The better your opsec, the harder your digital life is to…

The better your opsec, the harder your digital life is to inherit

Been thinking about the flip side of doing security right. Unique passwords in a manager, 2FA on everything, no reuse, maybe a pseudonymous email or two — that's the setup everyone recommends, and it works. It also means that if you get hit by a bus tomorrow, nobody gets in. Ever.

The tools sort of acknowledge this. Password managers have emergency access, Apple added a Legacy Contact, Google has Inactive Account Manager. But they're opt-in, buried, and almost nobody sets them up. Each one covers a single silo, too — your vault doesn't help anyone find the accounts that were never in it, or unlock the 2FA device that's now a brick.

The dead-man's-switch route (release the credentials after X days of no activity) exists, but it's niche and a little grim to run against yourself. The low-tech version — a master password in a sealed envelope in a drawer — quietly undoes half the point of the manager.

Perfect security and "someone should eventually be able to get in" pull in opposite directions, and the harder you lean on the first, the worse the second gets. I don't think there's a clean answer.

So for anyone who actually takes this stuff seriously: do you have a plan, or do your accounts just die with you?

0 replies