Dead Man's Switch
deadmansswitch.net
deadmansswitch.net
Do not use this service. With less than 60 seconds of looking, you can hijack people's deadmanswitch accounts with a simple CSRF on the email change API.
If you have a "high value secret" and you are a normal person, lawyers work pretty well. If you have a "high value secret" and you're Ed Snow, something like this site is not a solution you should use because it will get you killed. Nobody has a use for this...
And if you host that yourself, there's a chance your credit card could get canceled and your VM/docker container/whatever gets canceled and destroyed before it does its thing. ... but I mean who cares. No you. You're dead! :-P
You pay for it ahead of time in bitcoin and build redundancy.
It's not malice but solving sensitive problems without taking security seriously can actually have really big consequences for your users.
This is very true - but often the author does intend to take security seriously and they've simply overlooked something. The best approach in that scenario is just to talk to them and ask them to take a look at a vuln you've found, rather than immediately telling all their potential users to stay away.
I don't imagine this service gets an enormous amount of traffic. You might be among the handful of visitors to the site who are capable of noticing the CSRF issue, and maybe even the only one to go in and look at the source. He's had an email address up on his site for a while (hi@stochastictechnologies.com). Did you report the vuln to the author when you first found it?
Anyone who "cares" about security should know about CSRF. It is one of the 3 attacks that all web devs encounter. It's trivial to find.
I'm also not sanguine about the idea of using a service which is meant to handle information of such gravity as this, and which has also had an extremely well understood, trivially fixed, and enormously compromising information disclosure vulnerability go unfixed for a year or more. The reason why that situation has obtained is not interesting to me; that that situation has obtained is enormously so.
Don't get me wrong - I think very highly of what 'StavrosK is trying to do here, and I agree that it's counterproductive not to report an issue once found in a case like this. (There's a certain degree of nuance made necessary by the fact that kill-the-messenger reflexes make vulnerability reporting so fraught in general. But that doesn't seem likely to obtain in this case, so I'd report, probably not even anonymously.) But at this point that trust just isn't coming back.
That said, tens of thousands of users apparently have a use for this. I'd imagine it's mostly "last goodbyes" type of stuff, also many users email me saying they want something to send "something happened to me, please come so my dog won't starve".
"Millionaire with assets" and "Ed Snowden" aren't the only two possibilities.
Suicidal tendencies, then? While you are applying the "fix" may want to add a link to suicide prevention resources.
EDIT: Added!
No, it might surprise you to learn that all humans eventually die. Some of them even have families they want to send 'death-bed' notes to.
This seems uselessly snarky, especially since StavrosK (who I assume is the developer, based on other posts) gave a polite and snark-free response already:
> That's actually probably a good idea, I will add that, thanks.
Google Inactive Account Manager: https://support.google.com/accounts/answer/3036546
Facebook Legacy Contact / Memorialization: https://www.facebook.com/help/1568013990080948
I would be terrified of running a site like this unless I had a lot of experience with resisting DoS and state-sponsored attackers.
Everyone I know that uses PGP has lost their key at least once (including myself - I forgot to write down the passphrase for a key once it expired and I no longer used it daily to refresh my memory).
My verification idea was the self emails, but also a few friends would have to verify (or they could initiate). That way if you lost access to your email, you could avoid a false positive.
First, your point about controlling the message when you pass is TERRIFIC. How many of us have seen opportunistic acquaintances take over the memorial of a dead loved one. It really, really sucks, especially when the acquaintance colors everything through their own beliefs, and those beliefs contradict the beliefs/opinions of the deceased.
Then you gotta think about the potential to send individualized messages to your loved ones. Damn that would be touching.
Plus, what about stuff like Mark Twain's journals. Supposedly he had written much that he feared to publish because it was too incendiary. He thought it'd be ok for it to be published after his death. However his estate chose to keep it private.
Next you can imagine the fun you could have planning your account to 'haunt' people you didn't want to say nice stuff to.
