https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my-digital-life/ Terence Eden's Blog I've locked myself out of my digital life * By @edent on 2022-06-07 * 2fa passwords security * 41 comments * 1,450 words --------------------------------------------------------------------- Imagine... Last night, lightning struck our house and burned it down. I escaped wearing only my nightclothes. In an instant, everything was vaporised. Laptop? Cinders. Phone? Ashes. Home server? A smouldering wreck. Yubikey? A charred chunk of gristle. This presents something of a problem. In order to recover my digital life, I need to be able to log in to things. This means I need to know my usernames (easy) and my passwords (hard). All my passwords are stored in a Password Manager. I can remember the password to that. But logging in to the manager also requires a 2FA code. Which is generated by my phone. The phone which now looks like this: A melted phone. Credit: Reddit user Crushader. Oh. Backups I'm relatively smart and sensible. I regularly exported my TOTP secrets and saved them in an encrypted file on my cloud storage - ready to be loaded onto a new phone. But to get into my cloud, I need my password and 2FA. And even if I could convince the cloud provider to bypass that and let me in, the backup is secured with a password which is stored in - you guessed it - my Password Manager. I am in cyclic dependency hell. To get my passwords, I need my 2FA. To get my 2FA, I need my passwords. Perhaps I can use my MFA FIDO2 Key? A melted security key. Photo taken from A Side Journey To Titan: Revealing and Breaking NXP's P5x ECDSA Implementation on the Way. Oh. Emergency Contacts Various services allow a user to designate an "emergency contact". Someone who can access your account in extremis. Who do you trust enough with the keys to your digital life? I chose my wife. The wife who lives with me in the same house. And, obviously, has just lost all her worldly possessions in a freak lightning strike. Photo of a house engulfed in flames. Photo taken by Wikimedia user LukeBam06. Oh. Recovery Codes Most online services which have Multi-Factor Authentication, also provide "recovery codes". They are, in effect, one-time override passwords. A group of random characters which will bypass any security. Each can only be used once, and then is immediately revoked. I was clever. I hand-wrote the codes on a piece of paper (so they can't be recovered from my printer's memory!) and stored them in a fire-proof safe, secured with a key hidden under the cat's litter-box. Sadly, the fire-proof safe wasn't lightning-strike safe and is now obliterated. Along with the cat's litter-box. The cat is fine. I know... I know... I should have kept them in a lock-box in my local bank. The only problem is, virtually no banks offer safe deposit boxes in the UK. The one that does charges PS240 per year. A small price to pay, for some, to avoid irreversible loss. But it adds up to a significant ongoing cost. But, suppose I had stored everything off-site. All I'd need to do is walk up to the bank and show some ID which proved that I was the authorised user of that box. The ID which has just been sacrificed in tribute to mighty Thor and now looks like a melted waxwork. An AI generated image of a melted driver's licence. Oh. Friendly Neighbourhood Storage Perhaps what I should have done is stored all my backup codes and recovery keys on a USB stick and then given them to a friend? There are a few problems with that. 1. Every time I sign up to a new service, I would need to add it to the USB stick. How many times can I pop round with a fresh stick before it becomes an imposition? 2. What if my friend (or their kid) accidentally wipes the drive? 3. If a freak lightning storms hits both our houses at the same time, I still lose everything. 4. Even if I did all that, I would have to give the USB stick a strong password to make sure my friend didn't betray me. So I either need to remember that, or I'm stuck in the password-manager-paradox. Perhaps I could split the USB sticks between multiple friends using Shamir's Secret Sharing? That solves some problems - mostly the accidental losses and remembering a strong password - but creates even more issues. Now I have to do a lot more admin and worry about all my friends conspiring against me! Phone Home One of the weakest forms of identity is the humble phone number. Several of my accounts use my mobile number to text me authorisation codes. SMS isn't the most secure way to deliver passwords - it can be intercepted or the SIM can swapped to one controlled by an attacker. But, if I can get my phone number back, I stand a chance of getting in to my email and perhaps some other services. That's a weakness in my security posture. But one I may need to take advantage of. The only question is - how do I prove to the staff at my local phone shop that I am the rightful owner of a SIM card which is now little more than soot? Perhaps I can just rock up and say "Don't you know who I am?!?!" I know, I'll show them my passport! Burning EU passport 20180318 