encrypted 7-zip archive. Eventually I realised that putting it in my DropBox folder would be simpler than carrying around a USB drive, especially since it keeps the copies on all of my devices synched. I still keep a copy "offline" in another folder just in case DropBox goes berserk and decides to delete the file from all my devices, or somehow it gets truncated at 0 bytes and that gets synched across all my devices (DropBox does keep previous versions, so I could probably get it back still).

      Beyond that, the question is really, how will my surviving relatives access my DropBox, and how will they get the password to that archive.

    2. Re: encrypted file on flash drive by draxbear · · Score: 1

      Setup automated "are you still alive?" checking with http://www.deadmansswitch.net/ Have it email your password if you don't respond to a few checks in a few months. In lieu of the password, enough clues for family to reconstruct it if you're worried about these guys seeing it should do the trick. E.g First pet name + second pet name + wedding anniversary + favourite color etc etc.

      --
      --- I've completed diagnosis of your problem and can classify it as a YOYO...You're On Your Own
  49. Get over yourself by Anonymous Coward · · Score: 0

    You had a career in IT, not international espionage. You're also not a billionaire. Get over yourself and talk to a probate attorney.

  50. not binary by Tom · · Score: 1

    1: Talk to a notary.

    2: Digital methods can and will fail. Either on your end or because the recipient doesn't know how to use them properly.

    Talk to a notary. These people have been handing over sensitive information about bank accounts, secret swiss safe deposit boxes and other stuff from one generation to the next for centuries, and you have a human who can work around any failures.

    Sure, you can find 10 possible digital solutions on the pages of Applied Cryptography, but... goto 2

    throw new Exception("you failed to follow the goto");

    --
    Assorted stuff I do sometimes: Lemuria.org
  51. Fidsafe by aprentic · · Score: 1

    One of our clients does exactly this.

    https://www.fidsafe.com/

  52. why doesn't blueray have better ECC by Wycliffe · · Score: 1

    I've never understood why blueray didn't fix this. Blueray has plenty of space now. Screw higher definition, I want
    a disk that I can scratch 12 times with a razor blade and still get my data off. My guess is the only reason they
    haven't done this is because they want the disk to only last a half dozen times before starting to degrade so you
    have to buy the movie again.

    1. Re:why doesn't blueray have better ECC by Anonymous Coward · · Score: 0

      You can implement this yourself, dipshit. Start reading.

    2. Re:why doesn't blueray have better ECC by Wycliffe · · Score: 1

      This may or may not be possible with a disc I burn myself. I'm not sure how well optical readers handle large catestrophic errors
      and whether they can get anything off a disc with 50% damage but implementing it myself is not even an option when buying and/or
      renting dvds and bluerays. It's probably one of the reason blueray sales are falling faster than expected. Streaming quality sucks
      but even with the occasional buffering you still get to watch the whole movie. I can't tell you how many times a movie I've rented
      skips 10 minutes of the movie because of a minor scratch.

    3. Re:why doesn't blueray have better ECC by Anonymous Coward · · Score: 0

      FWIW, the error coding in Blueray is better than the one in CDs which was already very good. Apparently for CDs it could lose 2.5mm of data and still decode it. According to wikipedia at least, most errors with CDs are because the read-head loses track of where the data is (tracking error), not that it can't correct the errors...

    4. Re:why doesn't blueray have better ECC by Wycliffe · · Score: 1

      Thanks. I had guessed as much. So the drive technology becomes the limiting factor as you
      need something that can stay in the right "groove" when it encounters a scratch or be able to
      jump over it and find the rest of that ring.

  53. Arrrr matey by bukowski90210 · · Score: 1

    Have we not learned anything from Sid Meier? Bury it on a deserted Caribbean island, draw a crude map with a red 'x' marking the approximate spot where your treasure is buried, then go to some bar on some other island and get really drunk and leave the map there with the bartender. Yarr..petarrr!!

  54. You don't need a tech solution by BrodyVess · · Score: 1

    You need a *legal* solution. This is something you should be talking to a layer about, and not /.