Good shit
I run a service, Cronitor, essentially a dead man's switch for jobs, heartbeats, etc. Doing some analysis on notification method preferences (Email is top, followed by Slack) I noticed a webhook that will hit a url that ended with send_secrets.php if the creator doesn't ping at least once every day.
No alerts had yet been sent so the secrets seem to be safe. I added a todo for a couple more test cases around alert sending -- I'd hate to ship a bug that accidentally sends whatever the heck is in that file. I would suspect the creators of this service will feel that same pressure soon.
The service has been running for eight or so years now, and the safeguards against this have worked pretty well, but yeah, every change is a chance for something to go wrong. I have extensive tests for the sending code and the logic to check whether it's time to send, though.
I've used this site for years now and I can firsthand tell you how awesome it is. I once accidentally triggered my death when I dropped out of contact for a few months, but otherwise, it's amazing to know that even if I die, I can from beyond the grave, I can set in motion an elaborate chain of events that will end up with my family possessing all my digital assets (including about half a bitcoin), people whose digital assets I manage will receive full control back, and MOST importantly: my best friend will delete the porn on my computer in time, and only then surrender my passphrase to my family.
I'd like to see an answer to "How will you ensure the continued operation of this service over N years?" on the help page though.
Ideally this would require two or three separate methods to verify you're still alive. Or some form of challenge/response relying on at least two different mediums/communication networks/devices.
I'm just a regular guy, but the messages and details that I would leave in a service like this are too sensitive to be put on someone else's server for a period of years. (Maybe I'm just too private in this age of social networks).
We really need a PGP like solution for the masses. On that note, I wonder why someone like Mozilla doesn't take this on and push for human friendly client certificate authentication.
How would that solve the issue of putting the secret on someone else's server and guaranteeing that it'll be available after death only? They'd have to have a key to decrypt to release it (in any useful meaning of the word) then you're dealing with storing the key and the encrypted secret. You still have to ensure that the decrypt key will get released on your death but not before and used to unlock your other secret.
Then the workflow would be something like the service sending an email to each intended recipient with a short message saying keep this message saved it includes a passphrase that you will need later. Then when the switch fires another email is sent asking the recipient to provide the passphrase. The service will then decrypt the message with the passphrase.
I know this still requires a lot of trust, but it at least protects the data at rest.
There's too many "What if?"s. The biggest one being: What if their system glitches and mistakenly sends out emails even though I've been checking in?
What if I lose access to my email account? What if I end up in jail (regardless of reason) and can't hit the switch? What if they get a subpoena for the information contained within the emails? What if the service goes down? I'm under 30 - it's unlikely anything like this will be around for 50+ years.
To have a fully safe and secure Dead Man's Switch you would need more than just one layer of confirmation, and more than one layer of failsafes.
My thought so far is:
A service such as this one, except instead of an email with your secrets, it would simply release private key to certain key individuals. In said email would be only the key, and nothing else. This would have to be somewhat tech-savvy individuals that would know the significance of the key upon getting it. The email should come from my own personal address.
In my will I would entrust a different set of individuals (immediate family, etc) to one or more lockboxes contained an encrypted drive (HDD, SSD, flash drive.. something resilient.. maybe even the entire device.. maybe all of the above to protect against obsolescence.. ). The recipients of the first email would have to get in contact with these folks and mutually agree to decrypt the data on the drives.
If the emails are sent by mistake, then all I have to do is seek out my lockboxes and encrypt with a new key. The people who got the key will probably be asking "wtf is this?" about. Had I been dead, them seeing an email from my personal address with a private key would elicit a much different response.
Unfortunately this plan still relies on some technology to continuously log that I hit a button, which I don't like. I could misplace emails, I could lose access to my domain, if I do it via SMS, I could close my cell phone number... list goes on.
