CLAVITORBlack-box credential issuance
Sign in Use for free — 10 entries

George Orwell — 1984

"๋น„๋ฐ€์„ ์ง€ํ‚ค๋ ค๋ฉด, ์ž๊ธฐ ์ž์‹ ์—๊ฒŒ๋„ ์ˆจ๊ฒจ์•ผ ํ•œ๋‹ค."

์šฐ๋ฆฌ๋Š” ๊ทธ๋ ‡๊ฒŒ ํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‹น์‹ ์˜ Identity Encryption ํ‚ค๋Š” ๋ธŒ๋ผ์šฐ์ €์—์„œ WebAuthn ์ธ์ฆ๊ธฐ โ€” ์ง€๋ฌธ, ์–ผ๊ตด ๋˜๋Š” ํ•˜๋“œ์›จ์–ด ํ‚ค โ€” ๋กœ๋ถ€ํ„ฐ ํŒŒ์ƒ๋ฉ๋‹ˆ๋‹ค. ์šฐ๋ฆฌ ์„œ๋ฒ„๋Š” ๊ทธ ํ‚ค๋ฅผ ๋ณธ ์ ์ด ์—†์Šต๋‹ˆ๋‹ค. ์›ํ•œ๋‹ค ํ•ด๋„ ๋‹น์‹ ์˜ ๋น„๊ณต๊ฐœ ํ•„๋“œ๋ฅผ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ๋ˆ„๊ตฌ๋„ ๋งˆ์ฐฌ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค.

AI Agent You only Credential โ€” AI can read github_token ssh_key totp_github oauth_slack Identity โ€” only you credit_card cvv passport ssn

์ž๊ฒฉ ์ฆ๋ช… ๋ฐœ๊ธ‰ & ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ

๋‘ ๊ฐ€์ง€ ๋ฌธ์ œ. ํ•˜๋‚˜์˜ ์ œํ’ˆ.

AI ์—์ด์ „ํŠธ์—๊ฒŒ๋Š” ์ž๊ฒฉ ์ฆ๋ช…์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค

๋‹น์‹ ์˜ ์—์ด์ „ํŠธ๋Š” ์ฝ”๋“œ๋ฅผ ๋ฐฐํฌํ•˜๊ณ , ํ‚ค๋ฅผ ๊ต์ฒดํ•˜๊ณ , 2FA๋ฅผ ํ†ต๊ณผํ•ฉ๋‹ˆ๋‹ค โ€” ํ•˜์ง€๋งŒ ํ˜„์žฌ์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž๋Š” ๋ชจ๋“  ๊ฒƒ์„ ์ฃผ๊ฑฐ๋‚˜, ์•„๋ฌด๊ฒƒ๋„ ์ฃผ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. Clavitor๋Š” ๊ฐ ์—์ด์ „ํŠธ์—๊ฒŒ ๋ฒ”์œ„๊ฐ€ ์ง€์ •๋œ ์ž๊ฒฉ ์ฆ๋ช…๋งŒ ๋ฐœ๊ธ‰ํ•ฉ๋‹ˆ๋‹ค. ๋ณผํŠธ ํƒ์ƒ‰ ์—†์Œ. ๊ฒ€์ƒ‰ ์—†์Œ.

์ž๊ฒฉ ์ฆ๋ช…์—๋Š” ์ง„์งœ ์•”ํ˜ธํ™”๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค

๋ชจ๋“  ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž๋Š” ๋งˆ์Šคํ„ฐ ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์•ฝํ•˜๊ฑฐ๋‚˜ โ€” ์œ ์ถœ๋˜๋ฉด โ€” ์ „๋ถ€ ๋ฌด๋„ˆ์ง‘๋‹ˆ๋‹ค. Clavitor๋Š” ํ•˜๋“œ์›จ์–ด์—์„œ ํ‚ค๋ฅผ ํŒŒ์ƒํ•ฉ๋‹ˆ๋‹ค. ํ•ด๋…ํ•  ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž…ํ•  ๋ฐฑ์—…๋„ ์—†์Šต๋‹ˆ๋‹ค.


