5 ms·
Show HN: Laptop is the last place your secrets are still in plaintext
- notthetup 2mo agoJust a note, it’s on a Polyform Perimeter license.
- bukershok 2mo agoYes, but it's completely free for internal Personal and Company use.
- vintagedave 2mo agoInteresting idea! How do you achieve it? Some kind of file system driver that recognises the calling process?
- zahrevsky 2mo agoIf only there was a Markdown file in the repo, that explains it. It could have a URL, say, https://github.com/jitpass/jit/blob/main/docs%2Fgetting-started%2Fdelivering-secrets.md#how-a-migrated-env-stays-compatible-with-your-scripts https://github.com/jitpass/jit/blob/main/docs%2Fgetting-star...
- vintagedave 2mo agoPlease avoid the snark. I read the readme in full, I think that's an appropriate level of effort. Your link also still doesn't answer it, though it hints: 'A migrated .env is a live mount (a named pipe), not a plain file'. So is that a file system driver, or...? Even https://github.com/jitpass/jit/blob/main/docs/getting-started/how-it-works.md https://github.com/jitpass/jit/blob/main/docs/getting-starte... says it's a local encrypted store - and that's repeated many times across the docs Claude-style - but it doesn't explain the mechanism whereby reading a file gets the results from that store.
- bukershok 2mo ago[flagged]
- Animats 2mo agoThe install procedure, for something that's supposed to be a security product: curl -sL https://dl.jitpass.com/jitpass/jit/releases/latest/download/jitpass_darwin_arm64.tar.gz | tar -xz jit sudo mv jit /usr/local/bin/ What could possibly go wrong?
- thecopy 2mo agoWhat is wrong with it?
- 9dev 2mo agoThe pattern of piping an arbitrary script to your shell? This should be an ordinary app bundle to drop into /Applications, or be distributed as an installer. The readme even says so itself: > A bad curl | sh, a sketchy npm install, or one of the AI agents now running in your editor with your full permissions. And then, two paragraphs down, it suggests to do just that to install…
- hackernudes 2mo agoTechnically this one is piping it to tar? But I agree with the sentiment.
- kokx 2mo agoIt's not piped to a shell, but to the tar program with specific parameters to directly unpack the tar. You're still installing the program directly from github of course, instead of a source where hopefully a third party has also looked at it (like a package repository). But this is a lot better than the curl | sh pattern.
- tgv 2mo agoYou're not downloading from github, but from dl.jitpass.com. And an executable can do exactly the same as a shell script. The point is that whatever you're executing isn't verified, whether it's a shell script or a binary.
- efitz 2mo agoI am actually building the exact same thing- encrypted vaults for files or folders, encrypted with a biometric gated key in the Secure Enclave!
- deleted 2mo ago[deleted]
- necovek 2mo agoWhile this might be a useful tool for Mac users, it's all hackers here, so: * Most people do not have passwords in plain text — an SSH key protected with a passphrase is not "plain text", for instance * Most people have encrypted home or full disk encryption * How can we trust your crypto implementation? * If we are talking about in-memory plain-text during use, how does this tool protect against it? * Containerisation is a big topic when running untrusted software for exactly (but not just) this reason * While passwords/tokens might carry a big risk depending on what you do, I find that I worry more about my local data compared to my remote data — and virtualisation or containerisation helps with that.
- idoubtit 2mo ago* Dealing with encrypted files is easy, and more versatile than a generic wrapper. E.g. to load a secret environment: `eval $(age -d -i secrets.env.age)`. With the added bonus that it only relies on a trusted tool, age.
- Faaak 2mo ago> Most people have encrypted home or full disk encryption I don't see the point. Once your home is unlocked, every process can see the file contents
- bukershok 2mo ago[dead]
- necovek 2mo agoI guess you missed my "containerisation" point: if not restricted, every rogue package or agent has access to your full $HOME too. A secret is there to protect access to data you care about. If that data is there, well, not much achieved. Eg. imagine there's the source code for a service you deploy to AWS — rogue sw can modify it letting you unknowingly update it the next time (or why do you have those AWS keys anyway?). But not if they are part of non-classic Snap on Ubuntu or properly containerised Flatpak (on Linux, at least), or in a VM or LXC/Docker/Podman container.
- flaburgan 2mo agoI would have been interested if it was for Linux
- bukershok 2mo agoSoon, it will, yes.
- zahrevsky 2mo agoI don't know about how secure this is, but I just love the UX. Scanning and process grant are great features UX-wise.
- hypfer 2mo agoThe medicine did not actually cure my terminal illness, but it surely tasted great and made me feel good about myself.
- zahrevsky 2mo agoI don't agree with the analogy. Better UX affects users behaviour and can make a safe path easier for the user than the unsafe one, reducing total number of incidents.
