frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: How do you store private keys?

5•max_•7h ago
It seems there is no standard proper way to store private keys.

I have been using AGE [0]

And I really don't like the idea of having the keys stored in the home directory in plain text.

There is also a risk of losing the keys if my laptop is damaged or gets stolen.

Is there a proper tool for storing encryption keys?

Comments

dale_huevo•7h ago
> And I really don't liek the idea of having the keys stored in the home directory in plain text.

so encrypt them.

or store them in a hardware token.

or on a USB stick (poor man's hardware token).

> There is also a risk of losing the keys if my laptop is damaged or gets stolen.

backups, full disk encryption.

max_•7h ago
Hi,

Thanks for this reply. Could you recommend any good "hardware tokens"?

dale_huevo•7h ago
Nitrokey
stop50•7h ago
Smartcards + an printed backup in another location.
oulipo•7h ago
if you're referring to SSH keys, you can use something like 1Password which stores them encrypted and syncs them in the cloud, so you keep them even if you lose your laptop
mos_6502•7h ago
> It seems there is no standard proper way to store private keys.

The gold standard for this would be a Hardware Security Module (HSM), which is essentially a device that stores private keys with certain guarantees of physical security (e.g, that private key material cannot be extracted from the device once it has been generated or placed there, and the device performs operations using the key material on behalf of some client).

HSMs in various forms underpin all sorts of cryptosystems that society depends on, because securing private key material at rest is essential. You'll find them everywhere from your debit/credit card, to certificate authorities, financial institutions, defense, and your smartphone.

For your use case, I'd recommend taking a look at Yubikeys. I did a writeup a while back on how to use them to store different types of private keys for various purposes:

https://blog.ctis.me/2022/12/yubikey-piv-gpg/

znpy•6h ago
AFAIK you should also be able to store them on the TPM (trusted platform module) on your pc.
throwup238•6h ago
1Password with their SSH agent [1] for SSH keys, their CLI [2] for local secrets, and their terraform provider with service tokens for infrastructure keys/secrets. Yubikey for the secrets I’m most paranoid about.

You can essentially encrypt all environment variables, not just SSH keys, by aliasing your terminal commands to the 1password CLI. I have a “secrets” repo where all dotenv files are checked in with values like “op://vault-name/secret-name/key-name” that get injected by the op cli.

[1] https://developer.1password.com/docs/ssh/agent/

[2] https://developer.1password.com/docs/cli/get-started/

toomuchtodo•5h ago
https://openbao.org/
atmosx•3h ago
Paper. There’s a project called paperkey that allows you to store GPG keys on A4 paper. You could apply a similar approach to your age encrypted private keys or store them in plain text.

Modern smartphones have excellent OCR (optical character recognition) capabilities, so converting images of printed text back into digital form is now quite easy and reliable.

Personally, I use 1Password, and even they recommend printing out a PDF copy of your passwords and storing it in a secure location - like a physical vault. It’s a practical backup in case something happens and someone needs access to your credentials.

CPSC: Stop Using Chinese-Made Faucets from Amazon Due to Dangerous Lead Exposure

https://www.cpsc.gov/Warnings/2025/CPSC-Warns-Consumers-to-Immediately-Stop-Using-Certain-Chinese-Made-Faucets-Sold-on-Amazon-com-Due-to-Dangerous-Lead-Exposure-for-Infants-Young-Children-and-Pregnant-Women
1•josephcsible•11m ago•0 comments

Ask HN: Do startup founders/teams care about health during stressful times?

1•Bkimmy16•12m ago•0 comments

Divorce Is a Gift

https://www.nytimes.com/2025/05/16/style/modern-love-divorce-is-a-gift.html
1•littlexsparkee•12m ago•1 comments

WebGL Gray-Scott Explorer (2012)

http://www.mrob.com/pub/comp/xmorphia/ogl/index.html
4•joebig•15m ago•0 comments

Raspberry Pi Reduces Prices on 4GB and 8GB Compute Module 4

https://linuxgizmos.com/raspberry-pi-reduces-prices-on-4gb-and-8gb-compute-module-4/
1•teleforce•22m ago•0 comments

The Rift over Trump's A.I. Deals in the Gulf

https://www.nytimes.com/2025/05/16/business/dealbook/trump-nvidia-ai-middle-east.html
2•1659447091•22m ago•0 comments

