Scott Wright joins Tom and Kevin to walk through the Digital Legacy Tree framework and his upcoming book on digital legacy planning, covering roots (access), trunk (dependencies), and leaves (priorities), platform legacy-contact options, and how to keep accounts secure today while ensuring trusted access when you're gone.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Welcome to the Shared Security podcast, the longest running cyber security and privacy
show for actual humans.
No jargon, no hype, just honest analysis from industry veterans who've seen everything
and survived it.
Each week we break down the stories that matter, expose the nonsense that doesn't, and give
you the tools to stay safe in a world where everything is connected and nothing is guaranteed.
This is Shared Security.
This week on Shared Security, Scott Wright joins us to walk through his digital legacy
tree or DLT framework and the ideas behind his upcoming book, The Digital Legacy Tree,
ensuring your loved ones can access the digital accounts they need when you die.
Now it's an uncomfortable topic, but a practical one.
What happens to your accounts, photos, files, money, business assets, devices, recovery
codes and online identity if you die, become incapacitated, get sick, or are suddenly unavailable?
We spend years making our accounts harder to break into and of course that's good security,
but without a continuity plan it can become a painful problem for the people who need
to pick up the pieces.
So we're going to talk to Scott about how the digital legacy tree helps people
think beyond passwords, organize what matters, and make sure the right people can access
the right things at the right time without creating a security hole while you are alive.
And I have not just Scott, but I also have Kevin Tackett here to join us for this great
conversation.
Hey, Tom.
My only question is, I got to ask before we get started and I'm afraid that this
might get us a trademark strike or something.
Is this where Scott announces his new animated movie, All Good Data Goes to Heaven?
I didn't want you to mention that, Kevin.
Oh, Kevin, you ruined it.
Sorry, no, sorry.
What is good data?
That's a whole other topic.
That's a whole other episode, yeah.
That happens.
Yeah.
Yeah.
So Scott, talk a little bit about, I mean, we've had this topic once before a long
time ago.
We'll actually link it in the show notes of this episode.
If you're on YouTube, you can click the link above to check that out.
But what was the thought process behind digging back into this topic and then writing a book
about it?
Yeah.
So it actually started maybe 10 years ago and I used to do a lot of presentations for
financial advisor groups, you know, like they all have their professional associations
where they do their chapter meetings and stuff.
And I would go in and do talks about cybersecurity and then at the end, I had just read an
article at one point about this idea of digital legacy as a new concept.
It was, you know, protecting your accounts so that people can get access to them if you
die.
And nobody had really ever thought about that before at that point.
So I just put a slide in my deck and every time I got to that at the end of the presentation,
there'd be so many questions and stories and things like, wow, that's really cool.
How would that work?
You know, and I just sort of had it as a little throwaway thing at the end that
made people kind of remember me.
But I think more recently, I guess maybe in the last year, I've had a number of people
that I've had to help who've reached out and said, you know, I'm an executor and, you
know, my associate passed away and I'm trying to figure out how to help his widow get access
to their Gmail, which is interesting because as I started to dig into that, I learned,
you know, Gmail is not that easy and they're not just going to give access to somebody
and they're not, they don't, even if you can prove who you are, they don't give full
access, right?
They'll say, what information do you need, right?
But actually, since I started talking about this 10 years ago, the major platforms I've
actually made a bit of progress in terms of allowing you to designate people as
emergency alternate contacts.
And that's really the cleanest way to do it.
And you know, if I had one message for people from this episode is get your legacy
or emergency contacts set up for your most critical accounts.
So anyway, all that to say, I started thinking about this, you know, in the last six months
or so.
And then I realized each platform like Apple and Facebook and Microsoft and Google, they
all do things a little differently when it comes to how you might enable this.
And as a lot of us in security, you know, we work to secure things, as you said,
and we don't think about what would happen to people who actually had to get into
these things.
So I started to think maybe this would be a good topic for a book, you know, to do some
research, because I think there's enough different ways to look at this and things
that could trip people up.
And so that's what I basically started doing six months ago.
And it's been a fun project, actually.
And I've got people doing what we call beta reviews now.
And most of the feedback has been very good.
You know, I'm looking for the where, where does, where do people get tripped
up?
Where does it get confusing?
Where are the, you know, things I disagree with, you know, and Kevin hasn't
reviewed it yet.
So I don't have many of those.
So yes, that is to come.
But yeah.