Oh. Bootstrapping of trust I am lucky. I have a nice middle-class life and know lots of professionals - doctors, lawyers, teachers - who I hope would be happy to vouch for me. I could use one of my friends to confirm my identity for a replacement passport. Once I have a passport, I should be able to get a SIM card with my phone number. And, I hope, some online services. I would, however, need to use a credit or debit card to apply for a replacement passport. But all of my cards are melted to slag - and I can't prove to the bank that I am who I say I am because I don't know my account number, password, or mother's maiden name. You see, I was "clever" and took some idiot's advice about setting your mother's maiden name to being a random string of characters. Those details are, of course, stored in my inaccessible password manager! Hopefully one of my friends will be prepared to lend me the PS75.50 to get a new passport. I'll just call up one of my friends. Hmmm... now, where did I store their phone number? A melted phone. Credit: Reddit user Crushader. Oh. Starting over Again, I'm lucky. I live relatively close to some friends and family. And I'm confident that they'd be gracious enough to pay an emergency cab fare if I started hammering on their door at silly o'clock in the morning. With their help, I think I could probably call up enough insurance companies to figure out which one covered the property. I would hope the insurance company would have some way of validating with the emergency services that the house is, indeed, a smoking crater. I don't know if that would get me emergency cash, or if I'd have to rely on friends until I get access to my bank account. I assume my credit card companies can probably be convinced to send out replacement cards. But will they also be willing to change my address - or will the card go to the pile of ashes which was formerly my home? I don't know whether my insurance policy covers me for access to digital files. Even if it did, I'm not sure how they can force a company like - say - Google to give me access to my account. It isn't like Google went through a KYC (Know Your Customer) process when I signed up. Code Is Law This is where we reach the limits of the "Code Is Law" movement. In the boring analogue world - I am pretty sure that I'd be able to convince a human that I am who I say I am. And, thus, get access to my accounts. I may have to go to court to force a company to give me access back, but it is possible. But when things are secured by an unassailable algorithm - I am out of luck. No amount of pleading will let me without the correct credentials. The company which provides my password manager simply doesn't have access to my passwords. There is no-one to convince. Code is law. Of course, if I can wangle my way past security, an evil-doer could also do so. So which is the bigger risk: * An impersonator who convinces a service provider that they are me? * A malicious insider who works for a service provider? * Me permanently losing access to all of my identifiers? I don't know the answer to that. If you have a strong opinion, please let me know in the comment section. In the meantime, please rest assured that my home is still standing. But, if you can, please donate generously to the DEC's Ukraine Humanitarian Appeal --------------------------------------------------------------------- Share the love: * Twitter * Facebook * LinkedIn * Reddit * HackerNews * Lobsters * Email * Pocket * Mastodon * WhatsApp * Telegram * Like this: Like Loading... More posts from around the site: 41 thoughts on "I've locked myself out of my digital life" 1. 2022-06-07 01:00 [af5702c0] [diggingthe] Frank Meeuwsen says: Frank Meeuwsen bookmarked this Article on diggingthedigital.com. Reply 2. 2022-06-07 12:42 [ac519754] [jkpg] Gustav Lindqvist says: @Edent This is horrifying. I'm glad you guys are okay.Thanks for sharing, I'm going to look over my own security and password storage solutions. I'm pretty sure I'm in the risk of exactly the same happening to me. Reply 1. 2022-06-07 15:56 [5e127af1] chaozz says: Did you read the last paragraph? Reply 1. 2022-06-07 17:38 [bb5adf04] Kee says: Or perhaps the first word of the article? Reply 3. 2022-06-07 12:47 [D4zrLdmM] Joe says: I honestly had to sit there thinking "has Terence's house actually been struck by lightning and burned down? Announcing that purely via an educational blog post would be a very Terence thing to do..." before I got to the bottom of the post Reply 4. 2022-06-07 13:05 [P75-clvQ] [twitter] Seeker says: Reminder to test your disaster recovery plan. I can regain access to my digital life from things I've memorized and my yubikey, or failing that, a recovery packet I keep at my parents' house in another state. That same packet gets them in if I die. shkspr.mobi/blog/2022/06/i... Reply 1. 