# Data encryption and LastPass Emergency Access

**URL:** <https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341>\
**Category:** Factual Questions\
**Created:** [July 21, 2022, 8:34pm UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341 "2022-07-21T20:34:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [July 21, 2022, 8:34pm UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341/1 "2022-07-21T20:34:04Z")

</div>

If you use LastPass to store your passwords and such, there is an option called Emergency Access - you nominate another person who will be able to access your data (main use case is after you have died) - you specify a wait time - this enables you to decline their attempt to access your data while you are still alive.

When you pass away, they request emergency access - messages are sent to you alerting you of this, but as there is no email in Heaven/Hell, you do not respond. After the specified wait time, they are granted access to your data…

BUT

Doesn’t this imply that there is an unencrypted copy of the data on the LastPass server?

If it were the case that my data was encrypted using, say, a locally-created public key, then uploaded in encrypted form, and only decrypted locally (using the private key) after downloading/retrieving the encrypted form, then another person without my private key would only be able to gain emergency access to the encrypted form. If they can just get it after an interval (during which I specifically do not intervene or give them anything), that must mean the data can be decrypted outside of my control, must it not?

Or am I missing something?

---

<div class="post-metadata">

**Author:** ![duality72](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duality72/32/3910_2.png) [@duality72](https://boards.straightdope.com/u/duality72)\
**Post date:** [July 21, 2022, 8:38pm UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341/2 "2022-07-21T20:38:36Z")

</div>

Here is LastPass’s take on the matter:

> **[How is Emergency Access secure? - LastPass Support](https://support.lastpass.com/help/how-is-emergency-access-secure)**
>
> LastPass uses public-private key cryptography with RSA-2048 to allow users to share the key to their vault with trusted parties, without ever passing that information in an un-encrypted format to LastPass. When Emergency Access is activated, each...

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [July 21, 2022, 10:30pm UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341/3 "2022-07-21T22:30:12Z")

</div>

It’s been well worked out how to “share keys” in such a way that each key holder can access the data without anyone else being able to access it. You can even set up a system where, for example, any 3 of 5 people could get together and access something but not 2 of five.

But the usual crypto _caveat_ applies: Just because the idea is sound in no way means the implementation was done right.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [July 22, 2022, 6:43am UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341/4 "2022-07-22T06:43:07Z")

</div>

Thanks - that’s actually what I was hoping to find, but couldn’t see anywhere. Interestingly, I think the process just feels a bit too opaque - from my point of view, inviting someone to Emergency Access didn’t seem to do anything other than add them to a page (I was expecting there to be a process where I would see confirmation of key exchange)

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [July 22, 2022, 1:06pm UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341/5 "2022-07-22T13:06:36Z")

</div>

The simple way to do this is that none of the users actually has the decryption key for the big data set. Rather, you have a key that decrypts the encryption on one very small encrypted file, and that very small encrypted file contains the key used for the big data set. If you want multiple users to have access, then you just make multiple copies of the key, each one encrypted by a different user’s personal key.

It’s like one of those lockboxes that you mount on your porch with a spare key inside. Now make a different lockbox, with a different combination, and put a key in that, too.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [July 22, 2022, 1:29pm UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341/6 "2022-07-22T13:29:43Z")

</div>

This is why you really need to go to serious experts on encryption. What you suggest is not remotely what an expert would permit.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [July 22, 2022, 2:49pm UTC](https://boards.straightdope.com/t/data-encryption-and-lastpass-emergency-access/968341/7 "2022-07-22T14:49:25Z")

</div>

…True. I don’t see the weaknesses in my idea, but then, that would be precisely because I’m not an expert.