๋ฌธ์ œ

๋ชจ๋“  ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž๋Š” AI ์—์ด์ „ํŠธ๊ฐ€ ์กด์žฌํ•˜๊ธฐ ์ „์— ๋งŒ๋“ค์–ด์กŒ์Šต๋‹ˆ๋‹ค. ์ด์ œ ๋”ฐ๋ผ์žก์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ „๋ถ€ ์•„๋‹ˆ๋ฉด ์ „๋ฌด โ€” ์ด๊ฑด ์•ˆ ๋ฉ๋‹ˆ๋‹ค

๋‹ค๋ฅธ ๋ชจ๋“  ๊ด€๋ฆฌ์ž๋Š” AI ์—์ด์ „ํŠธ์—๊ฒŒ ๋ณผํŠธ์˜ ๋ชจ๋“  ๊ฒƒ์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ฃผ๊ฑฐ๋‚˜, ์•„๋ฌด๊ฒƒ๋„ ์ฃผ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. AI์—๊ฒŒ GitHub ํ† ํฐ์€ ํ•„์š”ํ•˜์ง€๋งŒ โ€” ์—ฌ๊ถŒ ๋ฒˆํ˜ธ๊นŒ์ง€ ๋ณผ ํ•„์š”๋Š” ์—†์Šต๋‹ˆ๋‹ค.

์ •์ฑ…์€ ๋ณด์•ˆ์ด ์•„๋‹™๋‹ˆ๋‹ค

"AI ์•ˆ์ „" ๋ณผํŠธ๋„ ์—ฌ์ „ํžˆ ์„œ๋ฒ„ ์ธก์—์„œ ๋ชจ๋“  ๊ฒƒ์„ ๋ณตํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค. ์„œ๋ฒ„๊ฐ€ ์ฝ์„ ์ˆ˜ ์žˆ๋‹ค๋ฉด, ์ง„์ •ํ•œ ๋น„๊ณต๊ฐœ๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ์ˆ˜ํ•™์€ ํ•ญ์ƒ ์ •์ฑ…์„ ์ด๊น๋‹ˆ๋‹ค.

์—์ด์ „ํŠธ์—๊ฒŒ๋Š” ์ž๊ฒฉ ์ฆ๋ช…์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค โ€” ๊ทธ๋ฆฌ๊ณ  2FA๋„

AI๋Š” ์ ‘๊ทผ ๊ถŒํ•œ ์—†์ด ๋กœ๊ทธ์ธํ•  ์ˆ˜๋„, 2๋‹จ๊ณ„ ์ธ์ฆ์„ ํ†ต๊ณผํ•  ์ˆ˜๋„, ํ‚ค๋ฅผ ๊ต์ฒดํ•  ์ˆ˜๋„ ์—†์Šต๋‹ˆ๋‹ค. clavitor๋Š” ์„ธ ๊ฐ€์ง€ ๋ชจ๋‘๋ฅผ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค โ€” ๊ฐ™์€ ํŒŒ์ดํ”„๋ผ์ธ์— ์‹ ์šฉ์นด๋“œ๋ฅผ ๋…ธ์ถœํ•˜์ง€ ์•Š์œผ๋ฉด์„œ.


์ž‘๋™ ๋ฐฉ์‹

"๋‹น์‹ ์˜ ๋น„์„œ๋Š” ํ•ญ๊ณตํŽธ์„ ์˜ˆ์•ฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์ผ๊ธฐ์žฅ์€ ์ฝ์„ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค."

๋ชจ๋“  ํ•„๋“œ๊ฐ€ ์•”ํ˜ธํ™”๋ฉ๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์ผ๋ถ€๋Š” ๋‘ ๋ฒˆ์งธ ์ž ๊ธˆ ์žฅ์น˜๋ฅผ ๊ฐ–์Šต๋‹ˆ๋‹ค. ๊ทธ ๋‘ ๋ฒˆ์งธ ํ‚ค๋Š” WebAuthn ์ธ์ฆ๊ธฐ์—์„œ ํŒŒ์ƒ๋˜๋ฉฐ ๋ธŒ๋ผ์šฐ์ €์—์„œ๋งŒ ์กด์žฌํ•ฉ๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” ๊ธˆ๊ณ ๋ฅผ ์ง€ํ‚ต๋‹ˆ๋‹ค. ๊ทธ ํ‚ค๋Š” ์˜ค์ง ๋‹น์‹ ๋งŒ ๊ฐ–๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

