points by n0n 4 days ago | hide | 0 comments
Genuine question: what's your thread model?

Vault gives time limited Tokens with Network Boundary. Instead of Keeper, i would just use age:

# write

echo "my secret" | age -r <recipient-pubkey> > secret.age

# read

age -d -i key.txt secret.age

sneak4 days ago | | | parent | | on: 47716354
https://git.eeqj.de/sneak/secret

This is an age+filesystem secrets manager that I made that is basically what you wrote, but with more organization.

babawere4 days ago | | | parent | | on: 47716354
not when you need an audit system
n0n4 days ago | | | parent | | on: 47716802
True, but AFAIK an audit system is worthless if it resides on the same potentially compromised machine, no?