Slashdot Mirror


Ask Slashdot: How To Bequeath Sensitive Information?

New submitter UrsaMajor987 (3604759) writes I recently retired after a long career in IT. I am not ready to kick the bucket quite yet, but having seen the difficulty created by people dying without a will and documenting what they have and where it is, I am busy doing just that. At the end of it all, I will have documentation on financial accounts, passwords, etc., which I will want to share with a few people who are pretty far away. I can always print a copy and have it delivered to them, but is there any way to share this sort of information electronically? There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data. Does anyone have any suggestions? Is paper still the most secure way to go?

143 of 208 comments (clear)

  1. The Giver by Anonymous Coward · · Score: 5, Funny

    Find a young child to give all your memories to. Hopefully he doesn't run away after learning the horrible secrets of the IT world.

    1. Re:The Giver by cjestel · · Score: 3, Insightful

      Find a young child to give all your memories to. Hopefully he doesn't run away after learning the horrible secrets of the IT world.

      long time since I read that book.

      I use keepass to keep my passwords for various things encrypted on my systems. It works with windows, max, linux, android, and probably iphones. Then you just have one password to share and all of your information is unlocked. Send it to them in a secure fashion or come up with some sort of shared storage they can access (dropbox) so that you can update passwords as they need to change and then you can put your password for keepass in your will so they don't have access to anything until you die.

    2. Re:The Giver by roc97007 · · Score: 1

      Same here. Used to use Secret (was a Palm Pilot user) but switched to Keepass.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  2. Put it on a disc by techno-vampire · · Score: 1

    Put all of your files on a CD/DVD and mail it to them, with an explanation of what the files are. That way, the data's off-line until they need it and safe unless somebody breaks in who knows what to look for. And, if your friend's good at hiding things, it may still be safe. (As an example, put the disc in a DVD or Blu-ray case behind another one with a movie on it.)

    --
    Good, inexpensive web hosting
    1. Re:Put it on a disc by ed1023 · · Score: 2

      Yes but with the problems of archived CD/DVDs falling to pieces/ not being readable after 10 years this is not the best idea.

    2. Re:Put it on a disc by techno-vampire · · Score: 1

      It doesn't have to. Enough of the data will need occasional updating that you'll probably be sending a new copy every two or three years.

      --
      Good, inexpensive web hosting
    3. Re:Put it on a disc by Loether · · Score: 4, Funny

      (As an example, put the disc in a DVD or Blu-ray case behind another one with a movie on it.)

      It's funny, I do the exact opposite, I hide selected movies behind CD's labeled "Finance Data."

      --
      TODO create witty sig.
    4. Re:Put it on a disc by ShanghaiBill · · Score: 1

      Here is what I do: I have a fireproof lock box bolted to the floor in my bedroom closet. My parents and siblings (all of whom live out of state) have the combination. If something happens to me, they can come and open the box, and have access to my will, trust documents, account information, passwords, etc., on paper and in digital format. The lock box also has backups of all the software I have written over my lifetime, decades of email archives, and thousands of photos, family movies, etc. The only information I have to give them is the six digit combination. It never changes, and it never goes out of date. I update the contents of the lock box with new backups at the end of every month.

    5. Re:Put it on a disc by roc97007 · · Score: 1

      I struggled with this for awhile, thought about the "pr0n pact" (good friends get together and decide that whomever dies first, the others will get on his machine and delete all his pr0n) but finally decided that anything I would need to hide from my family I probably shouldn't possess anyway. I think it was a good decision.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    6. Re:Put it on a disc by rjstanford · · Score: 2

      Even better - tell your lawyer. They have whole teams of people dedicated to solving this problem. Let them do the job that they're experts at and stop worrying about it.

      There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data.

      Yup. And when you give them money they may spend it on hookers and blow - or even donations to the Heritage Foundation or Greenpeace. You'll be dead. Once you've passed on the data and what it represents, its truly not your problem and no longer your concern.

      If it bothers you that much have your lawyers set up a trust instead. Again, let experts be experts.

      --
      You're special forces then? That's great! I just love your olympics!
    7. Re:Put it on a disc by L4t3r4lu5 · · Score: 1

      Why not just browse the adult web from an encrypted VM? Not only are you keeping your proclivities hidden, you're also protecting your system from the myriad of exploits pushed through these particular websites.

      --
      Finally had enough. Come see us over at https://soylentnews.org/
    8. Re:Put it on a disc by eggstasy · · Score: 1

      Or just use a Privacy Mode in your favorite browser.

      http://en.wikipedia.org/wiki/P...

    9. Re:Put it on a disc by datavirtue · · Score: 1

      encrypt it and devlier the password over the phone

      --
      I object to power without constructive purpose. --Spock
  3. Time-tested by Anonymous Coward · · Score: 1

    Write a parable, and share it orally.

  4. Paper, and physical equivalents by Overzeetop · · Score: 1

    A paper record is good. So is a plaintext file well organized and placed on a USB flash drive. Both can be mailed and locked in a safety deposit box, which is about as secure as you can get. Both require physical access, which means any other encryption or security is more likely to confound your subjects than actually secure your data.

    --
    Is it just my observation, or are there way too many stupid people in the world?
    1. Re:Paper, and physical equivalents by almitydave · · Score: 1

      A paper record is good. So is a plaintext file well organized and placed on a USB flash drive. Both can be mailed and locked in a safety deposit box, which is about as secure as you can get. Both require physical access, which means any other encryption or security is more likely to confound your subjects than actually secure your data.

      In addition, you could encrypt the plaintext file with a well-known algorithm (you can even specify which one and the parameters) using a very strong password contained in your will, to prevent unwanted disclosure.

      You could then apply Base64 encoding to the encrypted plaintext file, and print the result in a large font to enable scanning and OCR to recreate the digital file and decrypt it. This should be reliable enough - I don't think any of these technologies are going to go away any time soon.

      --
      my, your, his/her/its, our, your, their
      I'm, you're, he's/she's/it's, we're, you're, they're
  5. Lawyer by Neruocomp · · Score: 2, Insightful

    Isn't that what lawyers are for?

    --
    Physics is like sex. Sure, it may give some practical results, but that's not why we do it
    1. Re:Lawyer by ColdWetDog · · Score: 2

      That's right. Use a professional for a professional job. Create a relationship with a decent lawyer (maybe the one who draws up your will), pay them some nominal fee. Use the system the way it was designed.

      If the world goes to hell in a handbasket such that the rule of law has gone by the wayside, you probably don't need all of those logins...

      --
      Faster! Faster! Faster would be better!
    2. Re:Lawyer by Jane+Q.+Public · · Score: 1

      Isn't that what lawyers are for?

      Yes, but... it depends on what your biggest concerns are. For example, are you more concerned about delivery, in the sense that you want to make absolutely sure the recipient eventually gets the information, or are you more concerned about "security", in the sense that you DON'T want it getting out prematurely?

      Here is a way to ensure both: strongly encrypt the data. Give your recipients at least two copies, to put in (separate) safe places. Then hire TWO attorneys, unknown to the recipients. Give each of them them a sealed package containing the names of the recipients, along with the encryption key and instructions for decrypting the data, to be delivered only after your demise. Put seals on the packages, and see that the recipients know what the seals are and how to tell if they're broken. But don't tell them who the attorneys are.

      It still requires that you put SOME trust in the attorneys. If you don't trust them as much as you'd like, then split the key in half and give half the information to each attorney. That way, if one of them is dishonest, maybe the other one won't be.

      There is no perfect way. But this one is pretty good.

    3. Re:Lawyer by L4t3r4lu5 · · Score: 1

      Encrypt and checksum the data you give to your attourney. Give your friend / recipient of the data the checksum to check for tampering, and the key to decrypt the data transfered to them by the attourneys. You now need only trust your friend.

      --
      Finally had enough. Come see us over at https://soylentnews.org/
    4. Re:Lawyer by quoob · · Score: 1

      But consider my recent situation: My mother entrusted her will and other important papers to her lawyer. After her death, I discovered the lawyer had died several years previously, and his widow sold the business, including my mother's documents, to another lawyer. After much investigation, I discovered the name of the second lawyer and managed to contact her. Once. For several months, I heard nothing and my calls were unanswered. Just as my own lawyer was about to begin a long and expensive process for settling the estate with a will gone missing (much harder than if there is no will at all!), I got a call out of the blue from the missing the second lawyer. She had taken sick and had been hospitalized in serious conditions for months. Within a few days she had located the documents and shipped them to me.