Credential Encryption

AI ์ฝ๊ธฐ ๊ฐ€๋Šฅ

์ €์žฅ ์‹œ ์•”ํ˜ธํ™”, ๋ณผํŠธ ์„œ๋ฒ„๊ฐ€ ๋ณตํ˜ธํ™” ๊ฐ€๋Šฅ. AI ์—์ด์ „ํŠธ๋Š” CLI๋ฅผ ํ†ตํ•ด ์ ‘๊ทผํ•ฉ๋‹ˆ๋‹ค.

  • API keys & tokens
  • SSH keys
  • TOTP 2FA ์ฝ”๋“œ — AI๊ฐ€ ๋Œ€์‹  ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค
  • OAuth tokens
  • ๊ตฌ์กฐํ™”๋œ ๋ฉ”๋ชจ
Identity Encryption

๋‹น์‹ ์˜ ๊ธฐ๊ธฐ์—์„œ๋งŒ

WebAuthn PRF๋กœ ํด๋ผ์ด์–ธํŠธ ์ธก์—์„œ ์•”ํ˜ธํ™”. ์„œ๋ฒ„๋Š” ํ‰๋ฌธ์„ ์ ˆ๋Œ€ ๋ณด์ง€ ๋ชปํ•ฉ๋‹ˆ๋‹ค. ์ ˆ๋Œ€๋กœ.

  • ์‹ ์šฉ์นด๋“œ ๋ฒˆํ˜ธ
  • CVV
  • ์—ฌ๊ถŒ & SSN
  • ๊ฐœ์ธ ์„œ๋ช… ํ‚ค
  • ๊ฐœ์ธ ๋ฉ”๋ชจ

๋‹ค๋ฅด๊ฒŒ ์„ค๊ณ„๋˜์—ˆ์Šต๋‹ˆ๋‹ค

AI ์ฒดํฌ๋ฐ•์Šค๋งŒ ์ถ”๊ฐ€ํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ์•„ํ‚คํ…์ฒ˜ ์ž์ฒด๊ฐ€ ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.

ํ•„๋“œ ๋‹จ์œ„ AI ๊ฐ€์‹œ์„ฑ

๊ฐ ํ•„๋“œ๋Š” ์ž์ฒด ์•”ํ˜ธํ™” ๋“ฑ๊ธ‰์„ ๊ฐ–์Šต๋‹ˆ๋‹ค. AI๋Š” ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ์ฝ์ง€๋งŒ, CVV๋Š” ์ฝ์ง€ ๋ชปํ•ฉ๋‹ˆ๋‹ค. ๊ฐ™์€ ํ•ญ๋ชฉ, ๋‹ค๋ฅธ ์ ‘๊ทผ ๊ถŒํ•œ.

WebAuthn PRF

Identity Encryption์€ WebAuthn PRF๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค โ€” WebAuthn ์ธ์ฆ๊ธฐ(์ง€๋ฌธ, ์–ผ๊ตด ๋˜๋Š” ํ•˜๋“œ์›จ์–ด ํ‚ค)์—์„œ ํŒŒ์ƒ๋œ ์•”ํ˜ธํ™” ํ‚ค์ž…๋‹ˆ๋‹ค. ์ •์ฑ…์ด ์•„๋‹Œ ์ˆ˜ํ•™์ž…๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” ๋ฌธ์ž ๊ทธ๋Œ€๋กœ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

API ํ‚ค โ€” ํŠน๋ณ„ ๋Œ€์ƒ

์ „์šฉ API ํ‚ค ์นดํ…Œ๊ณ ๋ฆฌ๋ฅผ ๊ฐ€์ง„ ์œ ์ผํ•œ ๋ณผํŠธ โ€” ์—์ด์ „ํŠธ๊ฐ€ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•˜๋ฉฐ ์‹œ๊ฐ์ ์œผ๋กœ ๊ตฌ๋ถ„๋ฉ๋‹ˆ๋‹ค. Hosted ํ”Œ๋žœ์€ ๊ฐ€์ ธ์˜ค๊ธฐ ์‹œ API ํ‚ค๋ฅผ ์ž๋™ ๊ฐ์ง€ํ•ฉ๋‹ˆ๋‹ค. ์—์ด์ „ํŠธ๋Š” API ํ‚ค๋ฅผ ๊ฐ€์ ธ์˜ฌ ์ˆ˜ ์žˆ์ง€๋งŒ ์—ฌ๊ถŒ์€ ๋ณผ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