The only thing I can think of that doesn't involve another piece of technology is trusting the private key to a person (or organization) who is impartial and bound to secrecy to only divulge the key upon a copy of your death certificate. Lawyer perhaps?
Come to think of it, this could be a really cool add-on service to a life insurance policy. Instead of just cash, your beneficiaries get cash + vaulted information.
A couple ideas I have considered:
- Using a secret sharing protocol to split a key into N pieces for people you trust. This would be relatively simple, but there's the risk that they might be hard to get into contact with, or might have come into harm's way themselves. A threshold scheme can be used to allow N<M people to reconstruct the key. This is vulnerable to collusion. To prevent compromise of individuals in a targeted attack, the keys could be stored on smart cards. Also vulnerable to hardware failure.
- Unparallelizable time lock / time release crypto. The problem is, this needs to be able to be decrypted in a reasonable amount of time after my death. But if that's the case, then any bad actor could decrypt it given enough time. One solution is to embed the private key and program in an HSM, and use enough rounds that it will take, say, one week for the HSM to brute force. I could reset it daily, and connect it to my UPS. Should I die, I wouldn't be there to reset it, and it would release the private key. The problem there is, should I ever get held up for any reason, it'd be released. The idea sounds cool, but I'm not sure it'd work very well. Also, what if the hardware becomes damaged after my death? Or a violent criminal breaks into my house and steals the HSM with everything else indiscriminately?
Both schemes could also be used in parallel---the HSM key could be absolutely required in conjunction with everything else. If it is compromised, I generate new keys and redistribute them. This all requires more thought.
The scheme needs to be very unlikely to fail. If I die, I want it to include private keys for my disk encryption, select account passwords, etc so that my wife can access the information she needs, or would find valuable. I would also likely sign (cryptographically with my PGP key) a document that states that I have indeed died, to send to others.
As in, I don't want to use this service. Or any other.
The best part is that it goes based on your Google Account activity, which, for most people, consists of searches, Android/iOS use, etc -- not just clicking a link.
I had more than email as the check-in transport, and the trigger would have delivered more than just email (upload files and videos to online services, post to Twitter, etc).
Anyway, the domain is free again if anyone wants it.
Edit: spoke too soon, it appears to have been taken by someone else.
That's so discriminatory to cats with their nine lives! :D
Seriously, that's a great site, and I love the one-time fee model.
It struck me at the time as being insecure but the low tech solution worked.
Perhaps this site would have been a better solution.
Is there any guarantee that if "bad things happen" to the author(s) of this project, the emails will live on and will be sent?
What about using Ethereum and the likes for these services?
Of course that it depends on the amount of money needed..
I want that to sink in to all of you. Two of three of you wont have time for carefully crafting what you want to say, or to whom...Because you'll either BE dead, or WILL be shortly. And what i'll bet most of you want to say isn't about where you buried the treasure chest of Al Capone, or that you're the secret love child of Ronald Regan and Janet Jackson...It's that you love them, that you treasure this and that shared memory with them, and that you wish for them to remember you a particular way, or perform a certain ritual in your memory and honor, should they choose. Sure, this database wouldn't be hard to hack. What's in there is almost completely useless to anyone other than their loved ones. can you imagine how depressing it would be to read a hundred thousand dead people's communiques to snag the one juicy bit about some senator being the illegitimate son of Prince and Madonna? Yikes! All that being said, I've spent quite some time thinking on this subject, and the answer I keep coming back to on the "Verifying you're dead" problem I think should be handled by examination of the customers data footprint in some sort of routine way. If any of you have ever done data analytics or doxying, you'll know that there are some distinct signs that start to appear when your subject focus has died or dropped deeply off the grid, even after a few days. It seems to me that such qualities could be mathematically modeled into a set of software scripts, and that tied to the trigger. With a failsafe of primary and secondary inquiry designated by the client. I have a few other ideas along these lines that prudence dictates I should keep to myself until it can be developed and patented properly. If any of you would like to work with me on such a project, please contact me at dontfeartherepair@gmail.com
I'm not saying that this is that site's intent, but I'd be cautious about trusting them with anything particularly juicy.