    --
    No one expects the Spanish Inquisition!
  55. You need a 3rd Party by Anonymous Coward · · Score: 0

    The proper way to do this is to hire a law firm to handle your estate and they hold the intellectual property until your passing at which time they seek out and deliver the goods. You can create a rather long list of succession this way, and ensure that no matter who else passes your data is relatively secure. (Imagine a scenario where you transferred the information on to someone, who then passed away and the information was handed to his/her next of kin before your passing, someone who may not know you or have the same intentions)

  56. This is what lawyers are for by Anonymous Coward · · Score: 0

    No need to reinvent the wheel. Spend a small amount of money and consult a competent lawyer.

    They do this for a living and unlike you (and everybody else who isn't an actual legal professional) they understand the ins and outs of the law. This can matter a hell of a lot when dealing with stuff like wills and estates.

  57. It's already done for you... by Jawnn · · Score: 1

    If you "memories" have ever traversed a public network. Your tax dollars at work.

  58. First of all by WormholeFiend · · Score: 1

    Solve the problem of motivating someone to do your will after you're dead.

  59. Just Don't by 0xG · · Score: 1

    but is there any way to share this sort of information electronically

    Write it by hand.
    Photocopy it on an analog copier, or if you can't find one, use carbon paper.
    Send it by post.

    Safer than any encrypted email.

    --
    A pox on web designers who feel that window.innerWidth == screen.availWidth
  60. Discrete hardware by spire3661 · · Score: 1

    I jsut picked up a HP 7", 16 GB jelly bean android tablet WITH 4G radio and SIM for $120. Intel NUCS are $200 with RAM and the OS on flash. Raspberry PI, BeagleBones, Intel Gallileo, Arduinos equipped with SD slots. Put your data on discrete hardware, and have at it.

    --
    Good-bye
  61. Probate. by Vellmont · · Score: 1

    The MOST important part is documenting where your assets are, and account numbers. After you die, your assets go into probate, and aren't just simply accessible via logging into your bank. So the username and password isn't really as important as you think it is.

    Seriously, talk with a lawyer who's familiar with inheiritance in your state. Obviously documenting where all your assets are is very important, but don't just assume your loved ones are going to login to your account and transfer money out of it a few weeks after you're dead. That stuff gets locked into probate as soon as the financial institutions hear you're dead (with a few exclusions of course).

    --
    AccountKiller
  62. Another silly headline... by Anonymous Coward · · Score: 0

    No one has property rights in information ... and that means information cannot be "bequeathed"!

    It can be TRANSFERRED upon your DEATH. Put it in the hands of someone you trust, who will see the foot-shaped dent in your bucket.

  63. Post-mortem API by everyplace · · Score: 1

    I registered deathapi.com a while ago, after an acquaintance passed away, for this reason specifically. At the time, I had imagined a system that you OAuth against w/ all of your relevant accounts w/ full admin access, and specify a recipient of those keys after some pre-determined length of inactivity (a year, say). The idea still has a lot of relevancy in my mind, but it's so morbid to think about.

  64. Safety deposit box by Anonymous Coward · · Score: 0

    Print it out in plaintext on paper and put it in a bank safety deposit box. The executor of your estate will get access to the box after you die, and the executor is the one that will need that information.

    Very few people are capable of running encryption software successfully, so if you use that you are reasonably assured that your passwords will be lost after you die.

  65. Cleaning up a financial mess by Anonymous Coward · · Score: 0

    A more challenging problem than many posters think.

    Sometimes, an old person passes away alone. Their only surviving relatives (and friends) may be elderly, with no computer experience. The lawyer who drafted the will may be out of the loop, and the executor of the will may not get informed of the death. The probate court likely doesn't care,

    I worked with a forensic accountant, hired by the executor, to clean up the estate of a fairly wealthy widow. She had died with a will which hadn't been updated in 30 years. It was necessary to search out distant relatives, two of which knew nothing about the her (these people are called "Laughing Heirs")

    Her financial paperwork was quite undocumented - she kept records in a shoeboxes, and only one shoebox was found after her death - the others apparently were discarded or lost in the shuffle. The main way that we figured out her net worth was to wait for annual statements & tax papers to arrive in the mail. Closing her estate took over a year.

