Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Liberty

Hardware-bound secret manager (no more .env files)

Details

External ID
46612783
Source
HN
Company
—
Product
—
Website domain
—
Launched
Jan. 14, 2026
Cohort
—
Upvotes
7
Upvotes percentile
0.3544137022397892
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

I got tired of: - .env files committed to Git (seen it happen 100+ times) - API keys shared in Slack - Wondering who has access to what secretsSo I built Liberty - a CLI tool that replaces .env files with hardware-bound encryption.How it works: $ pip install liberty-secrets $ liberty add DATABASE_URL postgresql://... $ liberty add STRIPE_KEY sk-... $ liberty exec npm start Secrets are encrypted with a key derived from your machine's hardware (CPU ID + machine ID + disk serial). If someone steals your .liberty vault file, it's useless on their machine.Features: - Hardware-bound AES-256-GCM encryption - Complete audit trail (compliance-ready) - Works offline (no servers, no accounts) - Global vault (~/.liberty/ works from any directory) - MIT licensed, free for individual use GitLab: https://gitlab.com/deciphergit/libertyPyPI: https://pypi.org/project/liberty-secrets/Team features (secret sharing) coming soon as paid tier.Feedback welcome!

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Compliance & governance
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
hardware-bound secret management
Manually corrected
False

Could you build this?

Partial A basic CLI for secret storage is simple, but integrating genuine hardware-bound cryptographic security across platforms requires low-level TPM, Secure Enclave, or hardware key APIs.

What it would actually take: A production version requires platform-specific cryptographic bindings to Apple Secure Enclave (via CryptoKit/Keychain), Windows TPM (via CNG/TBS), and Linux TPM 2.0 (tpm2-tss), falling back to FIDO2/U2F devices. The hard part is securely handling hardware-backed key attestation, key generation policies, and avoiding side-channel leaks across heterogeneous OS environments. This requires a systems security engineer familiar with platform cryptographic providers and hardware security modules.

Discussion

4 comments analyzed.

Competitors mentioned: Windows DPAPI, OS secret storage APIs, password managers

Concerns raised: Low entropy from CPU ID, machine ID, and disk serial, Risk of permanent lockout from hardware upgrades or failures, Secrets should still be stored in password manager as backup, Methodology and underlying keys could be reverse-engineered by malware

Feature requests: Default DATABASE_URL to localhost and secrets to dummy strings, Integrate with OS native secret storage APIs, Generate random key and store in config directory instead of hardware identifiers, Store context name in .liberty file for secret retrieval

Competitors

Other products that read as similar to this one — 170 launches clear the similarity bar, closest 8 shown.

Attention rank: #101 of 171 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 76 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.