Hacker News new | ask | show | jobs
by justincormack 15 days ago
Use Secretive so your ssh keys are stored in the secure enclave. Keeping private keys in files is the 1990s security…
1 comments

Genuine question: if the LLM possesses the ability to use Secretive to retrieve secrets are you not back to square 1? I'm not familiar with Secretive but if it's just another way to store secrets that's not enough. For proper security the LLM needs a black box intermediary to do anything privileged. I don't know what that looks like in terms of software.

Or better yet it needs dead-end privileges with a system and data that doesn't matter.

They keys are stored in the secure enclave. You can't get them out. You can only let the secure enclave make calculations with it. And it needs your fingerprint to unlock.

Akamai akr should be able to do something similar, but would store the private key on your phone. It's the successor of krypton, which was bought by Akamai, and I liked that even more as you really need a second device.