    If her accounts had been online and tax forms filed online, we would never have seen this, and those accounts wouldn't have been caught and distributed.

    Throughout this, we were meticulously honest, and determined to get everything. This took far more effort than I expected. There were places where a dishonest person could have ripped off her estate, and plenty of opportunities to take shortcuts which would have lost money for the estate.

    Lessons that I learned:
      1) Secret passwords and encryption are a total blocker to a computer-incompetent. Lawyers, judges, and probate clerks are computer incompetents. An elderly accountant won't know how to use a linux shell account, even if given a password.
              So: Absolutely draw up a will. Make sure that it includes a listing of all your bank accounts, stocks, etc. Be sure to list all your relatives & friends, and include their addresses, phone numbers, emails, and facebook pointers. And yes, include your own email account and password.
      2) Your information seems really valuable to you. But when you die, the only things that probate court will consider is
              - living relatives
              - obvious financial assets
              - real estate
                        Things like online information, login passwords, bitcoin purses, and intellectual property, will be ignored unless you explicitly call 'em out in your will, and indicate that these things have real value.

    Don't assume that an intelligent, computer savvy person will be available.
    Rather, assume that a busy, harried, computer illiterate friend-of-a-lawyer will spend less than an hour pawing through whatever records can be found in your top desk drawer.

    In short, write your will the same way you write your source code, with detailed, easy to follow instructions.

  66. afternote.com by noblestreet · · Score: 1

    Hi UrsaMajor987, I just read your post and wanted to let you know that we have setup a service that's tailored to your question, Our service is called Afternote. Like you we had this same issue of not having a way to save wishes and important information. You can start a free account on www.afternote.com. If you have any questions or good feedback you can always contact me. Kind regards Arnaud

  67. How I Am Doing It by DERoss · · Score: 5, Interesting

    First of all, I assume you are serious and not trolling (as some others who replied have asserted).

    My son died in April of 2013. He lived with cancer for four years and then took four months to die. During that time, he ignored my pleas to create an estate plan with an attorney. I am still trying to unravel his estate. Divorced and without a will, his son (my grandson) is his sole heir. My grandson is 6 years old. After my son died, it was too late to create a trust for my grandson. Instead, I had to go to court (several hundreds of dollars in court fees, legal fees, and even appraisal fees) to be appointed the guardian of my grandson's inherited estate. (His mother is the guardian of his person.) I will then have to return to court every two years to report on the status of the guardianship. In the meantime, NO ONE had authority to pay my son's final bills. It took seven months after my son died before I had legal authority to collect his credit union accounts, IRA, Roth IRA, and multiple 401(k) accounts, by which time several bills had already been sent to collection. All the legitimate bills have now been paid, and all known assets have been collected (the last, just a week ago). In July, I will transfer the balance of my son's estate into my grandson's guardianship. That will not end the hassle as I will have to report the status to the court for the next 12 years.

    I am thus on a campaign that every adult needs an estate plan. Even if you have no heirs, even if your estate is small, you need to provide binding instructions on how to handle your assets after you die.

    Before my son started actually dying of cancer, my wife and I started a complete overhaul of our own estate plans. With the exception of our IRAs and Roth IRAs, all our assets are in trusts. We each are the other's beneficiary of the IRAs and Roth IRAs, with the trusts the contingent beneficiary. The trusts require two trustees, currently my wife and me. If one of us dies or becomes incapacitated, the replacement trustee is already identified in the trusts. When we are both dead, the replacement trustee must appoint another trustee to have two. CONTINUITY IS VERY IMPORTANT. Our credit unions, bank, and mutual fund group all have copies of the relevant portion of the trust documents to ensure they accept this continuity.

