Kyber Cypher v008/v007/v006/v005/v004/v003 KC//NODE-01 00:00:00:00

A backup you cannot reach is not a backup

Field Log // 026 Status Live Difficulty Free Cost Low
The Story

My backups were good. Multiple copies, one of them off site, restores tested on a schedule. I was pleased with them right up until I asked a question I had been avoiding: if the house were gone, what exactly would I do on the first morning?

The answer was embarrassing. I would need credentials to reach the off site copy. Those credentials were in a password manager. The password manager was unlocked by a key on a device in the house. The off site backup was fine. The way in was in the fire.

This is the failure that backup advice almost never covers, because the advice is about copies and this is about access. Three copies of a locked box is three locked boxes. The number people quote is about surviving loss of data. It says nothing about surviving loss of the ability to open it.

A spare key is only a spare if it is not inside the house. Taped to the inside of the front door, it is a spare key for someone who is already in.

So I built a small physical kit. An encrypted drive, carried by hand to a different building, with the passphrase written on paper and stored somewhere else again, in a bank box. Two objects, two locations, and neither one is useful alone. The drive is unreadable without the paper. The paper is a meaningless string without the drive.

The part I did not expect was how much of the work was deciding what not to protect. My instinct was to copy everything, because everything feels important when you imagine losing it. But a kit that takes three hours to assemble and a large drive to hold is a kit you update once and then never again, and a stale kit is a worse lie than no kit, because you believe in it.

So I cut. Media library: not in the kit, it is replaceable and enormous. Operating systems: not in the kit, they are downloads. What went in was the short list of things that are either irreplaceable or that would cost me weeks to reconstruct: the keys, the configuration that encodes decisions I have forgotten making, the documents nobody else has a copy of.

Deciding deliberately what you will lose is not defeat. It is the thing that makes the rest of the plan small enough to actually maintain. The honest catch is that I will be wrong about something on that list, and I will only find out at the worst possible moment.

The Build

How to build an encrypted recovery kit, what belongs in it, and how to keep the secret separate from the medium. Generic throughout, because the value is in the ordering and the honesty, not in a particular tool.

1. Write the first morning, as a story, before buying anything

Describe the actual sequence. Where are you, what device do you have, what is the first thing you need, and what unlocks it. Keep going until every step names something you could really put your hands on.

# first-morning.md
#   I am somewhere else with a borrowed laptop.
#   To reach the off site copy I need ............ which lives ............
#   To open that I need ............ which lives ............
#   Keep asking "and what unlocks THAT" until the answer is outside the house.

The loop appears on its own. Every chain that ends inside the building you just lost is a gap, and writing it as prose finds them faster than a checklist does.

2. Sort candidates into three honest buckets

Be ruthless. The kit's value is inversely proportional to its size, because size is what stops you refreshing it.

  1. Irreplaceable. Photographs, documents, anything only you hold. Goes in.
  2. Reconstructable but expensive. Keys, configuration, the notes that record why things are the way they are. Goes in, because weeks of your life is a real cost.
  3. Replaceable. Media, installers, anything you could download again. Stays out, and write down that you chose this.

Record the third bucket explicitly. An undocumented omission looks identical to an oversight when you find it later, and you will not remember which it was.

3. Encrypt the whole volume, not individual files

Full volume encryption means you cannot forget to encrypt something you add in a hurry. Use what your platform already ships; it is audited and it will still exist in five years.

# Linux: LUKS on the whole device
sudo cryptsetup luksFormat /dev/<device>
sudo cryptsetup open /dev/<device> kit
sudo mkfs.ext4 /dev/mapper/kit

# macOS: encrypted APFS volume via Disk Utility
# Windows: BitLocker To Go on the removable drive
# cross platform alternative: VeraCrypt container

Prefer a mechanism you can open from a machine that is not yours. An exotic tool you cannot install on a borrowed laptop is another lock without a key.

4. Generate the passphrase so that it is writable by hand

This thing has to survive being copied onto paper and typed back correctly under stress. Random words beat random characters for that, and are strong enough when you use enough of them.

# six or more random words, from a real random source
# write it in clear block capitals, and mark where the spaces go
# avoid characters that read ambiguously by hand: 0/O, 1/l/I, 5/S

5. Separate the secret from the medium, physically

Different buildings, not different drawers. The threat you are planning for destroys or denies access to one whole location.

# drive  -> location A   (a different building, a person you trust, a locker)
# paper  -> location B   (a bank box, a safe elsewhere)
# neither location holds both, and neither alone is enough

Write a short note on the paper saying what it opens and nothing about where that is. A found passphrase with directions attached is just a labelled key.

6. Restore from it, on a machine that is not yours

An untested kit is a theory. Borrow a laptop, or use a spare with a fresh install, and go through the whole sequence with only the kit and the paper.

# the test that counts
#   1. a machine with none of your credentials on it
#   2. unlock the drive using ONLY the written passphrase
#   3. open one file from each bucket you included
#   4. reach the off site backup using only what the kit gave you

Step four is the one that found my loop. Everything before it can pass while the plan is still broken.

7. Put a refresh date on it and keep it boring

Keys rotate, accounts move, the contents drift out of date. Pick an interval you will actually honour, and make the refresh a short job by keeping the kit small.

# kit.md, stored with the drive
#   contents  : short list of what is in here
#   OMITTED   : media, installers, anything downloadable  (deliberate)
#   refreshed : date, and who tested the restore
#   next due  : date

The honest catch: this protects against losing a place. It does not protect against losing yourself. If nobody else knows the kit exists, your plan has a single point of failure wearing your face, and that is a different log.

Related: reading the current screen instead of your memory of it is the companion habit, because recovery paths are exactly where remembered steps go wrong.