Google issues its backup codes in sets of 10, and generating a fresh set silently voids the one before it. A printed sheet can already be dead.
Most advice about digital estates stops at the password, which is the barrier a password manager already handles. The second factor is the harder one. It sits on a handset, on a paper sheet, or inside an app whose backup nobody has checked in years. Those objects rarely survive a death on their own, and the large providers refuse to issue a replacement login.
Google says it cannot provide passwords or other login details, and Apple’s legacy route skips the stored-password vault entirely. Each route ends in a data copy. So the work that matters happens while you’re alive and can still change a setting.
Two separate mechanisms cover an ordinary household. A password manager’s emergency access covers the vault, and a platform’s own legacy setting covers that one service and nothing else.
The two overlap far less than people expect, and the gap between them is where families get stuck. The order matters more than the brand. Set the platform tools first, because the model law behind most state statutes ranks that direction above a will. Then decide who holds the vault, and write down where each second-factor artifact physically lives in the house.
A plan that names a person but leaves the objects scattered fails at the moment somebody tries to use it. In practice the objects are the plan. Whether any of this belongs in your estate documents is a question for the lawyer who drafts them.
Backup codes are estate objects, and they expire quietly
Google’s backup codes arrive as 10 single-use codes, and each one works exactly once. Generating a new set kills the old one.
Nothing warns you that the printed sheet in the folder stopped working the day a replacement set was made. The paper itself looks exactly the same. A binder full of dead codes reads as a completed plan to everyone who opens it later. So a printed set needs a date on it, plus a habit of reprinting whenever the codes get regenerated.
Authenticator apps changed where the second factor lives, and Google’s version now syncs its seeds to the account itself. The codes no longer die with the phone. Those seeds are the secret values an app turns into codes, and they travel with the Google Account when sync is on.
Apple draws that line in another place. Its Legacy Contact route excludes iCloud Keychain, so the legacy key can’t decrypt stored passwords, payment information, or passkeys.
Your family can hold a valid legacy key, reach the photos and files, and still find every saved password missing. Those two vaults are separate by design. Apple’s own security documentation describes the beneficiary as the holder of the decryption key, which Apple cannot supply. So the key generated at setup is a physical object too, and it belongs wherever the rest of them live.
An inventory beats an intention, and the list is short—access keys, backup codes, and recovery addresses. Write down where each of them sits. A document naming the person who should receive them does nothing if the objects themselves have gone stale.
Emergency access in a password manager hands over everything at once
Bitwarden’s emergency access works by invitation, from a premium account holder to a trusted contact. That contact can later ask for access.
A configurable waiting period follows, with a minimum of one day, and silence from the owner hands the contact the vault. A veto during that window stops it. Takeover then sets a new master password and removes every two-step login method attached to the account. That second half is the part worth understanding, because it clears the two-factor barrier no death certificate could.
Three limits come with the feature, and none of them announces itself when you set it up. The grant always covers the whole vault. Handing over four logins while holding back the rest of the collection isn’t something the feature can do.
Payment is the next weak point in it. Emergency access rides on a paid plan, and it stops working when the plan lapses years before anybody needs it.
Silence is the third weakness, and it’s the one that undoes plans quietly after somebody has died. Nothing tells your trusted contact anything happened. The invitation sits in an inbox from years earlier, and the person who accepted it may have forgotten. Telling that person out loud, in the same conversation as the will, is what turns the setting into a plan.
Proton offers something comparable on its paid plans, with up to five contacts and a waiting period that grants access automatically. No such feature exists at 1Password today. Its staff confirmed the absence in October 2025, the request thread closed in March 2026, and nothing changed by July 28, 2026.
Whoever inherits the email can reset most of the rest
A study presented at The Web Conference 2021 named this the post-mortem privacy paradox. People value the planning and avoid doing it.
The same authors noted that inherited email silently confers password-reset power over most of a person’s other accounts. Email is the reset channel for nearly everything. A reset link goes to the mailbox, and whoever opens the mailbox becomes the account holder for that purpose. The study rested on 14 security-aware participants, and its authors say plainly that the sample doesn’t generalize.
For many households, the Google account sits at the center of this, because the seeds and the reset mailbox live together. That one account effectively unlocks the others. Turning on Authenticator sync makes the convenience real and makes the concentration worse at exactly the same time.
Your choice of person carries real weight. Naming an emergency contact for the vault hands one living person the ability to reset almost every account you hold.
That person can be someone other than the executor, and in many families the two roles sit apart. The two jobs call for different things. An executor deals with courts and banks, while a vault contact needs to be reachable and technically comfortable. Whether splitting them creates a problem for your estate is a question for the lawyer drafting your documents.
The platform settings sit above all of this, since the model law behind most state statutes ranks them above a will. Three settings outrank the paperwork. A vault plan built underneath them stays useful, while one built against them gets overridden without anybody noticing.
Where the codes live decides whether anybody finds them
Wills filed for probate become court records open to public inspection, a pattern confirmed against California and Texas statutes. Many county probate records are searchable online.
Consumer legal guides describe the same practice nationally, so a password written into a will can end up in a public file. Estate documents are there to grant authority. The access artifacts belong in a password manager, or in a letter of instruction kept somewhere else. What belongs in the will is a separate question, and it turns on granting authority rather than access.
A seed phrase makes the consequence terminal, because possession of the 12 to 24 words is possession of the funds. There’s no reset for that one. A phrase that reaches a public court file has already transferred the money to whoever reads it first.
A printed kit can fail in two ways. The Emergency Kit that 1Password documents names both—the sheet goes stale, and nobody finds it when it matters.
Staleness has a fix: date the page, and reprint after any change. Discovery is the harder half of it. A sealed envelope helps nobody if the person holding it has no idea what’s inside or when to open it. Telling one named person where the envelope is, and what triggers opening it, is the step that gets skipped.
One check takes a minute today, and it decides whether a living person ever sees the warnings a provider sends. Check the recovery address on your main account. Google sends its inactivity notices to the account and to that address, so a self-referring pair reaches nobody at all.