    5. Re:Lawyer by Kmatte81 · · Score: 1

      This sounds good in theory, but most law firms do not use any form of encryption for their email or data storage, so it is not that difficult for a hacker to get into your lawyers server and steal your information.

    6. Re:Lawyer by dcw3 · · Score: 1

      IANAL so this is just my $.02. Unless you have a complex plan for your will, or a significant (7digit+ size) estate, or expect that your will might be contested, an attorney is a waste of your time and money. Simple wills can be done, in nearly every state w/o legal assistance. It's no more difficult than formatting a hard drive in most cases.

      --
      Just another day in Paradise
    7. Re:Lawyer by nmr_andrew · · Score: 1

      I realize you're posting to the /. crowd, but do you realize how tremendously difficult formatting a hard drive is for most of the population?

    8. Re:Lawyer by Jane+Q.+Public · · Score: 1

      You don't need a checksum of what you're giving the attorney, because it's just the encryption key. If it's tampered with, it won't work. The recipients already have the encrypted data. And if THAT is tampered with, again it won't work.

      The only real issue here is keeping the attorneys apart from the recipients until your demise. For that, you can only trust that your attorney won't open the package and see who the recipients are. That's why I proposed splitting the key between two attorneys: you are doubling your chances of finding an honest attorney. (At the same time, however, you are at least theoretically reducing the odds of eventual successful delivery of the package.)

      But we've been trusting attorneys in this way for hundreds of years. I don't know a better way.

    9. Re:Lawyer by j-beda · · Score: 1

      This sounds good in theory, but most law firms do not use any form of encryption for their email or data storage, so it is not that difficult for a hacker to get into your lawyers server and steal your information.

      You would have the data on a drive unconnected to the network, and of course the password for the encryption is given to them on paper. If you are trying to guard against a dedicated group targeting you specifically, then of course more paranoia would be appropriate. The rest of us are not important enough to worry about that.

  6. Possible... by retech · · Score: 5, Insightful

    You could send them an encrypted file (#1) now with all the info you wish to share with them. Along with a password for a file that will arrive when you die. Then set up a service like deathswitch.com and have another encrypted file sent to them (#2). The password they already possess unlocks #2 and that contains the password(s) for #1.

    1. Re:Possible... by Anonymous Coward · · Score: 1

      TrueCrypt

    2. Re:Possible... by dotancohen · · Score: 1

      Your sig is apt for the context.

      --
      It is dangerous to be right when the government is wrong.
    3. Re:Possible... by ZeroPly · · Score: 1

      You're reinventing the wheel. Public key cryptography allows a key to be split up, so that you need a minimum of X out of Y pieces to recover the key. Split the key into 5 pieces where 3 are enough to unlock it, and hand it out to lawyer, friends, co-workers, etc.

      --
      Support microSD: in a post 9/11 world, it is unwise to carry your data on media that you cannot comfortably swallow.
    4. Re:Possible... by Anonymous Coward · · Score: 1

      Not unreasonable, but too complex. Just give the data in a plain-text document to your attorney to be delivered upon your demise.

    5. Re:Possible... by retech · · Score: 1

      It works for anything.

    6. Re:Possible... by retech · · Score: 1

      Cheers. Just a thought, what if 3 of the 5 got together prior to death?

    7. Re:Possible... by theshowmecanuck · · Score: 1

      Hire Johnny Mnemonic.

      --
      -- I ignore anonymous replies to my comments and postings.
    8. Re:Possible... by ZeroPly · · Score: 1

      The idea is to separate the five, so that it would be impractical for all five to know each other or to break your trust. So for example, your dentist that you've gone to for 20 years, your lawyer, a trusted coworker, your wife, and your brother in China.

      Of course, the 3 and 5 are not magic numbers. You could make it 12 out of 13 if you're really paranoid. You could make it 5 out of 25 if you want very low possibility of your data being lost (for example a large earthquake).

      --
      Support microSD: in a post 9/11 world, it is unwise to carry your data on media that you cannot comfortably swallow.
    9. Re:Possible... by retech · · Score: 1

      Cool. I really didn't know that was out there. Very cool to know. Any recommendations on tutorials? Applications? etc...?

      Thank you.

  7. Safety Deposit Box by Anonymous Coward · · Score: 3, Insightful

    you can do what my grandfather did

    wrote up the entire list on paper form and electronic on a flash drive. He laced them in a safety deposit box and shared the key with his executor who in turn had a copy of his will.

    When he did pass away it was a pretty smooth process getting all of the information needed to close accounts, collect on policies, etc. The only thing that had a hiccup was property in a state with different probate laws but that too worked itself out.

    1. Re:Safety Deposit Box by selectspec · · Score: 2

      This is by far the best approach out of all of the recommendations. Obviously, sending paper documents (or USB drives) via overnight delivery is relatively immune to intercept, but what if you relatives leave the documents out in an unsafe area? The best place is a safe deposit box, along with any portable valuables (nice watch, jewelry, etc). You can arrange in your will to have your estate trustee then disseminate the contents.

      --

      Someone you trust is one of us.

    2. Re:Safety Deposit Box by azadrozny · · Score: 4, Informative

      Safe deposit boxes can get funny depending on state law. First don't ever put the will in the box. The executor will need that access the box later. Furthermore, it could take several day or weeks to get the authority to open the box after the person has died, so don't put anything in there that is time critical.

    3. Re:Safety Deposit Box by plopez · · Score: 1

      Give he the will and your executor a key to the safety deposit box with the will in it. In my area they cost about $10/yr, so having 2 or more is an easy option. One for the will and one or more for other purposes, e.g. one for the component which when combined with its 6 mates will open the portals of hell.

      --
      putting the 'B' in LGBTQ+
  8. Updated info periodically by dbarron · · Score: 1

    And...how are you going to handle updating information as you are forced to change your password for whatever reasons?

    I don't have a good solution...I wish I did. There's no reason you can't change your email password today and die before you can document it (which if you're like most people might be a week later).

    1. Re:Updated info periodically by fermion · · Score: 1
      Here is how this was kind of handled in an automatic case with me. I knew the password to the computer where all the credentials were stored, and access to the file cabinet where all the paper stuff was. All the passwords and information was stored in one of those two places.

      For an individual person that may not work, as there may be sensitive sensitive information that you don't want anyone to see. In that case consider a separate account on your computer with the information that everyone will need in an eventuality, and a separate account on your computer. where you can do stuff you don't want people to see.

      Here is my take on this. There is a lot of stuff that I don't care if no one every gets to close it. Most of my online forum acounts like /.. I expect everything on my computer to go with me. Creating data sets that are going to expire in a few months seems a bit over the top to me. The solution to this problem is to think about what people need, and assume they are going to have physical access to your stuff when you are no longer here.

      --
      "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
  9. stone tablets by ThatsDrDangerToYou · · Score: 2

    .. worked for me.

    1. Re:stone tablets by rastos1 · · Score: 1

      Moses ..., is that you??

  10. Analog degrades gracefully by Gothmolly · · Score: 1

    Ink may fade, paper may yellow, but should still be readable. Put it on a CD or USB drive, flip 1 bit, and you lose everything.

    --
    I want to delete my account but Slashdot doesn't allow it.
    1. Re:Analog degrades gracefully by RabidReindeer · · Score: 1

      Ink may fade, paper may yellow, but should still be readable. Put it on a CD or USB drive, flip 1 bit, and you lose everything.

      This is this concept known as Error Checking and Correcting code. The ECC encoding on disks can easily repair all single-bit errors and many multi-bit errors.

      ECC will not guarantee that if you make regular replications of your data that nothing will get lost. But it will make it mathematically very difficult for the copy process to introduce undetected errors. And if you catch the errors early enough, you should be better able to pull out a spare copy and repair the data manually before it propagates and expands.

      I'm for stone tablets myself. Problem is, paper or stone, it takes an awful lot of space to store a Terabyte's worth of data. And few of the ancients thought to add ECC to their writings.