2022-06-07 14:53 [bbe12e9d] digital prepper says: Same. I have a tool to help me memorize key passwords that don't get daily use (i.e. everything that isn't my master password), like those for my email, Apple account, etc. If everything burns down, I get the corresponding 2FA backup codes from my parents' and use the memorized passwords to retrieve my vault. The only cost, aside from (very) occasional snail mail to my parents asking them to just put this piece of paper in their safe, is that I have to memorize 6 passwords instead of 1. And my parents' phone number. Reply 5. 2022-06-07 13:10 [G3sBtHlb] [twitter] HackerNewsTop10 says: I've locked myself out of my digital life Link: shkspr.mobi/blog/2022/06/i... Comments: news.ycombinator.com/item?id=316526... Reply 6. 2022-06-07 13:16 [0e0af9c1] Ian Betteridge says: The "leave something with friends/neighbours" option is interesting. That is, after all, what we already do: we have a set of keys for one of our neighbours' houses so we can pop in and walk their dog when required, and they still have a set of ours from when they used to pop in and feed our cat (RIP). They could, of course, come round and ferret through our drawers - but we would be able to work out they had pretty easily, even without the presence of a security camera. So: should our approach to digital security be the same? A trusted third party who could use your passwords, but if they did you would get notified? Reply 1. 2022-06-07 14:00 [63632727] @edent says: It's a tough one. Having liven in half-a-dozen locations since University - I don't think I've ever given a neighbour a set of keys. And, frankly, I'd probably refuse if they tried to foist them on me! That might be my antisocialness - or my paranoia. I'm not sure which. I have a lot of sympathy for the code-is-law crew. I shouldn't have to put my trust in anyone. But I also like the idea of a "canary" which fires if a trusted 3rd party attempts access. Reply 7. 2022-06-07 13:23 [a86fc3db] [mastodon] Haunted Owlbear says: @Edent I was very concerned until the last para! My off-site plan for everything else going FUBAR is reasonably solid, but it all goes to hell if the account that automatically pays its bills runs out of money. Reply 8. 2022-06-07 13:24 [C5RpZY0D] Dan says: A similar thing that haunts me the most is losing my memory. I use 1Password but what if I forget my pass phrase to get in? What if my iPhone doesn't want to accept faceid and demands my now forgotten passcode? Yubikey is nice but is only a 2nd factor, not 1st The worry is real! Reply 1. 2022-06-07 15:53 [d99a5c31] Fazal Majid says: A stroke can happen to anyone. Reply 9. 2022-06-07 13:25 [3ced54b7] Alex B says: I settled on a plain text file of credentials, split using Shamir's Secret Sharing and requiring at least 2 people to collaborate to reconstruct, with pieces shared on USB keys with my partner, my parent, and on various bits of storage I'm likely to have with me. I never actually got round to doing it, though... In the meantime, I'm relying upon grabbing my mobile phone or tablet, and wallet as I evacuate. Reply 10. 2022-06-07 13:27 [EwjyR32T] Paul Curry says: lmao I came here from HN to be like DUDE DO U NEED TO BORROW SOME STUFF ARE U OK Reply 11. 2022-06-07 13:28 [A1O8qiyx] [twitter] Dr Catherine Flick says: Yet more limitations of "code is law" Reply 12. 2022-06-07 13:30 [QdRAA86H] [twitter] Matt Secoske says: We are going to hear more and more of these stories. Tech is awesome, but it has serious downsides as well. shkspr.mobi/blog/2022/06/i... Reply 13. 2022-06-07 13:36 [483602e1] Daniel says: Shh! Don't say the quiet part out loud! We're all incredibly vulnerable to this. I have offsite backups of my most important data. However, I probably wouldn't be able to recover it without either my phone, laptop, desktop computer, or home server. I need one of them. These devices holds all my secrets under crypt and key. For most people, this is an unrecoverable situation. The more stuff you have -- whether that be online accounts or devices -- the harder it is to do disaster recovery. My "emergency plan" is to always carry my phone with me. It's my digital life and it holds a on-person backup of my most crucial stuff. Reply 14. 2022-06-07 13:59 [343688cb] [twitter] Ghostwire: Suurpelto says: shkspr.mobi/blog/2022/06/i... Kak-to oprashival narod v tvittere, zapisyvaiut li oni master-parol' ot menedzhera parolei na sluchai vnezapnykh bed s pamiat'iu, no real'nost', kak vsegda, byvaet uvlekatel'nei. Reply 15. 2022-06-07 14:09 [6s34qJVX] [?] Q (it/its) [?] [?] MCH says: Clearly we need to funge proof Terrence now, just in case Reply 16. 2022-06-07 14:18 [cc63f4aa] Linus Gasser says: I often think when I see an attack on some "badly done" security procedure like giving your birthdate to "authenticate" as a person: "Well, it's bad. But it's a good middle-ground between security and usability. And the few abuses are covered by insurance. So, all in all, it's not too bad." Which your story seems to underline. But of course the best way would be to have a t-out-of-n threshold decryption with your friends devices. Not? Reply 17. 2022-06-07 14:22 [f649bd0c] Richard says: So your problem is you can't access your online password manager without a MFA code to your phone? Is that basically it? If so, you just need an offline password manager like https:// keepass.info/ and then upload the password database to cloud storage to keep it safe and accessible. Problem solved? Reply 1. 