Scoped agent tokens

์—์ด์ „ํŠธ๋ณ„๋กœ ๋ณ„๋„ ํ† ํฐ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. ๊ฐ ํ† ํฐ์€ ์ง€์ •๋œ ํ•ญ๋ชฉ๋งŒ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํ•˜๋‚˜๊ฐ€ ์œ ์ถœ๋˜์–ด๋„ ๋‚˜๋จธ์ง€๋Š” ์•ˆ์ „ํ•ฉ๋‹ˆ๋‹ค.

๋‹จ์ผ ๋ฐ”์ด๋„ˆ๋ฆฌ, ๋‹จ์ผ ํŒŒ์ผ

Docker ์—†์Œ. Postgres ์—†์Œ. Redis ์—†์Œ. Go ๋ฐ”์ด๋„ˆ๋ฆฌ ํ•˜๋‚˜, SQLite ํŒŒ์ผ ํ•˜๋‚˜. Raspberry Pi์—์„œ ์‹คํ–‰. ์›” $4 VPS์—์„œ๋„ ์‹คํ–‰.

๋ฌด์—‡์ด๋“  ๊ฐˆ์•„ํƒ€์„ธ์š”

14๊ฐœ์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž์™€ ๋ธŒ๋ผ์šฐ์ €์—์„œ ๊ฐ€์ ธ์˜ค๊ธฐ. ๋ชจ๋“  ํ•„๋“œ ๋งคํ•‘, ๋ชจ๋“  ์œ ํ˜• ๋ณด์กด, ๋„์ฐฉ ์‹œ ์ด์ค‘ ์•”ํ˜ธํ™”. ๋ชจ๋“  ์†Œ์Šค ๋ณด๊ธฐ →


์—์ด์ „ํŠธ 10๊ฐœ.
๊ฐ๊ฐ ํ•„์š”ํ•œ ๊ฒƒ๋งŒ ์ •ํ™•ํžˆ ๋ฐ›์Šต๋‹ˆ๋‹ค.

์—์ด์ „ํŠธ๋ณ„๋กœ scoped CLI ํ† ํฐ์„ ์ƒ์„ฑํ•˜์„ธ์š”. ์—์ด์ „ํŠธ ํ•˜๋‚˜๊ฐ€ ์นจํ•ด๋˜๋ฉด ํ•˜๋‚˜์˜ ๋ฒ”์œ„๋งŒ ๋…ธ์ถœ๋ฉ๋‹ˆ๋‹ค โ€” ์ „์ฒด ๋ณผํŠธ๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค.

์™œ MCP๊ฐ€ ์•„๋‹Œ๊ฐ€? ์ž๊ฒฉ ์ฆ๋ช…์€ ๋ณผํŠธ์—์„œ ์•”ํ˜ธํ™”๋˜์–ด ์žˆ๊ณ  โ€” CLI๋กœ ๋กœ์ปฌ์—์„œ ๋ณตํ˜ธํ™”ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. MCP ์„œ๋ฒ„๋Š” ๊ทธ๋ ‡๊ฒŒ ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. CLI๋Š” ๋‹น์‹ ์˜ ๋จธ์‹ ์—์„œ ๋ณตํ˜ธํ™”ํ•˜๊ณ , ํ‰๋ฌธ์„ ๋ฐ˜ํ™˜ํ•˜๋ฉฐ, ๋ฏผ๊ฐํ•œ ์ •๋ณด๊ฐ€ ์„œ๋“œํŒŒํ‹ฐ ํ”„๋กœํ† ์ฝœ ๋ ˆ์ด์–ด๋ฅผ ํ†ต๊ณผํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

