Secretive helps you keep your SSH keys secret, keep them safe
Way back in January I noted that one of the features that had kept me from using Passwords as my only password management app was its inability to manage SSH keys, a feature offered by competitor 1Password.…
For those wary of using Passwords as their sole password manager, its lack of SSH key management was a hurdle. Apple's competitor, 1Password, offered this feature through a concealed approach. Instead of manually entering passphrases, users could authenticate keys via Touch ID or via their 1Password password. However, this feature remains absent from Passwords.
To address this gap, Secretive has emerged as an open-source solution. It enables users to store SSH keys within their Mac's Secure Enclave, ensuring their protection akin to the system's most confidential data. This protection extends to ECDSA-256 keys, and even post-quantum keys using the MLDSA-65 and MLDSA-87 algorithms on macOS Tahoe and later.
Despite requiring technical know-how, Secretive simplifies SSH key management. Users must edit configuration files and install keys themselves, though extensive guidance is available. Secretive is compatible with various developer tools and secure file transfer clients. However, the primary drawback is the inability to back up or transfer private keys.
Should a user's Mac fail or they switch devices, they must recreate their keys. Furthermore, maintaining SSH keys across multiple Macs necessitates Secretive setup on each device. While this system offers enhanced security, it's not as convenient. The ultimate goal remains Apple's integration of this process into its operating system.
Until then, Secretive remains a viable alternative, particularly for those seeking heightened security or looking to reduce their reliance on 1Password.
Written by urgent.news from Six Colors's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.