    2. Re:Analog degrades gracefully by Kaenneth · · Score: 1

      Each letter in an english word only stores one bit worth of data on average.

      see: http://www.maximumcompression....

      And moist anjone can eaiily correc simxle errors automaxically while reeding in there heads.

      I'm sure mistakes were made while carving stone tablets, and they just said 'Fuck it, it's fine.'

      I was at a Pho shop the other day, with etched glass windows reading 'NODDLE SOUP' (in Comic Sans...)

    3. Re:Analog degrades gracefully by nctritech · · Score: 1

      "Moist anjone" accurately describes my emotions right now.

  11. Document escrow is not new. by Anonymous Coward · · Score: 3, Informative

    Put the passwords, etc on a piece of paper. Put that paper in a large envelope. Give that envelope to a firm that does document escrow (many law firms will do this) with instructions on who should be given a copy after your death. Let your friends and relatives know who has your escrowed docs. They provide proof of your death, and everyone gets a copy.

    Why exactly are we reinventing the wheel here? This is old hat stuff. You don't need to trust anyone not to open their present early. Firms that do document escrow have better theft prevention techniques than anything you're likely to cobble together.

    If you want to go super fancy, use USB keys encrypted with a pre-shared password instead of paper. Then you don't really have to trust the escrow folks.

    1. Re:Document escrow is not new. by mlts · · Score: 1

      I do a similar version of this. I have a few document escrow services and a couple friends that have pieces of my master keys. It is a system that requires "x out of y" pieces to re-assemble the keys, so if one person is out, the key can still be recovered.

      I have a couple symmetric keys and a private key. That way, if RSA or ECC get broken, the core data is still protected until all the escrow places plop down their segment of the keys.

      To be safe, the key part and the SSSS (Shamir's Secret Sharing Scheme) utility is not just stored on an archival grade DVD and a USB flash drive, but also UUencoded and printed out (with a QuickPAR recovery record just in case.)

    2. Re:Document escrow is not new. by sexconker · · Score: 1

      Why exactly are we reinventing the wheel here? This is old hat stuff.

      Because self-important nerdulons think they're special or that things being done on computers or online somehow constitutes a separate reality.

    3. Re:Document escrow is not new. by bobbied · · Score: 1

      How about you just give the document escrow folks a one time use pad cypher and simply keep your "secure" documents encrypted using that pad. You can then "update" everybody electronically with an encrypted document that they cannot decrypt until they can obtain the one time pad from escrow.

      While you are alive, you need to protect your copy of the pad, but its not hard to invent some classy way to do that given that the pad has absolutely no useful information in it...Like using a your favorite MP3 or something...

      --
      "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
    4. Re:Document escrow is not new. by j-beda · · Score: 1

      How about you just give the document escrow folks a one time use pad cypher and simply keep your "secure" documents encrypted using that pad. You can then "update" everybody electronically with an encrypted document that they cannot decrypt until they can obtain the one time pad from escrow.

      While you are alive, you need to protect your copy of the pad, but its not hard to invent some classy way to do that given that the pad has absolutely no useful information in it...Like using a your favorite MP3 or something...

      I think that using the one-time-pad to encrypt multiple items ends up leaking information if someone gets their hands on those multiple updates. Since you are sending out those updates to "everyone", that doesn't sound optimal. I don't know that this "attack" is particularly feasible however.

  12. yes by Charliemopps · · Score: 1

    Is paper still the most secure way to go?

    Yes.

    Specifically, paper, in a safe deposit box, and the key with a lawyer.

  13. Skip technology by netsavior · · Score: 1

    Use Acid-free paper and just print it out. If you want to be more clandestine and secure, then print out the information about the accounts and the credentials in two separate places. Like for instance:
    Fed-ex the unlabeled passwords
    USPS the un-passworded accounts list

    The truth is, if you put it on a thumb drive, it might fail. If you put it on a CD it might fail (or 3 years from now, your grandma's iBookPro won't be able to read a CD).

    As humans, we read paper documents that were created 100 years ago. It is a reliable data mechanism that is predictable and will out-live you for sure.

    Plus it doesn't require that your executor be a cryptography nerd in order to make sure your wishes are followed.

    1. Re:Skip technology by eth1 · · Score: 1

      Fed-ex the unlabeled passwords

      USPS the un-passworded accounts list

      Actually, if you're mailing passwords, send the FUTURE passwords. Then once you've verified that the copies have reached the recipients unmolested, change the passwords to what you sent.

  14. Paper, lock, and key by ZahrGnosis · · Score: 1

    Write down everything in paper, then lock it away in a fireproof box or a safety deposit box (or both).

    I'm a fan of the phrase "we know how to secure a piece of paper". Not the sticky note taped to your desk that anyone can read and put back without your knowledge, but something really secure. You will know if your lock box has been stolen or broken in to; I would have no idea if someone broke into my e-mail or stole a file off of my computer or backup due to some weird exploit. If you want off-site safety, a deposit box is about as good as it gets with some assurance that no-one will go peeking. Let your close relatives and friends know where everything is so that when it is needed they can get to it, but they don't need access in the mean time if you have things you don't want them to know (or, you can give a copy of the key to someone if you want to... you have options, but you're still relatively safe in who accesses what).

    1. Re:Paper, lock, and key by ZahrGnosis · · Score: 1

      That's the deposit box. The lock-box under your bed is going to be tough even for the feds.

  15. Do this (My solution) by cbelt3 · · Score: 3, Interesting

    I keep an encrypted online database of my passwords. Sort of. I use a 'modular' password. One word is different, the other is always the same. So in my will I have the same word (and it's l33t combinations) written down, along with the address of the database. So anyone dealing after my death will know ALL my codes. My wife of 30+ years also keeps a copy of it, and knows the super secret codes.

    I started this after being in a coma, and my wife having to deal with my PDA bleeping about meetings to her until the battery died. Which made her cry even more.

  16. Its *all* at risk by nurb432 · · Score: 1

    Once it hits the other side..

    --
    ---- Booth was a patriot ----
  17. Ask a Lawyer by Rob+the+Bold · · Score: 4, Insightful

    Even though the "ask a lawyer, not Slashdot" answer gets trotted out all the time, I think it's appropriate here. Lawyers do this sort of thing for a living. Probably cheaper in the long run to ask one.

    --
    I am not a crackpot.
    1. Re:Ask a Lawyer by azadrozny · · Score: 1

      Second this. There are a lot of state and federal laws to navigate here. It may not be necessary or appropriate for someone to use your passwords to access your financial information. You could land yourself in a heap of trouble if you access someones account after they die, even if you are entitled to the money.

    2. Re:Ask a Lawyer by bobbied · · Score: 1

      I'm with you on this one... Come up with $100 or so and pay a lawyer. After all, they got to eat too.

      --
      "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
    3. Re:Ask a Lawyer by Rambo+Tribble · · Score: 1

      Of course, you'd first need to find a lawyer you could trust. That's a task Sisyphus might quail at.

  18. Lastpass by Allasard · · Score: 1
    http://lastpass.com/

    Put it in secure notes. Give them all the login/password.

    If they test it regularly, then have a locally cached copy if Lastpass goes belly up, which can be opened with Lastpass Pocket or whatever it's called now.

  19. Safety Deposit Box by richtopia · · Score: 2

    You still control it, yet it is remote and will be properly searched when you die. You can put a usb key in or some paper documents with the relevant information.

  20. How long? by jchoyt · · Score: 1

    How long do you expect this to last before it's needed? DVDs and USB drives are common, but I see DVDs heading out at this point. Paper has the advantage that in 40 years it'll still be readable. Of course if your passwords change you'll have to update this information anyway. Assuming you update passwords occasionally because of a) good practice or b) some company gets hacked, I'd send it electronically and encrypted, so the person needs to actually enter a password to get to the data. Unless the recipient gets a keylogger installed, you should be safe. A text file encrypted with pgp is good for the knowledgeable recipient. For someone less savvy, I'd send them an encrypted tiddlywiki. Obviously give them the password over the phone, in person, or via snail mail.