Agent workflow

# Agent fetches exactly what it's scoped to
$ clavitor-cli get "GitHub Deploy" --field password
ghp_a3f8...

Claude Code

# Install the skill โ€” Claude Code learns your vault
$ clavitor-cli skill > ~/.claude/skills/clavitor.md

# Then just ask:
# "get me the AWS credentials"
# "store this API key as 'Stripe Prod'"

๋ชจ๋“  ์–ธ์–ด์™€ ํ”Œ๋žซํผ ๋ณด๊ธฐ →

CLAVITOR Agent 1 dev Agent 2 social Agent 3 finance Agent 4 infra Agent 5 deploy github ssh gitlab twitter slack discord stripe plaid aws k8s docker vercel netlify

์—์ด์ „ํŠธ์™€ ๋‹น์‹  โ€” ๊ฐ™์€ ๋ณผํŠธ, ์˜ฌ๋ฐ”๋ฅธ ์ ‘๊ทผ

๋„ค ๊ฐ€์ง€ ๋ฐฉ๋ฒ•. ๊ฐ๊ฐ ๋‹ค๋ฅธ ๋งฅ๋ฝ์„ ์œ„ํ•ด ์„ค๊ณ„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ชจ๋‘ ๋™์ผํ•œ ์•”ํ˜ธํ™”๋œ ์ €์žฅ์†Œ๋ฅผ ๊ฐ€๋ฆฌํ‚ต๋‹ˆ๋‹ค.

CLI

AI ์—์ด์ „ํŠธ์šฉ

์—์ด์ „ํŠธ๋Š” CLI๋ฅผ ํ˜ธ์ถœํ•˜์—ฌ ์ž๊ฒฉ ์ฆ๋ช…์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค โ€” ์—์ด์ „ํŠธ๋ณ„ scoped. ๊ฐ ์—์ด์ „ํŠธ๋Š” ๋ถ€์—ฌ๋œ ๊ฒƒ๋งŒ ๋ด…๋‹ˆ๋‹ค. ๋ณผํŠธ ํƒ์ƒ‰ ์—†์Œ, ๊ฒ€์ƒ‰ ์—†์Œ.

Extension

๋ธŒ๋ผ์šฐ์ €์˜ ์‚ฌ๋žŒ์„ ์œ„ํ•ด

๋น„๋ฐ€๋ฒˆํ˜ธ ์ž๋™ ์ž…๋ ฅ, 2FA ์ฝ”๋“œ ์ธ๋ผ์ธ ์ƒ์„ฑ, ์ธ์ฆ๊ธฐ๋กœ Identity ํ•„๋“œ ์ž ๊ธˆ ํ•ด์ œ โ€” ํŽ˜์ด์ง€๋ฅผ ๋ฒ—์–ด๋‚˜์ง€ ์•Š๊ณ .

CLI

ํ„ฐ๋ฏธ๋„ ์›Œํฌํ”Œ๋กœ์šฐ์šฉ

์ž๊ฒฉ ์ฆ๋ช…์„ ์Šคํฌ๋ฆฝํŠธ์™€ CI ํŒŒ์ดํ”„๋ผ์ธ์— ์ง์ ‘ ํŒŒ์ดํ”„ํ•ฉ๋‹ˆ๋‹ค. vault get github.token โ€” ๋.

API

๊ทธ ์™ธ ๋ชจ๋“  ๊ฒƒ์„ ์œ„ํ•ด

Scoped tokens๊ฐ€ ์žˆ๋Š” REST API. ๋ฐฐํฌ ํŒŒ์ดํ”„๋ผ์ธ์— ์Šคํ…Œ์ด์ง• ํ‚ค ์ฝ๊ธฐ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜์„ธ์š”. ๊ทธ ์ด์ƒ์€ ์—†์Šต๋‹ˆ๋‹ค.


