<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dhblumenfeld1</title><link>https://news.ycombinator.com/user?id=dhblumenfeld1</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 01 Sep 2026 07:45:54 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dhblumenfeld1" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dhblumenfeld1 in "Show HN: Keypo – Secure Enclave encrypted secrets for AI coding agents"]]></title><description><![CDATA[
<p>Every developer using Claude Code, Codex or Cursor has the same problem: your agent runs your code but it can also read your .env files. API keys, database credentials, anything on disk is visible to the agent.<p>I built keypo-signer, an open-source CLI that encrypts secrets in a vault backed by your Mac's Secure Enclave. The key command is vault exec: it decrypts secrets via Touch ID, injects them as environment variables into a child process, and the agent gets back stdout and an exit code. It never sees the secret values. They never touch disk, shell history, or the agent's context window.<p>See it in action: <a href="https://youtu.be/rOSyWQ3gw70" rel="nofollow">https://youtu.be/rOSyWQ3gw70</a><p>It's open source and self-custody: no cloud provider, no accounts to maintain.<p>There are three vault tiers: open (no auth), passcode and biometric (Touch ID).<p>Two demos showing what you can build on top of this:<p>1. Secure Agent Checkout (<a href="https://github.com/keypo-us/keypo-cli/tree/main/demo/checkout" rel="nofollow">https://github.com/keypo-us/keypo-cli/tree/main/demo/checkou...</a>): Tell your agent "buy me a hat" and it completes a real Shopify checkout with your actual credit card. Card details live in the biometric vault. The agent calls a wrapper script, Touch ID pops up on your Mac, and a headless browser fills the payment form inside a child process the agent can't inspect. You get an order confirmation email. The agent never sees your card number.<p>2. Agent Wallet (<a href="https://github.com/keypo-us/keypo-cli/tree/main/demo/hermes-checkout" rel="nofollow">https://github.com/keypo-us/keypo-cli/tree/main/demo/hermes-...</a>): A hardware wallet for your agent. Uses EIP-7702 smart accounts with the Mac Secure Enclave so your agent can send on-chain transactions but the private key never leaves the hardware. Touch ID gates every signature.<p>macOS/Apple Silicon only (Secure Enclave is the point). Swift + Rust. brew install keypo-us/tap/keypo-signer<p><a href="https://github.com/keypo-us/keypo-cli" rel="nofollow">https://github.com/keypo-us/keypo-cli</a></p>
]]></description><pubDate>Tue, 17 Mar 2026 16:27:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47414891</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47414891</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47414891</guid></item><item><title><![CDATA[Show HN: Keypo – Secure Enclave encrypted secrets for AI coding agents]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/keypo-us/keypo-cli">https://github.com/keypo-us/keypo-cli</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47414878">https://news.ycombinator.com/item?id=47414878</a></p>
<p>Points: 5</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 17 Mar 2026 16:26:23 +0000</pubDate><link>https://github.com/keypo-us/keypo-cli</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47414878</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47414878</guid></item><item><title><![CDATA[New comment by dhblumenfeld1 in "Privacy-first tools you buy once and own forever. No subscription.Productivity"]]></title><description><![CDATA[
<p>This is dope. Love local-first tools. Would be dope to have an iOS/macOS version that I can just buy through the app store (and is hence synced across my devices).</p>
]]></description><pubDate>Fri, 13 Mar 2026 22:07:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=47370611</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47370611</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47370611</guid></item><item><title><![CDATA[New comment by dhblumenfeld1 in "The anxiety driving AI's brutal work culture is a warning for all of us"]]></title><description><![CDATA[
<p>Increasingly convinced that most AI doomerism is coming from the VC / Startup ecosystem because the industry, or game, they've been playing for the last 20 years is undergoing the most disruption.</p>
]]></description><pubDate>Fri, 13 Mar 2026 22:00:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=47370555</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47370555</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47370555</guid></item><item><title><![CDATA[New comment by dhblumenfeld1 in "E2E encrypted messaging on Instagram will no longer be supported after 8 May"]]></title><description><![CDATA[
<p>wouldn't signal fall under this category (same entity control the client and server in between) but they have no way of peaking inside any envelopes?</p>
]]></description><pubDate>Fri, 13 Mar 2026 21:55:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47370496</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47370496</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47370496</guid></item><item><title><![CDATA[New comment by dhblumenfeld1 in "You deleted everything and AWS is still charging you?"]]></title><description><![CDATA[
<p>I recently dealt with something similar with a CDN I used for a project 3 years ago. They kept charging me $0.01/month after I got all of my content off of their servers. Took months to resolve, luckily was pennies so it wasn't a big deal but very frustrating.</p>
]]></description><pubDate>Fri, 13 Mar 2026 21:52:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47370460</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47370460</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47370460</guid></item><item><title><![CDATA[New comment by dhblumenfeld1 in "Can I run AI locally?"]]></title><description><![CDATA[
<p>Have you found that using a frontier model for planning and small local model for writing code to be a solid workflow? Been wanting to experiment with relying less on Claude Code/Codex and more on local models.</p>
]]></description><pubDate>Fri, 13 Mar 2026 21:49:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47370436</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47370436</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47370436</guid></item><item><title><![CDATA[New comment by dhblumenfeld1 in "Show HN: Ash, an Agent Sandbox for Mac"]]></title><description><![CDATA[
<p>this is great. The environment variable control is particularly interesting to me. I've been working on a related problem but different approach: encrypting/decrypting secrets using the Mac's secure enclave (<a href="https://github.com/keypo-us/keypo-wallet/tree/main/keypo-signer-cli" rel="nofollow">https://github.com/keypo-us/keypo-wallet/tree/main/keypo-sig...</a>). The two approaches seem complementary: Ash controls the perimeter, encrypted vaults protect the values themselves.</p>
]]></description><pubDate>Wed, 11 Mar 2026 17:06:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47338233</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47338233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47338233</guid></item><item><title><![CDATA[New comment by dhblumenfeld1 in "Show HN: AgentSign – Open-source zero trust engine for AI agents"]]></title><description><![CDATA[
<p>V interesting. Does the passport have history of what the agent has done in the past and if so, how are you able to verify that work? Specifically thinking about agents that may work across different systems.<p>Might be worth checking this out: <a href="https://www.8004.org/" rel="nofollow">https://www.8004.org/</a> it's more crypto specific but trying to tackle the problem of verifying an agent cross platforms.</p>
]]></description><pubDate>Wed, 11 Mar 2026 16:58:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=47338116</link><dc:creator>dhblumenfeld1</dc:creator><comments>https://news.ycombinator.com/item?id=47338116</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47338116</guid></item></channel></rss>