    --
    Sometimes the truth is arrived at by adding all the little lies together and deducting them from all that is known.
  21. I go old school by the_skywise · · Score: 1

    All of my financial info is with Quicken on my PC. Everything else related to teh intertube world is recorded on a textfile on my PC with the passwords being represented as a cypher. The cypher is a one or two word comment relating to the password phrase I use (which I, in turn, munge to be first letter of each word or some other pattern, yadda) I've got the username/password cypherlist stored on my smartphone as well (Because I can't keep up anymore) and the cypher key is kept only as a hardcopy along with a hard copy of the textfile stored in a fireproof lockbox in my home. (The textfile points out the key is in the lockbox too).

    I should probably just put the cypher key list in a separate lockbox (without any other username/account info) and geocache it to make it more fun for my heirs...

    1. Re:I go old school by RabidReindeer · · Score: 1

      You're in trouble, then. Quicken's file format is proprietary and unpublished. Your financial data is only as retrievable as Intuit allows it to be.

      Assuming Intuit is still around when your heirs need it and not gone the way of Ashton-Tate or other software institutions of yore.

      But, hey, what are your heirs going to do with your financial data anyway? Use it to settle your estate?

    2. Re:I go old school by Rob+the+Bold · · Score: 1

      But, hey, what are your heirs going to do with your financial data anyway? Use it to settle your estate?

      A surviving spouse might still want to pay the bills and track the investments.

      --
      I am not a crackpot.
    3. Re:I go old school by Oligonicella · · Score: 1

      If a surviving spouse needs that to know what the bills are, they haven't been very intelligent about things in the first place. Same for investments. For that matter, same for passwords.

    4. Re:I go old school by alexander_686 · · Score: 1

      I would tend to doubt that.

      Quicken, and things like this, are good at handling internal flow data. How much am I spending on overpriced coffee drinks? What is my internal rate of return on investments? Etc. This data is most helpful for a continuous, ongoing business. The wife continues to run the personal finances; the business partner continues to run the business. However, this kind of implies that these people had access, and were using, Quicken prior to the death. So no change there.

      On the other hand, I feel that the situation we are talking about represent "breaks" instead of "continuous" business. A new person enters the picture and inherits the assets. Normally they don't care what the deceased spent on coffee or what their old investments returns were. They might need prior knowledge of what is going on, but the normal course of action is for the new person to load the inhered data into their own accounting systems.

    5. Re:I go old school by Anonymous Coward · · Score: 1

      > Quicken on my PC.

      That's a terrible idea. Intuit constantly makes incompatible changes to the file format. It's such a hack that they are embarrassed to publish the format. When my father passed away, we were unable to open his files with newer versions of Quicken. The copy he had lost its activation so it was no longer usable. Intuit refused to sell us a copy of Version 6 for Windows which is what he used or version 2000 or older which they claimed would open the file. I had to buy an old PC on Craiglist to open it. That took me about three months of posting ads looking for old PCs that had Quicken installed, and I had to drive about four hours roundtrip to pick it up. Don't put your data in a dead-end, undocumented, and intentionally made obsolete file format. Unless you constantly upgrade, your files will probably not be able to be used. According to the Wiki page, Intuit has dropped support for 24(!!) different versions of Quicken in just the past decade.

    6. Re:I go old school by RabidReindeer · · Score: 1

      A lot of spouses aren't "intelligent". They don't know what the bills are and I happen to have one who doesn't even know where all my investment accounts are despite being required to sign off on the annual tax return.

      I don't use Quicken. I gave up on it because it didn't have the power to do things like handle non-ESOP stock antics. I use an open-source equivalent and the file format for it is well-documented. Plus it keeps multiple generations of backups automatically.

      I expect that should the need arise that still isn't going to help my spouse, but it won't be because the data isn't accessible or readable.

    7. Re:I go old school by alexander_686 · · Score: 1

      Which kind of speaks to my point. From my personal experience, the spouse (usually the wife) is going to adopt a new accounting system that they are more comfortable with. And my definition of accounting systems run from custom enterprise jobbies to the shoe box variety. All they need at that point are the last statements to update their accounts. Rarely is there a strong need to have access to the old accounting system.

    8. Re:I go old school by RabidReindeer · · Score: 1

      Tax audit?

    9. Re:I go old school by alexander_686 · · Score: 1

      For a tax audit, Quicken et. al. only helps you a little. It is just a program with imputed numbers. Who is to say that the inputted numbers are valid? Normally you want original documentation.

      There are expectations if you are running a business. Mileage forms, etc. Expect that if it is a ongoing business then the spouse / business partner would normally have access to the accounting system prior to death or would have access to the printed (or al least PDFed) year end documents that were generated. I mean you should not be preparing new tax reports for a tax audit - Those should be generated from the base data when the taxes and done.

  22. Shamir's Secret Sharing and Encryption. by grnbrg · · Score: 2

    Pick a nice, long, secure passphrase. Use it to secure a GPG keypair. Back up this keypair in multiple locations, and with multiple people who know "This is the key that encrypts all of my digital stuff. My family will need it when I die.".

    Use that keypair to encrypt all of your important passwords and data. Back up the encrypted files in multiple locations. Make sure your family knows where these locations are, and why thy and the files they contain are important.

    Download a copy of http://passguardian.com/ . Load the saved copy (preferably in an offline PC) in a browser, and use it to convert your passphrase into several N of M parts. ie: Create 10 parts, and require at least 6 to reconstruct the passphrase.

    Use something like http://goqr.me/ (or any other generator) to create QR codes for the 10 secret shares. Laser print the text share, QR code and some instructions onto a business card sized piece of paper, and have them laminated.

    You now have 10 waterproof, hard to damage cards, any 6 of which will unlock your digital data. Distribute them to trusted parties and locations with instructions to use the shares once they hear and confirm your death. These parties don't have to be literate enough to merge and decrypt the data themselves, they just need to know that it is possible with their share. On your death, they will arrange to bring the shares and data together, and even if they have to hire a nerd to help them, they will unlock what they need.

    1. Re:Shamir's Secret Sharing and Encryption. by Mike+Van+Pelt · · Score: 1

      This. I've idly thought about this every now and then, and passguardian.com is exactly the tool I was thinking of.

      In my case, what I'll be distriubting is parts of my LastPass login and password, with the actual data stored there.

  23. Print it to microfilm... by Narcocide · · Score: 1

    ... then roll it up, stick it in a tiny airtight canister and cram it faaar up your ass.

  24. Weird questions... by carlhaagen · · Score: 2

    You state that you have a long career in IT, and at the same time you ask how to electronically hand over information generated within IT. Among those things, you even claim that you have passwords, meaning that they have been stored insecurly. This has "IT Janitor" written all over it, or possibly a concocted story.

    1. Re:Weird questions... by UrsaMajor987 · · Score: 2

      Nope, not a concocted story. A long career in IT; the last 19 years with a major international bank that took great pains to secure sensitive data both within the data center and in transit between data centers. The problem I am trying to solve is different. With the bank, we were sending sensitive data from one secured facility to another; what I need to do is send sensitive data from my (reasonably secure) home system to a location where I can not be sure of the security. How do I keep sensitive data secure in a remote location that is not necessarily well protected? At first I thought it would be easy; just use a password protected zip file and put it on DVD or USB. Send the media and password through different channels. But then I thought, what if someone gets curious and unzips onto their hard disk and leaves the files unprotected? The more I thought about all the possible scenarios for compromise, I realized plain old paper was the best solution. I was hoping there was some way of doing it electronically since there will be updates in the future but I could not think of any safe way of doing it via computer. The best solution suggested so far is to print everything out on paper and keep in a safe deposit box in the local bank. I can send the branch location and deposit box number to the siblings and since the paper is kept locally, updates should require nothing more than a trip to the bank. Kind of ironic that after all those years in IT and worrying about securing systems and data; I am reduced to using paper. Maybe I will seal the documents with wax and a ring :-)

  25. Encryption! by Mini-Geek · · Score: 1

    Encrypt the file with a secure password or key, maybe using AESCrypt. Email the encrypted file to the relevant parties. Put the password to the file in your will (keep it under appropriate trusted guard, to be released only on your death). As long as the will and the encrypted file are kept apart until after your death, the file will remain secure until then. You can also modify the encrypted file as things change, encrypt with the same password, and resend the file.

    There's still the possibility that their computer is compromised after you die and they decrypt the file. They could reduce this risk by opening it only on a known-secure system (e.g. an Ubuntu LiveCD boot), if it really matters. In any case, this greatly reduces the security exposure by not have this file sitting around for years for anyone to read.

