Show HN: End-to-End Encrypted Dead Man's Switch
cipherwill.com
cipherwill.com
For now, I'm rocking:
* yubikeys pre-provisioned with keys given to select family members
* sops to encrypt my "will" to those keys
* sops-encrypted file hosted on google drive, pre-shared to select family members
Luckily I have enough technical family and friends that they would eventually figure out how to run `sops decrypt`. And/or enough funds that they can hire someone if need be.
Weakest part here is my BIP39 is not Shamir'd, so a rouge family member could empty my wallet. But I trust them. More than a third party presuming-for-profit service. :( Not to be a party-pooper, it's a neat idea.
(edit, s/bip32/bip39/g)
Anyway, I decided I didn't want to migrate my wallet, so I'll look into this. Arbitrary key support is also interesting. Thanks for the tip!
Using the app, we actually produce the SLIP-39 recovery mnemonics from the underlying BIP-39 seed, and since we can recover the underlying seed, we can regenerate the BIP-39 mnemonics, and import that into a standard hardware wallet.
I don’t have any investments or crypto and, sorry, if I ever did I wouldn’t trust you with that info and give you the means to rob and/or steal my identity. That’s a bold ask with a closed source app.
I built my own dead man’s switch, which lives in the open on GitHub. It’s a simple rails app w/ encrypted tables and some background jobs to send email checks and reset numbers, or blast out info if you’re not answering. I have no valuable info to put in it.
This is very high-level and doesn't actually answer the question asked.
I also don't see anything here regarding the decentralized blockchain storage you mentioned in another comment. How does that fit in here?
> Each security factor is represented by a public/private key pair, which is used to encrypt your data on your device.
So where are the private keys stored? AFAICT, this is just a web app and I know of no way to securely store a private key from one. Even if there is a desktop application and my private key is stored there, what happens if I lose my desktop? Am I locked out of my will permanently?
> Cipherwill uses Homomorphic encryption to encrypt data pods again, creating a "time capsule" key. This key ensures that the data remains encrypted and inaccessible until a specified time.
Is there anything preventing you from releasing these "time capsule" keys ahead of schedule other than good will?
> Data pods are encrypted using 256 or 512 AES encryption
512 AES encryption? Seeing as AES only goes up to 256, you aren't exactly inspiring confidence here.
> If you and your beneficiaries have security factors enabled, it is impossible for anyone, including Cipherwill, to access or decrypt your data.
So it's end-to-end encrypted only if me and my beneficiaries all choose it to be? That is a very different claim from what's on your main page.
Overall, this "how it works" page is too vague for my liking, and I wouldn't trust this website with my will.
1. Private Key Storage: Private keys are derived locally from your security factors when you set up them.
2. Time Capsule Keys: The release of "time capsule" keys is governed by strict protocols, ensuring they’re only accessible at the specified time.
3. AES Encryption: We use AES-256, not 512, will fix that typo.
4. End-to-End Encryption: yes, End-to-end encryption requires both you and your beneficiaries to enable security factors.
I'm sure the product has potential, and lots of effort has gone into it. I also see that criticism is hard, but if you can't be open about these basic questions then there are fundamental problems.
I should say, I'm a fan of crypto' (both types) and i'm likely your target market because currently my plans after death are not nearly as secure as i'd like!
What are these "security factors" you keep mentioning? It's a vague term and I don't see a definition on your website. Can you also describe how private keys are derived from them? That's what I'm most curious about. Is this derivation process something that could be replicated by an attacker?
Aside, but I don't think I'm alone in considering this a non-starter combined with the whole stack including the client being closed-source.
Fresh advertising but still needs way more transparency (and a round of eyes on your ToS and Privacy Policy) to not look like a honeypot.
> Where an how is user data stored? Do you use cloud providers/SaaS and in which jurisdiction? Considering legal requests for user data are being served, location/jurisdiction for both CipherWill and its servers are important and I don't seem to find this mentioned.
For example, I'm highly interested in it, but don't sign up because I don't know if they'll be around in a year or 10. So I'd like to see one long established before going all in, but it's hard for one to get long established without early users.
Which blockchain? In what sense is it decentralized from perspective of CipherWill users?
Also, I can see the use of commutative encryption for the time capsule support but I’m not seeing where homomorphic encryption fits in.
This looks like a SaaS solution in search of a problem.
I have a document that contains all of our subscriptions, our key information, contacts, last will, etc, that I update monthly, put on a thumb drive, and hide in a place my wife knows. I can't encrypt it because she isn't tech savvy enough, but physical obscurity is enough for me. I encrypt the copy on my PC. I also print out a copy and have it in our lockbox.
In addition, we have a shared password manager with a Yubikey that she has access to for MFA, and she knows the password.
If we both die at the same time, one of my close friends knows where all of this is and can provide to the lawyer handling our kids provenance.
I don't have much crypto because I think it's by and large a scam market, but it's on a drive that is described in the document on the USB.
At the end of the day, the things that are important to me are written down as physical copies. We print off photos and put them in photo books. My favorite music is on CDs.
All that said, I see the real benefit in a service like this for the older generation like my in-laws. I've had multiple conversations with him about the passwords to all their online accounts and all their critical information, and all their passwords are just stored in his Google Chrome password manager. My MIL doesn't know the password to his Chrome account. If he dies first, she's going to have a helluva time getting access to everything. So if he could sign up to a service like this that we could trust, it would be immensely helpful.