Show HN: Seal – Letters and passwords that open for your family after you die
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Show HN: Seal – Letters and passwords that open for your family after you die
Unofficial Hacker News client; not affiliated with Y Combinator.
itake · · focus · HN ↗
What happens if someone loses their phone or buys a new phone? What happens if they forget to tell you that they need a new key?
jpage2 · · focus · HN ↗
In an example, my mom holds a piece of my key. She upgrades her iPhone. She signs into iCloud, Face ID works, she opens Seal and it knows exactly who she is. Everything looks normal. But her piece of my key is dead, because that piece was locked to the old phone. She has no reason to suspect anything is wrong, which is why I need to fix this in the app ASAP I think. She needs to Seal her Envelopes again with the new phone's key.
She can also have a backup hardware key to restore the credential but she has to re-seal again as well in this scenario if she is logged out of her Apple account or broke her main hardware key.
sebmellen · · focus · HN ↗
Rewrite this Readme without Claude?
Also
> There's also no server at all besides a free Cloudflare static site. The encrypted bundles of passwords and photos are in Cloud Kit. Sign-in/identity is a passkey Face ID/Touch ID or a Hardware Key. It's all Crypto Kit, so there's no dependencies required.
To me, this clearly implies that there’s a server involved… Apple’s server. Am I wrong?
jpage2 · · focus · HN ↗
evil-olive · · focus · HN ↗
> After 90 days of countdown, 21 days of warnings, and 14 days of grace, the envelope opens
vs
> it needs that company to still exist and be honest on the day it matters
> there's no company in the middle
which is it?
there's no middleman, but also I need to log in to your app regularly to avoid being declared dead?
skeledrew · · focus · HN ↗
Technically, until we get to a point where we still have embedded "life signal" chips, there's no way to automatically detect that someone has died. Other than those who've actually seen a body, the best we have is "not seen - at Y - for a while".
jpage2 · · focus · HN ↗
jpage2 · · focus · HN ↗
With a company ran vault, they can mess up by failing to exist, not being honest, and they have to make the correct decision when someone dies.
With Seal, no single person makes the decision when the person is gone/inactive. There's no company to decrypt anything, which is what I was trying to paint the picture of with "no company in the middle", but yeah you have to also make sure the software exists so they can check in.
The envelopes also will open when the user can no longer check in because the countdown will end and the family can use the keys to decrypt without a backend needed.
sicutarinaru · · focus · HN ↗
jpage2 · · focus · HN ↗
skeledrew · · focus · HN ↗
Yet this seems dependent on Apple's ecosystem. That's a company in the middle.
pixel_popping · · focus · HN ↗
jpage2 · · focus · HN ↗
I think the main thing restricting it though is that there's nothing in the browser where the person's piece of the key is locked to their phone's chip and cannot copied? Sorry I could be wrong
jpage2 · · focus · HN ↗
[dead]