    Now for the original question: In California, where my wife and I live, a bank safe deposit box is NOT sealed if one of us dies. The box remains available to the other persons who are listed at the bank -- with their signatures -- as having access to it, which includes our daughter and will eventually include our replacement trustee. The complete original documents for our estate plan are in the safe deposit box. Right now, I can see a ring binder with a copy. The replacement trustee has a copy. A list of all our accounts is in the safe deposit box. An inventory of our mutual funds (IRAs and Roth IRAs) is in the safe deposit box.

    In a sealed envelope in the safe deposit box are a floppy disc, a compact disc, and a printout of my OpenPGP public and private keys and my OpenPGP passphrase (the latter otherwise exists only in my brain). (I chose three media since I have no way to predict what formats might become obsolete before I die.) That envelope also contains a list of all my important Internet passwords, which are encrypted on my PC.

    I have an unencrypted list on my PC titled "Where Is It?" that describes where everything should be found: checkbooks, bank statements, insurance policies, durable powers of attorney for health care, mutual fund statements, deed to our house, etc. When I update this list, I E-mail a copy to our daughter; another copy is in the ring binder with our estate plan. Also in the ring binder is the paperwork for our purchase of burial plots.

    1. Re:How I Am Doing It by Anonymous Coward · · Score: 0

      That sounds reasonably thorough. If you have an extensive collection, say of model trains, add a catalogue with appraisals for ease of liquidating, should your heirs prefer that. It at least helps ensure the value doesn't vapourize that easily, and comes in handy for insurance.

      You could add a usb key on a neck chain to the list of things storing the papers, though I'd at least encrypt them. Some people wear their medical history and tax papers this way. I also hope you encrypt those email updates. Electronic stores also should be encrypted, or at least kept thoughly offline.

    2. Re:How I Am Doing It by xplosiv · · Score: 1

      So how did you learn about all of this? Do you do this for a living, or did a lawyer help you figure this out? I'd like to do something similar, so my wife doesn't have to deal with anything should something happen (she already has access to my passwords if needed, mostly concerned about financials, house, etc.).

  68. gpg / paper by Anonymous Coward · · Score: 0

    Not so hard. Put all your passwords, sensitive account details etc. in a text file, gpg it with a good long complex password, burn the data to a CD, write the good long complex password in your safe or bank vault or whatever.

  69. There's a great blog post about this by Anonymous Coward · · Score: 0

    http://www.moserware.com/2011/11/life-death-and-splitting-secrets.html

  70. um, cd? by roc97007 · · Score: 1

    My stuff is on a CD in the bookcase.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  71. Should you even do this on your own? by plopez · · Score: 1

    FTA, "At the end of it all, I will have documentation on financial accounts, password, etc."

    It sounds like you are documenting sensitive company or client information. As such it is beyond the scope of you as an individual to place any of this information in a private store. You need some sort of formal business procedure for this. One place I worked THE COMPANY had safety deposit boxes. At another we would put emergency back up passwords in an envelope and give them to the administrative assistant who would keep them under lock and key in case I and/or others were killed e.g. on vacation. The company owners and managers knew about it and it was part of our policy.

    If you are removing sensitive information from a company network and storing it somewhere in you personal control, you are looking for trouble. If there is a breach you could be personally liable either civilly or criminally. Do I what I did and make sure that there is a documented policy and attendant procedures, and follow them.

    --
    putting the 'B' in LGBTQ+
  72. on computer by roc97007 · · Score: 1

    There's a file on my computer called "for my daughter". It's got everything she needs to know. Also backed up on a CD in the bookcase.

    Besides the required stuff, I used the opportunity to also wax long and poetic about my life and how her life changed mine, and wrote about all the interesting things about her childhood that I could remember. Included words of (hopefully) wisdom. I don't remember where I got the idea from, but since I was writing everything else down, decided to include that as well, so her last memories of me wouldn't be dry facts and figures.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  73. Why? by nospam007 · · Score: 1

    Why on earth would you want to tell anybody the passwords for your financial stuff? Just to save them some bad traffic?

