this post was submitted on 11 Jan 2025
182 points (97.9% liked)
Asklemmy
44331 readers
1032 users here now
A loosely moderated place to ask open-ended questions
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- [email protected]: a community for finding communities
~Icon~ ~by~ ~@Double_[email protected]~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Encrypt secret. Post it publicly. Configure a web server to email the private key to any number of addresses if you don’t log in every week.
going to have to be careful with the timing, though. A week can easily be reached if you are ever in an (actual) accident.
Also, note that having a publicly known dead mans switch can be exploited and cause the opposite of what you want: Imagine a competitor (be it idustrial or nation state) wants the secret to leak. Why not speed it up?
The thought of e.g. some foreign adversary having you KILLED just so your secret leaks… that’s wild.
Host the server on Tor. Have a second secret server on Tor that passively monitors the health of the first and distributes the key if it is taken down. Have a one-time pad of passwords memorised, not written down or taken from a book.
Ciphers get broken. What you save out there now can be pulled down and then saved until it can be cracked 10 years from now.
Wild concept to consider for those who haven’t heard of it
On that subject makes me wonder if insurance.aes has been cracked yet
That's an optimization for just having the automated email send the secret directly.
depending on the size of the secret, it helps to have people download it ahead of time.
Also, it acts as a time stamp proving that you knew the secret at a certain time if that’s useful.
Right, that's what i mean by optimization. It's accomplishing the same goal, but amortizes the transfer over more time, saving bandwidth.
The timestamp feature could also be accomplished by publicly posting a small hash of the data ahead of time, but similarly bandwidth can be optimized by distributing the encrypted blob ahead of time.