    --
    do {print "Mini-Geek Rules!\n";}
    until ($TheEndOfTheWorld);
  26. Yes, paper. by ShaunC · · Score: 1

    Forget doing it digital. Your beneficiaries may have no idea how to decrypt something, or how to access whatever's become of some dead man's switch. Really, if I got hit by a bus tomorrow, even if I had things stored in quadruplicate across various flash drives, I'm not so confident anyone would know what to do with them.

    Type the important stuff up, and seal it in an envelope (or several, if you're dividing things up amongst likely heirs). Present those things to an attorney and have him draw up a will. The attorney will retain those envelopes and ensure that things are done properly once you're gone. If your very important passwords change, revise the documents and stop by the lawyer's office with new copies in new envelopes. They might not even charge you anything for that.

    I know we generally hate lawyers here, but this is one really worthy function that many of them can perform, and the courts know full well how to deal with written and physically signed documents. In the event that you outlive your lawyer, his or her office will retain custody of your will and your envelopes, or you can find a different lawyer.

    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
  27. I got it by necro81 · · Score: 2

    Take pictures of all the documents and send them via snapchat. Isn't this the kind of application it was made for (restrictred permission viewing)? It's, like, toooootally secure.

  28. ive used a time tested solution. by nimbius · · Score: 1

    Many of the 'knowledge share' sessions ive taken part in have requested my notes and musings on the technologies ive handled. Cryptography is the most logical means of securing this data as we all know, but the method by which one achieves this should be carefully followed.

    1. Choose a cypher whos strength is measured in the number of heat deaths of a cruel gods distant universe. Many will suggest a 256 bit cypher, but dont let that stop you from pursuing the correct size, a 256 megabyte cypher.

    2. passwords for archives and files should be sized accordingly as the md5 sum of the number of office parking spaces multiplied by the number of empty toilet paper rolls in the nearest bathroom to the largest conference room. the password must only contain characters whos hexadecimal value falls between the number of chairs warmed by the morning sun in the main lobby, and the number of lights in the break room that flicker when first turned on.

    3. You can never be too careful with USB drives. potting has long been a method of deterrence for unauthorized reverse engineering, but many dont know that a far more economical means of securing your USB data is to plunge it into an identical reproduction of a fifteenth century hessian crucible on the first blood moon of Rajab, the holy month of Allah.

    4. your paper trail should be auditable, and the business should know to whom you've shared information in order to determine future knowledge owners and process managers of your data. a CMS like system (similar to sharepoint) can easily be constructed by liberally dredging your paper documents and binders in a mixture of polychlorinated dibenzodioxins and low-yield fissile byproducts. the checked out or viewed copies will then be easy to track using simple FEMA disaster response processes.

    and congratulations on your retirement! give yourself a pat on the back because you deserve it. I hope my tips help you achieve a smooth and manageable transition.

    Regards,
    BOFH

    --
    Good people go to bed earlier.
  29. Re:Why complicate things? by Em+Adespoton · · Score: 4, Informative

    This is the way to do it -- I've added one more step. My safety deposit box also includes a master password and a 1TB encrypted USB backup drive. Since the professional who wrote my will also advised leaving a copy in the box and registering that this is where the "official" notarized original is located, my executor will, by local laws, just have to provide proof of death and the copy of the will indicating they are the executor to access my box. Having the key (which they likely would) would help too.

  30. Few options by tyggna · · Score: 1

    So, what I would do is pick a few passphrases that are long and cryptographically secure. Print these out and store them in a safety deposit box, bequeathing said box to whomever you want to give this information to.

    From there, the linux command-line utility gpg will work nicely.

    gpg -c filename

    Will prompt for a passphrase twice (use one on your sheet), and output "filename.gpg" leaving filename still in tact.

    From there, you can do whatever you want with the encrypted file--store it on a USB and put it in the safety deposit, email it, whatever. No one will be able to do anything with it until they have the passphrase.

    The other way I'd do that, which is more of the day-to-day stuff, is create two bitmessage accounts and just send it via that.

    PGP encrypted email is also a good way to go, so long as the recipient has their private key properly protected.

    1. Re:Few options by Overzeetop · · Score: 1

      Simpler version: put the data in the safety deposit box.

      No need for linux, or command lines, or encryption, or anything else. The only advantage to the encrypted file is that you don't have to get off your ass to make changes (i.e. put the updated data in the SDB).

      Because, let's face it, as soon as the SDB is compromised, your entire security system is compromised. It's just a matter of time and computational effort at that point. And the risk is that the person who needs the information will not be able to access your information due to an error, or simple inability to work the technology. Anyone who is "after" your precious data will have the wherewithal to decode your stuff, but Aunt Matilda or cousin Jeb may end up just stuck.

      --
      Is it just my observation, or are there way too many stupid people in the world?
  31. The old fashioned way by jeffmeden · · Score: 1

    You will die exactly once (barring a zombie apocalypse, in the event of which I am going to disavow any credit for this post) so why reinvent the wheel if it's only going to get one turn anyway? Hire a reputable family lawyer, set up a will detailing your important documents (and whatever else you are giving away), name an executor, choose a safe place (in meatspace) for the documents to live in the meantime, and then enjoy your retirement.

  32. You have no control by DerekLyons · · Score: 1

    There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data. Does anyone have any suggestions? Is paper still the most secure way to go?

    You have no control of what happens once the data leaves your control - whether the data is held and transmitted electronically or held and transmitted physically.

    That being said, though IANAL*, it seems that it's your executor who needs the data rather than people "pretty far away".

    * And really, when it comes to drawing up a will, there should be one involved. It'll save everyone involved a whole ton grief in the long run if you set things up right in the first place.

  33. Re:"long career in IT" by JazzLad · · Score: 1

    I call BS on the whole thing, "long career in IT" =/= UID over 3.5M

    --
    "If you have nothing to hide, you have nothing to fear." - Every fascist, ever
  34. not binary by Tom · · Score: 1

    1: Talk to a notary.

    2: Digital methods can and will fail. Either on your end or because the recipient doesn't know how to use them properly.

    Talk to a notary. These people have been handing over sensitive information about bank accounts, secret swiss safe deposit boxes and other stuff from one generation to the next for centuries, and you have a human who can work around any failures.

    Sure, you can find 10 possible digital solutions on the pages of Applied Cryptography, but... goto 2

    throw new Exception("you failed to follow the goto");

    --
    Assorted stuff I do sometimes: Lemuria.org
  35. Fidsafe by aprentic · · Score: 1

    One of our clients does exactly this.

    https://www.fidsafe.com/

  36. why doesn't blueray have better ECC by Wycliffe · · Score: 1

    I've never understood why blueray didn't fix this. Blueray has plenty of space now. Screw higher definition, I want
    a disk that I can scratch 12 times with a razor blade and still get my data off. My guess is the only reason they
    haven't done this is because they want the disk to only last a half dozen times before starting to degrade so you
    have to buy the movie again.

    1. Re:why doesn't blueray have better ECC by Wycliffe · · Score: 1

      This may or may not be possible with a disc I burn myself. I'm not sure how well optical readers handle large catestrophic errors
      and whether they can get anything off a disc with 50% damage but implementing it myself is not even an option when buying and/or
      renting dvds and bluerays. It's probably one of the reason blueray sales are falling faster than expected. Streaming quality sucks
      but even with the occasional buffering you still get to watch the whole movie. I can't tell you how many times a movie I've rented
      skips 10 minutes of the movie because of a minor scratch.

    2. Re:why doesn't blueray have better ECC by Wycliffe · · Score: 1

      Thanks. I had guessed as much. So the drive technology becomes the limiting factor as you
      need something that can stay in the right "groove" when it encounters a scratch or be able to
      jump over it and find the rest of that ring.

  37. Arrrr matey by bukowski90210 · · Score: 1

    Have we not learned anything from Sid Meier? Bury it on a deserted Caribbean island, draw a crude map with a red 'x' marking the approximate spot where your treasure is buried, then go to some bar on some other island and get really drunk and leave the map there with the bartender. Yarr..petarrr!!

  38. You don't need a tech solution by BrodyVess · · Score: 1

    You need a *legal* solution. This is something you should be talking to a layer about, and not /.

