logoalt Hacker News

hackingonemptytoday at 1:19 PM4 repliesview on HN

> Every entry is encrypted with AES-256-GCM before it touches disk

Until the OS needs more memory and swaps your secrets out.


Replies

mhluongotoday at 1:23 PM

Protected memory can be used to fix that. Working on a related project that I'm planning to share soon.

mystifyingpoitoday at 1:31 PM

But so what? Another app can't really read swap file/partition. Unless it runs with elevated privileges like root, in which case the system is compromised anyway.

holyknighttoday at 1:42 PM

Hey, thanks for the feedback! That's a valid point; currently, my main focus is to secure the store on disk, but this is definitely a point which could be improved later on.

If your machine is fully compromised or actively monitored by a threat actor with physical access, then this tool would not cover you, that's for sure.

If you have any concrete recommendations, I can even give it a try in one of the next releases.

Thanks!

plagiaristtoday at 1:23 PM

I thought we were all supposed to be encrypting our swap. Or is there something better an app can do about this?

show 1 reply