frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: enveil – hide your .env secrets from prAIng eyes

https://github.com/GreatScott/enveil
13•parkaboy•1h ago

Comments

umairnadeem123•1h ago
this solves a real problem. i run coding agents that have access to my workspace and the .env files are always the scariest part. even with .gitignore, the agent can still read them and potentially include secrets in context that gets sent to an API.

the approach of encrypting at rest and only decrypting into environment variables at runtime means the agent never sees the raw secrets even if it reads every file in the project. much better than the current best practice of just hoping your .gitignore is correct and your AI tool respects it.

one suggestion: it would be useful to have a "dry run" mode that shows which env vars would be set without actually setting them. helps verify the config is correct before you realize three services are broken because a typo in the key name.

anshumankmr•52m ago
What about something like Hashicorp secrets? We have a the hashicorp secrets in launch.json and load the values when the process is initialized (yeah it is still not great)
hjkl_hacker•25m ago
This doesn’t really fix that it can echo the secrets and read the logs. `enveil run — printenv`
Datagenerator•16m ago
Not the author but No, the decryption would ask the secret again? The readme mentions it's wiped from memory after use.
Datagenerator•23m ago
Looks good. Almost stopped reading due the npm example, grasped it was just a use case, kept reading.

Kernel keyring support would be the next step?

PASS=$(keyctl print $(keyctl search @s user enveil_key))

hardsnow•18m ago
Alternative, and more robust approach is to give the agent surrogate credentials and replace them on the way out in a proxy. If proxy runs in an environment to which agent has no access to, the real secrets are not available to it directly; it can only make requests to scoped hosts with those.

I’ve built this in Airut and so far seems to handle all the common cases (GitHub, Anthropic / Google API keys, and even AWS, which requires slightly more work due to the request signing approach). Described in more detail here: https://github.com/airutorg/airut/blob/main/doc/network-sand...

SteveVeilStream•14m ago
Sometimes I need to give Claude Code access to a secret to do something. (e.g. Use the OpenAI API to generate an image to use in the application.) Obviously I rotate those often. But what is interesting is what happens if I forget to provide it the secret. It will just grep the logs and try to find a working secret from other projects/past sessions (at least in --dangerously-skip-permissions mode.)
l332mn•9m ago
I use bubblewrap to sandbox the agent to my projects folder, where the ai gets free read/write reign. Non-synthetic env cars are symlinked into my projects folder from outside that folder.
pedropaulovc•1m ago
1Password has this feature in beta. [1]

[1]: https://developer.1password.com/docs/environments/

Work experience kids messed with manager's PC to send him to Ctrl-Alt-Del hell

https://www.theregister.com/2026/02/23/who_me/
1•vismit2000•3m ago•0 comments

NASA's Perseverance Now Autonomously Pinpoints Its Location on Mars

https://www.nasa.gov/missions/mars-2020-perseverance/perseverance-rover/nasas-perseverance-now-au...
1•pieterr•5m ago•0 comments

Everyone in AI is building the wrong thing for the same reason

https://www.joanwestenberg.com/everyone-in-ai-is-building-the-wrong-thing-for-the-same-reason/
1•pmg101•8m ago•0 comments

DJI Romo's MQTT broker had no ACLs – one token, 7k home cameras

https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt
1•bakibab•11m ago•0 comments

Anthropic: AI helps break the cost barrier to COBOL modernization

https://claude.com/blog/how-ai-helps-break-cost-barrier-cobol-modernization
2•aquir•13m ago•1 comments

"Just a little detail that wouldn't sell anything"

https://unsung.aresluna.org/just-a-little-detail-that-wouldnt-sell-anything/
3•bobbiechen•16m ago•0 comments

Trolley: Run Terminal Apps Anywhere

https://github.com/weedonandscott/trolley
2•todsacerdoti•18m ago•0 comments

A website for you to sell equity in your micro-SaaS

https://openstartuphub.com/
1•JasonHEIN•19m ago•0 comments

Russia investigating Telegram founder Durov as part of criminal case

https://www.reuters.com/business/media-telecom/russia-investigating-telegram-founder-durov-part-c...
2•gdrift•20m ago•0 comments

Xiaoyin Qu on X: "Stanford CS grads can't find jobs right now."

https://twitter.com/quxiaoyin/status/2025977959195005149
1•doppp•20m ago•0 comments

Indistinguishable from Magic: Manufacturing Modern Computer Chips

https://www.youtube.com/watch?v=NGFhc8R_uO4
1•pinkmuffinere•24m ago•0 comments

I'm building fitness SaaS – learning about pricing psychology in India

1•waaznfit•24m ago•0 comments

Sigma, camera and lens manufacturer, begins rice cultivation in the Aizu region

https://www.sigma-global.com/en/news/2026/02/24/012026/
1•10729287•26m ago•0 comments

How HN: Invariant Governance – Deterministic governance for autonomous systems

https://invariant-governance.com
1•bot-in-the-loop•29m ago•1 comments

Show HN: I built an AI Voice note taker transcriber

https://apps.apple.com/us/app/gist-transcribe-audio-to-text/id6758212955
1•bubbly_snow•31m ago•0 comments

The Picture They Paint of You

https://ferd.ca/the-picture-they-paint-of-you.html
1•donutshop•33m ago•0 comments

Components.build: open-source standard for modern, composable and accessible UI

https://www.components.build/
1•handfuloflight•35m ago•0 comments

The Market for Marriage

https://worksinprogress.co/issue/marriage-customs-very-different-from-ours/
2•ciju•35m ago•0 comments

LipoVive Supplement: Activate Your Metabolism and Burn Fat Naturally

https://www.morningstar.com/news/accesswire/1138075msn/lipovive-reviews-shocking-2026-report-what...
2•hanxpalz•36m ago•1 comments

Explaining AI Chess for Humans

https://andys.blog/p/1c3f06df-ca88-4eff-b472-44cd23b45f29/
2•andytratt•37m ago•0 comments

EverythingQuickSearch: Get Everything Search Inside Windows Start Mwnu

https://github.com/PinchToDebug/EverythingQuickSearch
2•thunderbong•42m ago•0 comments

Show HN: Multi-Agent Simulations for Assumption Testing and Analysis (Free)

https://www.nichesim.com/
3•justincxa•44m ago•0 comments

We scaled our AI Assistant to use virtually unlimited tools

https://gaia-fork-oz2l3yz60-gaia-2.vercel.app/blog/how-tool-calling-works
3•aryanranderiya•45m ago•0 comments

Show HN: Chemistry Lab Simulator (for AS Level)

https://cambridge-chem-lab.onrender.com/
2•sriram_iyengar•48m ago•1 comments

I got tired of how bloated design tools have became.

2•epic_ai•48m ago•0 comments

Downsizing Is Bonkers?

1•downsizer•49m ago•1 comments

Show HN: Cord – Constitutional AI enforcement engine for autonomous agents

https://github.com/zanderone1980/artificial-persistent-intelligence
2•Alexpinkone•50m ago•1 comments

The Absolute Insider Mess of Prediction Markets

https://philippdubach.com/posts/the-absolute-insider-mess-of-prediction-markets/
1•toomuchtodo•53m ago•0 comments

Pace Layering: How Complex Systems Learn and Keep Learning (2018)

https://longnow.org/ideas/pace-layers/
1•walterbell•55m ago•0 comments

The 'botlash' movement is gaining momentum

https://www.ft.com/content/ecead6b9-eb42-4a85-bd33-073c659e84bf
1•johntfella•57m ago•0 comments