    If you die and they access it after the fact, they'll go to jail.

    They'll just have to go to the normal system, walking to the bank with a court order respecting your will from your lawyer or whatever else to prove that they inherited your money legally.

    Unless it's just to change your social networking status to 'deceased' they won't need any of those.

    Now if you had a 1 -3 figure slashdot account, that would be another thing, they could sell that for 20 bucks to a newbie.

    If you have illegal funds hidden from the IRS stashed in the Caimans or Switzerland, it's just gone.
    Bury your stuff in the backyard, like normal people.

  74. Keepass by rootmon · · Score: 1

    Use Keepass and convey the master key verbally or some other medium, it's designed for this sort of thing...

    http://keepass.info/

    --
    "As flies to the wanton boys are we to the gods; they kill us for sport." - William Shakespeare, King Lear
  75. KISS by westlake · · Score: 1

    I can always print a copy and have it delivered to them, but is there any way to share this sort of information electronically? There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data.

    Put an envelope and its contents in a UL rated fire safe and it will most likely survive any household disaster you could name. The diaries, account books, and letters of family members active in the early nineteenth century remain perfectly legible after close on to 200 years.

  76. I wrote a subroutine call into my will by Applehu+Akbar · · Score: 2

    The paper copy that is notarized and filed away at the bank includes the reference "Refer to folder X in file drawer Y of my home office file for a current list of online file names, site names and logins." I can easily keep this list current without having to keep re-issuing the official will.

  77. Secret Sharing by CptJeanLuc · · Score: 1

    The problem; trust. Say you had a number of deposit boxes with valuable contents. Do you give someone copies of all your keys, as you intend for them to get the contents later - and trust them not to open any of it until the time comes. Do you invent some clever scheme that they will find the keys when they go through your stuff when the time comes - though the thing is they may never find it, and noone will ever know. Or do you buy some service from ShadyCo Care Services to keep copies of your keys, with a promise they will be delivered to the right people when the time comes.

    The problem is trust. Ultimately with these examples, you either trust one particular person more than you would normally want to do (it is nice to have close family and friends, but we do not necessarily give them all the passcodes to access our bank accounts and do stuff in our name), trust some entity which ultimately cannot be trusted (e.g. corporation), or bet on some chain of events to unfold as planned.

    Within the area of cryptography, there is a concept called "secret sharing", that instead of one password (or "master secret"), a number of secrets are produced which when combined in various pre-defined ways, will create the master secret. You encrypt a file with the secret information you want to pass on, using very strong encryption and a very strong password - and then create a number of secrets from the master password. E.g. if you have 2 siblings and 3 children, you could split up the key such that any one sibling together with two of the children, would be able to reconstruct the master password.

    So what is the nice thing about this type of scheme? It means you do not need to trust people as much. In order to "screw you over" by going against your instructions, with the above example three of the people you think are closest to you would have to collaborate - which is a lot less likely to happen than if one single person held all the power.

    There are some practical issues - each person would have to get a secret to be protected, preferably in some way which cannot be hacked - and a piece of software that they will be able to use to reconstruct the secret - something portable which will run on anything and which can also be operated by computer illiterates. I would not expect anyone has written software specifically for this, though it would have been quite easy, as the concept of secret sharing is pretty straightforward, e.g. the secret lies along a n-th degree polynomial with known x-value e.g. x=0, and each person gets coordinates for a different point along the graph. Any n points are sufficient to resolve the coefficients of the polynomial f(x), and thus determine f(0).

  78. Not just death by Megaport · · Score: 1

    Its not just death that is the problem. My ex-wife is in a coma, not dead. Helping the kids access her data involved an EC2 cloud of GPUs. Please people, leave your password around so your loved-ones can obtain it even without a death certificate or will, because there are some situations that are even more complicated than simple old death.

    Your safety deposit box schemes all mostly fail on this point alone.

