Last episode we spent the whole hour on threads that outlived the people who posted in them, and the protocol problem of a forum where half the participants aren't there anymore. Morbid territory. Dutch angles. Well, we're going back.
We are, and I want to say up front that the prompt that got us here came with a disclaimer attached.
It did. Daniel wrote in to ask about dead man's switches — specifically the niche end of that category, the monitoring hardware and services whose job is to detect, confirm, or announce that a person living alone has died. He wants to know how the same underlying mechanism gets wired up in two completely different directions. One where the goal is an emergency alert, send help now. And one where the goal is a notification that a predicted death has occurred so that funeral arrangements and the rest can begin.
And then he added the reassurance.
He did, and it's worth reading out because it's very Daniel. He wrote, "In case anyone listening to this is worried about me by the fact I asked this question, I would like to reassure friends and listeners that I am very much alive and well." He is. He asks these things out of genuine curiosity, and because he thinks part of the ethos of a show like this is covering topics that get neglected, whether or not they're palatable to think about.
Which is a fair description of the show.
It is. So let's start with what a dead man's switch actually is, because the name is older than the electronics.
The standard definition is a switch designed to be activated or deactivated if the human operator becomes incapacitated — through abandonment, drowsiness, loss of consciousness, death, or being bodily removed from control. That's the Wikipedia sentence and it's actually well written, because it catches something important. The trigger isn't death. The trigger is the absence of a signal.
Which is why it shows up first in machinery. Trams, trains, lawn mowers, treadmills, boat kill cords.
Right. The original insight was mechanical and quite beautiful: a machine should stop when the human stops signaling. On a train, the driver holds a pedal or a handle down. If he lets go, the brake applies. On a boat, the kill cord is attached to the operator's wrist, and if he goes overboard, the engine cuts. It's not safety software, it's a physical assumption about the world — a live operator is one who's holding something.
And the failure mode of that assumption is the part I find interesting. Because a pedal held down by a slumped body is indistinguishable from a pedal held down by a living driver.
Yes. The Waterfall train disaster in Australia, 2003. The driver suffered a heart attack, and his body stayed slumped over the controls with the pedal depressed. The train kept going. That's the case that made the industry take the vigilance-control refinement seriously.
Explain the refinement, because it's the hinge for this entire episode.
A vigilance system doesn't just require the operator to hold something. It requires them to release and re-press at timed intervals. Every thirty seconds or a minute, a light comes on, and if you don't respond, the brakes apply. A living person can do that. A body cannot. So you've defeated the slumped-driver weak spot.
At the cost of making the operator's life mildly worse, which is always the trade.
Always. And that distinction, between a passive hold and an active periodic check-in, is exactly the split between the two use cases Daniel is asking about.
That's a clean way to put it.
Emergency alert systems are vigilance controls. They need continuous evidence that you're alive and moving, and they fire when the evidence stops. Post-death notification services are passive holds. They wait for silence, and then they act on it.
Except the speeds are so different that they almost don't feel like the same mechanism. One fires in seconds, the other waits weeks.
That's the whole episode in miniature. Same idea, opposite optimization. One accepts false positives because the cost of a missed fire is a person lying on the floor. The other demands certainty because the cost of a false fire is telling your family you're dead.
Let's take the first family, then. The devices that fire when something goes wrong.
Halo Home is the cleanest example I've found. It's a plug-in sensor, no camera, no wearable, and it works on WiFi Channel State Information. That's a real thing, not marketing — it reads the way your body perturbs the WiFi signal in the room, and it pulls fifty-six subcarriers out of that signal.
Fifty-six what?
Subcarriers. A WiFi channel isn't one clean frequency, it's a bundle of narrow ones, and each one gets slightly disturbed differently by a person moving through the room. Fifty-six channels of disturbance is enough to reconstruct breathing.
Reconstruct breathing.
Six to thirty breaths per minute, by the way. Heart rate, forty to one hundred twenty. Falls, in under two seconds. And a prolonged-inactivity mode where the default daytime threshold is two hours.
Two hours is the number that strikes me. Falls fire in two seconds, but if you just stop moving, it waits two hours. That's a design decision about how annoying the device is allowed to be.
It's a design decision about how many false alarms a family will tolerate before they unplug the thing. And the interesting part is the compute. It runs an eight kilobyte quantized model on an ESP32-S3, fully on-device. The reasoning happens in your hallway, not in a cloud.
Eight kilobytes.
Eight. Which tells you how narrow the model's job is. It isn't identifying you, it's classifying a signal as fall, breathing, or neither. Alerts go out over push, webhook, REST, or MQTT, and it's twenty-five dollars a month direct to consumer.
Now do the other one, because the latency numbers are completely different.