This implementation is a bad idea to use because of the aforementioned security smell.
Another implementation would have to solve the problem of how to ensure message security while still being able to deliver the message at the right time.
The "right" answer for something like this is as you said, lawyers, but "get you killed" is... overly dramatic. Snowden is, after all, still alive.
You were fine before your "Snowden is still alive" thing. I don't have an opinion about whether Stavros's site is a serious privacy application. Maybe it isn't. But other manifestly unqualified people have tried to deliver privacy to people and failed catastrophically.
Given the way people are likely to use it, I can't see how it would not be.
You stop.
Edit: I'm being absolutist because it's easier, rhetorically, but if I have to be explicit, I'm saying that the realistic occurrence of murder as a result of privacy tool usage, one way or another, is low, to understate things. To talk about murder as a problem in cybersecurity is like talking about meteors hitting car windshields.
If you intend it to be only a toy, then you can, and I think ethically must, make that clear.
If people persist despite all warnings in using it in ways that might cause them harm, then you can, and I think ethically must, cease to make it available.
To do otherwise is dangerously cavalier at best, and incompatible with the minimal degree of responsibility which I would require of an employee or a colleague. Perhaps you feel otherwise. That's your prerogative. But, if so, I do hope, for the sake of any users you might have, that you aren't in a position to make similar decisions yourself.
Sounds like he did what you said, anyway.
Your greeting card website's threat model doesn't include this.
Have meteors hit car windshields? Because people have died by not correctly securing sensitive information.
Read this: https://www.washingtonpost.com/news/worldviews/wp/2016/06/13...
Then consider that 'coming out of the closet' would be a very viable use of a site like this if someone is gay and they live in an oppressive country.
Actually, on further reflection, I wouldn't be comfortable running a service like this at all, for reasons amply detailed elsewhere in these comments - in short, it's a great way to paint a target on your chest for everybody from random scammers to state-level actors. I must admit I am considerably impressed by your courage in continuing to do so. Don't get me wrong - I think you must be a madman. But I can respect a very brave madman!
That's not something I like saying, and I can't imagine it's all that pleasant to hear, either. I wouldn't say it at all if I did not feel it necessary, and I feel it necessary precisely because there seems to be a severe mismatch here between the gravity of any potential compromise of your service and the measures taken to prevent such a compromise from occurring. You know a lot more about the nature and scope of those measures than I do, of course, and it's possible I'm underestimating them here. I do hope that's the case. If it is, please accept my apologies for having spoken harshly where doing so was unwarranted. If it isn't, I hope you'll attend to that situation as best you can without delay. If you're not sure, then for the sake of your users, I hope you'll bring in someone with the capability to evaluate and resolve whatever security issues exist, and do so with as little delay as possible.
In any case, you've (perhaps accidentally) put yourself in a position that encourages people to invest a great deal of trust in you, and it seems that many people have done so. Had I put myself in such a position, I would not be comfortable remaining in it if I could not be entirely confident I had either done everything within my power to fulfill that trust, or removed myself from that position without betraying the trust I'd found myself ultimately unable to fulfill. But that's just my own evaluation, and perhaps you feel differently.
I'm responding more to the indignant claim that casual security/privacy tools can't harm people. It's true: they are very unlikely to harm the kinds of people who read and write comments like these. Like I said, it was the allusion to Snowden that moved me to comment.
Yes, definitely. I need to spend a bit of time clearly communicating "it's fine for telling people you love them, but not that your multinational's CEO defrauded millions of pensions".
Can we discuss this over email?
If you don't want this to happen, I suggest taking more care to edit flamebait out of your comments. Leading with "Don't be so melodramatic," "That's so unbelievably false it makes me sad that you," "You stop", etc. guarantees poor results and therefore off-topic snippage.