    --M

    --
    # grep slashdot access.log | grep html | sort | uniq | wc -l 2604
  79. Email was never designed to be confidential by Kmatte81 · · Score: 1

    How do you know a conversation is private? You know who you are talking to and you know others cannot eavesdrop. Phil Zimmerman, a foremost expert on email security, says: Email that uses standard Internet protocols cannot have the same security guarantees that real-time communication has. There are far too many leaks of information and metadata intrinsically in the email protocols themselves. Email as we know it . . . cannot be secure. The reason...email was never designed for confidential communications. Most email providers only encrypt your digital information while it is in transit (and this encryption is fairly easy to defeat). The problem is that your data spends most of its life in storage completely unprotected. If your email service providers have access to your password, they can view and share your information as they fit. Even most secure email providers only encrypt your messages some of the time, and can read your emails and attachments. There is no expectation of privacy when using public email systems such as Gmail, and likely never will be. Their livelihood depends on being able to read your email. Email also allows anonymous users and is routed through multiple servers across multiple domains, making it impossible to know if and by whom email is intercepted, or even who is on the other end of the line. I work for a company called Absio that has developed a new digital communications protocol that enables the first truly confidential alternative to email for messages and files that need to remain confidential. Unlike Ãoesecureà email providers, Absio does not have centralized access to passwords, keys or metadata related to your email. Each message and attached file is individually encrypted with its own key on your device before they are sent over an encrypted Internet connection to the Absio servers. Absio does not have access to your encryption keys, and does not have an alternate decryption key. This means Absio does not have the ability to decrypt messages or attachments, not even a subject line. Absio cannot see or share decrypted information, because Absio never has it. Our first application is called Absio Dispatch. When using Absio Dispatch, messages and attachments are automatically stored in encrypted form on your personal devices. Absio Dispatch transmits your encrypted data through an encrypted connection, and encrypts all metadata except for the Absio ID (like an email address) to whom the message is going. There is no spam, because your Absio Dispatch application can only receive messages from the list of trusted contacts you designate. The only people you need to trust with your data are you and the trusted contacts who receive your messages. We strongly believe that digital information is private property and carries all the rights and obligations that are associated with other forms of property, and all individuals deserve for their personal information to remain private.

  80. Securesafe.com by neopirate · · Score: 1

    Maybe this would work for you. I am using them.

  81. self destructive usb by Anonymous Coward · · Score: 0

    Encrypt it as suggested by others here.
    But also store it in an ironkey which will self destruct when someone enters the wrong password a few times...
    www.ironkey.com

    Ask them to open it only from the ironkey and not to copy it locally.

  82. Use a two-part scheme by Sortova · · Score: 1

    This is what I have done: 1) create a document with all sensitive information (passwords, account numbers, etc.) 2) encrypt it with the keys of two tech-savvy friends 3) e-mail the file to two non-tech-savvy friends with instructions to send it to the people in step 2 upon my death I'm not sure what you would do if you don't have enough friends (grin) but this seems to be a pretty simple and robust solution for my needs.

  83. why? by dala1 · · Score: 1

    This honestly seems over complicated. Why should anyone have this information before you die, especially financial information? The simple thing to do is put a hard copy (sealed, of course) of the information in a safety deposit box with a copy of your will. As long as your executor knows about the box, they can access it after you die and distribute the information per your instructions.

  84. Long Access; it exists by Anonymous Coward · · Score: 0

    Copying from the source: https://www.longaccess.com/

    """
    Longaccess is your safe deposit box in the cloud: A place where you can safely store your files in a way they will be accessible by you, your lawyer or your kids. For decades.
    """

  85. Shamir's Secret Sharing Scheme by blavallee · · Score: 1

    I encountered an issue where our 'boss' thought it was important to know the root passwords. But my team came up with a compromise.
    Shamir's Secret Sharing Scheme

    Allowing us to provide the passwords to multiple non-tech members of the company, without risking the loose of the actual root passwords.
    At least three staff members need to combine their parts to reconstruct the ACTUAL passwords.

