Skip to content

Show HN: macOS data protection keychain for Electron apps

github.com/biw
24 pointsbiwills3 comments
On HN

Hey HN,

I've been working on Hansel [1] (an encrypted personal data store you can query with agents), and there wasn't a good way to use the modern macOS Data Protection Keychain.

Electron's safeStorage [2] uses the legacy file-based keychain, which allows other apps/agents to query it with the `security` CLI. Not great when you have a dozen agents running in the background! The Data Protection Keychain is nice because it limits access via code-signing access groups and lets you set access rules like Touch ID and/or password.

1: https://hansel.so/

2. https://www.electronjs.org/docs/latest/api/safe-storage

Comments

Useful but kind of defeats electron's primary purpose of being cross platform.

true and I'd love to be able to expand support out for the equivalent versions in linux / windows. For now, you can always fall back to using safeStorage on non macOS platforms!

The security CLI being able to read safeStorage entries is a real problem with agents running everywhere. Code-signing access groups are a much better boundary.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.