Ask HN: Best practice securing secrets on local machines working with agents?
10 points| xinbenlv | 1 month ago
We already use password managers, OAuth, scoped keys, and sandboxing, but agents introduce new risks: prompt injection, tool misuse, unexpected action chains, and secrets leaking via logs or model context. Giving agents enough permission to be useful seems at odds with least-privilege.
I haven’t seen much discussion on this. How are people thinking about secret management and trust boundaries on dev machines in the agent era? What patterns actually work in practice?
bilbo-b-baggins|1 month ago
varshith17|1 month ago
CriptoSeguro25|1 month ago
xinbenlv|1 month ago
algebra-pretext|1 month ago
[0] https://www.descope.com/
unknown|1 month ago
[deleted]
xinbenlv|1 month ago
nojs|1 month ago
xinbenlv|1 month ago
deflator|1 month ago
xinbenlv|1 month ago