    Distribute the information to multiple parties, including your Lawyer. The information is 'safe' until a predefined number of parties work to reconstruct the passwords.

  86. Things that work by Anonymous Coward · · Score: 0

    Please realize that this is not a maintenance-free situation. You must put some thought and effort into this.

    Depending on the IT information you have collected, you may wish to put the information in escrow â" held by a third party â" with legal guidance on when to turn the information over to the other party(ies). Think hard about that last part; depending on what you still have access to, you (and therefore your estate) may be legally liable should a âoefourthâ party gain access to the system / information / capability through an (un)documented back door or triggering an (un)documented logic/time bomb. May your god(s) help you and your family if you trigger a religious, cult or political organization.

    Here is one solution that has worked (so far):

    0) Think about how long your timeline is, to where the file(s) must be recovered.
    a) Will the hardware be available?
    b) Will the software work on that/then/there hardware?
    c) How might you ensure that to be the case, assuming it is now a hostile world to that hardware / software.
    d) I have held in my hands, and read, the letters from my distant ancestors in the 1800s. It was graphite pencil on paper. Can you do that with your stuff today? (Acid free paper â" they did that then. Archival grade, now.)

    (N.B.: I am in a happy, long-term relationship with an I-Love-You spouse, both between people and legally. We intend to carry this until Death do us part. This will not apply in all circumstances. Where it does not, you must take additional precautions. If you do not trust them, you must set up an independent executive and legal structure. Seriously consider pre-nuptial agreements, depending on your age(s), finances, relationship(s) and circumstances. I was young, naÃve, and lucky. Most other people don't seem to be so lucky.)

    1) Record all your online / offline digital identities, websites or files, logins and passwords in a plain text file (*.txt) using your favorite ASCII text editor. Encrypt that file with an ID / password that is very different from (orthogonal to) any other account or location you use. Capture a copy of the encryption software on other long-term media (flash, hard drive, optical, etc.)
    2) Record the access data for that file, either on paper or in human memory, shared with whoever you trust with your life data (hereafter: trusted agent).
    3) Store that access data physically, in plaintext, in places that are geographically separated. That might be in a lawyer's office; a safe deposit box; with your executor; with your (trusted) spouse / friend / family member / lawyer / agent.
    a) Change access (ID/password/crypto key) regularly â" annually, for this exercise. More frequently, depending on your circumstance or degree of tin-foil-hat paranoia.
    4) Once per year, print that whole access file to paper, seal in an envelope (or double-sealed envelope) and store in various physical locations (safe deposit box; lawyer; executor; spouse; other trusted agent).
    a) And, review your estate plan, documents, powers of attorney, etc. Update them all. You DO have those critical documents, don't you? Distribute them all as a package to the same locations, particularly to the people that must act on them. Copies on you or quickly locatable; originals in correct locations to ensure copies can be verified.
    5) Once a year, test that you can recover from those backups. Coach whoever is your trusted agent in âoehow toâ or leave them keystroke-by-keystroke instructions plus a copy of whatever software is required to access those file(s) and format(s).
    a) Repeat at every big change: moving across country; change in relationships, etc.
    6) Lather, rinse, repeat.
    7) Every several years, upgrade the media used to store the information, to ens

  87. Shamir Secret Cipher. by Anonymous Coward · · Score: 0

    Shamir Secret Cipher.

    Create a dossier of everything necessary to pass on.
    Encrypt it.
    Split the passprase into M chunks in which N are needed to recover the passphrase.
    Send individual chunks to your attorney, lawyer, Deposit box, lawyer, SO etc. with a copy of the encrypted dossier and how to recombine them and decrypt.
    Engrave one on a ring (titanium?) to be passed on as part of your effects. ....
    Inherit?!

  88. I solved this problem recently by mtthwbrnd · · Score: 1

    I flew to see my co-global-head-of-everything-awesome and hypnotised her with all of the data she requires to keep our empire growing in the even of my death. My obituary will contain trigger words to activate the programming.

