Disappearing is for your outgoing messages only. Just don't send the Gift wrap to yourself and you won't be able to recover your messages.
Discussion
Thanks.
This scheme does NOT have forwarded Secrecy of the receiver, right?
I guess there is forward Secrecy for the sender due to the ephemeral key of the gift wrap. But the receiver has only a single long term static key.
And as soon as your backup scheme is used, there is no forward secrecy anymore anyhow.
Is that true? I was hoping the link between the keys remained offline. The secrecy would only break if the attacker got the main key and the backup key.
Ah, so the main key does a gift wrap to send the backup to a new pubkey, thats why the relationship between these two keys is private?
And thus even if the main key leaks, the backup keys are not known.
And if you need to access the backups just giftwrap them with yet another key so that they backup key never leaves the backup client.
Yep, the main key doesn't have any gift wrap to recover from.