    --
    No one expects the Spanish Inquisition!
  39. Re:Yes, Paper by TheCarp · · Score: 1

    I tried to get my wife to use keepass too, she did do it.....changed all her passwords then.... forgot to save the file and her computer rebooted with windows updates. She called me at work rather upset and spent the rest of the day resetting her passwords.

    5 years later I am just now getting her warmed up to trying again.

    --
    "I opened my eyes, and everything went dark again"
  40. It's already done for you... by Jawnn · · Score: 1

    If you "memories" have ever traversed a public network. Your tax dollars at work.

  41. First of all by WormholeFiend · · Score: 1

    Solve the problem of motivating someone to do your will after you're dead.

  42. Re:"long career in IT" by alen · · Score: 1

    long career of inserting punch cards into computers

  43. Just Don't by 0xG · · Score: 1

    but is there any way to share this sort of information electronically

    Write it by hand.
    Photocopy it on an analog copier, or if you can't find one, use carbon paper.
    Send it by post.

    Safer than any encrypted email.

    --
    A pox on web designers who feel that window.innerWidth == screen.availWidth
  44. Discrete hardware by spire3661 · · Score: 1

    I jsut picked up a HP 7", 16 GB jelly bean android tablet WITH 4G radio and SIM for $120. Intel NUCS are $200 with RAM and the OS on flash. Raspberry PI, BeagleBones, Intel Gallileo, Arduinos equipped with SD slots. Put your data on discrete hardware, and have at it.

    --
    Good-bye
  45. Probate. by Vellmont · · Score: 1

    The MOST important part is documenting where your assets are, and account numbers. After you die, your assets go into probate, and aren't just simply accessible via logging into your bank. So the username and password isn't really as important as you think it is.

    Seriously, talk with a lawyer who's familiar with inheiritance in your state. Obviously documenting where all your assets are is very important, but don't just assume your loved ones are going to login to your account and transfer money out of it a few weeks after you're dead. That stuff gets locked into probate as soon as the financial institutions hear you're dead (with a few exclusions of course).

    --
    AccountKiller
  46. Post-mortem API by everyplace · · Score: 1

    I registered deathapi.com a while ago, after an acquaintance passed away, for this reason specifically. At the time, I had imagined a system that you OAuth against w/ all of your relevant accounts w/ full admin access, and specify a recipient of those keys after some pre-determined length of inactivity (a year, say). The idea still has a lot of relevancy in my mind, but it's so morbid to think about.

  47. Re:Why complicate things? by richy+freeway · · Score: 1

    You're assuming he's never going to update the storage before he dies. If he dies tomorrow, then it won't take twenty or thirty years for the will to be executed and the drive fired up.

    If he lives for another 10 years and another popular interface and storage format comes along then I'd assume (based upon the effort put in so far) that he'd replace the USB hard drive with whatever the next big thing is.

    So what was your point again?

  48. afternote.com by noblestreet · · Score: 1

    Hi UrsaMajor987, I just read your post and wanted to let you know that we have setup a service that's tailored to your question, Our service is called Afternote. Like you we had this same issue of not having a way to save wishes and important information. You can start a free account on www.afternote.com. If you have any questions or good feedback you can always contact me. Kind regards Arnaud

  49. How I Am Doing It by DERoss · · Score: 5, Interesting

    First of all, I assume you are serious and not trolling (as some others who replied have asserted).

    My son died in April of 2013. He lived with cancer for four years and then took four months to die. During that time, he ignored my pleas to create an estate plan with an attorney. I am still trying to unravel his estate. Divorced and without a will, his son (my grandson) is his sole heir. My grandson is 6 years old. After my son died, it was too late to create a trust for my grandson. Instead, I had to go to court (several hundreds of dollars in court fees, legal fees, and even appraisal fees) to be appointed the guardian of my grandson's inherited estate. (His mother is the guardian of his person.) I will then have to return to court every two years to report on the status of the guardianship. In the meantime, NO ONE had authority to pay my son's final bills. It took seven months after my son died before I had legal authority to collect his credit union accounts, IRA, Roth IRA, and multiple 401(k) accounts, by which time several bills had already been sent to collection. All the legitimate bills have now been paid, and all known assets have been collected (the last, just a week ago). In July, I will transfer the balance of my son's estate into my grandson's guardianship. That will not end the hassle as I will have to report the status to the court for the next 12 years.

    I am thus on a campaign that every adult needs an estate plan. Even if you have no heirs, even if your estate is small, you need to provide binding instructions on how to handle your assets after you die.

    Before my son started actually dying of cancer, my wife and I started a complete overhaul of our own estate plans. With the exception of our IRAs and Roth IRAs, all our assets are in trusts. We each are the other's beneficiary of the IRAs and Roth IRAs, with the trusts the contingent beneficiary. The trusts require two trustees, currently my wife and me. If one of us dies or becomes incapacitated, the replacement trustee is already identified in the trusts. When we are both dead, the replacement trustee must appoint another trustee to have two. CONTINUITY IS VERY IMPORTANT. Our credit unions, bank, and mutual fund group all have copies of the relevant portion of the trust documents to ensure they accept this continuity.

    Now for the original question: In California, where my wife and I live, a bank safe deposit box is NOT sealed if one of us dies. The box remains available to the other persons who are listed at the bank -- with their signatures -- as having access to it, which includes our daughter and will eventually include our replacement trustee. The complete original documents for our estate plan are in the safe deposit box. Right now, I can see a ring binder with a copy. The replacement trustee has a copy. A list of all our accounts is in the safe deposit box. An inventory of our mutual funds (IRAs and Roth IRAs) is in the safe deposit box.

    In a sealed envelope in the safe deposit box are a floppy disc, a compact disc, and a printout of my OpenPGP public and private keys and my OpenPGP passphrase (the latter otherwise exists only in my brain). (I chose three media since I have no way to predict what formats might become obsolete before I die.) That envelope also contains a list of all my important Internet passwords, which are encrypted on my PC.

    I have an unencrypted list on my PC titled "Where Is It?" that describes where everything should be found: checkbooks, bank statements, insurance policies, durable powers of attorney for health care, mutual fund statements, deed to our house, etc. When I update this list, I E-mail a copy to our daughter; another copy is in the ring binder with our estate plan. Also in the ring binder is the paperwork for our purchase of burial plots.

    1. Re:How I Am Doing It by xplosiv · · Score: 1

      So how did you learn about all of this? Do you do this for a living, or did a lawyer help you figure this out? I'd like to do something similar, so my wife doesn't have to deal with anything should something happen (she already has access to my passwords if needed, mostly concerned about financials, house, etc.).

  50. um, cd? by roc97007 · · Score: 1

    My stuff is on a CD in the bookcase.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  51. Should you even do this on your own? by plopez · · Score: 1

    FTA, "At the end of it all, I will have documentation on financial accounts, password, etc."

    It sounds like you are documenting sensitive company or client information. As such it is beyond the scope of you as an individual to place any of this information in a private store. You need some sort of formal business procedure for this. One place I worked THE COMPANY had safety deposit boxes. At another we would put emergency back up passwords in an envelope and give them to the administrative assistant who would keep them under lock and key in case I and/or others were killed e.g. on vacation. The company owners and managers knew about it and it was part of our policy.

    If you are removing sensitive information from a company network and storing it somewhere in you personal control, you are looking for trouble. If there is a breach you could be personally liable either civilly or criminally. Do I what I did and make sure that there is a documented policy and attendant procedures, and follow them.

    --
    putting the 'B' in LGBTQ+
  52. on computer by roc97007 · · Score: 1

    There's a file on my computer called "for my daughter". It's got everything she needs to know. Also backed up on a CD in the bookcase.

    Besides the required stuff, I used the opportunity to also wax long and poetic about my life and how her life changed mine, and wrote about all the interesting things about her childhood that I could remember. Included words of (hopefully) wisdom. I don't remember where I got the idea from, but since I was writing everything else down, decided to include that as well, so her last memories of me wouldn't be dry facts and figures.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  53. Re:Encryption by roc97007 · · Score: 1

    I thought about that, but my daughter classically can't remember passwords she uses every day; there's no way she's going to remember a password she'll only need once.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  54. Why? by nospam007 · · Score: 1

    Why on earth would you want to tell anybody the passwords for your financial stuff? Just to save them some bad traffic?