2022-06-07 14:31 [f649bd0c] Richard says: Ah, you already said you need MFA to log into your cloud account, my bad, didn't see that the first time around. Is that an actual requirement though? I don't believe I have MFA on my MS OneDrive... Reply 18. 2022-06-07 14:30 [923daf36] Mikael says: Interesting, indeed. As I live in an area well known for having produced some nasty earthquakes, I'd foresee that if my house were reduced to rubbles it'd be together with most of the neighbors' houses. And the rubbles might very well get very well charred once the local natural gas lines burst. So... Hm. I have set up my wife as an emergency contact for my password manager, which wouldn't help in this scenario, but I'm thinking that I should set up a second emergency contact in the form of family members who live outside the area. It would still make the process of getting into stuff takes very long time, but eventually I should be able to get in that way. If I can survive without email for that long, of course. Reply 19. 2022-06-07 14:35 [X09Rkei3] [twitter] Tero Keski-Valkama says: All service providers should be legally obligated to accept national identity provider schemes like passports or national electronic ids. shkspr.mobi/blog/2022/06/i... Reply 20. 2022-06-07 14:40 [b8fc8c7d] Yash says: The reason I don't use generated passwords for valuable accounts Reply 21. 2022-06-07 14:40 [AGTj0dqP] James Campbell says: Reminds me of the time my phone was stolen. So I needed to buy a new one so I needed to move money around in my bank to be able to buy one. But I needed the same phone to login to the bank. So many increasing dependencies in our lives like this and not enough talking about it Reply 22. 2022-06-07 14:50 [d97fd912] [mastodon] Michael says: @Edent Really wish there were more affordable alternatives to off site storage.I am in similar danger but I don't have any trusted party near me to keep a USB stick with all my keys.Currently i keep an encrypted USB hidden in my car so at least if the apartment goes up in flames I'd have that... Reply 23. 2022-06-07 15:11 [a81c2d81] octotherp says: AFAIK we still have no "multiple fido2 keys" unlocking option for keepass.db. https://github.com/keepassxreboot/keepassxc/issues/3560 Reply 24. 2022-06-07 15:17 [e5b55502] Matthijs says: Interesting story, hope all will be fine soon again. For the safe storage, what I did was to dig a casing pipe into the ground between our house and our neighbours. We have 2 utp cables in this, one for them and one for us. Now we have a NAS in their house and vice versa. We both cannot access each other's NAS, we don't know the passwords. Now it was quite some digging, but as a result we have a (we think) safe backup of everything. Chances of both houses burning or flooding or whatever are slim. Reply 1. 2022-06-07 16:50 [2c9d776f] Aaron Axvig says: Consider lightning, as mentioned in this very blog post. If it strikes one of the houses, it could easily traverse the UTP cable and fry the other NAS. And lightning could presumably strike both houses, or the utility feed that supplies both houses. Reply 25. 2022-06-07 15:50 [qs164hcm] [twitter] Pete Keen says: shkspr.mobi/blog/2022/06/i... This has me thinking about my strategy a bit. I have a waterproof USB drive with my @1Password recovery kit on it, but what if that gets destroyed too? Can I pay an attorney to hold onto a USB drive? Hollywood seems to imply that that's a thing. Reply 26. 2022-06-07 16:41 [nBPOzo4z] [twitter] zaptac says: Neues aus der Serie "Niemand will Backup, alle wollen Restore": shkspr.mobi/blog/2022/06/i... Reply 27. 2022-06-07 16:47 [2c9d776f] Aaron Axvig says: Consider the case of cash currency, which one may think of as "paper is law". There are many ways in which a $20 bill can be lost forever, with absolutely no . Still people find cash useful, and even preferred, for some things. And obviously unsuitable for many things. Similarly, code as law is useful for some things and not for others. Reply 28. 2022-06-07 16:56 [be9cc55e] [twitter] Simon Willison says: I think about this nightmare scenario quite a bit: it's not even your digital life any more, it's your LIFE I have enough stuff in a cloud account with a password I know that I could reboot from scratch... but I'd have to talk customer support into disabling 2FA for me to do it! Reply 29. 2022-06-07 17:06 [PUJr9hh0] [twitter] Nick Drage says: Excellent points all round, and it illustrates the weakness in ignoring "availability" to users in your threat modelling... Reply 30. 2022-06-07 17:08 [JXCFrpwb] [twitter] Wojtek | voitek.eth says: Risks behind the 'code is law' approach Reply 31. 2022-06-07 17:53 [_PeBtbpn] [twitter] Bjorn Fridgeir Bjornsson says: I need to think about things. Reply 32. 2022-06-07 17:54 [c0mdGkqB] [twitter] Nick Stevens | Let's make business better says: Having recently discovered that MS Authenticator doesn't back up by default (and in my case, at all), and that Discogs doesn't implement 2FA correctly, this really is the stuff of nightmares. hat tip @inthecompanyof Reply 33. 