Planning for My Kidnapping
blog.luap.info
blog.luap.info
Sooo many eggs in one basket. Unless you are the son of an oil or shipping magnate, I suggest that your risk of being kidnapped pales in comparison to your risk of being hacked.
>> Currently after 24h without changing activity a first notification is sent to my own email so that if this is a mistake I can stop the system before it is too late. And if 6 hours later I've still haven't changed of activity then a mail is sent to my parents.
30 hours? I take it that the author has not done much international traveling, or traveling generally. And they haven't worked a job involving long hours, or a back-to-back shift after someone calls in sick. For any adult, 30 hours without connectivity is not enough to trigger a kidnapping alarm.
I guess the question is whether they are encrypted or not, or how they are otherwise protected.
I keep personal info in my password store. I figure if that file gets compromised I'm pretty screwed anyway. But compromising that also requires the attacker to have my private key and the password for that key.
I guess the question is what the OP considers the cost of a false alarm to be.
Because you're right of course. Lots of things can happen that put you out of communication for an extended period. Communications is more and more ubiquitous but phones and laptops break. The US still has rather large areas with no cell phone coverage. And so forth. In the past 10 years, I'm sure there have been multiple times when I've gone more than 30 hours with cellular service or WiFi.
I think it's mostly an age-related thing but a lot of people just can't imagine not being in touch almost constantly. There was a discussion just the other day where someone was worried about being tracked at protests. But "Just leave your phone at home?" basically did not compute.
In general, for a rare event, it can be a difficult problem to activate on the absence of a signal fast enough and reliably enough to be useful, without having false positives.
I wouldn't leave my phone at home either; a smartphone is the single most useful thing to have on your person when facing unexpected problems of almost any kind. And no idea about those particular protests, but protesters over here have started heavily coordinating and sharing information via phones, so you might have an actual information deficit without one.
That said, switching off cellular (or the device itself), disabling biometric auth, that might be a good idea.
Your wallet contains a lot of pretty damn good ways for someone to impersonate you and rob you blind, yet "just leave your wallet at home" will stubbornly fail to compute for a lot of adults.
In the last 10 years the longest I went without Internet was during trans pacific flights, so never longer than 15 hours. I think this level of connection —- basically intermittent connection during the entire waking hours —- is super common in today’s society.
If I was disconnected for longer than 30 hours w/o prior knowledge of being disconnected it would mean something seriously bad has happened to me, and it would be nice if my next of kin had access to all the documents they would need to settle my affairs.
Madras is a small town of about 7 000 people, in a county of about 25 000 people. Estimates are that around 100 000 people came there for the eclipse. The cellular infrastructure there was not able to handle the volume.
For the ~28 hours I was there, I was never once able to view a web page via cellular internet. I and a friend who also picked Madras to watch from tried to call each other a few times, and never got through. Most text messages we tried to exchange were lost, although we did each manage to get a couple through, although those came through hours after they were sent.
We both had T-Mobile. I don't know how AT&T, Sprint, and Verizon were doing.
Apart from that, emergency contacts usually do get notified where I live, police take care of that, and they have to be involved with any major accident. Phones are sturdy things in practice, and if not there's my identity card and a card with important phone numbers in my wallet.
And if they didn't, my partner would hardly sit around doing nothing if I randomly disappeared.
(OP here) Well I'm kind of digital nomad so traveling very often and I also maintain a Saas platform, so I basically need to be with internet access all the time, I know this may not be the case for everyone, but in my case if I'm going to be without internet for more than 12 hours I know it ahead of time
Sounds like a dream job really. The ubiquity of internet-everywhere these days - even in third-world countries - is quite astonishing really. When I was traveling in Kenya a decade ago I was able to blog (via 2G) in the middle of the Maasai Mara!
The author appears to be an individual who digitally documents events as mundane as eating. I don't think going days without an internet connection is a big risk for him.
Personally I just keep an encrypted flash drive with all my passwords and documents in a safe. My whole family knows the password but they don't know the combination. If I go missing they can cut the hinges off in minutes with my angle grinder. They can't access it without me finding out and hypothetical burglars wouldn't be able to decrypt it. Simple and doesn't rely on any external services.
My wife’s sister and her husband were violently attacked and almost kidnapped, but somehow managed do escape. It happened in the jungle I. Thailand.
They are very average people, from Eastern Europe without any expensive possessions or ties with rich people.
It’s still a puzzle to them why they were attacked.
Unrelated to this, I'm curious why everyone is picking so much on Thailand. I'm not sure if this is my own bias because I've went there multiple times, but people use Thailand for a lot of (mostly) bad examples. Even though Thailand is probably as safe as it gets in South East Asia (with the exception of Singapore). I know multiple people from Thailand and the Philippines, and everyone is saying that the Philippines is more corrupt and more dangerous.
I’m not picking on it. But I’m just telling and anecdote, where someone not from hiso was attacked and kidnapped, but they escaped.
OP was saying that only hiso individuals should worry. My point is that anyone can be kidnapped. Don’t need to be rich or famous.
Otherwise I agree with your sentiment about Thailand being more safe than most. In some respects it’s safer than many western countries. Probably for everything except traffic deaths, which they are almost leading the world in.
Where I live (less than an hour from Seattle), I have had power outages longer than the proposed death countdown, my DSL goes down immedidately without utility power, and the cell towers only stay online for 4-6 hours. If it starts while I'm awake, I'll let people know, but if it starts at midnight, I might be out of communication until it's over.
All this software setup with various servers etc is way too fragile and hard to maintain and the lack of regular real life testing means it will probably not work the way you imagined in an actual emergency for any sort of edge case or other reason you haven't considered or you get false alarms and scare your parents with no reason etc.
It's already difficult to keep all this info up to date. Keeping a technical solution maintained is just extra distraction from the main points. The key difficulty is anticipating all the issues that will pop up when you actually die, practical stuff like interactions with banks etc. What will your parents need to know? What untied loose ends do you leave behind? It's uncomfortable to think about these things so most people put it off.
I don't see an explicit reference to "recent image of me" in your "First step" list of data - photos in legal docs/credentials may not accurately represent your current physical appearance.
The idea is that you choose people who act as proxies in an emergency event; if something happens, a configured number of them have to approve access to your vault of documents/information before it can be viewed
I've been thinking it would be neat to have something like a very long term will execution/time capsule, for example to release biographies or other such information a long time in the future (say the 100+ year range).
Something like that would require a lot of things to go right, one of which is the a good expectation that the company would be around by then, for example the old banks such as Lloyds (I doubt they offer this kind of service to individuals if at all however).
Curious to know if you had any thoughts for how a service similar to that would work (or if they exist already), if its even feasible.
The obvious concerns here are the storage media used, the DR plans for the service, and more importantly, trusting that the company will do right by you after you're gone – even if it goes under new management or bankrupts. While I always struggle to find applications for blockchain, perhaps this is a scenario where it could be useful... perhaps you could upload the encrypted data to the chain, and form a contract where the key to decrypt it is released after X years?
This seems like too short of a duration. What happens if the email is sent between 23:00-01:00 (your parents timezone? They are probably asleep and the email will expire at 5-7AM. Will they see the email in time?
* https://xkcd.com/538/ (or a health emergency quarantines you without a data connection)
What do people have set up in case of more an "unexpected death" situation?
I have basically all information someone would need to access any of my accounts in a password repository, but I don't have the key or password shared with anyone.
Obviously that would be an issue if I was incapacitated.
What is the recommended way to handle these things?
If I told one of my coworkers that I use `pass` [0] to keep my passwords encrypted and synced into an online git repository, they would know what that means. My wife would have no idea.
So then it's not just a matter of "here are the relevant credentials", it's also "Here are the relevant technologies and X would know how to piece it all together"
But then at the same time, maybe it just doesn't really matter and I should just get a safe deposit box at the bank and put everything relevant in there in paper form.
My financial accounts are probably the main things. I don't know that I have any beneficiary stuff set up on them.
I was maybe overly specific in my asking.
Basically the thing I am wondering is:
What do I need to have in place to make sure my wife / kids have access to my assets, etc. in the event that I die unexpectedly?
It would make cancelling subscriptions not needed anymore or transferring them to another person much easier I guess.
Both our accounts have strong passphrases and are secured with MFA of course.
They are distributed among friends and family to be cut open in the event of my death.
It's based on the trust that not more than 5 of those 10 people will conspire against me while I am still alive, but also at least 5 of them will be able to find one another, and unlock the password should I pass.
... good reminder, it's due for an update
Today I finally decided to read the Wikipedia page and figure out how it works.
Really neat. Uses the fact that you need `k` points to uniquely define a `k-1` degree polynomial.
So if you want the secret to be recoverable by any `k` pieces, you just need to define a `k-1` degree polynomial and generate a series of points along that curve, with the secret at a known location on the curve
Basically it sets your secret to the polynomial constant term (i.e. the y value for x=0), generates random coefficients for the rest of the polynomial factors, and then computes however many points you requested. The shares are just encoded (x,y) pairs.
There is slightly more complicated math it to better obscure the secret, but in essence that's all it is. I thought that was really neat.
EDIT: I saw now that it is "rented" so it is remote I guess.
I will admit that I am way more interested as to why someone is planning that ( I had a boss who had a reputation for being a major pain in the ass and once gave me a speech how she is prepared for being kidnapped and few other uncommon eventualities ).
Then again, I may be looking at it this through US lens. It may be a more common issue in other places ( like Africa maybe )?
If I was veryvery rich and working in an industry that is suspicous at all, and I was located in USA or a South American or African country, I dont think preparing for kidnapping would be so out of the question.
2. Don't save encryption key
3. Buy life insurance, a few million dollars
4. ...
5. Beneficiary uses insurance payout to spin up some u-24tb1.metal AWS instances
6. Crack encryption key
7. Profit
Also, you have to keep the encrypted treasure a secret, or someone else with money could snatch it out from under the heirs.
2. Don't save encryption key
3. Buy life insurance, a few million dollars
4. ...
5. Surviving spouse uses insurance pay out to spin up u-24tb1.metal AWS instances
6. Crack encryption key
7. Profit
There is very low risk for someone having access to my bank account to actually do something with it.
So am my important information is on google docs, shared with the people I trust.
By far (very much far) I want to be sure that the information is available without the need for physical access and up to date.
A DBA I had worked with years ago disappeared from work. Nobody on the contract knew where he was. After a week or so, his parents, who lived maybe 100 miles away, called the contract manager. He discovered that the man was in the county morgue as John Doe, having been found dead on the sidewalk outside his apartment, without ID on him.
I assume most HN readers are
- younger than the DBA, who was probably in his mid-fifties - in better condition, for he was obese - in a wider social circle, for he was pretty anti-social
Still, it isn't bad to have people who will know that you have disappeared.
(Disclosure: I work for Google, speaking only for myself)
what i actually meant is the stuff he describes on how he expects this to work for him. for example a kidnapper would already know the best time to kidnap him is after he had lunch because that's a recorded activity which resets the timer. they also know he will send location data so they might take his phone on a different tour directly after kidnapping and there is probably more usable information in this post...
however, i assume here this is a kidnapping specifically targeting someone with proper due diligence. but that might not be very realistic at all and you actually are telling me about it. referring to them as fb/whatsapp users just made me think you might talk about technical aspects they would not get but i think there is more to it that might be easier to comprehend.
Around here, when someone is kidnapped, it's usually because a person from the victim entourage leaked some financial information. The kidnappers would just remove the phones from the victim and drive the victim around in a car for hours. After it the victim is moved into a safe house.
It's a pretty low tech business (from what I've heard from surviving victims or the family members of those that did not survive), no one will bother with investigating the online aspects of victim's life.
Yes, last wills do both, too, but they have a long history with lots of jurisprudence about what you can and cannot arrange for after you die, and how you should arrange that (https://en.wikipedia.org/wiki/Will_and_testament#Requirement...)
Multiple solutions for this currently available on f-droid. simple and easy.