secretive

Protect your SSH keys with your Mac's Secure Enclave

RAW Doc

CONTRIBUTING

Contributing to Secretive

Thanks for your interest in contributing to Secretive! Before you contribute, there are a few things I'd like to lay out.

Security

Security is obviously paramount for a project like Secretive. As such, any contributions that compromise the security or auditabilty of the project will be rejected.

Dependencies

Secretive is designed to be easily auditable by people who are considering using it. In keeping with this, Secretive has no third party dependencies, and any contributions which bring in new dependencies will be rejected.

AI/LLM Policy

For security and auditing reasons similar to the policy Secretive has on dependencies, any code generated with AI or LLM tools will not be accepted.

Code of Conduct

All contributors must abide by the Code of Conduct

Localization

If you'd like to contribute a translation, please see Localizing to get started.

Credits

If you make a material contribution to the app, please add yourself to the end of the credits.

Collaborator Status

I will not grant collaborator access to any contributors for this repository. This is basically just because collaborators can accesss the secrets Secretive uses for the signing credentials stored in the repository.

Secretive is Opinionated

I'm releasing Secretive as open source so that other people can use it and audit it, feeling comfortable in knowing that the source is available so they can see what it's doing. I have a pretty strong idea of what I'd like this project to look like, and I may respectfully decline contributions that don't line up with that vision. If you'd like to propose a change before implementing, please feel free to Open an Issue with the proposed tag.


README

Secretive [](https://github.com/maxgoedjen/secretive/actions/workflows/test.yml)

Secretive is an app for protecting and managing SSH keys with the Secure Enclave.

Why?

Safer Storage

The most common setup for SSH keys is just keeping them on disk, guarded by proper permissions. This is fine in most cases, but it's not super hard for malicious users or malware to copy your private key. If you protect your keys with the Secure Enclave, it's impossible to export them, by design.

Access Control

If your Mac has a Secure Enclave, it also has support for strong access controls like Touch ID, or authentication with Apple Watch. You can configure your keys so that they require Touch ID (or Watch) authentication before they're accessed.

Notifications

Secretive also notifies you whenever your keys are accessed, so you're never caught off guard.

Support for Smart Cards Too!

For Macs without Secure Enclaves, you can configure a Smart Card (such as a YubiKey) and use it for signing as well.

Getting Started

Installation

Direct Download

You can download the latest release over on the Releases Page

Using Homebrew

brew install secretive

FAQ

There's a FAQ here.

Auditable Build Process

Builds are produced by GitHub Actions with an auditable build and release generation process. Starting with Secretive 3.0, builds are attested using GitHub Artifact Attestation. Attestations are viewable in the build log for a build, and also on the main attestation page.

A Note Around Code Signing and Keychains

While Secretive uses the Secure Enclave to protect keys, it still relies on Keychain APIs to store and access them. Keychain restricts reads of keys to the app (and specifically, the bundle ID) that created them. If you build Secretive from source, make sure you are consistent in which bundle ID you use so that the Keychain is able to locate your keys.

Backups and Transfers to New Machines

Because secrets in the Secure Enclave are not exportable, they are not able to be backed up, and you will not be able to transfer them to a new machine. If you get a new Mac, just create a new set of secrets specific to that Mac.

Security

Secretive's security policy is detailed in SECURITY.md. To report security issues, please use GitHub's private reporting feature.

Acknowledgements

sekey

Secretive was inspired by the sekey project.

Localization

Secretive is localized to many languages by a generous team of volunteers. To learn more, see LOCALIZING.md. Secretive's localization workflow is generously provided by Crowdin.


SECURITY

Security Policy

Security Principles

Secretive is designed with a few general tenets in mind:

It's Hard to Leak a Key Secretive Can't Read The Key Material

Secretive only operates on hardware-backed keys. In general terms, this means that it should be _very_ hard for Secretive to have any sort of bug that causes a key to be shared, because Secretive can't access private key data even if it wants to.

Simplicity and Auditability

Secretive won't expand to have every feature it could possibly have. Part of the goal of the app is that it is possible for consumers to reasonably audit the code, and that often means not implementing features that might be cool, but which would significantly inflate the size of the codebase.

Dependencies

Both in support of the previous principle and to rule out supply chain attacks, Secretive does not rely on any third party dependencies.

There are limited exceptions to this, particularly in the build process, but the app itself does not depend on any third party code.

Supported Versions

The latest version on the Releases page is the only currently supported version.

Reporting a Vulnerability

To report security issues, please use GitHub's private reporting feature.