As Patrick said, my name is Dean Saxe. I'm here to present Breaking Glass about restoring access to my own digital accounts after a disaster.
So, first a bit about who am I. I am a Principal Security Engineer for Identity and Access Management at Remitly. We're a financial services company doing cross-border remittances, and I'm responsible for workloads, AI, enterprise identity, as well as consumer identity from a security perspective. I also co-chair the Death in the Digital Estate Community Group at the OpenID Foundation. And I'm the former co-chair of the Enterprise Deployment Working Group at the FIDO Alliance, as well as the IPSE Working Group at the OpenID Foundation.
But because we're all a bit social media addicted, myself included, a little alt text might be helpful here. This is not my words. This is replaced by Claude.
I am, quote, the friend at dinner who can explain passkeys, fiduciary access, and why your memorialized Facebook account is a governance failure. Somehow, professionally specialized in the fact that people die, and platforms pretend they do not. But why am I here? I'm here because I spend a bit too much time thinking about death and dying. It's not because I'm goth. It's not because I like this as a topic. But it's a really interesting research topic. It's an interesting edge case, or maybe not an edge case, for all of us who work in digital identity or identity in any way.
And last year, I started really thinking about disasters and the intersection of disasters and recovering from disasters with the work I'm doing with death in the digital estate. And the reality is disasters do not discriminate. They happen around the world all the time. We don't know when they're going to happen. We don't know where they're going to happen. But we do know they are going to happen, and we are going to be subject to those disasters. And that may cause us to lose access to our own digital assets.
And I started thinking about this in response to Hurricane Helene in the southeastern part of the United States, which impacted some of my friends and some people who may even be here in this room tonight. The Pacific Palisades fires in Los Angeles, but also the floods in Spain, in Austria, in Poland, wildfires in Greece. Disasters happen around the world.
Now, I live here in the upper left corner of the United States in a place called Seattle, my adopted hometown. And we are no stranger to disasters ourselves. We sit along the Ring of Fire, the Pacific Rim, where tectonic plate activity creates earthquakes and volcanoes and other things. This mountain right here is actually a stratovolcano. This is Mount Rainier. It sits about 100 kilometers from my home in Seattle. If I walk out my front door and down the street a little bit, I can see it on the horizon. And it's a really important part of Seattle culture.
We know the weather's nice in Seattle when someone says, quote, the mountain is out because we are famously gray and rainy in Seattle. So on those glorious days when you can see the mountain, obviously you know it's a nice day. But this also means these are all of the disasters that could happen to us in Seattle at any point in time. And so what do we do in case of an emergency? We break glass.
Now, you may not be familiar with this particular break glass that I'm showing here. This would be in a building where you have maybe a fire extinguisher or a fire hose behind this. And in case of an emergency, like a fire, break the glass, pull out the fire extinguisher, put out the fire. So how do you break glass in your own life?
Well, for years I have maintained a personal break glass kit. And this consists of things like my one-password emergency kit. And I put it away in case of emergency so that if I ever lost access to everything, I'd be able to recover. But the thing is, I never really tested it. And so I wanted to go and test my break glass kit, make sure it works like I think it does, make sure it's accessible to me, to my spouse, to my children.
And to do so, coming from a background as a scientist, you may or may not know I'm a geneticist by training, I decided I needed some rules of engagement to frame up this test and make sure it was a fair and reasonable test. And so my rules of engagement are fairly simple. I can't use my laptop, my phone, my watch, my hardware security keys, my familial devices, or my work laptop for this work. I have to do it in a place that is clean and has no leftover data on it that might influence the outcomes. I do have access to identity documents.
As an American, our primary identity document is a driver's license. Passport also works. And I have access to my safe deposit box key. So in the States, I can go to my bank and rent a box within the vault, and in order to get to that box, I have to show up with an identity document and a key. Presenting those two things, the banker takes their key, signs me in, we go into the vault, unlock the box, and I have access to everything inside. And I have a newly imaged Mac to restore my digital life.
Because, again, I don't want any holdovers from a previous login to Google or iCloud or anything, so I just have a freshly imaged Mac to start from. So nothing can influence the outcomes here. I also need some recovery targets because there are about 1,000 credentials in my one-password vault, and it would be really challenging to try and recover all of them. So instead, I put together some targets that if I can reasonably access these targets, I'm able to access everything else. And the first is my credential manager, as I mentioned. This is one password.
The second is Apple iCloud, because I have a lot of familial data here, photos, videos, backups of my iPhone, et cetera. Google Workspaces is where I host my personal domains. Gmail. These are other accounts that are used by me, in some cases for their own break glass purposes. And my mobile phone service.
Because, of course, some providers are still going to want to text me an SMS OTP, and I need to be able to catch that and then replay it and then play it back in order to actually recover access to those accounts. So the problem here is this is Schrodinger's break glass kit. It exists in this quantum state between perfectly engineered and catastrophically broken. And I and you won't know until I do the test. So let's go. Let's start. So this is inside the vault of the bank. What you're seeing in front of you is there's a metal table underneath a box. That box is my safe deposit box.
On top is an envelope with some chicken scratches that you probably can't read. It says one password emergency kit, backup YubiKey, iCloud recovery code. And last updated, July 13, 2023. I did this test on August 12, 2025. Two years have passed from the time I put this away. Bring it home. I'm excited. We're going to get started. So I hop onto the Mac. I download one password. Entering the data from my emergency kit. And make it through the secret key and password. All this is fairly easy. Then I get to this step. Two-factor authentication. Cool. I've got my backup YubiKey. It's in the kit.
Plug it into the device. Tap the disk. Nothing. Pull it out. Plug it in again. Still nothing. Try a different USB port. Nope. Not that one either. And I don't know what's going wrong. And I'm not getting any error messages. I'm not getting any feedback whatsoever. It's when I realize I can hop over to the web-based version of 1Password and try there. And so I do that. I go through the same steps. And I get to the second factor. And then I get this message. You're using a security key that's not registered with this website. That's my oh, crap moment.
Because if I can't get into 1Password, those 1,000 credentials in 1Password are now inaccessible to me. And my family. And anyone who succeeds me. And I have a real problem. I could stop here. I could say, thank you very much, good night, we're done. But that's not really a good answer. It's not a satisfying answer. So I reach into my backpack, I pull out another YubiKey, plug it into the device, and I unlock my vault. I broke the rules. I broke the rules that I had purposely set for myself to see if I could do this experiment. But I broke them for a good reason. Because I still had to try.
Even if I knew what I had messed up, putting the credential in the YubiKey, I still had to try to recover everything beyond that. But as a former roller derby ref, that's me, full frontal nerdity, I would be yelling, sending myself to the bench, blowing my whistle, throwing up hand signals, all these things, because I'm doing the wrong thing. But I'm doing it for a good purpose.
So first, I fix the glitch. You can see on the upper left corner safe deposit box with the hardware key icon. This is from 1Password's interface. I fix the glitch, I put the credential on the key, and the key now exists in my safe deposit box. Everything else was easy.
Apple, Gmail, Google, all of it just happened really quickly. I had the credentials I need, either from the YubiKey or from my 1Password vault. And then I get to my mobile phone. And here I have a problem. Because in order to log in to try and generate a new eSIM on a new device, here's what I'm expected to do. Enter an SMS OTP. An SMS OTP that I cannot get. And so I try account recovery, figuring surely there's a better way.
Well, you know what account recovery requires? An SMS OTP that I cannot catch.
Now, to be fair, I could go to a physical store, I could call up customer service. There are ways that I probably could have recovered, but because this was a test and I didn't want to mess up my own personal mobile service, I chose not to do that. So a couple lessons learned. The first one, Ian knows I'm showing this here.
This guy, Ian Glazer, he's not the fraud. I'm the fraud. Because I'm supposed to be the expert at this. I'm supposed to be the one who's thought about this, who's put a lot of work into this, and really figured out how to make this work. If I can't do it, do any of us have any hope of doing it? I'm not really sure. This is actually quite difficult. My break glass kit was accessible when I needed it. It's accessible to my family, it's accessible to me. The credentials were securely stored. That was great. That worked perfectly. But they were so securely stored, they were inaccessible.
And SMS OTPs, for the reasons I cited, also inaccessible to me. So it was a failed experiment. Before I go on, quick show of hands. Do you have a break glass kit? About 15% of you, 10% of you. Keep your hands up, those of you who had your hands up. How many of you think your break glass kit is sufficient after what I've just shown you? About 90% of you dropped your hands. And that's about what I expected. So let's talk about rebuilding.
So, as I mentioned, I did this experiment in August of last year. And for about six months after fixing the immediate glitch of the YubiKey, I sat on this, and I didn't really know what to do. Because building a break glass kit that's usable by others, building a break glass kit that's durable, that can last over time, that's continuously updated, is very, very difficult to do. And I didn't know how to do it. And a couple months into thinking about this problem and kind of ignoring it and procrastinating, I started using Claude a lot.
And I know, you thought you were going to get away without hearing about AI tonight. But unfortunately, I'm going to talk a bit about AI. Part of my use of Claude was to help rebuild some of my home infrastructure. And in rebuilding some of that home infrastructure, I wanted to build a disaster recovery plan.
And hey, that looks an awful lot like a break glass kit, doesn't it? So can I use Claude to build a break glass kit? The answer is yes. And so I set to work. I started building a skill to build my own break glass kit, to have it walk me through a series of interviews so that I can figure out what parts I need in order to put together so somebody else can recover, or I can recover if necessary. And I worked on this for a little while, and I went through a bunch of iterations, a bunch of test data, etc., before I finally tested it on myself.
And when I did, I sat for 90 minutes, I walked through all the parts of the skill, got a whole bunch of documents on the other side that told me exactly what was good and what was bad and how somebody could break glass. And I thought, wow, this is great. This is the break glass kit of my dreams. This is exactly what I wanted. But there was a problem, because the break glass kit that I worked on last summer was built for me, and that was one of the big challenges from that. It wasn't built for anyone else.
So I asked Claude, hey, Claude, can you take on the persona of my wife, Stephanie, and review the documents and tell me whether the documents are sufficient, whether they meet her needs? And here's what Claude had to say as my wife.
Quote, if you died tomorrow, I'd keep the house running and eventually untangle the rest. Some of the things you've written down as, quote, documented are actually just promises to document them later. The architecture is right. The execution isn't finished. You know this. You wrote it down yourself in the review doc. I'm telling you the same thing from my chair.
Folks, I sat on the couch crying. Now, the document was much larger than this, and examined all of the flaws, and there were many. And I didn't exactly know what to do. But here's the thing. Death isn't an edge case. It has a 100% uptake. All of us will eventually die. Many of us, I shouldn't say many of us, some of us may become incapacitated or may be involved in some sort of a disaster where we need this. And so I stopped thinking about me, and I started thinking about we, and how I could build a skill that could help all of us through this situation, because all of us need this.
So I built a skill that captures what your people will actually need if you become, if you die, if you become incapacitated, or you might need if you suffer a disaster. And it does this by walking you through a series of 12 different question-and-answer sessions, roughly, that cover things like jurisdictional context, the keys to everything, what's your password manager, your e-mail, how do I get access to your phone, where are your insurance and benefits and property, where is your digital property?
And you can see a lot of this goes beyond just the digital domain because all of this is important. If you die, someone needs to know where all of this exists. And in my case, even after thinking about this for a couple of years, I had to go discover where some of this existed because I didn't know. And the outcome, or the output of the skill, is in multiple parts, but there are two key documents tuned to key moments in your life. The first is a short, stress-readable break glass kit.
For the first 48 hours after disaster, incapacity, or death, someone can read this, you can read this, and figure out, what do I need to do right now? And then a longer, comprehensive inventory and administrator quick reference guide that you can read in the weeks and months following death or incapacity to help do the recovery that's necessary and unwind somebody's digital estate and their larger estate as well.
Now, the skill adapts to where you live and your personal situation because it has two concepts. The first, plug-ins. So plug-ins represent composable artifacts. Think of law. I live in the state of Washington in the United States. The state of Washington has estate law. The U.S. has estate law. Those have to be composed together. I assume the same would be true for the various countries that make up the EU as well. So plug-ins are composable, and they consider jurisdiction, culture, and religion, three things which impact the choices you make about your own estate.
And facets are not composable. Facets are independent facts. I'm married. I have one minor child, one adult child, which that only happened a few weeks ago. It's still weird to say. But these facets are independent facts that describe the size and shape of your familial and non-familial relationships that may be impacted by your death or incapacity. And it does cover incapacity and not just death because death, yes, that does have, as I said, a hundred percent uptake, but incapacity will happen to some of us as well. And today I'm releasing it as an open-source project.
If you go to GitHub at this URL right here, you'll find it. And I need to provide some context for this as I'm releasing this to you. First of all, Claude and I are not lawyers. My mom wanted that so bad. I was such a disappointment. We are not fiduciaries, and Claude's not even human. The information it produces may be incorrect. It is up to you to validate everything the skill outputs, and it's not a will. You have to work with competent local professionals to put together a will or an estate plan or whatever the appropriate documentation is in your jurisdiction.
And it doesn't yet support a worldwide perspective. Remember, I started building this for me, and I built a bunch of test cases, and you can see these in the GitHub repo, but the skill doesn't cover jurisdictions outside broadly the U.S. and the state of Washington, and it doesn't cover religion because I'm not a religious person, and so it wouldn't be fair for me to try and put together some plug-ins for religion or culture that aren't my own.
And this is where I invite all of you to bring your intelligence, your knowledge to the party, and share what you can to help make this skill better over time. And there are docs about building plug-ins and facets, how that works, and how to submit a PR so that we can review that and add that to the skill. So where's my own break glass kit today?
Well, it's better than it was. I can break glass successfully, I think. It's still Schrodinger's break glass kit. I haven't tested it again. But one of the things the skill has helped me do is put together a checklist of what's missing. What haven't I done yet? What do I still need to do? I get reminded every morning that I still need to make that appointment with the lawyer to review my estate plan and make sure it's up to date now that it's 7 years old, and my circumstances, our familial circumstances have changed. And so it is an ever-evolving break glass kit.
It will never be done, because there is no done here. It will always change as my life and my life circumstances change. So one last thing before I go. Quick show of hands. Who's going to build a break glass kit after EIC?
All right, very well. That's exactly what I want to see. Thank you all so much for your time, for your attention. I realize I'm the last thing standing between you and beer, so please, go have a beer. Don't be too depressed about your own death and digital estate. But please, do this work, because it's important. It's important for you, it's important for your family, it's important for your loved ones. Thank you very much.
Dean, thank you so much for this very personal thing, and I saw a lot of hands raised, which makes me quite confident. Next year, we will ask who has created it, actually. There you go. We will test it. Thanks a lot. That was it for the day.
Thanks, Dean. Enjoy the rest of the evening, and see you tomorrow again for the last day of EIC. Thank you very much. Thank you all.