> Every entry is encrypted with AES-256-GCM before it touches disk
Until the OS needs more memory and swaps your secrets out.
But so what? Another app can't really read swap file/partition. Unless it runs with elevated privileges like root, in which case the system is compromised anyway.
Hey, thanks for the feedback! That's a valid point; currently, my main focus is to secure the store on disk, but this is definitely a point which could be improved later on.
If your machine is fully compromised or actively monitored by a threat actor with physical access, then this tool would not cover you, that's for sure.
If you have any concrete recommendations, I can even give it a try in one of the next releases.
Thanks!
I thought we were all supposed to be encrypting our swap. Or is there something better an app can do about this?
Protected memory can be used to fix that. Working on a related project that I'm planning to share soon.