    If you die and they access it after the fact, they'll go to jail.

    They'll just have to go to the normal system, walking to the bank with a court order respecting your will from your lawyer or whatever else to prove that they inherited your money legally.

    Unless it's just to change your social networking status to 'deceased' they won't need any of those.

    Now if you had a 1 -3 figure slashdot account, that would be another thing, they could sell that for 20 bucks to a newbie.

    If you have illegal funds hidden from the IRS stashed in the Caimans or Switzerland, it's just gone.
    Bury your stuff in the backyard, like normal people.

  55. Re:Paper stored somewhere safe by roc97007 · · Score: 1

    I second the advice to NOT use a safe deposit box. In some states safe deposit boxes that have been untouched for a certain number of years (sometimes 15 but can be as low as 3) are declared "unclaimed items" and are confiscated by the state. There's been a few high profile cases recently. Burying a coffee can by the tree in the back yard may be a better idea. Or maybe a bus station locker. (At least, that's what they're always using in movies...)

    Banks are not safe places for long term storage.

    Regarding family fighting over my money after I'm dead. Bwaaaa hahaha. (wiping tears from my eyes) They'll be lucky if there's enough for cremation.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  56. Keepass by rootmon · · Score: 1

    Use Keepass and convey the master key verbally or some other medium, it's designed for this sort of thing...

    http://keepass.info/

    --
    "As flies to the wanton boys are we to the gods; they kill us for sport." - William Shakespeare, King Lear
  57. KISS by westlake · · Score: 1

    I can always print a copy and have it delivered to them, but is there any way to share this sort of information electronically? There are lots of things to secure transmission of data, but once it arrives on the recipients' desktop, you run the risk of their system being compromised and exposing the data.

    Put an envelope and its contents in a UL rated fire safe and it will most likely survive any household disaster you could name. The diaries, account books, and letters of family members active in the early nineteenth century remain perfectly legible after close on to 200 years.

  58. I wrote a subroutine call into my will by Applehu+Akbar · · Score: 2

    The paper copy that is notarized and filed away at the bank includes the reference "Refer to folder X in file drawer Y of my home office file for a current list of online file names, site names and logins." I can easily keep this list current without having to keep re-issuing the official will.

  59. Secret Sharing by CptJeanLuc · · Score: 1

    The problem; trust. Say you had a number of deposit boxes with valuable contents. Do you give someone copies of all your keys, as you intend for them to get the contents later - and trust them not to open any of it until the time comes. Do you invent some clever scheme that they will find the keys when they go through your stuff when the time comes - though the thing is they may never find it, and noone will ever know. Or do you buy some service from ShadyCo Care Services to keep copies of your keys, with a promise they will be delivered to the right people when the time comes.

    The problem is trust. Ultimately with these examples, you either trust one particular person more than you would normally want to do (it is nice to have close family and friends, but we do not necessarily give them all the passcodes to access our bank accounts and do stuff in our name), trust some entity which ultimately cannot be trusted (e.g. corporation), or bet on some chain of events to unfold as planned.

    Within the area of cryptography, there is a concept called "secret sharing", that instead of one password (or "master secret"), a number of secrets are produced which when combined in various pre-defined ways, will create the master secret. You encrypt a file with the secret information you want to pass on, using very strong encryption and a very strong password - and then create a number of secrets from the master password. E.g. if you have 2 siblings and 3 children, you could split up the key such that any one sibling together with two of the children, would be able to reconstruct the master password.

    So what is the nice thing about this type of scheme? It means you do not need to trust people as much. In order to "screw you over" by going against your instructions, with the above example three of the people you think are closest to you would have to collaborate - which is a lot less likely to happen than if one single person held all the power.

    There are some practical issues - each person would have to get a secret to be protected, preferably in some way which cannot be hacked - and a piece of software that they will be able to use to reconstruct the secret - something portable which will run on anything and which can also be operated by computer illiterates. I would not expect anyone has written software specifically for this, though it would have been quite easy, as the concept of secret sharing is pretty straightforward, e.g. the secret lies along a n-th degree polynomial with known x-value e.g. x=0, and each person gets coordinates for a different point along the graph. Any n points are sufficient to resolve the coefficients of the polynomial f(x), and thus determine f(0).

  60. Not just death by Megaport · · Score: 1

    Its not just death that is the problem. My ex-wife is in a coma, not dead. Helping the kids access her data involved an EC2 cloud of GPUs. Please people, leave your password around so your loved-ones can obtain it even without a death certificate or will, because there are some situations that are even more complicated than simple old death.

    Your safety deposit box schemes all mostly fail on this point alone.

    --M

    --
    # grep slashdot access.log | grep html | sort | uniq | wc -l 2604
  61. Email was never designed to be confidential by Kmatte81 · · Score: 1

    How do you know a conversation is private? You know who you are talking to and you know others cannot eavesdrop. Phil Zimmerman, a foremost expert on email security, says: Email that uses standard Internet protocols cannot have the same security guarantees that real-time communication has. There are far too many leaks of information and metadata intrinsically in the email protocols themselves. Email as we know it . . . cannot be secure. The reason...email was never designed for confidential communications. Most email providers only encrypt your digital information while it is in transit (and this encryption is fairly easy to defeat). The problem is that your data spends most of its life in storage completely unprotected. If your email service providers have access to your password, they can view and share your information as they fit. Even most secure email providers only encrypt your messages some of the time, and can read your emails and attachments. There is no expectation of privacy when using public email systems such as Gmail, and likely never will be. Their livelihood depends on being able to read your email. Email also allows anonymous users and is routed through multiple servers across multiple domains, making it impossible to know if and by whom email is intercepted, or even who is on the other end of the line. I work for a company called Absio that has developed a new digital communications protocol that enables the first truly confidential alternative to email for messages and files that need to remain confidential. Unlike Ãoesecureà email providers, Absio does not have centralized access to passwords, keys or metadata related to your email. Each message and attached file is individually encrypted with its own key on your device before they are sent over an encrypted Internet connection to the Absio servers. Absio does not have access to your encryption keys, and does not have an alternate decryption key. This means Absio does not have the ability to decrypt messages or attachments, not even a subject line. Absio cannot see or share decrypted information, because Absio never has it. Our first application is called Absio Dispatch. When using Absio Dispatch, messages and attachments are automatically stored in encrypted form on your personal devices. Absio Dispatch transmits your encrypted data through an encrypted connection, and encrypts all metadata except for the Absio ID (like an email address) to whom the message is going. There is no spam, because your Absio Dispatch application can only receive messages from the list of trusted contacts you designate. The only people you need to trust with your data are you and the trusted contacts who receive your messages. We strongly believe that digital information is private property and carries all the rights and obligations that are associated with other forms of property, and all individuals deserve for their personal information to remain private.

  62. Securesafe.com by neopirate · · Score: 1

    Maybe this would work for you. I am using them.

  63. Re:Why complicate things? by Em+Adespoton · · Score: 1

    Exactly -- I've come to realize that storage format doesn't really matter -- what matters is keeping it current. In my case, that 1TB drive doubles as my offsite backup; it gets swapped out about every 3 months. I've already changed actual medium used 3 times since I started this; at the start, it was only essential files on a thumb drive, as hard disks weren't small enough back then to fit in the box.

    Another benefit of this is that even if my home computer gets scrubbed/sold/stolen/etc, all my passwords are stored on my keychain on that fully bootable drive. So the drive just needs a hardware-compatible computer to connect to and the appropriate password in order to access anything.

    Sure, some TLA could force the bank to open my box, retrieve the drive, and have access to my entire life plus full identity theft privileges... but then most TLAs can already do that without the hassle of involving a bank.

  64. Re:Why complicate things? by Em+Adespoton · · Score: 1

    Oh, for that matter: if you don't update your Will and associated documentation within 20 years, the contents are probably void anyway. Things change over time, and you need to keep that stuff current.

    Otherwise, your wife and kids may be a bit upset that you left everything to your mother and some non-profit that doesn't even exist anymore.

