A colleague passed away unexpectedly last month. He was 46. In the weeks that followed, his LinkedIn profile kept suggesting I congratulate him on his work anniversary. His Facebook account continued to surface in "People You May Know." His blog, hosted on a personal domain, stayed live with its last post dated three days before he died. It was a review of a SIEM product. Mundane and permanent.
This experience forced me to think seriously about something I had been mentally filing under "eventually" for years: what happens to our digital lives when our physical ones end?
The Scope of the Problem
The average security professional in 2010 maintains accounts on dozens of services. Email, social networks, professional networks, cloud storage, financial accounts, domain registrations, hosting accounts, maybe a blog or two. Many of these accounts contain sensitive information - not just personal data, but in our line of work, potentially access credentials, client information, research notes, and professional correspondence that organizations would very much like to recover or secure.
When someone dies, there is no master switch. Each service has its own policies, its own procedures, and in many cases no procedure at all for handling the accounts of deceased users. Facebook introduced its "memorialization" feature in 2009, which freezes the account and removes it from suggestions and ads. Google has no formal policy. Most smaller services have never considered the scenario.
The legal landscape is equally fragmented. Digital assets do not fit neatly into existing estate law frameworks. A will can bequeath your house and your car, but the legal status of your Gmail archive or your World of Warcraft characters is murky at best. Several states have begun passing digital estate legislation, but there is no federal standard and the laws that do exist vary wildly in scope.
Services That Help
A small but growing number of services have emerged to address this gap. Legacy Locker, launched in 2009, acts as a digital safety deposit box where you store account credentials and designate beneficiaries who receive access upon your death. Entrustet offers a similar service with the added option of designating an "account executor" who can manage your online presence posthumously.
These services solve the practical problem of access, but they raise their own security concerns. You are essentially creating a centralized store of all your credentials and handing it to a third party. If Legacy Locker gets breached, the attacker gets the keys to your entire digital life. The irony of creating a security vulnerability in order to solve an estate planning problem is not lost on me.
A simpler approach - and the one I have personally adopted - is a sealed document stored with your will that contains account information and instructions. Less elegant than a web service, but the attack surface is considerably smaller.
What Enterprises Should Think About
This is not just a personal problem. When an employee dies or becomes incapacitated, the organization needs to recover access to corporate accounts, shared credentials, and work product stored in personal or semi-personal cloud services. If your only DBA had root passwords stored in a personal password manager with no corporate backup, you have a serious business continuity problem.
Enterprise identity management and access governance programs should account for this scenario explicitly. Shared credential vaults, documented recovery procedures, and clear policies about where work product can be stored are all part of the solution. The principle of no single point of failure applies to people just as much as it applies to hardware.
Planning Ahead
My recommendations are straightforward. First, create an inventory of your significant online accounts. Second, document your wishes for each - should it be deleted, memorialized, or transferred to a specific person? Third, store that documentation securely and make sure your executor knows it exists. Fourth, review and update it annually, because your digital footprint in 2011 will look different from your digital footprint today.
It is uncomfortable to think about. Nobody wants to spend a Saturday afternoon writing instructions for their own digital afterlife. But the alternative is what happened to my colleague - an online shadow that persists without purpose or oversight, slowly becoming a ghost in the machine that his family has no ability to manage.
The security community talks constantly about data lifecycle management. It is time we applied that thinking to ourselves.