Three-Dimensional Printing Resin-Based Dental Provisional Crowns and Bridges

https://www.mdpi.com/1996-1944/18/10/2202
1•PaulHoule•27m ago•0 comments

TabPFN: Foundation Model for Tabular Data

https://github.com/PriorLabs/TabPFN
1•talles•27m ago•0 comments

Coming to a Brain Near You: A Tiny Computer

https://www.wsj.com/tech/brain-implant-musk-als-tbi-neuralink-f733998f
1•Bostonian•29m ago•1 comments

PIGO8 – A PICO-8 Inspired Fantasy Console Framework in Go

https://github.com/drpaneas/pigo8
1•drpaneas•29m ago•0 comments

Trump’s Push to Defund Harvard Prompts Clash Over Veteran Suicide Research

https://www.nytimes.com/2025/05/16/us/politics/trump-harvard-veterans-research.html
3•standardUser•30m ago•0 comments

Mnemonic Finder – Extension to find mnemonic meanings by right-clicking words

https://chromewebstore.google.com/detail/mnemonic-finder-–-right-c/dlfjdmnhefchjkndgpfjobabibdomifh
1•harivpanjwani•35m ago•1 comments

Show HN: VibePM, a Lightweight Task Manager for Cursor

https://getvibepm.com
1•baetylus•35m ago•1 comments

Grml 2025.05 – codename Nudlaug – Release Notes

https://grml.org/changelogs/README-grml-2025.05/
1•pabs3•36m ago•0 comments

OSSF Best Practices

https://github.com/ossf/wg-best-practices-os-developers
2•Brysonbw•39m ago•0 comments

I made a floor out of popsicle sticks

https://buttondown.com/redmonk/archive/redmonk-may-2025-update/
1•mooreds•39m ago•0 comments

Microsoft provided AI to Israeli military but denies use to harm people in Gaza

https://apnews.com/article/microsoft-israel-military-gaza-hamas-artificial-intelligence-20b2adb438b39ee9cb6eb2f52c1ae44a
2•c420•41m ago•0 comments

Regular Expression Denial of Service – ReDoS

https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
2•Brysonbw•42m ago•0 comments

New stem cell model sheds light on human amniotic sac development

https://www.crick.ac.uk/news/2025-05-15_new-stem-cell-model-sheds-light-on-human-amniotic-sac-development
1•gmays•42m ago•0 comments

The Arm Evolution: From IP to Platform for the AI Era

https://newsroom.arm.com/news/new-arm-product-naming-architecture
1•layer8•47m ago•0 comments

A rare snail is filmed laying an egg from its neck

https://apnews.com/article/zealand-snail-egg-neck-powelliphanta-augusta-3cb8082547a83b8c47848b6621c06cb0
4•gmays•52m ago•0 comments

Google Worried It Couldn't Control How Israel Uses Project Nimbus, Files Reveal

https://theintercept.com/2025/05/12/google-nimbus-israel-military-ai-human-rights/
4•zhengiszen•52m ago•0 comments

When was peak message in a bottle?

https://interconnected.org/home/2025/05/16/bottle
1•LorenDB•1h ago•1 comments

Soviet Refugee Igor Tulchinsky Became a Hedge Fund Billionaire

https://www.forbes.com/sites/johnhyatt/2025/05/16/this-billionaire-quant-is-turbocharging-his-trading-models-with-chatgpt-style-ai/
2•walterbell•1h ago•0 comments

Is there anything similar to xcancel or nitter but for Bluesky?

3•ranoutofnames•1h ago•1 comments

It's Not Just a Feeling: Data Shows Boys and Young Men Are Falling Behind

https://www.nytimes.com/2025/05/13/upshot/boys-falling-behind-data.html
11•jnord•1h ago•0 comments

Constrained Random Walks

https://github.com/ivanbelenky/pywalker
1•ivanbelenky•1h ago•0 comments

MIT Says It No Longer Stands Behind Student's AI Research Paper

https://www.msn.com/en-us/money/other/mit-says-it-no-longer-stands-behind-student-s-ai-research-paper/ar-AA1EUFwO
2•jnord•1h ago•0 comments

Amp Is Now Available. Here Is How I Use It.

https://ampcode.com/how-i-use-amp
1•handfuloflight•1h ago•0 comments

Supplements

https://near.blog/supplements/
1•bilsbie•1h ago•0 comments