2022-06-07 18:45 [6JfWh3ZH] [twitter] Jonathan Peacher says: frantically reviews digital life Reply 34. 2022-06-07 19:52 [af5702c0] [www] I've locked myself out of my digital life says: This Article was mentioned on indiehackers.com Reply Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment *[ ] Name * [ ] Email * [ ] Website [ ] [ ] Notify me of follow-up comments by email. [ ] Notify me of new posts by email. [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Learn More) [ ] [Ping me!] Found this post useful? Click the icons to support this blog More ways to support my blog Get new posts by email Enter your email address to subscribe to this blog and receive brand new posts by email. (Or subscribe to this RSSAtom Feed.) Join 13,360 other subscribers. Email Address [ ] Free Sign Up Search Blog Posts Search for: [ ] [Search] Explore The Archives 2022 January 30 posts February 23 posts March 15 posts April 19 posts May 19 posts June 4 posts July August September October November December 2021 January 31 posts February 28 posts March 31 posts April 30 posts May 31 posts June 30 posts July 31 posts August 31 posts September 30 posts October 31 posts November 30 posts December 31 posts 2020 January 31 posts February 29 posts March 31 posts April 30 posts May 31 posts June 30 posts July 31 posts August 31 posts September 30 posts October 31 posts November 30 posts December 31 posts 2019 January 31 posts February 12 posts March 17 posts April 12 posts May 12 posts June 10 posts July 7 posts August 5 posts September 6 posts October 14 posts November 30 posts December 17 posts 2018 January 8 posts February 4 posts March 6 posts April 14 posts May 5 posts June 6 posts July 6 posts August 13 posts September 14 posts October 8 posts November 30 posts December 4 posts 2017 January 12 posts February 9 posts March 8 posts April 4 posts May 10 posts June 5 posts July 5 posts August 6 posts September 3 posts October 4 posts November 30 posts December 2016 January 10 posts February 10 posts March 11 posts April 9 posts May 8 posts June 9 posts July 6 posts August 9 posts September 4 posts October 2 posts November 30 posts December 14 posts 2015 January 8 posts February 11 posts March 10 posts April 4 posts May 9 posts June 3 posts July 7 posts August 9 posts September 10 posts October 2 posts November 30 posts December 4 posts 2014 January 13 posts February 13 posts March 14 posts April 14 posts May 8 posts June 7 posts July 9 posts August 5 posts September 5 posts October 1 post November 30 posts December 20 posts 2013 January 25 posts February 17 posts March 15 posts April 18 posts May 11 posts June 14 posts July 6 posts August 14 posts September 6 posts October 4 posts November 30 posts December 14 posts 2012 January 14 posts February 8 posts March 13 posts April 15 posts May 10 posts June 16 posts July 8 posts August 8 posts September 6 posts October 6 posts November 30 posts December 31 posts 2011 January 13 posts February 11 posts March 11 posts April 12 posts May 8 posts June 8 posts July 6 posts August 5 posts September 11 posts October 7 posts November 30 posts December 17 posts 2010 January 6 posts February 15 posts March 12 posts April 13 posts May 4 posts June 3 posts July 15 posts August 8 posts September 11 posts October 9 posts November 30 posts December 9 posts 2009 January 1 post February 5 posts March 3 posts April 7 posts May 12 posts June 8 posts July 10 posts August 10 posts September 12 posts October 22 posts November 31 posts December 15 posts 2008 January 2 posts February March 2 posts April 3 posts May 2 posts June July 1 post August 3 posts September 1 post October 3 posts November 2 posts December 1 post 2007 January February March April May June July August September October November 4 posts December 5 posts 2006 January February March April 1 post May June July August September October November 1 post December 2005 January February March 1 post April May June July August September 1 post October November December 2004 January February March April May 5 posts June 3 posts July 1 post August September October November December 2003 January February March 2 posts April May June July August September October November December 2002 January February 1 post March April 3 posts May June July August September October November December 2001 January February March April May June July 1 post August September October 1 post November December 2000 January February March 1 post April May June July August September October November 1 post December 1999 January February March April May June July August September 1 post October November December 1 post 1997 January 1 post February March April May June July August September October November December 1995 January February March 1 post April May June July August September October November December 1987 January February March April May June July August September October November December 1 post * (c) Terence Eden * Contact Me * Subscribe * Citations * Support My Blog * About Me ISSN 2753-1570 %d bloggers like this: