Shared Security Podcast

Scott Wright joins Tom and Kevin to walk through the Digital Legacy Tree framework and his upcoming book on digital legacy planning, covering roots (access), trunk (dependencies), and leaves (priorities), platform legacy-contact options, and how to keep accounts secure today while ensuring trusted access when you're gone.

Show Notes

Scott Wright joins Shared Security to discuss his Digital Legacy Tree framework and upcoming book, The Digital Legacy Tree. We talk about what happens to your accounts, passwords, devices, files, money, cloud storage, crypto, and online identity if you die, become incapacitated, or are suddenly unavailable — and how to plan for trusted access without weakening your security today.

The conversation covers why “just use a password manager” is not enough, the roots-trunk-leaves model for organizing access, dependencies, and priorities, platform legacy-contact options, and the one practical first step: set up legacy or emergency contacts on your most critical accounts.

** Links mentioned on the show **

Scott Wright — securityperspectives.com (Digital Legacy Tree, Digital Legacy Tools, book beta review)
https://securityperspectives.com/digital-legacy-tools/

RUFADAA — Revised Uniform Fiduciary Access to Digital Assets Act
https://en.wikipedia.org/wiki/Revised_Uniform_Fiduciary_Access_to_Digital_Assets_Act

OpenID Foundation (digital legacy / account handover research)
https://openid.net

Prior Shared Security episode — What Happens to Your Social Media Accounts After You Die?
https://sharedsecurity.net/2021/08/31/what-happens-to-your-social-media-accounts-after-you-die/

** Watch this episode on YouTube **

[YOUTUBE URL]

** Become a Shared Security Supporter **

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

** Thank you to our sponsors! **

Guardsquare

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

SLNT

Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

** Subscribe and follow the podcast **

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

What is Shared Security Podcast?

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Welcome to the Shared Security podcast, the longest running cyber security and privacy

show for actual humans.

No jargon, no hype, just honest analysis from industry veterans who've seen everything

and survived it.

Each week we break down the stories that matter, expose the nonsense that doesn't, and give

you the tools to stay safe in a world where everything is connected and nothing is guaranteed.

This is Shared Security.

This week on Shared Security, Scott Wright joins us to walk through his digital legacy

tree or DLT framework and the ideas behind his upcoming book, The Digital Legacy Tree,

ensuring your loved ones can access the digital accounts they need when you die.

Now it's an uncomfortable topic, but a practical one.

What happens to your accounts, photos, files, money, business assets, devices, recovery

codes and online identity if you die, become incapacitated, get sick, or are suddenly unavailable?

We spend years making our accounts harder to break into and of course that's good security,

but without a continuity plan it can become a painful problem for the people who need

to pick up the pieces.

So we're going to talk to Scott about how the digital legacy tree helps people

think beyond passwords, organize what matters, and make sure the right people can access

the right things at the right time without creating a security hole while you are alive.

And I have not just Scott, but I also have Kevin Tackett here to join us for this great

conversation.

Hey, Tom.

My only question is, I got to ask before we get started and I'm afraid that this

might get us a trademark strike or something.

Is this where Scott announces his new animated movie, All Good Data Goes to Heaven?

I didn't want you to mention that, Kevin.

Oh, Kevin, you ruined it.

Sorry, no, sorry.

What is good data?

That's a whole other topic.

That's a whole other episode, yeah.

That happens.

Yeah.

Yeah.

So Scott, talk a little bit about, I mean, we've had this topic once before a long

time ago.

We'll actually link it in the show notes of this episode.

If you're on YouTube, you can click the link above to check that out.

But what was the thought process behind digging back into this topic and then writing a book

about it?

Yeah.

So it actually started maybe 10 years ago and I used to do a lot of presentations for

financial advisor groups, you know, like they all have their professional associations

where they do their chapter meetings and stuff.

And I would go in and do talks about cybersecurity and then at the end, I had just read an

article at one point about this idea of digital legacy as a new concept.

It was, you know, protecting your accounts so that people can get access to them if you

die.

And nobody had really ever thought about that before at that point.

So I just put a slide in my deck and every time I got to that at the end of the presentation,

there'd be so many questions and stories and things like, wow, that's really cool.

How would that work?

You know, and I just sort of had it as a little throwaway thing at the end that

made people kind of remember me.

But I think more recently, I guess maybe in the last year, I've had a number of people

that I've had to help who've reached out and said, you know, I'm an executor and, you

know, my associate passed away and I'm trying to figure out how to help his widow get access

to their Gmail, which is interesting because as I started to dig into that, I learned,

you know, Gmail is not that easy and they're not just going to give access to somebody

and they're not, they don't, even if you can prove who you are, they don't give full

access, right?

They'll say, what information do you need, right?

But actually, since I started talking about this 10 years ago, the major platforms I've

actually made a bit of progress in terms of allowing you to designate people as

emergency alternate contacts.

And that's really the cleanest way to do it.

And you know, if I had one message for people from this episode is get your legacy

or emergency contacts set up for your most critical accounts.

So anyway, all that to say, I started thinking about this, you know, in the last six months

or so.

And then I realized each platform like Apple and Facebook and Microsoft and Google, they

all do things a little differently when it comes to how you might enable this.

And as a lot of us in security, you know, we work to secure things, as you said,

and we don't think about what would happen to people who actually had to get into

these things.

So I started to think maybe this would be a good topic for a book, you know, to do some

research, because I think there's enough different ways to look at this and things

that could trip people up.

And so that's what I basically started doing six months ago.

And it's been a fun project, actually.

And I've got people doing what we call beta reviews now.

And most of the feedback has been very good.

You know, I'm looking for the where, where does, where do people get tripped

up?

Where does it get confusing?

Where are the, you know, things I disagree with, you know, and Kevin hasn't

reviewed it yet.

So I don't have many of those.

So yes, that is to come.

But yeah.

I mean, it's really tough for people to spend time thinking about how the

unthinkable might happen to them, you know, in your world, things seem to

be going smoothly.

But imagine, you know, your, your spouse or partner, you know, sitting at

the kitchen table after an emergency, not knowing if or when you're ever

going to be able to access this stuff again.

Maybe they do know.

But at that point, you know, all they know is that your, your online bills get

paid somehow and you've got social media accounts where you've been updating

people on how you're doing.

And they want to access those things.

And if you haven't done a little bit of preparation, and it's, it's not

just about passwords, as you said earlier on, I've learned there's a

lot of dependencies and that's kind of what evolved this idea of a

tree concept.

So, you know, I'll leave it at that and you can sort of let me know if

you've got questions about that.

Yeah, I kind of wanted for you to explain the, the framework that you kind

of talk about in the book and how obviously it relates to a tree, but

maybe can you talk a little bit about that from a.

Yeah, for sure.

So the way I started thinking about it, well, we, in order to access

anything, you need the passwords, right?

So we, and one of the things that I found when I looked at what

books had actually been written on this, almost every one of them says,

do a full inventory of all your accounts.

And I can't think of anything more daunting or demotivating and sitting

down and trying to go through that.

And I have like over a thousand accounts in, in Bitwarden right now.

So how do you decide?

And, and if somebody has to take over that, how do they know

which ones to start with?

Right.

So I started by just saying, let's look at this from something

that evolves and grows kind of like a tree, right?

You start with something very small, like the critical mass.

I think of it in terms of, first of all, your primary email

address is probably one of the top things people are going to

need your mobile device, because all of your two factor

authentication is going to go through that.

And then if you have one, a password manager.

So those three things together will get you a long way, you

know, into finding the things that you actually need.

But that's what I would call the roots, right?

So those are the basic things you're really going to need.

And they're not very well organized.

If somebody just looks at it from that point of

view, if they're given access, so it kind of looks like a

mess of roots, you know, tangled up everywhere.

The idea of the trunk of the tree is to make it reliable

so that you can look at where are the dependencies?

What device does this account rely on?

What two factor authentication, you know, you might

actually have more than one two factor authentication

app on your phone and do it.

Does anybody know that?

Right.

So there's a whole bunch of dependencies that I

discovered that could trip people up.

And so the idea of the trunk is to take, start

organizing the access, the basic access stuff to make

it more reliable.

And then at the top, it's really, what do people need?

And what are they looking for rather than just a bunch

of passwords?

And one of the best things that I learned as I

was researching this, I talked to one of the

people I was helping, I said, if they, if they

had a, if the person who passed away had a drawer

with a little note or a books that they'd written in

there, what would you have wanted to see in it?

And he said, that's a good question.

He says, I would like to have seen a section that

says, how I live my life.

And I thought that was really interesting because

it's like, what are your priorities?

You know, how do you treat this particular

email account versus this social media account?

Which one's more important?

So that's kind of what the whole idea of the

tree growing.

And it's not just the fact that there's roots

and trunk and the leaves I call it, but the

fact that it grows and you re, you update it

every once in a while and you don't have to do it

all at once.

You start with just your critical accounts and

you get that working so that it's immediately

usable by somebody.

And that's how the tree kind of evolves.

Mobile apps are just part of everyday life now.

Banking, healthcare, shopping, entertainment, you

name it.

And with that comes a lot of trust because

users are putting their personal data

directly into your app.

But here's the reality.

Mobile apps are a growing target.

A recent survey found that 72% of organizations

experienced a mobile app security incident

last year and 92% say threats are only

increasing and the way attackers are going

after apps is pretty sophisticated.

They're reverse engineering them, modifying

them and redistributing fake versions

through phishing campaigns, side loading

and even third party app stores.

So from a user's perspective, everything

can look completely legitimate.

That's why taking a proactive approach to

mobile app security really matters.

You want to stay ahead of these threats, not

react after the damage is done.

This is where Guard Square comes in.

They provide advanced protection for both

Android and iOS apps, along with

automated security testing to catch

vulnerabilities early and real time

threat monitoring so you can actually see

what's happening out there.

If your mobile app is critical to your business

and it probably is, this is something

worth paying attention to.

You can learn more at GuardSquare.com.

That's GuardSquare.com.

I really like that from a framework

perspective. It's just easy to understand

and I think that's going to really

resonate with people that read the book.

And I think I guess one question I have

for you is like after doing all of this

research, and I know you're kind of

still in the middle of the book writing

in that, but what's one thing that

really came to light as you were

researching this of like or one thing

that you would offer to listeners

to focus on first?

I know you mentioned mobile device, right?

Yeah, first, I mean, first of all,

from a practical point of view, the

first thing you should do is set up

those legacy contacts so that somebody

does have access that you intend them

to access. And it's interesting how

they've done it in a way where

you're not just saying this person has

access when they want it.

It's they have to make a request

and you can set a time horizon on it

so that you know that you're going

to probably be logged into, you know,

your password manager or something

within the next, you know, within

three days or four days if you're

alive or if you're not

incapacitated.

And if somebody makes a request

and you don't want them to, you can

deny that request.

But after a certain time horizon, if

you don't respond, then they would

automatically get access.

And I think that's a cool way to

set it up.

OK, that they're leaving it kind

of up to you.

But it's not an instant access

thing. It really depends on that

situation where you're not

available. The other thing I

would say that is really

important for people to just think

in terms of the principles around

this is we have this

the curse of knowledge.

You've heard of it, right?

So it's hard for us to imagine

what somebody else will think

or or experience.

And we think we've

got it all organized in a way

that everybody will be able to

just open your password manager

and get access to things.

But there are sometimes when people

don't even know account accounts

exist. And if if it's something

like, you know, cryptocurrency or

even online banking, I don't

necessarily store in my password

manager, because I

I don't really want that to be,

you know, in any way vulnerable.

And so people can't access things

they don't know exist.

And I think that's a really

important principle is you have to

be able to start by documenting

what does exist and from the most

important on down.

Yeah, I can also see this, you

know, if you or a person

you know that might encounter

something, you know, obviously

we're all going to die one day.

It's inevitable, Tom.

You know, it is inevitable like

death and taxes, but

like it's a really good point you

made about, you know, if people

have businesses, side businesses,

they have all these things tied to

their email and, you know,

the authentication piece alone.

We don't think about that and

prepare our loved ones

and in that for these

situations.

Like I came in imagine

like the chaos that there's

just so many things I discovered

that I think need to be

documented somewhere that for

people to learn. And I did

create a resource page on our

website. Before I forget, I'll

mention security perspectives.com.

I'll have a little banner there

where you can get to the digital

I call it digital legacy tools

page. But in there, you know,

it's all the different ways that

some of these platforms operate

or in terms of what you need to

do to set things up.

And what's really interesting I

discovered, you know, you

and I know that some platforms

don't use passwords.

You put in your email and they

send you a magic link.

And if somebody's looking for how

to get into this particular

account and they see, well,

here's the email, but there's no

password. Oh, my God, there's no

password. What am I going to do?

And they don't even try.

So if you don't document how

some of these things have

unique access processes,

it could actually be stressful

and frustrating for people as

well. Yeah, I'm just thinking

of all the different ways,

right? Like, you know, mobile

authentication app or text

message or magic link.

Or I mean, it goes on and

on and on. And then there's

of course, you know, whether

people store passwords in a

password manager or not,

right? Because like we talked

about in the show too is, you

know, a lot of older people

keep, you know, passwords written

down. Written. So where is that?

Where is that book of passwords

that's written down and that

kind of thing? You can put it

in a safe. But how many people

do you know that actually have

a safe? And then you need to

code the safe and the safe that

you buy at, you know, we're

going to get pushed back

because safe you buy at Staple

or, you know, we're business

depot, whatever, aren't

necessarily if they're under

two or three hundred dollars,

they're probably not really

security safes. They're more

like opportunistic avoidance

safes, right? But the idea

that you should put stuff, your

password notebook in a safe

isn't necessarily that

practical. And I'm not in the

book, I'm not teaching people

about security of, you know,

all these things. I'm just

saying this is what you may

have. And do your best to

try and make it a place you

can get too easily or that

somebody could get too easily,

but isn't obvious for people.

So it's a little bit of, you

know, contradiction from a

security point of view, but you

have to have that tradeoff.

Well, I love that you're doing

this, Scott. I think this is so,

so important. It's something

that most of us don't even

think about. And everyone

is left scrambling when

something happens to loved

ones. It doesn't have to be

death, either, like you said,

like if somebody is

incapacitated because of an

accident or a health

condition, or there's so

many situations that this is,

this is sorely needed.

So, yeah, thank you for doing

this. And I think, you know,

you had a call to action too,

right? You have got a request

for people to help out.

Yeah, as I haven't yet

published the book, it'll be

self published, but I am going

through this process of beta

reviewing. And I've invited

you guys, but it's still

open. If people go to my

website, securityperspectives.com

you'll see a banner or pop

up to end the comma, put

a link to directly to the

page. But there is a form

there that you can actually

volunteer to, you know, do

a review of the manuscript as

it is right now and or sign up

for a discounted pre-release

copy that I'll probably issue

in the next month or two.

Awesome. I can ask a question

that might be irrelevant or

ridiculous, or may even be

covered in the book. I haven't

yet reviewed. Yes, during

yesterday, I have it about,

OK, so this is not a new

issue. It's a new twist on an

issue, right? We when I was

growing up, there was always

stories and books about the

idea that, you know, somebody

died and then they found out

that they had gold buried in

the backyard. Yeah, yeah, they're

in the backyard. Now it's

crypto offline wallets.

Yeah, right? You know, and

so I'm curious if, and this

kind of twofold, if one, the

variety of privacy laws

around the world, countries,

whatever, have or have to be

adapted to this idea of

after death. I know that that

in some of the privacy laws,

there are rules around how the

data a company holds is

affected by death. But that I

don't think they really

address the handover. And

in second part is, are there

any efforts? Are you

shareholding? You're and

that's shareholding. That's

a new word phrase. Are you

championing any efforts to

build standards like, you

know, 800 dash dead race

that, you know, that, that

pushes an idea of, Hey, if I'm

building an app, like let's

flip this around from the

consort side to the business

side. Is there any effort to

say, Okay, I'm building an

app. Let me follow this

standard process on legacy

accounts or stuff. Is there

any there actually is. I just

found something. It was

published about almost a year

ago in help net security. I

don't actually have it off the

top of my head, but I'll

provide it to Tom. Yeah, there

was a paper, a couple of

papers written by the, I

think it's the founders or

heads of open ID foundation.

Does that make sense? They

actually were doing some

research in this area and

wrote some papers that I've

yet to read. I've downloaded

them, but I haven't read

them. But it actually tries

to address that issue. I

believe. So it's a great

question. And I'm going to put

that in my tools website at

some point as well. But I'll

try and get the link to

because that article links to

a couple of those artifacts

that they created. So yeah,

that makes useful for for

people. I think for a

security and privacy

practitioners to understand

what what hasn't been done

so far where it's going. I

know that in the US,

there's actually a law called

Rufata. I don't know if

you've heard about it, but

the revised uniform

fiduciary access to digital

assets act. Wow, I'm amazed

that I remembered that. But

impressed. Not every state

has adopted it, but many

have. But what it really

does is it gives the online

platforms a framework of

priorities, saying if you

have a will, it takes

precedent over whether

somebody gets legal access

to your accounts. And then

if you don't have a will,

there's other couple of

other layers of priority

there. And it's really good.

I was really happy to find

that stuff and understand,

you know, it's up until

then I was just saying, well,

the laws don't help you if

you if just because you

have legal access doesn't

mean the platforms are going

to do anything for you

because it's not in their

business model or interests

necessarily to let people

who have no personal data

or posts or interactions for

them to monetize to help

you get access to them,

right? But now there are

some legal precedents that

are starting there.

Also, thank you.

Nice. Good to know.

All right. Well, we will have

links to all this in the show

notes. So how to contact Scott

how to sign up if you're

interested in helping review

the book and all the links

that he has talked about on

this episode. Thank you again,

Scott, for for doing this.

It's so sorely needed.

One other quick note I would

like to squeeze in and that

is anybody here who has a

financial advisor or an

estate planner, it would

be really interesting for

you to reach out to them and

say, is this something that

you should be thinking about?

And secondly, if they'd be

interested in collaborating

with me or getting in touch

because I'm actually starting

a series of panel sessions

for advisors as well.

So if you know of anybody

or if you are one, feel free

to reach out on that.

Awesome. All right.

Well, thank you everyone

for listening. And until next

time, stay safe, stay secure

and stay private.

Thank you for listening or

watching. If you like this

episode, hit subscribe, share it

with your friends and

colleagues or jump into our

community at shared security

net slash supporter to keep

the conversation going.

Thanks again, and we'll see

you next week for another

episode of shared security.