Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Sesame

a local-first, open-source password manager

Details

External ID
49483038
Source
HN
Company
—
Product
Sesame
Website domain
usesesame.app
Launched
Aug. 28, 2026
Cohort
—
Upvotes
66
Upvotes percentile
0.8870967741935484
Tags
—
Fetched at
Sept. 10, 2026, 5:31 a.m.
Updated at
Sept. 10, 2026, 5:31 a.m.

Description

I have been working on Sesame, an open-source password manager that keeps your vault local by default. You don't need an account to create or use a vault, and the hosted service never receives the vault itself. It's still early software and the independent security review isn't finished yet, so I am mainly interested in feedback, testing, and people looking through the code.(Linux support is yet to be released on v0.1.2, but currently is in the works.)

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Vertical SaaS
Audience
B2C
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
local-first password manager
Manually corrected
False

Could you build this?

No Production password managers require rigorous cryptographic implementations, secure memory management, and formal security audits where subtle bugs lead to total credential exposure.

What it would actually take: A secure password manager requires a core written in Rust/C using audited cryptographic primitives (e.g., Argon2id, ChaCha20-Poly1305, OS keychain/DPAPI integrations) and zeroize patterns for memory safety. Developing it requires deep applied cryptography and systems security expertise to avoid timing attacks, memory snooping, and improper nonce handling.

Discussion

20 comments analyzed.

Competitors mentioned: 1Password, LastPass, Firefox password manager, Yubikey/Nitrokey hardware tokens, PrivacyGuides recommendations

Concerns raised: Supply chain attacks on password managers, Decrypting all passwords when unlocking any single password, 1Password CLI requires full account access for 10 minutes, Browser integration phishing vulnerabilities, LLM-generated passwords shared with provider

Feature requests: Flat Seal-like app network access restrictions for Android/Windows, Phishing-resistant browser autofill by specific website domain, Per-item authentication instead of process-wide access, Hardware-anchored encryption with physical user consent, Rate limiting and secure enclave integration

Competitors

Other products that read as similar to this one — 78 launches clear the similarity bar, closest 8 shown.

Attention rank: #14 of 79 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 289 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a vertical saas tool for Insurance yet.