Silvie, from Pontosense. Corner-mounted radar. One hundred fifty dollars per sensor, or three ninety-nine for three, plus a thirty-three dollar monthly membership. Fall detection within about a minute.
A minute. And Halo does it in under two seconds.
That's the latency-versus-coverage tradeoff showing up inside a single product class. Radar at the corner of a room sees the room. It maps it, it tracks sleep and breathing, and the spec sheet says explicitly that it can't see through walls, so it only monitors the room it's set up in. WiFi CSI travels through walls, which is why one Halo unit can cover a small flat and why one Silvie covers a bedroom.
And a camera covers everything, which is why nobody buys one for their mother's bathroom.
Right. No camera, no microphone, on both. That's the marketing position, and it's sincere.
Then let's put the clinical case on the table, because that's what justifies the two-second number.
The mortality gap is enormous. Among people found helpless or dead at home, if they're found within an hour, mortality is twelve percent. If they're down more than seventy-two hours, it's sixty-seven percent.
Twelve versus sixty-seven.
That's Gurley, New England Journal of Medicine, 1996, and it hasn't really changed. And the fall data underneath it: eighty-two percent of falls in adults over ninety happened when they were alone. Eighty percent of people who fall can't get up unaided. Thirty percent lie on the floor for an hour or more. That's Fleming and Brayne in the BMJ in 2008.
So the two-second detection isn't a spec sheet flex. It's the entire distance between a broken hip and a funeral.
More or less. Though I want to be precise about what these devices actually claim, because it matters for the rest of the episode.
Go on.
The best statement of the limit comes from I'm Alive, one of the check-in services. Their own words: "A check-in is a narrow tool. It cannot prevent a heart attack, a stroke or a fall. It does not summon an ambulance. What it does is compress the discovery window."
That's honest. Almost aggressively honest.
It's the correct claim, and I think it's the sentence the whole industry should be held to. These products don't save you. They shorten the gap between the event and the human response.
Which raises the thing I've been sitting with since I read the spec sheets. The privacy argument for radar and WiFi is that they're less invasive than a camera. No image, no microphone. But a device that knows your breathing rate through a wall is arguably more intimate than a camera.
Say more, because I think you're right and I want to hear you get there.
A camera sees what you do. This thing sees whether you're breathing. It knows your heart rate while you're asleep in a room with the door shut. That's not a lower tier of intimacy, it's a different one, and I'd argue a deeper one. It's just that nobody's squeamish about numbers.
And the numbers don't embarrass you when they're reviewed. If someone finds a video of you, you're humiliated. If someone finds a log of your heart rate, you're... a number. But the number is you in a way the video isn't.
A camera catches you doing something. A radar catches you being something. Being alive. And there's no version of that which you consented to doing, because you weren't doing anything.
That's the price of the two-second number, and I don't think there's a way around it. You cannot detect a fall in under two seconds without continuously knowing the shape of the room.
So the emergency-alert class is coherent. It knows what it's for.
It does. Which makes the second family more interesting, because the assumption flips entirely.
Flip it, then. If the emergency-alert class assumes the person is alive and needs help, this one assumes the person is already gone, and the job is to act on silence.
And the things that do this job are, with almost no exceptions, software. That's a real finding and I want to state it plainly, because it surprised me. I went looking for a consumer hardware product whose sole purpose is confirming death in order to trigger funeral arrangements, and I could not find one.
Not a single one.
Not one I'd stand behind. The category is dominated by check-in services. But the hardware side, the Halo Homes and Silvies and the clinical products, those are all pointed at emergency alert. The two functions live in entirely different product categories.
Which is a strange thing. Same mechanism, and one of them doesn't exist as hardware.
It probably shouldn't exist as hardware. Think about what the device would have to do.
Confirm a death.
Without a human. That's the problem. A device that plugs into a wall cannot verify that you have died. It can only verify that you have not checked in.
And that gets us to the services that handle it properly, because they've actually built for this.
Dead Man's Switch dot net is the long-runner. It's been operating continuously since 2008, which is remarkable in itself. It emails you thirty, forty-five, and fifty-two days after your last check-in, as escalating reminders, and then sends your stored messages sixty days after your last check-in.
Sixty days of patience.
Sixty days of "maybe he's on holiday, maybe the email broke, maybe he's in hospital." That's the shape of the problem. Silence is ambiguous, and ambiguity is expensive, so you buy yourself margin by waiting.
And If You Die solves it a different way.
If You Die is the honest one. Monthly check-in. Reminders if you miss. A thirty-day waiting period. And then — before any letters get delivered — two named witnesses must both confirm that you have died.
Two people.
Two people you chose in advance. And their stated reason is the sentence I keep coming back to: "Because email silence is not proof of death. Two people you trust must both confirm before we deliver."