์™œ ์ด๊ฒƒ์ด ์ค‘์š”ํ•œ๊ฐ€

2022๋…„์— ์นจํ•ด๋‹นํ–ˆ์Šต๋‹ˆ๋‹ค. ๋…„์—๋„ ์—ฌ์ „ํžˆ ํ”ผ๋ฅผ ํ˜๋ฆฌ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

2022๋…„, LastPass๋Š” ์•”ํ˜ธํ™”๋œ ๋ณผํŠธ ๋ฐฑ์—…์„ ์œ ์ถœํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ฐ ๋ณผํŠธ๋Š” ๊ณ ๊ฐ์˜ ๋งˆ์Šคํ„ฐ ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ์•”ํ˜ธํ™”๋˜์–ด ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. ์ˆ˜๋…„์ด ์ง€๋‚œ ์ง€๊ธˆ๋„ ๊ณต๊ฒฉ์ž๋“ค์€ ์—ฌ์ „ํžˆ ํ•ด๋…ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค โ€” ์•ฝํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ถ€ํ„ฐ, ๊ทธ ๋‹ค์Œ ๊ฐ•ํ•œ ๊ฒƒ๋“ค. FBI๋Š” $1์–ต 5์ฒœ๋งŒ์˜ ์•”ํ˜ธํ™”ํ ๋„๋‚œ์„ ๊ทธ ๋‹จ์ผ ์นจํ•ด๋กœ ์ถ”์ ํ–ˆ์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์•”ํ˜ธํ™”ํ๋Š” ๋ˆˆ์— ๋ณด์ด๋Š” ํ”ผํ•ด์ผ ๋ฟ โ€” ๊ฐ™์€ ๋ณผํŠธ์— ์€ํ–‰ ๋กœ๊ทธ์ธ, ๊ธฐ์—… VPN ์ž๊ฒฉ ์ฆ๋ช…, ์˜๋ฃŒ ํฌํ„ธ, ์„ธ๊ธˆ ๊ณ„์ •๋„ ๋“ค์–ด ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

$150M+

๋‹จ์ผ ์นจํ•ด๋กœ ์ธํ•œ ํ™•์ธ๋œ ์•”ํ˜ธํ™”ํ ๋„๋‚œ. FBI ์ถ”์ . ์•„์ง๋„ ์ฆ๊ฐ€ ์ค‘. Krebs on Security โ†—

3๋…„

๋„๋‚œ์€ ๊ณ„์†๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•”ํ˜ธํ™”๋Š” ๊ณ ๊ฐ๋ณ„์ด์—ˆ์ง€๋งŒ โ€” ํ‚ค๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ์˜€์Šต๋‹ˆ๋‹ค. ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ํ•ด๋…๋ฉ๋‹ˆ๋‹ค. Security Affairs โ†—

forever

Clavitor ํ•˜๋“œ์›จ์–ด ํ‚ค๋ฅผ ์ดˆ๋‹น 1์กฐ ๋ฒˆ์˜ ์‹œ๋„๋กœ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž…ํ•˜๋ฉด, ์šฐ์ฃผ๊ฐ€ ์กด์žฌํ•œ ์‹œ๊ฐ„๋ณด๋‹ค 1์กฐ × 1์กฐ × 1์กฐ × 1์กฐ ๋ฐฐ ๋” ์˜ค๋ž˜ ๊ฑธ๋ฆฝ๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ๋น„์œ ๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ์ด๊ฒƒ์ด ์ˆ˜ํ•™์ž…๋‹ˆ๋‹ค.

Clavitor์˜ ๋‹ต: 21๊ฐœ ๋ฆฌ์ „ โ€” ๋ชจ๋“  ๋ณผํŠธ๋Š” ๊ฒฉ๋ฆฌ๋œ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์ด๋ฉฐ, ๊ณต์œ  ํ…Œ์ด๋ธ”์˜ ํ–‰์ด ์•„๋‹™๋‹ˆ๋‹ค. ๋ชจ๋“  ์ž๊ฒฉ ์ฆ๋ช…๊ณผ ์‹ ์› ํ•„๋“œ๋Š” WebAuthn ์ธ์ฆ๊ธฐ โ€” ์ง€๋ฌธ, ์–ผ๊ตด, YubiKey ๋˜๋Š” ๋ชจ๋“  FIDO2 ๊ธฐ๊ธฐ โ€” ์—์„œ ํŒŒ์ƒ๋œ ๊ณ ์œ ํ•œ ์•”ํ˜ธํ™” ํ‚ค๋ฅผ ๊ฐ–์Šต๋‹ˆ๋‹ค. ๋‹น์‹ ์ด ์„ ํƒํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ์„ ํƒํ•  ์ˆ˜ ์žˆ์—ˆ๋˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋„ ์•„๋‹™๋‹ˆ๋‹ค. ์–ด๋–ค ์„œ๋ฒ„์—๋„ ์กด์žฌํ•œ ์ ์ด ์—†๊ณ , ์–ด๋–ค ๋ฐฑ์—…์—๋„ ์กด์žฌํ•œ ์ ์ด ์—†์œผ๋ฉฐ, ์• ์ดˆ์— ๋ฌธ์ž์—ด์ด ์•„๋‹ˆ์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž…์ด ๋ถˆ๊ฐ€๋Šฅํ•œ ํ‚ค์ž…๋‹ˆ๋‹ค.

์ด ํž˜์—๋Š” ์ฑ…์ž„์ด ๋”ฐ๋ฆ…๋‹ˆ๋‹ค. ํ•ญ์ƒ ์ตœ์†Œ ๋‘ ๊ฐœ์˜ ๊ธฐ๊ธฐ๋ฅผ ๋“ฑ๋กํ•˜์„ธ์š” (ํœด๋Œ€ํฐ + ๋…ธํŠธ๋ถ). ๋” ์ข‹์€ ๋ฐฉ๋ฒ•: ๋ณต๊ตฌ ํ‚ค๋ฅผ ์ธ์‡„ํ•˜๊ณ , PIN์œผ๋กœ ๋ณดํ˜ธํ•˜๊ณ , ์ง‘ ๋ฐ–์— ๋ณด๊ด€ํ•˜์„ธ์š”. ๋ชจ๋“  ๊ธฐ๊ธฐ๋ฅผ ์žƒ์œผ๋ฉด, ๊ทธ ์ธ์‡„๋ฌผ์ด ์œ ์ผํ•œ ๋ณต๊ตฌ ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” ๋„์šธ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค โ€” ์„ค๊ณ„์ƒ ๊ทธ๋ ‡์Šต๋‹ˆ๋‹ค.


๊ฒฝ์Ÿ์‚ฌ

์šฐ๋ฆฌ๋Š” ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๋ชจ๋‘ ํ•ด๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค.

์‹ค์ œ ์‚ฌ์šฉ์ž๋“ค์˜ ์‹ค์ œ ๋ถˆ๋งŒ โ€” 1Password, Bitwarden, LastPass์— ๋Œ€ํ•œ. ํฌ๋Ÿผ, GitHub ์ด์Šˆ, Hacker News์—์„œ ์ˆ˜์ง‘. ์ž์‚ฌ ์‚ฌ์šฉ์ž ์˜๊ฒฌ์„ ์„ ๋ณ„ํ•œ ๊ฒƒ์ด ์•„๋‹™๋‹ˆ๋‹ค.

1PASSWORD โ€” Community Forum

"The web extensions are laughably bad at this point. This has been going on for months. They either won't fill, wont' unlock, or just plain won't do anything (even clicking extension icon). It's so bad"

โ€” notnotjake, April 2024 โ†—


  • clavitor: ๋ฐ์Šคํฌํ†ฑ ์•ฑ ์˜์กด์„ฑ ์—†์Œ. ํ™•์žฅ ํ”„๋กœ๊ทธ๋žจ์€ ๋กœ์ปฌ ๋ณผํŠธ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์ง์ ‘ ํ†ต์‹ ํ•ฉ๋‹ˆ๋‹ค โ€” IPC ์—†์Œ, ๋™๊ธฐํ™” ์—†์Œ, ์ž ๊ธˆ ํ•ด์ œ ์ฒด์ธ ์—†์Œ.

BITWARDEN โ€” GitHub Issues

"Every single website loads slower. From Google, up to social media websites like Reddit, Instagram, X up to websites like example.com. Even scrolling and animation stutters sometimes. javascript heavy websites like X, Instagram, Reddit etc. become extremely sluggish when interacting with buttons. So for me the Bitwarden browser extension is unusable. It interferes with my browsing experience like malware."