  65. Use a two-part scheme by Sortova · · Score: 1

    This is what I have done: 1) create a document with all sensitive information (passwords, account numbers, etc.) 2) encrypt it with the keys of two tech-savvy friends 3) e-mail the file to two non-tech-savvy friends with instructions to send it to the people in step 2 upon my death I'm not sure what you would do if you don't have enough friends (grin) but this seems to be a pretty simple and robust solution for my needs.

  66. why? by dala1 · · Score: 1

    This honestly seems over complicated. Why should anyone have this information before you die, especially financial information? The simple thing to do is put a hard copy (sealed, of course) of the information in a safety deposit box with a copy of your will. As long as your executor knows about the box, they can access it after you die and distribute the information per your instructions.

  67. Shamir's Secret Sharing Scheme by blavallee · · Score: 1

    I encountered an issue where our 'boss' thought it was important to know the root passwords. But my team came up with a compromise.
    Shamir's Secret Sharing Scheme

    Allowing us to provide the passwords to multiple non-tech members of the company, without risking the loose of the actual root passwords.
    At least three staff members need to combine their parts to reconstruct the ACTUAL passwords.

    Distribute the information to multiple parties, including your Lawyer. The information is 'safe' until a predefined number of parties work to reconstruct the passwords.

  68. Re:Paper stored somewhere safe by pnutjam · · Score: 1

    That depends on the state in some states a safe deposit box is the best place for a will and the law has special allowances to search for one. I think Pennsylvania is this way, maybe Indiana.

  69. Re:Why complicate things? by pnutjam · · Score: 1

    I am spinning up an offsite backup/archive company. I plan to offer annual data backup plans. I'll bill you and send you a flash device for your data, which will be loaded to a server that hashes it and uses some other processes to protect the data integrity.

    I am considering offering an escrow service where data can be released to a third party when certain criteria are met. The site is empty now, but check back to find out more, http://www.o2ark.com./

  70. I solved this problem recently by mtthwbrnd · · Score: 1

    I flew to see my co-global-head-of-everything-awesome and hypnotised her with all of the data she requires to keep our empire growing in the even of my death. My obituary will contain trigger words to activate the programming.

    1. Re:I solved this problem recently by mtthwbrnd · · Score: 1

      Seriously though, you should write everything down and give it to an attorney who will pass it onto the recipient after your death. It is then up to the recipient whether they want to commit to memory and burn or keep it in a safe etc.

  71. Re: encrypted file on flash drive by draxbear · · Score: 1

    Setup automated "are you still alive?" checking with http://www.deadmansswitch.net/ Have it email your password if you don't respond to a few checks in a few months. In lieu of the password, enough clues for family to reconstruct it if you're worried about these guys seeing it should do the trick. E.g First pet name + second pet name + wedding anniversary + favourite color etc etc.

    --
    --- I've completed diagnosis of your problem and can classify it as a YOYO...You're On Your Own
  72. when you go.... by JWSmythe · · Score: 1

    In the last several years, things have happened. Someone very close to me died with no notice. Quite literally, I saw him alive and normal at home. I went outside. A few minutes later I went back inside and he was dead. Natural causes.

    I went in for spine surgery a few weeks ago. I could have walked away from it, or have been rolled away to the cemetery.

    I always make sure someone knows how to do what I do. That person usually knows where everything is. They don't necessarily have all my passwords, but they know where the "key" is, which guides them to the vaults (one logical, one physical). I double checked the key, and the instructions for the vaults before surgery, and reminded them where the "key" is hidden. My "key" has another more colorful name, so I'm not even giving away secrets here. :) Your "key" could be something like an envelope marked "1997 expense reimbursements", with just a piece of paper containing a few important passwords and instructions for the rest.

    It doesn't have to be a life changing (or ending) event, or even an employment terminating event. It could be something as dumb as you're stuck in a remote airport during a blizzard, with no data service, and something major happened. Sure, everything *could* wait a week for the storm to pass. Or you could say "Call X. Tell them to go get the key. They will understand and can take care of everything." The instruction to "Call X" is kind of redundant, as the primary people should already know who the "oh shit" person is to contact. It's just reaffirming, "I'm stuck, and can't do anything from here."

    Just be very sure you can trust the people holding your secrets.

    --
    Serious? Seriousness is well above my pay grade.
  73. Re:Paper stored somewhere safe by dcw3 · · Score: 1

    They'll be lucky if there's enough for cremation.

    Not saying that you haven't thought of this, but a lot of people don't...

    Most IT employees are covered under some type of insurance...Accidental Death & Dismemberment, and company covered life insurance. You've also likely got a 401k...I've met many people who don't know how much they have in theirs.

    --
    Just another day in Paradise
  74. Each jurisdition is different by trialjudge · · Score: 1

    The laws of each State are different. This is true in other countries. I suggest you consult a local attorney at law in your jurisdiction, with a knowledge of Intellectual Property law. I suspect you MAY be looking for a "durable" power of attorney. (That means the power of attorney survives your death.) The power would instruct the person you chose "At the time of my death, please do X, Y and Z." Then the power dies, and is of no further effect. If there are huge financial implications, you might consider having the holder of the power post a bond to insure full performance. But please, get a professional to help with this. I don't try and fix my computer, because.... well.... I'm clueless. As far as I'm concerned it's all magic and that's the end of it. It took me three tries to get this posted, how's that for clueless? Just my humble opinion.

  75. Not necessary by RJFerret · · Score: 1

    I'm surprised only one other person pointed out almost none of that info is needed. Banks, courts, insurance, attorneys, brokers, all of them have procedures which negate passwords/PINS/all that info the executor of the estate typically doesn't know.

    What you do want is to get way more copies of the death certificate than you imagine you'll ever need. The death certificate and the institution's forms will gain you legal access to everything. Accessing them improperly could lead to trouble.

    (A list with passwords should be outdated in a matter of weeks when passwords are changed anyway, account numbers when accounts are closed/moved, etc. It's just quicker/easier to use the institutions process and doesn't ruffle any feathers.)

  76. Re:Yes, Paper by TheCarp · · Score: 1

    Total rookie mistake but, also a very common one. I have burned myself more than once not saving a document. Usually, it isn't all of my passwords.

    Actually keepass has an option to save after every change, it just isn't turned on by default.

    --
    "I opened my eyes, and everything went dark again"
  77. I got it by Kmatte81 · · Score: 1

    Snapchat is not totally secure (http://www.cnn.com/2014/01/01/tech/social-media/snapchat-hack/). There are other tools available where the service provider does not store passwords or keys, and therefore, cannot be the source of a breach (Absio, Wickr, etc.).

  78. Re:Why complicate things? by Em+Adespoton · · Score: 1

    I am spinning up an offsite backup/archive company. I plan to offer annual data backup plans. I'll bill you and send you a flash device for your data, which will be loaded to a server that hashes it and uses some other processes to protect the data integrity.

    I am considering offering an escrow service where data can be released to a third party when certain criteria are met. The site is empty now, but check back to find out more, http://www.o2ark.com./

    First off: sounds like a good idea.
    Second: It's going to need a LOT of work. I'm not going to send some random person a flash device with my data on it, even in encrypted form. The service is going to require not just escrow but a pretty heavy bond; basically, you're going to have to set yourself up like a bank. Then there's the issue of jurisdiction. If you're in the US, there's no way I'm going to trust my data to your server, when it's been shown that government WILL step in and look at things just because they can. Other countries aren't much better; they just don't have a Snowden leak. to back things up. Compared to this, fully offline safety deposit boxes have a ton of legal precedent to prevent third party snoopers.
    Third: You're going to be competing with data protection behemoth Iron Mountain. Are you up for that?

  79. Re:Why complicate things? by pnutjam · · Score: 1

    Yes, I'm targeting more of the low bandwidth households that can't back up to the cloud and those smart enough not to trust the crowd, but not educated enough to roll their own solution. I don't see an offering from Iron Mountain that caters to the new mom with 10GB of baby photos.

    Data security is something I will have to deal with. I think offline encrypted volumes will be pretty tough to snoop.

  80. Re:Encryption by j-beda · · Score: 1

    I thought about that, but my daughter classically can't remember passwords she uses every day; there's no way she's going to remember a password she'll only need once.

    Then you WRITE IT DOWN. Then give her the piece of paper with it written down upon. Or give the encrypted files and/or paper with the password to one or more lawyer types to do the holding on for, if you want to really have it properly curated.