- xixixao 2mo agoYou can do some of this with 1Password as well btw. Looks nice!
- bukershok 2mo agoThanks!
- hn_submit 2mo agoOperating systems should work like Android currently does. Assuming all installed apps are potentially malicious and isolates each of them from the others and the OS. So even if an app is compromised there's not much it can do when it's installed. All desktop and server operating systems currently assume the user should have "full control" making a single compromise fatal for the user or even an entire organization.
- hypfer 2mo agoSnake oil claude slop. No other words for it. If someone or something is executing code on your machine, you have already lost. Making it _slightly harder_ for it to eventually get your passwords anyway is mostly a performative action. __ Btw, enable "showdead" and enjoy OP actually pasting LLM output verbatim as a "defense". - https://news.ycombinator.com/item?id=49317802 https://news.ycombinator.com/item?id=49317802 - https://news.ycombinator.com/item?id=49317819 https://news.ycombinator.com/item?id=49317819 Maybe claude can reword your claude slop for you. You can still edit those posts I guess. __ bukershok 2 minutes ago [dead] | parent | context | flag | vouch | favorite | on: Show HN: Laptop is the last place your secrets are... Worth separating two things here. That's curl | tar, not curl | sh, as a few people noted. But the real answer is: don't use it. The recommended install is brew install jitpass/tap/jitpass. Releases are Developer ID signed and notarized by Apple. Homebrew quarantines its download and Gatekeeper checks it against the notarization ticket before it runs. jit doctor reports the Team ID it verified, so you can check rather than take my word for it. jit upgrade refuses to install anything whose signature and checksum don't both verify, with no override flag. The tarball line is there for people without Homebrew, and it is the weaker path precisely because curl sets no quarantine bit, so Gatekeeper never consults the ticket. Point taken: leading with it in the README undercuts the argument on the same page. I'll flip the order. __ Sorry if this violates the "no dunking" rule or whatever, but this cancer needs to be eradicated.
- bukershok 2mo ago[flagged]
- bukershok 2mo agoHypfer, I am a security leader at the age of 42 with more than 15 years of experience in the field, and I will tell you the truth: I lead a lot of cyber incidents. The purpose of this tool is to help you and companies protect yourselves from supply chain attacks and infiltrators for free no cost, no need for expensive 1Password tools. I put my heart into this tool, so give it a try and contact me directly if you need anything. I will be glad to get your feedback on the tool. No AI fluff :) linkedin - https://www.linkedin.com/in/menitasa/ https://www.linkedin.com/in/menitasa/
- adamddev1 2mo agoThis looks like a really cool idea. But since it's a new project and has all the Claude stuff I immediately feel unsure about the solidity and reliability of a security-critical piece for software like that. I wish I could go back to my pre-LLM levels of skepticism.
- bukershok 2mo ago[flagged]
- halJordan 2mo agoA lot of this concern is ersatz and virtue signaling. Do you really think an llm cant code a fork/exec? Or that it can't setup a named pipe? And what would be the other concerns? That you have a possibly malicious piece of software reading your secrets that you haven't encrypted? That's literally the raison d'etre of this tool. By definition it's better than nothing.
- ryuuseijin 2mo agoFor development on linux I like to use dotenvx, which lets you put encrypted secrets in an .env file and supply the private key separately. I have a small wrapper script [1] that prompts for the private key which allows me to paste it from my password manager and launches a shell with the env variables decrypted. This allows me to avoid storing any secrets while still having shell session open where I can terminate and restart a server process for example without having to re-enter the secret all the time. [1] https://gist.github.com/ryuuseijin/0cf6ab852fbb18d6702933a24388e014 https://gist.github.com/ryuuseijin/0cf6ab852fbb18d6702933a24...
- LeBit 2mo agoFnox and Nono are the ones I know that do credentials proxying. That approach seems quite better than scanning a host file system for secrets.
- chanux 2mo agoI was trying out fnox recently. It won't allow me to enter the master password for keepassdb. I have to set FNOX_KEEPASS_PASSWORD. A bit uncomfortable in leaving a secret in the history. Hence I was looking for a tool like this.
- nf-x 2mo agoi wonder when Claude/Codex would start baking it as first-party features
- _august 2mo agoI've moved my secrets to 1Password Environments (https://www.1password.dev/environments https://www.1password.dev/environments), which works really well for everyday use. It works with 1password cli (https://www.1password.dev/cli https://www.1password.dev/cli) to access for agents/scripts, and I get a nice UI to manage them in the 1password app.
- nf-x 2mo agoBut the IPC is process-wide, not vault-dependent. And requires touch approval on every access, without “trust this process for X minutes” possibility. Other 1pass is a great UX. It was even greater before Electron refactor and non-subscription model.
