9 ms·
Show HN: macOS data protection keychain for Electron apps
Hey HN,
I've been working on Hansel [1] (an encrypted personal data store you can query with agents), and there wasn't a good way to use the modern macOS Data Protection Keychain.
Electron's safeStorage [2] uses the legacy file-based keychain, which allows other apps/agents to query it with the `security` CLI. Not great when you have a dozen agents running in the background! The Data Protection Keychain is nice because it limits access via code-signing access groups and lets you set access rules like Touch ID and/or password.
1: https://hansel.so/ https://hansel.so/
2. https://www.electronjs.org/docs/latest/api/safe-storage https://www.electronjs.org/docs/latest/api/safe-storage
- deleted 1mo ago[deleted]
- useiris 1mo ago[flagged]
- anishvarghese 1mo ago[dead]
- hankbond 1mo agoUseful but kind of defeats electron's primary purpose of being cross platform.
- biwills 1mo agotrue and I'd love to be able to expand support out for the equivalent versions in linux / windows. For now, you can always fall back to using safeStorage on non macOS platforms!
- clem_rw 1mo agoThe security CLI being able to read safeStorage entries is a real problem with agents running everywhere. Code-signing access groups are a much better boundary.