Recovery approach

Recently I tried to figure out which service to use for a break-glass recovery scenario. Like if I lose all my devices, forget all my passwords, and need to recover everything: password manager database, access to accounts, my docs.

The weird thing for me is that no two well-known services share the same recovery approach. All services are pretty similar in terms of signing in but when it comes to account recovery, everyone invents their own thing.

Here’s a simplified comparison of services:

Whether the secret is short enough to write down matters for offline paper storage. Someone could try to write down Filen’s 640 random characters, but it was clearly not designed for that.

The option to rotate the recovery secret becomes important when the secret was compromised or entered on an untrusted device during recovery. This is where I see a hard trade-off Ente has made. When I asked the community why the recovery code can’t be changed, they said it would require full re-encryption of the entire Ente media library. Proton is in the same situation, but wrapping a permanent secret with a rotatable one solves this limitation in similar cases.*

Ente addresses this by encouraging people to use their SSS implementation, while it’s meant as a legacy route, it also works as a personal recovery solution. But it makes the secret non-writable in the current implementation. They also have recovery through trusted contact.

One more note on Ente: while I mentioned email as required in addition to the secret, users can actually bypass this by writing to support.

Proton’s approach is the most flexible: users can choose whether to store one passphrase that bypasses everything, or split data and account recovery (Filen-style). For data restore you need key files, and for account recovery a phone or email. The recovery passphrase is still the simplest approach and the one Proton itself recommends — and the only option where a single artifact requires nothing else.

Tuta’s approach is the strictest: they allow users to forget their password or lose their 2FA, but not both. I’d say if Proton wins in terms of chances of successful recovery, Tuta wins in terms of how hard it is to use the recovery route to steal an account.

More mainstream services like Google are less interesting to the crowd here. But broadly: Microsoft is closer to Proton’s approach, Apple closer to Tuta’s. Google is in its own league — as far as I know, with Advanced Protection enabled there’s no clear list of what a user has to provide if they lose their key. This looks intentional, and turning on APP is generally considered a good thing if you use Google. APP probably makes Google more secure, but a less predictable recovery option.

Personally I find Proton’s approach the most straightforward and reasonable, and do the same with a self-hosted solution. But I’m not sure if there’s a consensus in the community.

*Proton Drive also supports rotating the “permanent” secret if you ask them — but that requires removing all files from Proton Drive and a conversation with Proton support.

1 Like

One option is to run KeePassXC with Syncthing and keep the database on your computers and phone, synced to an always-on home server or a Raspberry Pi. If a device is lost or seized, you still have another copy to retrieve, as long as the server is somewhere safe and you can access it. I’d also keep a separate offline backup.

The important catch is that Syncthing syncs the file, it doesn’t recover a forgotten KeePassXC master password. Make that password unique and memorable, and keep a sealed paper backup somewhere secure in case you forget it.

That’s nice plan and I already do the same (with Resilio Sync — I stopped using Syncthing after all the maintainer issues). But yeah, as I said, losing all devices is the scenario I’m targeting here

Honestly, if you’re planning a scenario losing every device, you should be able to get back in from memory.

Memorize your important passwords.

We manage to remember poems, lyrics, and all sorts of rules, so it’s not impossible.

Sure, I’m kind of good at memorizing random word lists (thank you, humanities degree). so memorizing a 7—8 dice-passphrase is usually fine, and Proton’s 12 words could probably be memorized too. Though it’s a bit of a strange thing to do, since you tend to forget things you don’t type regularly within a few months and a recovery passphrase may only ever be typed once.

That’s why I said Proton’s approach makes the most sense for now, with some tuning on a self-made solution.