frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Best practice securing secrets on local machines working with agents?

6•xinbenlv•8h ago
When building with autonomous / semi-autonomous agents, they often need broad local access: env vars, files, CLIs, browsers, API keys, etc. This makes the usual assumption — “the local machine is safe and untampered” — feel shaky.

We already use password managers, OAuth, scoped keys, and sandboxing, but agents introduce new risks: prompt injection, tool misuse, unexpected action chains, and secrets leaking via logs or model context. Giving agents enough permission to be useful seems at odds with least-privilege.

I haven’t seen much discussion on this. How are people thinking about secret management and trust boundaries on dev machines in the agent era? What patterns actually work in practice?

Comments

deflator•56m ago
I've been having success using Doppler for secret storage. Takes it off the filesystem.
xinbenlv•19m ago
My question is not about on or off storage, is more about when you give agent access, it assume the environment agent runs is safe
algebra-pretext•53m ago
I’m not too familiar with the space, but a friend of mine works at Descope[0] where they offer IAM solutions for agents.

[0] https://www.descope.com/

xinbenlv•20m ago
is the permission device+client based or role based?
nojs•48m ago
Run the agent in a sandbox without access to production secrets.
xinbenlv•19m ago
What if you simply need to give them access. E.g if you want them to do code review you have to at least give them code repo read access. But you don't know if the environment where agent runs will be compromised
CriptoSeguro25•28m ago
TBH, the best pattern I've seen is just nuking the secrets at the input level. Run a local regex watcher in-memory that flags anything looking like a PK or seed phrase before it even hits the agent's context window. Keeps it off the network stack entirely
xinbenlv•21m ago
Any prompt injection attack could by pass this by simply do a base64 or any encoding, I guess?

Ask HN: Is Claude Down for You?

21•philip1209•47m ago•17 comments

Ask HN: Best practice securing secrets on local machines working with agents?

6•xinbenlv•8h ago•8 comments

Ask HN: What's the best virtual Linux desktop experience on macOS for devs?

2•darkteflon•26m ago•1 comments

Ask HN: Claude Down?

3•emschwartz•41m ago•2 comments

Ask HN: Modern test automation software (Python/Go/TS)?

7•rajkumar14•2h ago•2 comments

Ask HN: What is your opinion on non-mainstream mobile OS options (e.g. /e/OS)?

5•sendes•5h ago•3 comments

Ask HN: Any good ressources facility location planning using GIS?

2•skalilopa•1h ago•0 comments

Ask HN: How do you verify cron jobs did what they were supposed to?

5•BlackPearl02•12h ago•3 comments

Ask HN: Industrial smart glasses with online / offline capabilities?

3•aureliusm•9h ago•0 comments

Ask HN: Anyone doing production image editing with image models? How?

3•geooff_•6h ago•0 comments

Ask HN: Is there any good open source model with reliable agentic capabilities?

4•baalimago•17h ago•0 comments

Tell HN: Drowning in information but still missing everything

5•akhil08agrawal•12h ago•5 comments

Ask HN: Unusual Network Filter

3•gman21•9h ago•0 comments

Ask HN: How do you authorize AI agent actions in production?

3•naolbeyene•8h ago•3 comments

Ask HN: Do you have any evidence that agentic coding works?

433•terabytest•2d ago•437 comments

Tell HN: 2 years building a kids audio app as a solo dev – lessons learned

132•oliverjanssen•1d ago•74 comments

Ask HN: Why are so many rolling out their own AI/LLM agent sandboxing solution?

27•ATechGuy•1d ago•11 comments

Ask HN: Thoughts on monitoring multi-chain staking and alerts with KoinyxBot

2•eeezl0dey•4h ago•0 comments

Ask HN: I'm sure more than just Microsoft is down rn

8•koconder•2h ago•4 comments

Ask HN: GitHub "files changed" tab change?

2•nonethewiser•6h ago•0 comments

Ask HN: COBOL devs, how are AI coding affecting your work?

168•zkid18•3d ago•183 comments

Ask HN: Does "Zapier for payment automation" exist?

8•PL_Venard•1d ago•12 comments

Ask HN: Revive a mostly dead Discord server

19•movedx•2d ago•28 comments

Tell HN: Claude session limits getting small

23•pragmaticalien8•1d ago•14 comments

Ask HN: Why does Google Maps still use mercator projection?

5•hbarka•16h ago•3 comments

Ask HN: Is GitHub Down?

11•AznHisoka•8h ago•5 comments

Tell HN: Avoid Cerebras if you are a founder

34•remusomega•1d ago•14 comments

Ask HN: How locked down are your work machines?

18•donatj•1d ago•22 comments

Ask HN: Do you have side income as a software engineer?

10•andrewstetsenko•6h ago•3 comments

Ask HN: Which common map projections make Greenland look smaller?

18•jimnotgym•2d ago•17 comments