Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> We really need a PGP like solution for the masses.

How would that solve the issue of putting the secret on someone else's server and guaranteeing that it'll be available after death only? They'd have to have a key to decrypt to release it (in any useful meaning of the word) then you're dealing with storing the key and the encrypted secret. You still have to ensure that the decrypt key will get released on your death but not before and used to unlock your other secret.



Assuming we restrict the solution to this problem space. Since I trust the service to send the message, then I trust them as well to generate the encrypted package and communicate the passphrase needed to decrypt. I trust them enough to not keep that passphrase around.

Then the workflow would be something like the service sending an email to each intended recipient with a short message saying keep this message saved it includes a passphrase that you will need later. Then when the switch fires another email is sent asking the recipient to provide the passphrase. The service will then decrypt the message with the passphrase.

I know this still requires a lot of trust, but it at least protects the data at rest.


That at least protects it on the server but the secret sitting in the email is pretty insecure since the generated decryption key is only as strong as the least secure recipients security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: