Cheat sheet for if I'm gone
thoughtscollected.tech
thoughtscollected.tech
My father had a stroke so debilitating that he lost language entirely, lives in a brain care unit 24/7, and has zero chance of regaining even the most basic idea of a life. But by not being biologically "dead" he retains a lot of legal protections that don't really suit his situation and my mother is unable to sell her home without the permission of the Court of Protection. We filed for said permission 14 months ago.. and, you can guess the rest. With a lasting power of attorney, she'd have been able to organise her life properly within weeks.
Fundamentally, the OP isn't faced with a tech problem. People need to start with greater awareness of power of attorney, wills, and probate.
In a probate situation, your loved ones don't have to know all your passwords and so on. They do need to know where your assets are so they can contact the right organisations to claim them. And you can make that process easier for them by avoiding having small accounts all over the place.
In the first case the account is inaccessible for a fair bit of time if either X or Y dies. In the latter case both can always access it.
My partner's aunt got hit by this when her husband was 100% incapacitated and hospitalized. She couldn't even pay her rent or buy groceries, because she couldn't prove her husband agreed with the spending.
We switched our account to the "or" style really fast after that.
If you just have the access permission and the main owner is incapacitated or dead, your access is not valid anymore and it's a huge hassle to get access to the funds.
You want the co-owned style where both have equal rights to the funds on the account. The easiest way to check it is just to contact your bank and make sure it's set up that way the exact terminology seems to vary a bit between banks.
It's much rarer now because checks are basically gone, but you used to be able to get accounts that would require both signatures on the check, not just one.
I imagine if we ever get around to accepting euthanasia as a society the idea around a living will need to become formalised. For decades my dad was very clear he would prefer to be dead than exist in the state he is now but sadly the law insists he, or whatever is left of him, must suffer.
The key point is that the whole process should be far easier if these things are setup in advance, while the person is still able to make their wishes clear, i.e. while they can still say who they trust to make decisions for them.
She'd also made my sister and I co-owners on her bank account, so we had no difficulty accessing money for her care in the short term.
His stroke was one of the emotionally hardest times of my life. He had lost language entirely as well - and most movement.
I lost all but one of the hundreds of domains I owned, 10 years of email, and of the thousands of online accounts I had when I was locked up, only about 3 were accessible after I got out due to changes in security policies or email addresses (I'm looking at you Gmail) that I could no longer log into despite having the username and password.
This problem is only going to get worse as more sites, sensibly, require MFA. As long as you are compos mentis and have physical access to your devices everything is grand, but once that breaks down, you (or your loved ones) might be screwed.
Then you can give them access to 1Password or similar in some way.
She has abridged [1] and long checklists [2] that everyone should complete. Most of us probably don't even think about these things:
- will
- power of attorney (in varying forms)
- what happens to pets
- what happens to kids
- money
- burial/funeral wishes
- insurance
- living will
- etc.
[0]: https://getyourshittogether.org/
[1]: https://getyourshittogether.org/wp-content/uploads/2021/04/G...
[2]: https://getyourshittogether.org/wp-content/uploads/2021/04/G...
* Not including divorces or if you change how you want to do things.
** If you haven't been involved in settling an estate, that bar is probably far lower than you'd expect.
You can use Nolo or Rocket for most of it (and you should, at least bforna first draft, because the expensive attorney is doing the same thing, like H&R Block or an accountant for taxes). Try to save their time for complex stuff; they will be happy to charge $hundreds/hr for data entry eqivalent of running TurboTax.
The "how it works" section has more information [3] but it essentially boils down to trusted individuals requesting access - which can be manually approved by account holder or they are automatically granted access after a pre-defined wait time.
Bitwarden (paid version) also claims this - "If your premium features are cancelled or lapses due to failed payment method, your trusted emergency contacts will still be able to request and obtain access to your Vault. You will, however, not be able to add new or edit existing trusted emergency contacts."
[1] - https://bitwarden.com/help/emergency-access/ [2] - https://github.com/dani-garcia/vaultwarden/wiki/ [3] - https://bitwarden.com/help/emergency-access/#how-it-works
Self host with Vaultwarden and do not use this feature.
I would assume that only the "trusted individual(s)" - a spouse or whatever - has the "private key" of the vault, so only that person can access it (not Bitwarden, and nothing can be circumvented.)
If you have a house, which has windows, your locks do not provide security against someone smashing open the window. Key cutting schemes are a bit like this - no key offers security, only one of several access routes.
Having multiple access routes may be desirable and simultaneously a concern - a fireman smashing through your window to save your life is desirable, a burglar slitting your throat after smashing through your window is not.
Encryption is more like a lockbox or a safe room - having a burglar compromise your safe room is undesirable, and going into one during a fire is also undesirable. But you do want to use one in the event of a burglary.
A key cutting scheme may be useful in the case of mutli tenancy, but it is not a reasonable dead man switch - if your data needs to be re-encrypted either the keys themselves must be related (calling into question the security of the keys), or the encrypting party must multi encrypt the data, meaning whomever does the encrypting has full access to all the key data.
If e.g. you are yourself encrypting the data, you must multi encrypt - it would be faster just to share the key yourself, as you already have all the keys. If the third party is encrypting, this means they have side channeled your data such that they can decrypt at any point.
Again, even in the case there are e.g. two mathematically related keys, you cannot then enforce a timeout without first referencing and thus controlling the original key. You MUST distribute your keys yourself to your 3rd parties, or your data cannot be secure.
No. Cutting a key in half doesn't halve its security, but it reduces it exponentially.
256 bits = 2^256 possibilities for bruteforcing
255 bits = 2^255 possibilities for bruteforcing, or half
128 bits = 2^128 possibilities, or 1/(2^128) the security
2. Half of K is a random 256 bit X
3. Other half is (K xor X), still 256 bit
Having half of key is still 256 bit bruteforcing.
256 bits = 2^256 possibilities for bruteforcing
255 bits = 2^255 possibilities for bruteforcing, or half the security of 256 bits
128 bits = 2^128 possibilities, or 1/(2^128) the security
But you can have encryption schemes requiring N-of-M private keys to decrypt.
At no point does Bitwarden the server have a copy of anyone's private key. And no splitting of keys is necessary. This is just the normal way asymmetric encryption works.
This, of course, all breaks down if you don't trust Bitwarden the company, since they provide you the client. As far as I understand, US law enforcement doesn't have the legal ability to force a company to modify their own software to make it malicious (as opposed to doing something much simpler like forcing them to turn on IP logging on a VPN server). But if your threat model includes the possibility of US covert intelligence services MITM-ing Bitwarden the company and sending you their own malicious client, then yeah, keep your secrets in a physical vault guarded by people willing to die in a shootout with the FBI before betraying you. Make sure they'll answer to your successor if you die.
It still comprises a break in the end-to-end crypto, and can still bypass the time delay and decrypt your passwords today without your involvement.
But you _don't_ want trusted parties to be able to access this in case you are incapable due to being arrested, or choosing to simply elope.
What got me interested is that Bitwarden is open-source and empowers you to self-host, which for me goes a long way for establishing trust. It has a modern interface through desktop, browser extensions and CLI. You can choose to cloud-host your vault on bitwarden servers, for convenience, with a very generous free tier. Which is what i've been doing for years now, no complaints really.
I had used LastPass for a few years, and begrudgingly started paying when they went the "desktop or mobile only" option for free accounts - I need both for complicated reasons. The switch made me pretty bitter with them over the whole thing. It was like I was tricked into trusting them to deliver one thing, then they started to charge me for the "privilege", with no tangible improvement to the service they were providing.
After I saw the thread and started to read up a bit on their past issues (https://en.wikipedia.org/wiki/LastPass#Security_issues), I was motivated enough to make the switch.
Personally, I've had nothing but great things to say about Bitwarden since moving over. The import from one to the other was pretty painless.
I still have to interact with LastPass for certain job-related things, and the difference is really very noticeable. Much easier to generate usernames and passwords in the web extensions on BW. Things are laid out a bit more logically, in my opinion. It also feels like BW signs in/loads significantly faster in the browser extension (I might just be imagining things). It just feels less cumbersome than LP is.
The only negative I can think of is that LP is a bit prettier to look at.
The Bitwarden access request seems cool since it has a "quarantine period" where the owner gets notified of the access request and can deny it, if still alive (against a malicious spouse request).
If you're sure you never face the "malicious spouse" scenario, then sure, but how many marriages end up in divorce again?
I dunno about you, but I kind of got married to them because I trust them.
Also, tracking back, what I'd need to store somewhere (hence I asked "Where?" originally) is:
- password to password manager
- password to encrypted laptop
- password to email account (not stored in password manager)
- frequently used PIN codes (mobile screen lock and various apps)
I could store the PIN codes in the password manager to make things a bit easier, but I'd still be storing the two passwords somewhere that can unlock my online identity, plus the laptop password that unlocks some really private stuff. None of these would be acceptable to me to get into the hands of a nefarious spouse, whether or not I could sue for it later.
As to "Where?"... an alternative to the Bitwarden feature could be to store these passwords using some sort of 3/5 multi-sig encryption with friends and family members where they'd have to collude in order to get a hold of my stuff. But I wouldn't want to give them access either, my spouse only. But then again, what if we both die in a plane crash?
Perhaps there's no optimal solution. Maybe the good ol' lawyer would work. Give a lawyer the passwords, along with contacts to hand over the information in an order of precedence, like spouse->brother->mother->friend. If something happens, give first person alive in the list the information in X weeks.
So... keep it simple and be NOT the 'Family patriarch silver back' who is the only one who has full knowledge ;-)
Under that type of stress it's very easy to forget passwords which might make criminals believe you're not cooperating. Having some things writen down (probably not all?) has come in handy for me personally.
But besides this, yeah, this may also be a valid case for some simple recovery strategy.
But, in the middle of the ordeal and panic I had to give them access to my car which had a security code to be able to turn the engine on. My family had prepared for this (the reality of the city at the time) so we had the code writen down somewhere in the car. I just gave them the piece of paper to avoid errors or hesitation as I was quite nervous, I didn't want ANY mistakes :/
https://lifehacker.com/organize-your-familys-essential-infor...
and what my family should know incase if something happen to me.
https://ussvicb.org/documents/What%20My%20Family%20Should%20...
Somethings like the above. I've added more info such as 2FA etc in a separate sheet and saved all QR Codes for all the 2FA in my Authenticator apps, and printed them and kept two copies of it in two different locations known to family members. Updates are added as additional sheets to the binder as new codes are added and as a practice, one full dump around a 6 months to 8 months is also added.
You never know what emergency might come in.
I'm always surprised to see the amount of external trash/bloat scripts loaded by some websites. Thank god for uBlock Origin 'Medium Mode'...
[/offtopic]
The "give it to an attorney" plan would also worry me, unless I knew exactly who/what/when/where/why/how access was controlled and GUARANTEED (after all, an attorney's system could break down as easily as any other).
edit: I see other commenters shared this idea too.
Having a safe at home is an option, but it needs to be mounted properly to prevent a burglar from being able to simply carry it out and try and access later.
At the end of the day, your best bet is to keep instructions on accessing your data (minus the actual code that is needed) somewhere it can easily be found by your family, and make sure that one or more family members have copies of the code but don't know the full details of where to use it without those instructions.
That seems astonishingly thorough, as if it must have been targeted? The burglaries I've heard of locally just grab the most reachable items, especially car keys.
> GUARANTEED
The thing with giving it to an attorney is you would have an contract, and I would expect them to explain very clearly what liability they would have in the event of this kind of mistake. I would also expect them to be good at keeping paper secrets in boxes, that's a very traditional practice.
In your house, and maybe with trusted friends, keep the instructions sheet with logins and a reference to the relevant password number. "To access my email account, username is foo@gmail.com and use password #5122 from the password list".
Simple, and provably useless to an adversary unless they have both passwords (aside from knowing password length/format with one).
And then the rest is the set of URLs which point to the various things, having a key/URL in the keystore, which own the DNS, the VM, the mailboxes, the bank accounts, you-name-it
the keystore also has QR codes to restore the 2FA. It has the unlock for the devices which are live on the 2FA codes, but can recover most of them. The exception is a single bank token which seems to use the secure region on my phone to bootstrap its one-time state, and so you have to re-initialize through the bank.
Since the only account of merit is a joint account, either I'm survived by the person who has access anyway, or we're both gone and legally the account is frozen.
What it also says is "FOR GOODNESS SAKE DO NOT TELL <FAANG> I AM GONE" because they will lock things up: Better to gain access, learn what you need torrid or not, and then let them do it.
My dad unexpectedly passed away recently, and there were a lot of problems because we didn't even know his phone unlock PIN (to be fair, he did told us several time, just that none of us bothered to remember). But one of the main problems is that tons of research fund is tied up in my dad account, so it's basically frozen until we can execute his will.
My mom manage my dad tax return so at least we think we know where all his money and debts are.
This event prompted most of my dad co-worker to create something like this cheat-sheet.
I know when my partner died that I was not supposed to log in to her accounts and just transfer shit around; banks instead have very well defined processes for working out who is the legally correct person to do that and then empowering them to do so.
Remember, banks and other big companies deal with this all the time. They necessarily must have robust processes for doing it with the existing societal/legal systems of establishing who is the ‘right person’.
As far as assets in the estate, the job of the executor is to preserve, as far as possible, the value of the assets at the time of death until they can be disbursed. That means, for example, don't take any intentional action to increase the value of the assets after the date of death, such as moving checking accounts higher yielding to certificates of deposit, etc.
The lesson from this markdown file is that if your partner can’t figure this stuff out on their own you need to sort it out yesterday. I doubt that the information being open source or being in markdown format is going to help out your partner whatsoever.
There's an increasing number of single people and lone-livers.
> if your partner can’t figure this stuff out on their own you need to sort it out yesterday.
I don't know how common it is, but I know there are some couples who just don't think of this kind of stuff, at all, until it's too late.
Mostly I've heard of it through a sudden death - the other person now has to figure out what and how all the things are paid for and handled.
I know of another where one partner got ownership of a small business after a divorce, but had no idea how to handle personal or business taxes/paperwork/etc. Had never done much more than sign their name under tax records, or whatever - and suddenly had to figure out all of that on their own.
Of course, using your logic, getting is sorted "yesterday" could mean sitting down and having your loved one understand how to access all this data using MD. Even better would be to have them build the data up with you.
Keeping your money in crypto means that, by default, it dies with you, unless you take special effort to ensure otherwise, and are willing to trust a solution you can't possibly debug because you'll be dead.
As people in China who have had their bank accounts frozen for months, and now their health status flagged red when they were planning to protest, are finding out, https://www.cnn.com/2022/06/15/china/china-zhengzhou-bank-fr...
Minorities in America have historically faced similar challenges of unfair treatment under the justice system.
(A conspiracy theory I have no evidence for but might believe is that the US has been very tolerant of cryptocurrency and stablecoins for the same reason as China bans them: enabling capital flight from China to the US.)
https://bitwarden.com/help/emergency-access/
Essentially you grant another BitWarden user as an emergency access user. They can request access, and you have 7 days to decline access. After 7 days it grants them access to your vault.
https://bitwarden.com/help/about-organizations/
Which are perfect for sharing access to logins like utilities or insurance.
Maybe encrypt the passphrase under an m of n scheme and distribute to family & friends that you can trust to not collaborate unless you are truly incapacitated?
Give a chunk of your password to N friends who you trust, with instructions to recombine it.
One of the few use cases that I find very compelling with regard to blockchain/web3 tech is as a means of ID/auth much in the same way that many sites now offer options to log in with FB/Google/etc.
One big obstacle (I imagine, I haven't really looked into this that far) is that of the password reset. Some non-trivial amount of people will forget the passwords to their identity tool, and in this scenario there's no central power with the capability to reset it for them.
The simplest option is to designate trusted friends who you could delegate authority to in order to perform some multi-sig reset, but then there's the issue of a FriendCoup. If you strike it big and turn on or ignore your friends, there's nothing stopping them from getting together and performing a takeover. Even if there are individual objectors, because it's blockchain, everything's public, and these are identity wallet contraptions, everyone knows who the hold out is and can lean on them or find some way to get their password, etc.
Even outside of a FriendCoup scenario, a FedCoup scenario where the government just leans on your buddies to grant them control is pretty plausible.
So I guess the question is, what sort of strategy for this is FriendCoup/FedCoup resistant but still grants the necessary amount of delegated power?
Not entirely relevant to the above, as doing this pen and paper for a password manager is a little harder for outsiders to game given that the holders aren't public, but still a question I've been batting around. Curious about anyone's thoughts/ideas or any existing work in this space.
Edit: After thinking about this for an extra minute, if it's not time sensitive a deadman switch could probably do it. If your friends perform the multi-sig and you haven't logged in in X days, then and only then will the reset occur, so you can void an attempt. That said, falls down on the FedCoup scenario since you'd presumably have restricted access to the internet.
No amount if crypto will stand up to a Russian mobster with a crowbar and some creativity, like the xkcd https://xkcd.com/538/.
What you need is to develop a threat model and then select an appropriate solution that matches your threat model. If the threat is the KGB might torture me and my buddies, then kill switches are appropriate. Otherwise it’s no solution.
Perfect security doesn’t exist, it’s all about tradeoffs.
Leave. Your. Passwords. With. An. Attorney. And also your phone unlock code. A reputable attorney (preferably attached to a big firm) won't lose your stuff, and if they die or go out of practice they will have procedures in place to make sure you are set. This is not a situation where you want some clever DIY scheme that might fail and leave your loved ones scrambling to sort your finances when they are already devastated and mourning.
That's what OP suggests (Shamir's Secret Sharing).
It is geared for a BIP-39 seed phrase, but those also make excellent master passphrases for almost any other application.
If you are super cautious, leave an encrypted copy (or half the passwords etc) with one lawyer/escrow, and have a separate lawyer/escrow hold the decryption key/other half of the passwords etc. Along with easy instructions on how to decrypt!
End of the day, if I die at an old age, my heirs will also be old and possibly not into computers/tech. I prefer a simple approach that requires minimum skill/effort on their part aside from presenting the relevant death certificate/paperwork to the lawyer.
https://www.deadmansswitch.net/help/
How can I be sure you'll outlive me?
We don't have to outlive you! If the service shuts down while you're alive, we'll send you an email well in advance so you can switch services. That said, the service has been running successfully since 2007.
Say probate is taking a long time, so someone logs into the bank account and withdraws money for everyday essentials. That’s probably one reason the deceased person left the cheatsheet. But what happens when a bank notices money being withdrawn from the bank account of a dead person? Presumably it gets flagged as fraud. And if the estate is still going through probate, the person withdrawing money might not have a legal right to do that.
For a couple, this is one reason to think carefully about which assets are in joint names and which are separate. Ideally, they should have enough money in joint, liquid accounts to cover however long it may take to be granted probate.
My recommendation always remains the same: don’t over complicate it and work with the existing societal processes. Society deals with people dying all the time. All major companies, industries, etc. have means for dealing this which have established legal precedent and won’t get anyone in the shit by following them. Let those processes unfold and instead focus on providing your loved ones with the means of having what they need to do so.
When my mom passed away 18 years ago, we looked high and low for every paper and file to help my dad start to become competent with the household finances. It was a big challenge at an already challenging time.
However, recently I've heard some horror stories from friends about losing access to their phones or being detained in immigration or other places with little access to the outside world. So I've created a document with important information in the case of emergencies that I've shared with trusted contacts. It includes how to access copies of my identity documents, contacts of key people in my life, my last known address, upcoming travel plans, contact information for my clients. I'm considering automating some parts of it, but for now it's basically just a text document in a cloud drive.
keepass database with passwords and secrets, paswword protected archive of 2FA qr codes, on usb drives, in two locations.
Master key and phone pin in the safe at the bank
> We recommend inviting another GitHub user to be your successor, to manage your user owned repositories if you cannot
https://docs.github.com/en/account-and-profile/setting-up-an...
The successor has only access to the public repositories after presenting a death certificate.
I see some people here suggested Samir Secret sharing which sounds like a great idea. But how do you make that practical for non-technical relatives?
I prefer a method that can work in case me and my partner pass at the same time (e.g. accident). A paper will work for my partner, parents, siblings or an attorney in case of emergency.
I would add: Do you have any private investments? Convertible notes or stocks?
Should have a login for AngelList or whatever platform if it’s through one.
Then other assets like bank account, brokerage account, deeds to house and car.
And I agree this is stuff that — if possible — should be shared and discussed in real time.
Edit: Or alternatively, keep a printed document and copies of all of that in a bank vault. Document lockers cost less than 100EUR per year.
Another commenter talked about lasting PoA and they are good to have too in case of incapacitation. But it should also be accompanied with guidelines so people know how to give care for both the indisposed and those most immediately affected.
All of this boils down to this being a document that shows your survivors how much you love them by dealing with this while you can.
Even now, I always think: After all, nothing would matter if I am gone. Why bother with all of that?
To you, perhaps; but I would guess most everyone else would disagree.
> Why bother with all of that?
It's not for you.
Consider that relationships among your heirs and assigns are not always good, and death and money have a way of making things worse.
I put it together after my wife wrote a brief “if I’m dead here is what’s important to me” and I was reminded of a friend who passed several years ago and left his family in an awkward tech state because of his nerdy idiosyncrasies.
https://davieshouser.com/wp-content/uploads/2018/05/19-What-...
if(christophercalm_is_gone) {
follow_his_instructions();
}
...will not execute.On a more serious note though, on a social level, I think «if I'm gone» is much better phrasing than «when I'm gone» if the intention is to be prepared for unforeseen tragic events. Unless one is facing a terminal illness or is past a certain age, using when is too melodramatic, especially when the target audience are close loved ones. It doesn't only imply the inevitability of being gone some day, but also implies the certainty that ones current loved ones will have to face it and must know what to do.
I imagine that the author hopes to live to a ripe old age and probably outlive his "somewhat complex" home setup. In that regard, the if makes more sense, as it is nowhere near certain that anyone will have to deal with his home setup when he is gone.
For those who use a domain with a catchall on it for various purposes... do you have a plan for dealing with what happens if you die and all those many many aliases inadvertantly get handed to some new domain owner?
Too bad they got rid of their native apps....what a pain. I wish 1password had a feature like that.
1. Update it every year or so, and 2. Everytime you update it you print a copy version and distribute that as needed.
I'm not saying it's perfect, but you're dealing with people and sometimes you need to make things simple rather than perfect to get the job done.
There's no ultimate solution. The closest that I have, and it is far from perfect, is that I have a family subscription to 1Password, and a very private shared vault, that my wife has access to, containing the most important stuff. She has a PDF and printed emergency access sheet for the 1Password account.
Here is something that a friend of mine posted on Facebook (She's a professional writer), a couple of years ago. She had to deal with a number of things:
The first time a doctor told me to “get my affairs in order,” I didn’t know whether that meant to do the bills or clear my browser history. (Both are a good idea.) I’ve had to do it a few times now, and apparently this is unusual. In what follows, I’m going to lay out my decidedly non-professional but overly experienced guide to “getting your affairs in order.”
This isn’t just what you do when you’re gonna die. If you think you might be out of commission for a while, you’ll want to make sure (as best you can) that when you recover, you can resume your life as you know it.
What follows are some basics. Some of this won’t apply to you, and I’m sure I missed some things. If you have sizable assets or a complicated life, consult an attorney. (My attorney friends strongly suggest that you talk to them about any of this. I am SO not a professional. This is just my experience.) This is going to seem overwhelming, but you can actually get it handled in an afternoon - while you’re healthy and clear.
So here we go:
Make sure someone has keys to your house.
Pull some cash, in case you need to send people to the grocery for you etc.
File for a tax extension and an absentee ballot NOW. You probably won’t need it. Just in case.
Is your ID/passport/car registration due to expire soon? Maybe get that handled.
Create a “RED FILE” that’s easily findable but not out in the open. I use an actual red file folder.
In it, place the following: I’ll explain below.
Contingency plans for pets/kids (and any guardianship docs you need for that)
Copy of your insurance card and ID
Relevant medical history
Meds list (include supplements, gym stacks, and mood stabilizers)
allergies
Medical Power of Attorney
Advance Directive
POLST
Financial Power of Attorney
SEALED ENVELOPE with PIN
A DIFFERENT SEALED ENVELOPE with passwords and a list of email accounts, social media accounts, etc.
copies of credit cards
list of bills that need to be paid and how
a will, if you have one
Bills - If you have bills like car payment, mortgage, etc that will have consequences for late payment, pay a little early if you can and/or set to autopay. Autopay absolute minimums on everything you can - you need your money to last, but you also don’t want to return to a credit apocalypse (I did. Credit apocalypse is treatable — but expensive.) Make a list of all your bills and how they’re paid, in case someone has to take over for a while.
I am brutally aware that most of us don’t have a financial cushion. Thinking about how to triage in a catastrophe is a lot easier when you’re not in the middle of it. Make the best decisions you can. But make the decisions, so these things are not surprises when you’re not in a place to think them through. Many places are agreeing to suspend utility cutoffs for now. Student loans can go on forbearance. You may be able to deal with lapsed credit cards better than a vehicle repo. Think it through.
MPOA, FPOA, POLST, Advance Directive, Will: These docs should be signed and notarized. That’s not a big deal; bring them to your bank *unsigned,* and if they won’t notarize them free or for low cost, they’ll refer you to someone who will. You’ll sign them in front of the notary; s/he has to witness that.
Medical Power of Attorney is a form that designates who makes medical decisions for you when you can’t. It doesn’t have to be a family member, and it helps if everyone knows ahead of time who that is. But they should know your wishes, and have the fortitude to carry them out. If they will be a pushy advocate, even better. Don’t choose your nicest friend. Choose the one who won’t be afraid to kick ass, or pull the plug.
An Advance Directive is a legal document in which you articulate what your wishes are if you’re really sick or injured and can’t speak for yourself. You can google a form or write something out (I do a combination).
A POLST is a medical form that gets super specific about the above. The acronym stands for Physician’s Orders for Life Sustaining Treatment. Some doctors like it filled out onsite, but a notarized one in the hands of your MPOA will help even if they have to copy from there onto a fresh form (annoying, but lots of things about health care are annoying). There’s a single form most states use; google your state to make sure you have the right form. NOTE: Filling this out will make your stomach hurt. You only have to do this once in your life, unless you change your mind about something - and remember, you will probably never need it.
Financial Power of Attorney (also called Durable Power of Attorney) allows someone access to all your assets (they should know what they are, and how to access what they might need (insurance policies, for example). At very least, they should be in a position to pay your bills, deposit checks, and get some cash if it’s needed, and to suspend your autopay gym membership while you’re not using it. If you have Venmo or Paypal or Bitcoin, they should know how to access it. If arrangements for pets/dependents have a financial component, they should be able to handle that. Make sure it’s someone you trust BIG. Don’t worry about hurting feelings when you make this decision.
Will: If you have simple assets, pull a simple will from LegalZoom or suchlike, and get it notarized when you take in the rest of your forms. Any assets that are registered - your car, even if it’s a hoopty; your retirement account, if you have such a thing; house, etc - all of it is much more easily transferred if there’s a will. For smaller things - you might simply want to write down in a separate, informal note that Lola gets your party dresses and you’d kinda like it if your books were donated to the prison library, or whatever. It might not matter. But if you know your brothers are gonna fight over your bicycle, do everyone a favor and make that decision for them. They don’t have to know unless - it’s that time.
In your red file is a *sealed* envelope addressed to your FPOA with your PIN numbers, online banking password, etc. DO NOT WRITE ON THE OUTSIDE OF THE ENVELOPE WHAT IS CONTAINED IN IT. JUST ADDRESS IT TO YOUR FPOA. DON’T MAIL IT AND DON’T GIVE IT IN ADVANCE.
If there is more than one person involved in your plans, make sure they all have each other’s contact info. You might consider creating a group chat that says something like, “Hi everyone, I just want to make sure you all have easy access to each other in case of an emergency. Heather, my dogsitter, has the house keys; Jamil is my medical POA and makes decisions for me when I can’t…” etc.
Someone needs to have your social media life in their hands. You don’t need to notarize or pull forms, but there should be an envelope addressed to this person. Include the passcodes to your phone and computer, and if you use a password wallet, how to access that. Are you on Instagram, Twitter, LinkedIn? Grindr? No judgment. Just make sure someone can protect your identity -and your brand, if you’re social-media intensive - while you’re away.
Don’t want them to know you’re on, um, Petfinder? Delete now, just in case. (It’s no time for a hookup, anyway.) Also delete/destroy any docs you don’t want someone else to find, including old journals. Also, consider clearing out anything else in the house you don’t want people to find. You can buy a new (whatever it is) later. And clear your browser history!If I'm running a service that manages these documents for thousands, millions of people I know have a well known target appealing to a wide array of actors with nearly unlimited payoff.