>In the latter case you will probably be forced to cough up the decryption keys.
Not if you make the users password the key.
Not if you make the users password the key.
Seems like the only way.
I'm honestly interested because I'm building a distributed system where only the user has the decryption key, and I've always just assumed that password recovery is a lost cause in such systems.