- oulipo 2mo agoI do the same indeed
- theozero 2mo agoTry adding varlock on top. It fixes some of the rough edges of using 1pass for dev purposes. Lots of neat features. We are 1pass users ourselves so our 1P plugin is quite good.
- nf-x 2mo agoHow funny it may sound, but I was recently researching around for these kinds of tools for the same exact purposes. Where I got stuck was at the Secure Enclave storing biometric-crypted payloads in the keychain, but couldn’t get it to work without Apple Developer subscription for code signing, otherwise these features wouldn’t work. And nobody with an Apple Developer subscription wants to sign someone else’s code, obviously. I really wonder why Apple itself, or any other reputable company, didn’t publish an utility like this already - it’s also a trust issue, when you run code like this. The issue is that /usr/sbin/security invocations can be obscured to read from keychain, but require password typing every time, which is annoying. And lazy people can just hit “trust” by mistake. And then it’s just another clear text, but more annoying to reach. Even though, it may be possible to show a touchID prompt in two other scenarios: - encrypting payload with a key stored in the enclave - then it becomes closer to SOPS approach. Age plugin for sops also supports using private keys on yubikey, by the way. But SOPS UX feels clunky. - just calling the APIs to show touchID as part of the application logic, like all modern password managers do. But then you really have to trust the password manager or the tool that does it, because touchID doesn’t equal security in this case. Some password managers support CLI, SDK, and Terraform providers for working with their secrets, but that requires an IPC enabled, potentially increasing the risk for the other secrets stored in the same password manager. Oh well, tough choices everywhere.
- chanux 2mo ago> potentially increasing the risk for the other secrets stored in the same password manager. As pointed to me by a friend, this is one reason not to give in to the convenience of the secrets manager you already use. My use case for fnox with keepassdb back-end was partially validated but as I mentioned elsewhere in the thread, having to set master password in an env var is a bit of snag for the workflow.
- nf-x 2mo agokeepass is great, because it doesn't require any service to operate - it's just a file. technically, you are responsible for backing it up, but more centralized options possible. I used it for 4 years pre-touchID era in a corporate setting and it worked great. For a single device. UX was very "open source", but hey - it's a free software with other focus in mind. i know other people partitioning their secrets into multiple keepassx vault files, so the argument about using the same password manager can be interpreted differently.
- bukershok 2mo ago[flagged]
- ekianjo 2mo agoon Linux use systemd-credentials. It already does that
- porridgeraisin 2mo agoYes, you can even have it tpm-backed. echo -n "sk-proj-12345..." | systemd-creds encrypt --with-key=tpm2 --name=openai_key - openai.cred And then at runtime export OPENAI_API_KEY=$(sudo systemd-creds decrypt openai.cred)
- deleted 2mo ago[deleted]
- bukershok 2mo agoSoon it will also be for Linux
- nf-x 2mo agothere are so many great tools in the baseline core infrastructure. and there's so much NIH syndrome still. appreciation and OS aside, systemd-creds relays long-lived creds into long-lived processes, and author's AI slop attempts at short-lived/on-demand injections. Apparently, author's AI slop gets a lot of iterations, but has not much of external scrutiny yet.
- chanux 2mo agoAvailable since 2021 (systemd v250) and I just got to know. Better late than never I guess. PS: Thank you!
- tiku 2mo agoI don't get why you would have PRODUCTION secrets in those local .env files. It should only be dev tokens.
- bukershok 2mo agoI can't agree more.
- hnlmorg 2mo agoThis isn't just for local .env files. It can be quite common to need production tokens for cloud systems if you job requires any amount of ops. eg doing anything aws cli work may result in a token stored in ~/.aws But even that aside, there's still merit in protecting rogue processes from trashing your non-production environments
- jan_tilde_zone 2mo agoGreat Implementation. I was always looking for a way to further lock down credentials on Mac machines in our org. This could be a great additional layer of defense against supply chain attacks. Especially the 8 hours valid aws SSO access token felt super risky to have available in plain text. Would those those temporary credentials work as well?
- nf-x 2mo agoto begin with, why not setting validity for 1hr? you don't need to onboard an untrusted tool then.
- simpleintheory 2mo agoDupe of https://news.ycombinator.com/item?id=49156231 https://news.ycombinator.com/item?id=49156231
- theozero 2mo agoVarlock solves many of these problems, and a lot more. Including having a built in credential broker - and works everywhere. Missing some easier DX around things that are typically detected from global files, but working on it.
- mzajc 2mo agoMost of your comments on this site, including both of your comments on this thread, are differently-worded promotions of this one product. Please don't use the forum exclusively to advertise.