What 72 hours without access to my digital life taught me about privacy, password managers, and having a backup plan for your backup plan.
I’ve spent years making my digital life harder to break into.
Strong unique passwords. Email aliases. Encrypted email. A password manager. Hardware security keys. My own domains. VPNs. Recovery protections. Enough layers that getting into one of my accounts without permission should require either serious effort or a very motivated government agency.
Then one day, the security worked.
On me.
And for the next 72 hours, I got a very intimate lesson in what happens when you build a digital fortress and accidentally lock yourself outside of it.
It Started With QuickBooks
The disaster started innocently enough.
I was helping my mom set up QuickBooks for her business. We were using her computer, and at some point it was simply easier to use my email account during the setup.
There was a reason for this.
My email is organized. I use aliases. I know where things are.
My mom has somewhere around 30,000 emails.
Thirty. Thousand.
Opening her inbox is less like checking email and more like conducting an archaeological excavation. Somewhere beneath the newsletters, receipts, and forgotten account notifications, I assume civilization continues.
So I signed into Proton Mail on her computer, we finished what we needed to do, and eventually I went home.
Later, I remembered something.
I hadn’t logged out.
For someone who spends an unreasonable amount of time thinking about privacy and security, leaving my primary email signed into another computer bothered me immediately.
Easy fix, I thought.
I opened Proton’s security settings and revoked the other sessions.
Problem solved.
Except I had misunderstood exactly how large of a hammer I was swinging.
Congratulations. You Have Secured Yourself From Yourself.
My Proton account isn’t just an inbox.
Over time, Proton had become the center of my digital life. Proton Mail handles my primary email and aliases. Proton Pass handles my passwords. My domains, websites, financial accounts, business services, work accounts, and a truly stupid number of other online accounts depend on that infrastructure.
I have more than 300 online accounts.
Then came the really beautiful part.
My Proton Account password was stored in Proton Pass.
Proton Pass was now inaccessible.
Read that again.
The password I needed to get into Proton was stored inside the Proton service I needed the password to access.
I had created a perfect little cybersecurity circle of hell.
For years, I had been carefully creating strong passwords I didn’t know, because that is generally the entire point of a password manager.
The system worked wonderfully right up until I needed the one password that probably shouldn’t have existed only inside that system.
I had built a vault.
Then I put the key inside the vault.
Excellent work.
One Session Was Still Alive
I wasn’t completely dead in the water.
On my main computer, Prometheus, I still had one authenticated Proton Mail browser session alive.
That session became the most valuable browser tab I have ever had open.
Everything else might as well have been on another planet, but that surviving session gave me a path into Proton’s signed-in password recovery process.
There was just one small feature.
I had to wait 72 hours.
Seventy-two hours doesn’t sound particularly dramatic until your password manager contains the credentials for more than 300 accounts and you suddenly can’t get into it.
Banking was in there.
My domains were in there.
Website infrastructure. Business accounts. Work accounts.
Years of my digital existence had been neatly organized behind a door whose key I had misplaced inside the building.
I hadn’t lost ownership of those accounts. Nobody had stolen them. They were still there.
But I had lost my normal ability to authenticate to a huge portion of my life.
And if Proton recovery failed, rebuilding access would have become an enormous account-by-account recovery operation.
That’s when the funny mistake stopped feeling particularly funny.
The Longest 72 Hours I’ve Had in a While
I slept about six hours during those three days.
Not six hours a night.
Six hours total.
There was also considerably more alcohol involved than any sensible disaster-recovery procedure would recommend.
I suggest neither strategy.
Fortunately, past me had accidentally done present me a favor.
Most of my important bills were already on autopay.
So while I sat in front of a computer reconsidering every technological decision I’d made for the last five years, electricity companies and financial institutions continued happily moving money around in the background as though their customer weren’t having a minor digital existential crisis.
Autopay suddenly became one of my favorite cybersecurity features.
There is something uniquely humbling about spending years protecting yourself from hackers, scammers, data brokers, and account takeovers, only to discover that the most immediate threat to the system is the idiot operating it.
Me.
Seventy-Two Hours Later
Eventually, the clock ran out.
Using that surviving authenticated session, I was able to reset my Proton Account password and regain control.
I cannot adequately describe the relief.
Once I was back inside, I did something I should have done long before any of this happened.
I created an independent offline backup of the critical recovery information and stored it securely.
The password that unlocks my digital life will never again exist solely inside the digital life it unlocks.
That sounds painfully obvious now.
It did not feel painfully obvious before I spent three days learning it.
And this is probably the most important part of the story:
Proton didn’t fail me.
For the most part, Proton did exactly what a privacy-focused encrypted service should do.
It obeyed my security commands.
It didn’t casually bypass its protections because I was suddenly inconvenienced.
It preserved an authenticated session that gave me a recovery path, and its security process imposed a waiting period before allowing a sensitive password reset.
The weak point wasn’t the encryption.
It wasn’t Proton Pass.
It wasn’t the authentication system.
It was architecture.
I had allowed too much of my digital life to depend on one ecosystem without maintaining a truly independent recovery path outside of it.
Privacy Needs Redundancy
Privacy conversations usually focus on keeping other people out.
Use a password manager.
Use unique passwords.
Turn on two-factor authentication.
Use aliases.
Protect your email.
Secure your accounts.
All good advice.
But there’s another question that deserves just as much attention:
How do you get yourself back in?
If your password manager disappears tomorrow, can you access its master password?
If your primary email account becomes unavailable, can you recover your financial accounts?
If your phone is destroyed, do you still have your two-factor authentication backups?
If one company provides your email, passwords, and authentication infrastructure, do you have something outside that ecosystem capable of helping you recover it?
Those aren’t arguments against encrypted services or password managers.
They’re arguments for redundancy.
My mistake wasn’t taking privacy too seriously.
My mistake was assuming that because every individual piece of my system was secure, the entire system was resilient.
Those are not the same thing.
A fortress with one entrance is extremely secure.
Right until you’re standing outside.
What I Changed
I still use Proton.
I still use Proton Mail.
I still use Proton Pass.
I still believe that owning my domains, using aliases, using strong unique passwords, and reducing how much personal information I scatter across the internet is the right approach for me.
If anything, this experience reinforced why those systems matter.
But I now treat account recovery as part of security rather than something you configure once and forget.
Critical recovery information has an independent offline backup.
The password protecting the ecosystem no longer depends exclusively on the ecosystem itself.
And before I hit anything labeled “revoke” again, I intend to spend considerably more time appreciating the philosophical implications of that button.
Privacy is about controlling access to your information.
That includes keeping corporations, criminals, and random strangers out.
It also includes making damn sure you can still get back in.
I spent years building a digital fortress.
For 72 hours, I learned what the moat looks like from the wrong side.