I mean, it's really tough for people to spend time thinking about how the
unthinkable might happen to them, you know, in your world, things seem to
be going smoothly.
But imagine, you know, your, your spouse or partner, you know, sitting at
the kitchen table after an emergency, not knowing if or when you're ever
going to be able to access this stuff again.
Maybe they do know.
But at that point, you know, all they know is that your, your online bills get
paid somehow and you've got social media accounts where you've been updating
people on how you're doing.
And they want to access those things.
And if you haven't done a little bit of preparation, and it's, it's not
just about passwords, as you said earlier on, I've learned there's a
lot of dependencies and that's kind of what evolved this idea of a
tree concept.
So, you know, I'll leave it at that and you can sort of let me know if
you've got questions about that.
Yeah, I kind of wanted for you to explain the, the framework that you kind
of talk about in the book and how obviously it relates to a tree, but
maybe can you talk a little bit about that from a.
Yeah, for sure.
So the way I started thinking about it, well, we, in order to access
anything, you need the passwords, right?
So we, and one of the things that I found when I looked at what
books had actually been written on this, almost every one of them says,
do a full inventory of all your accounts.
And I can't think of anything more daunting or demotivating and sitting
down and trying to go through that.
And I have like over a thousand accounts in, in Bitwarden right now.
So how do you decide?
And, and if somebody has to take over that, how do they know
which ones to start with?
Right.
So I started by just saying, let's look at this from something
that evolves and grows kind of like a tree, right?
You start with something very small, like the critical mass.
I think of it in terms of, first of all, your primary email
address is probably one of the top things people are going to
need your mobile device, because all of your two factor
authentication is going to go through that.
And then if you have one, a password manager.
So those three things together will get you a long way, you
know, into finding the things that you actually need.
But that's what I would call the roots, right?
So those are the basic things you're really going to need.
And they're not very well organized.
If somebody just looks at it from that point of
view, if they're given access, so it kind of looks like a
mess of roots, you know, tangled up everywhere.
The idea of the trunk of the tree is to make it reliable
so that you can look at where are the dependencies?
What device does this account rely on?
What two factor authentication, you know, you might
actually have more than one two factor authentication
app on your phone and do it.
Does anybody know that?
Right.
So there's a whole bunch of dependencies that I
discovered that could trip people up.
And so the idea of the trunk is to take, start
organizing the access, the basic access stuff to make
it more reliable.
And then at the top, it's really, what do people need?
And what are they looking for rather than just a bunch
of passwords?
And one of the best things that I learned as I
was researching this, I talked to one of the
people I was helping, I said, if they, if they
had a, if the person who passed away had a drawer
with a little note or a books that they'd written in
there, what would you have wanted to see in it?
And he said, that's a good question.
He says, I would like to have seen a section that
says, how I live my life.
And I thought that was really interesting because
it's like, what are your priorities?
You know, how do you treat this particular
email account versus this social media account?
Which one's more important?
So that's kind of what the whole idea of the
tree growing.
And it's not just the fact that there's roots
and trunk and the leaves I call it, but the
fact that it grows and you re, you update it
every once in a while and you don't have to do it
all at once.
You start with just your critical accounts and
you get that working so that it's immediately
usable by somebody.
And that's how the tree kind of evolves.
Mobile apps are just part of everyday life now.
Banking, healthcare, shopping, entertainment, you
name it.
And with that comes a lot of trust because
users are putting their personal data
directly into your app.
But here's the reality.
Mobile apps are a growing target.
A recent survey found that 72% of organizations
experienced a mobile app security incident
last year and 92% say threats are only
increasing and the way attackers are going
after apps is pretty sophisticated.
They're reverse engineering them, modifying
them and redistributing fake versions
through phishing campaigns, side loading
and even third party app stores.
So from a user's perspective, everything
can look completely legitimate.
That's why taking a proactive approach to
mobile app security really matters.
You want to stay ahead of these threats, not
react after the damage is done.
This is where Guard Square comes in.
They provide advanced protection for both
Android and iOS apps, along with
automated security testing to catch
vulnerabilities early and real time
threat monitoring so you can actually see
what's happening out there.
If your mobile app is critical to your business
and it probably is, this is something
worth paying attention to.
You can learn more at GuardSquare.com.
That's GuardSquare.com.
I really like that from a framework
perspective. It's just easy to understand
and I think that's going to really
resonate with people that read the book.
And I think I guess one question I have
for you is like after doing all of this
research, and I know you're kind of
still in the middle of the book writing
in that, but what's one thing that
really came to light as you were
researching this of like or one thing
that you would offer to listeners
to focus on first?
I know you mentioned mobile device, right?
Yeah, first, I mean, first of all,
from a practical point of view, the
first thing you should do is set up
those legacy contacts so that somebody
does have access that you intend them
to access. And it's interesting how
they've done it in a way where
you're not just saying this person has
access when they want it.
It's they have to make a request
and you can set a time horizon on it
so that you know that you're going
to probably be logged into, you know,
your password manager or something
within the next, you know, within
three days or four days if you're
alive or if you're not
incapacitated.
And if somebody makes a request
and you don't want them to, you can
deny that request.
But after a certain time horizon, if
you don't respond, then they would
automatically get access.
And I think that's a cool way to
set it up.
OK, that they're leaving it kind
of up to you.
But it's not an instant access
thing. It really depends on that
situation where you're not
available. The other thing I
would say that is really
important for people to just think
in terms of the principles around
this is we have this
the curse of knowledge.
You've heard of it, right?
So it's hard for us to imagine
what somebody else will think
or or experience.
And we think we've
got it all organized in a way
that everybody will be able to
just open your password manager
and get access to things.
But there are sometimes when people
don't even know account accounts
exist. And if if it's something
like, you know, cryptocurrency or
even online banking, I don't
necessarily store in my password
manager, because I
I don't really want that to be,
you know, in any way vulnerable.
And so people can't access things
they don't know exist.
And I think that's a really
important principle is you have to
be able to start by documenting
what does exist and from the most
important on down.
Yeah, I can also see this, you
know, if you or a person
you know that might encounter
something, you know, obviously
we're all going to die one day.
It's inevitable, Tom.
You know, it is inevitable like
death and taxes, but
like it's a really good point you
made about, you know, if people
have businesses, side businesses,
they have all these things tied to
their email and, you know,
the authentication piece alone.
We don't think about that and
prepare our loved ones
and in that for these
situations.
Like I came in imagine
like the chaos that there's
just so many things I discovered
that I think need to be
documented somewhere that for
people to learn. And I did
create a resource page on our
website. Before I forget, I'll
mention security perspectives.com.
I'll have a little banner there
where you can get to the digital
I call it digital legacy tools
page. But in there, you know,
it's all the different ways that
some of these platforms operate
or in terms of what you need to
do to set things up.
And what's really interesting I
discovered, you know, you
and I know that some platforms
don't use passwords.
You put in your email and they
send you a magic link.
And if somebody's looking for how
to get into this particular
account and they see, well,
here's the email, but there's no
password. Oh, my God, there's no
password. What am I going to do?
And they don't even try.
So if you don't document how
some of these things have
unique access processes,
it could actually be stressful
and frustrating for people as
well. Yeah, I'm just thinking
of all the different ways,
right? Like, you know, mobile
authentication app or text
message or magic link.
Or I mean, it goes on and
on and on. And then there's
of course, you know, whether
people store passwords in a
password manager or not,
right? Because like we talked
about in the show too is, you
know, a lot of older people
keep, you know, passwords written
down. Written. So where is that?
Where is that book of passwords
that's written down and that
kind of thing? You can put it
in a safe. But how many people
do you know that actually have
a safe? And then you need to
code the safe and the safe that
you buy at, you know, we're
going to get pushed back
because safe you buy at Staple
or, you know, we're business
depot, whatever, aren't
necessarily if they're under
two or three hundred dollars,
they're probably not really
security safes. They're more
like opportunistic avoidance
safes, right? But the idea
that you should put stuff, your
password notebook in a safe
isn't necessarily that
practical. And I'm not in the
book, I'm not teaching people
about security of, you know,
all these things. I'm just
saying this is what you may
have. And do your best to
try and make it a place you
can get too easily or that
somebody could get too easily,
but isn't obvious for people.
So it's a little bit of, you
know, contradiction from a
security point of view, but you
have to have that tradeoff.
Well, I love that you're doing
this, Scott. I think this is so,
so important. It's something
that most of us don't even
think about. And everyone
is left scrambling when
something happens to loved
ones. It doesn't have to be
death, either, like you said,
like if somebody is
incapacitated because of an
accident or a health
condition, or there's so
many situations that this is,
this is sorely needed.
So, yeah, thank you for doing
this. And I think, you know,
you had a call to action too,
right? You have got a request
for people to help out.
Yeah, as I haven't yet
published the book, it'll be
self published, but I am going
through this process of beta
reviewing. And I've invited
you guys, but it's still
open. If people go to my
website, securityperspectives.com
you'll see a banner or pop
up to end the comma, put
a link to directly to the
page. But there is a form
there that you can actually
volunteer to, you know, do
a review of the manuscript as
it is right now and or sign up
for a discounted pre-release
copy that I'll probably issue
in the next month or two.
Awesome. I can ask a question
that might be irrelevant or
ridiculous, or may even be
covered in the book. I haven't
yet reviewed. Yes, during
yesterday, I have it about,
OK, so this is not a new
issue. It's a new twist on an
issue, right? We when I was
growing up, there was always
stories and books about the
idea that, you know, somebody
died and then they found out
that they had gold buried in
the backyard. Yeah, yeah, they're
in the backyard. Now it's
crypto offline wallets.
Yeah, right? You know, and
so I'm curious if, and this
kind of twofold, if one, the
variety of privacy laws
around the world, countries,
whatever, have or have to be
adapted to this idea of
after death. I know that that
in some of the privacy laws,
there are rules around how the
data a company holds is
affected by death. But that I
don't think they really
address the handover. And
in second part is, are there
any efforts? Are you
shareholding? You're and
that's shareholding. That's
a new word phrase. Are you
championing any efforts to
build standards like, you
know, 800 dash dead race
that, you know, that, that
pushes an idea of, Hey, if I'm
building an app, like let's
flip this around from the
consort side to the business
side. Is there any effort to
say, Okay, I'm building an
app. Let me follow this
standard process on legacy
accounts or stuff. Is there
any there actually is. I just
found something. It was
published about almost a year
ago in help net security. I
don't actually have it off the
top of my head, but I'll
provide it to Tom. Yeah, there
was a paper, a couple of
papers written by the, I
think it's the founders or
heads of open ID foundation.
Does that make sense? They
actually were doing some
research in this area and
wrote some papers that I've
yet to read. I've downloaded
them, but I haven't read
them. But it actually tries
to address that issue. I
believe. So it's a great
question. And I'm going to put
that in my tools website at
some point as well. But I'll
try and get the link to
because that article links to
a couple of those artifacts
that they created. So yeah,
that makes useful for for
people. I think for a
security and privacy
practitioners to understand
what what hasn't been done
so far where it's going. I
know that in the US,
there's actually a law called
Rufata. I don't know if
you've heard about it, but
the revised uniform
fiduciary access to digital
assets act. Wow, I'm amazed
that I remembered that. But
impressed. Not every state
has adopted it, but many
have. But what it really
does is it gives the online
platforms a framework of
priorities, saying if you
have a will, it takes
precedent over whether
somebody gets legal access
to your accounts. And then
if you don't have a will,
there's other couple of
other layers of priority
there. And it's really good.
I was really happy to find
that stuff and understand,
you know, it's up until
then I was just saying, well,
the laws don't help you if
you if just because you
have legal access doesn't
mean the platforms are going
to do anything for you
because it's not in their
business model or interests
necessarily to let people
who have no personal data
or posts or interactions for
them to monetize to help
you get access to them,
right? But now there are
some legal precedents that
are starting there.
Also, thank you.
Nice. Good to know.
All right. Well, we will have
links to all this in the show
notes. So how to contact Scott
how to sign up if you're
interested in helping review
the book and all the links
that he has talked about on
this episode. Thank you again,
Scott, for for doing this.
It's so sorely needed.
One other quick note I would
like to squeeze in and that
is anybody here who has a
financial advisor or an
estate planner, it would
be really interesting for
you to reach out to them and
say, is this something that
you should be thinking about?
And secondly, if they'd be
interested in collaborating
with me or getting in touch
because I'm actually starting
a series of panel sessions
for advisors as well.
So if you know of anybody
or if you are one, feel free
to reach out on that.
Awesome. All right.
Well, thank you everyone
for listening. And until next
time, stay safe, stay secure
and stay private.
Thank you for listening or
watching. If you like this
episode, hit subscribe, share it
with your friends and
colleagues or jump into our
community at shared security
net slash supporter to keep
the conversation going.
Thanks again, and we'll see
you next week for another
episode of shared security.