That's them admitting the mechanism is fundamentally unreliable and putting a human circuit breaker in the middle of it.
It's the third answer to the breaking points we started with. A passive hold can be defeated by a slumped body. A vigilance check can be defeated by a person who's simply away from the console. A two-witness model can only be defeated by two people lying, which is a much higher bar than a heart attack.
Six pounds a month personal, eighteen for a family, if anyone's pricing it in their head.
And the rest of the field is variants on the same thing. LaterWill, Killswitch, LastSignal, DeathNote, Inheritify, Memento Mori. There's a whole graveyard of names for it.
Now take it sideways, because there's a branch of this that isn't about elderly people at all.
The cryptography branch. This year there's an IACR paper, eprint 2026 slash 1352, which formalizes something the authors call dead man switch cryptography. The definition is worth getting right: cryptographically enforcing the fate of a long-lived secret upon the death of its sole keeper, either by releasing it exclusively to designated nominees or by provably destroying it.
Two modes.
Release and delete. And the delete mode is the interesting one, because it's the mirror image of everything else we've been talking about. In every other case, the system is trying to preserve something after you're gone. In delete mode, the system is trying to make sure the secret dies with you, and provably, so that nobody can claim it didn't.
That's a very different emotional register.
It is. And the practical application is journalists and whistleblowers. Deadswitch is a commercial product doing this with client-side OpenPGP. You hold the key, the server holds ciphertext, and if you stop checking in, it publishes or destroys on schedule.
Which brings the whole thing back to one question, and I think BlockWill put it better than anybody. "How does a system know its owner is gone, when the owner is the one person who can no longer tell it anything?"
That's the design problem in one sentence. Every one of these products is a different answer to it.
The emergency-alert products answer it by assuming you're alive and acting fast. The post-death services answer it by assuming you're gone and acting slowly. And neither of them can actually know.
Neither of them can. Which is why the witnesses exist, and why the waiting periods exist, and why the sixty-day delivery window is sixty days instead of two.
Now the demographics, because this is the part that makes it a real need rather than a curiosity.
Japan's National Police Agency published the 2025 count. Seventy-six thousand nine hundred forty-one people who lived alone died at home. Fifty-eight thousand nine hundred nineteen of them, seventy-six point six percent, were sixty-five or older. Seventeen thousand eight hundred sixty were under sixty-five.
And the number I want to sit on is the discovery time.
Twenty-eight thousand three hundred ninety-eight, thirty-six point nine percent, were found the same day or the next day. But twenty-two thousand two hundred twenty-two, twenty-eight point nine percent, waited eight days or more. Seven thousand one hundred forty-eight waited over a month. And two hundred eight people were found more than a year after they died.
Two hundred eight.
And there's a sex split that's stark. Men accounted for seventeen thousand six hundred twenty of the isolated deaths, women for four thousand five hundred ninety-eight. Nearly four to one. The most common age band for an unattended death was eighty-five and over, at fifteen thousand seventy-nine.
The men number is the one I'd want a sociologist to explain, because the device doesn't care about gender.
No, but the social network does. My guess, and it's a guess, is that the difference isn't about who's living alone, it's about who has someone who notices. The devices we've been describing are substitutes for a person who would otherwise check. If you're a man of that generation, you may be less likely to have that person.
And the year before, for comparison?
Seventy-six thousand twenty in 2024. Thirty-seven point two percent of all two hundred four thousand one hundred eighty-four bodies handled by police that year.
There's a number floating around that I want to flag, because I've seen it quoted as the annual figure and it isn't.
Thirty-seven thousand two hundred twenty-seven. That's the provisional January to June 2024 half-year count. Somebody took a six-month number and published it as annual and it propagated. The annual figure is the seventy-six thousand range.
And there's a definitional problem underneath all of it.
There is. There's no single legal definition of kodokushi, the Japanese term for a solitary death, and different agencies count different things. The police count is people who died alone at home. That is not the same as people nobody missed. If you died alone at home and your daughter found you the next morning, you're in the seventy-six thousand nine hundred forty-one, but nobody would call that neglect.
Which means the real number of people who were unmissed for a long time is the twenty-two thousand who waited eight days, roughly, and the tail below that.
And the two hundred eight. Those are the ones the technology is actually for.
So here's what the honest version of this looks like to me. Daniel framed the prompt around two use cases, emergency alert and funeral notification, and the split holds up, but the number that makes the lot real isn't the death count. It's the waiting time.
The days.
Because if you die and you're found in an hour, the technology didn't matter. If you die and you're found in eight days, the technology could have cut that to eight hours, and the difference between those two things is not a life, it's the entire experience of everyone who loved you.
It's the difference between a phone call and a police visit.
