2 ms·
Anyone who uses this risks being locked out forever because the "key" will be destroyed if they upgrade their computer or suffer hardware failures.
by nosuchthing 9mo ago
Anyone who uses this risks being locked out forever because the "key" will be destroyed if they upgrade their computer or suffer hardware failures.
- ZeroConcerns 9mo agoNot really -- any secrets stored using this method should also live in a password manager somewhere. It's about providing more-secure programmatic access to secrets. Basically, it rebuilds Windows DPAPI from first principles, which is fine (I've done it many times myself!), and something non-Windows platforms sorely need. It changes the impact of malware from "they dumped all our secrets from prod to their C2" to "they got some encrypted values, and now someone will need to figure out our methodology and underlying keys", which is a meaningfully higher bar.