![](https://lemmy.blahaj.zone/pictrs/image/6Q16C1TbuJ.jpg)
![](https://lemmy.world/pictrs/image/0da8d285-3457-4e5b-af21-b38609b07eea.webp)
my understanding is:
- the emergency contact sends their public key to the owner of the vault
- the owner encrypts the key for the vault using said public key and stores the result on bitwarden’s servers
- the emergency contact can now request the decryption key from bitwarden, which they will receive either if the vault owner manually approves the request or if the request is not rejected within a certain amount of time
- the emergency contact can then decrypt the stored vault key using their private key, and use that to access the vault
that just sounds like nixos impermanence with extra steps