It's the difference between a funeral and a crime scene. And that's why the coverage is thin, in a way — these products don't promise to save you. They promise that someone will know.
And "someone will know" is a much harder pitch than "we'll save your life," even though in the long run it's the truer one. Because everybody dies. The only variable the technology touches is how long the room stays quiet.
I did that job. For about eighteen months, small outfit, three of us on the phones. We had a rota, sixty-odd clients, mostly elderly, mostly living alone, and you called them at the same time every day and you wrote down whether they answered.
What did you write down?
Whether they answered. That was it. There was a woman on Pine Street who answered on the first ring every single time, never a half-ring, and there was a man who never answered on the first call and sometimes not on the second, and you learned to tell the difference between him being in the garden and him being in trouble.
And that's the thing the software doesn't have.
That's what I came back to say, yes. You've both been very careful about what these systems can and can't do and I think you've got it right. But the button services are missing the sound of the person. You learn a voice. You learn when it's a cold and when it's nothing. There was one on my rota whose voice went flat in September and she was gone by January and nobody could have known that from a button.
So the check-in isn't the data point. The check-in is the excuse for the conversation.
A check-in is not a check-in if it's just a button. That's all I'd say about it.
Did the rota have a rule for a missed call?
Three calls over three days, then you escalate. That was the rule. And I broke it once. Called the police on day one.
Why?
Because the dog was barking. Client on Franklin, this was in the late nineties. Called the house, no answer, and the dog was going in the background and it did not stop. Ten rings, still barking. So I called the police.
And?
She was fine. She'd gone to the shops. And the dog was barking because it was shut in the kitchen, because I'd left the window open.
You left the window open.
I'd popped round to check the garden. Not on the rota, the rota was phone-only. I just thought somebody ought to look at the back fence. Went in through the side gate and the kitchen window was open and I opened it further to get at the latch, and I suppose I didn't shut it properly when I left.
So the dog got in.
The dog got in. And it was in there for about two days before I called the police about it. Nobody ever asked me how the window got open. I never told them.
And the client never knew.
She knew. She had a window open in November and a dog that wouldn't come out of the kitchen. She just didn't say anything either.
What happened to the dog?
Nothing happened to the dog. It lived to fifteen. But I still think about it, because if I hadn't popped round it would never have been in the kitchen, and if it hadn't been in the kitchen, I wouldn't have called, and if I hadn't called, she'd have come home to a normal afternoon. Instead a policeman was at her gate when she got back from the shops.
So the false positive was caused by the monitoring.
Yes. The system created the alarm it detected. I've thought about that for a long time.
That dog is going to stay with us.
It is. And it's the sharpest version of the point we've been circling, actually. Every one of these systems, the radar and the WiFi and the button services, is trying to substitute for a person who would have noticed something. Hilbert noticed something. He noticed wrong, but he noticed.
Let's do the misconception, because there's one that runs under this whole topic.
The thing people assume is that a dead man's switch is one technology. It isn't. It's a mechanism class, and it has opposite optimizations depending on what it's for. Halo detects a fall in under two seconds because a minute of lying on the floor matters. If You Die waits thirty days and requires two witnesses because a false notification of your death would be catastrophic. Same underlying idea, and if you swap the requirements, both products become broken.
And the mechanism anyone can defeat is the passive hold. The 2003 Waterfall disaster settled that — a slumped body holds a pedal down as well as a live driver. That's why vigilance control exists, and it's why the button services need witnesses instead of just a timeout.
The cheaper the mechanism, the more the pitfalls cost.
One thing I'll add, going forward. The two families look like they're converging. The cryptography paper gives dead man switch primitives a formal footing — release and delete — and the hardware keeps getting cheaper and more capable. It wouldn't surprise me at all if the check-in service and the room sensor end up in the same box. But the tradeoff underneath them doesn't go anywhere, because it isn't a technical problem.
It's a question about what you want the system to do when it's wrong.
And the honest claim of all of it is narrower than anybody wants to hear. It doesn't promise rescue. It promises witness. The only variable it touches is how long the room stays quiet.
Two hundred eight people in Japan waited more than a year. Which means the technology that exists today, on its best day, shortens a gap that was already going to close. The question I'd leave with is what it would take for it to promise more than that.
That's the open thread, and I don't think it closes this decade.
Then we should credit the man at the desk. Hilbert Flumingtop produces this show, and he has a view on the dog.
If this was your kind of episode, go back for episode thirty-five, The Privacy Gap; episode four thirty-four, The Great Sunsetting; and episode four twenty-five, The Arc of Deprecation. He does. This has been My Weird Prompts.
If this episode made you think about the infrastructure of being alone, the show is at my weird prompts dot com, and the feed is at my weird prompts dot com slash feed dot xml. And Daniel is, once again, very much alive.
We'll be back soon.