    1. Re:I solved this problem recently by mtthwbrnd · · Score: 1

      Seriously though, you should write everything down and give it to an attorney who will pass it onto the recipient after your death. It is then up to the recipient whether they want to commit to memory and burn or keep it in a safe etc.

  89. Autogenerated quote at the end of this page: by Anonymous Coward · · Score: 0

    "Let's organize this thing and take all the fun out of it."

  90. Google Inactive Account Manager by Anonymous Coward · · Score: 0

    Store all the things in google and google drive, then configure googles inactive account manager to give access to your next of kin, etc, once you not longer are logging in.

  91. when you go.... by JWSmythe · · Score: 1

    In the last several years, things have happened. Someone very close to me died with no notice. Quite literally, I saw him alive and normal at home. I went outside. A few minutes later I went back inside and he was dead. Natural causes.

    I went in for spine surgery a few weeks ago. I could have walked away from it, or have been rolled away to the cemetery.

    I always make sure someone knows how to do what I do. That person usually knows where everything is. They don't necessarily have all my passwords, but they know where the "key" is, which guides them to the vaults (one logical, one physical). I double checked the key, and the instructions for the vaults before surgery, and reminded them where the "key" is hidden. My "key" has another more colorful name, so I'm not even giving away secrets here. :) Your "key" could be something like an envelope marked "1997 expense reimbursements", with just a piece of paper containing a few important passwords and instructions for the rest.

    It doesn't have to be a life changing (or ending) event, or even an employment terminating event. It could be something as dumb as you're stuck in a remote airport during a blizzard, with no data service, and something major happened. Sure, everything *could* wait a week for the storm to pass. Or you could say "Call X. Tell them to go get the key. They will understand and can take care of everything." The instruction to "Call X" is kind of redundant, as the primary people should already know who the "oh shit" person is to contact. It's just reaffirming, "I'm stuck, and can't do anything from here."

    Just be very sure you can trust the people holding your secrets.

    --
    Serious? Seriousness is well above my pay grade.
  92. Serious + Funny by Anonymous Coward · · Score: 0

    There are some online services that will keep (for a cost) some digital files for you and give them to the next of kin (see as an example https://www.netarius.com/, Google is your friend).
    If you don't trust this, just call a relative and tell them the information over the phone. After your death they can retrieve the information from NSA via a FOIA.

  93. Each jurisdition is different by trialjudge · · Score: 1

    The laws of each State are different. This is true in other countries. I suggest you consult a local attorney at law in your jurisdiction, with a knowledge of Intellectual Property law. I suspect you MAY be looking for a "durable" power of attorney. (That means the power of attorney survives your death.) The power would instruct the person you chose "At the time of my death, please do X, Y and Z." Then the power dies, and is of no further effect. If there are huge financial implications, you might consider having the holder of the power post a bond to insure full performance. But please, get a professional to help with this. I don't try and fix my computer, because.... well.... I'm clueless. As far as I'm concerned it's all magic and that's the end of it. It took me three tries to get this posted, how's that for clueless? Just my humble opinion.

  94. Not necessary by RJFerret · · Score: 1

    I'm surprised only one other person pointed out almost none of that info is needed. Banks, courts, insurance, attorneys, brokers, all of them have procedures which negate passwords/PINS/all that info the executor of the estate typically doesn't know.

    What you do want is to get way more copies of the death certificate than you imagine you'll ever need. The death certificate and the institution's forms will gain you legal access to everything. Accessing them improperly could lead to trouble.

    (A list with passwords should be outdated in a matter of weeks when passwords are changed anyway, account numbers when accounts are closed/moved, etc. It's just quicker/easier to use the institutions process and doesn't ruffle any feathers.)

  95. I got it by Kmatte81 · · Score: 1

    Snapchat is not totally secure (http://www.cnn.com/2014/01/01/tech/social-media/snapchat-hack/). There are other tools available where the service provider does not store passwords or keys, and therefore, cannot be the source of a breach (Absio, Wickr, etc.).