โ€” julianw1011, 2024 โ†—


  • clavitor: ์ฝ˜ํ…์ธ  ์Šคํฌ๋ฆฝํŠธ ์ œ๋กœ. ํ™•์žฅ ํ”„๋กœ๊ทธ๋žจ์€ ํŽ˜์ด์ง€์— ์•„๋ฌด๊ฒƒ๋„ ์ฃผ์ž…ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค โ€” ๋‹น์‹ ์ด ์š”์ฒญํ•  ๋•Œ๋งŒ ๋ธŒ๋ผ์šฐ์ € ์ž๋™ ์ž…๋ ฅ API๋ฅผ ํ†ตํ•ด ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

LASTPASS โ€” Hacker News

"The fact they're drip-feeding how bad this breach actually was is terrible enough... Personally I'm never touching them again."

โ€” intunderflow, January 2023 โ†—


  • clavitor: ์…€ํ”„ ํ˜ธ์ŠคํŒ…ํ•˜๊ฑฐ๋‚˜ Identity Encryption์ด ํฌํ•จ๋œ ํ˜ธ์ŠคํŒ…์„ ์ด์šฉํ•˜์„ธ์š” โ€” ์šฐ๋ฆฌ๋Š” ์ˆ˜ํ•™์ ์œผ๋กœ ๋‹น์‹ ์˜ ๋น„๊ณต๊ฐœ ํ•„๋“œ๋ฅผ ์ฝ์„ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์œ ์ถœ๋  ๋ณผํŠธ ๋ฐ์ดํ„ฐ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค.

1PASSWORD โ€” Community Forum

"Since doing so, it asks me to enter my password every 10 minutes or so in the chrome extension"

โ€” Anonymous (Former Member), November 2022 โ†—


  • clavitor: WebAuthn ์šฐ์„ . ์ธ์ฆ๊ธฐ๊ฐ€ ๊ธฐ๋ณธ ์ž ๊ธˆ ํ•ด์ œ ์ˆ˜๋‹จ์ž…๋‹ˆ๋‹ค. ์„ธ์…˜์€ ๋กœ์ปฌ์— ์œ ์ง€ โ€” ์„œ๋ฒ„ ์ธก ๋งŒ๋ฃŒ๋กœ ์ธํ•œ ์žฌ์ธ์ฆ ๊ฐ•์ œ ์—†์Œ.

BITWARDEN โ€” Community Forums

"the password not only auto-filled in the password field, but also auto-filled in reddit's search box!"

"if autofill has the propensity at times to put an entire password in plain text in a random field, autofill seems like more risk than it's worth."

โ€” xru1nib5 โ†—


  • clavitor: LLM ํ•„๋“œ ์ธ์‹. ํ™•์žฅ ํ”„๋กœ๊ทธ๋žจ์ด ์–‘์‹์„ ์ฝ๊ณ , ๋ชจ๋ธ์—๊ฒŒ ์–ด๋–ค ํ•„๋“œ๊ฐ€ ๋ฌด์—‡์ธ์ง€ ๋ฌผ์–ด๋ด…๋‹ˆ๋‹ค โ€” CSS ์„ ํƒ์ž๊ฐ€ ์•„๋‹Œ ์˜๋„๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

BITWARDEN โ€” Community Forums

"Bitwarden REFUSES to autofill the actual password saved for a given site or app...and instead fills an old password. It simply substitutes the OLD password for the new one that is plainly saved in the vault."

โ€” gentlezacharias โ†—


  • clavitor: LLM ํ•„๋“œ ์ธ์‹์ด ์˜๋„๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋งค์นญํ•ฉ๋‹ˆ๋‹ค. ํ•ญ๋ชฉ์€ URL๋กœ ์ธ๋ฑ์‹ฑ๋ฉ๋‹ˆ๋‹ค โ€” ์˜ฌ๋ฐ”๋ฅธ ์‚ฌ์ดํŠธ์— ์˜ฌ๋ฐ”๋ฅธ ์ž๊ฒฉ ์ฆ๋ช…, ๋งค๋ฒˆ.

๋ชจ๋“  ์ธ์šฉ๋ฌธ์€ ๊ณต๊ฐœ ๊ฒŒ์‹œ๋ฌผ์—์„œ ๊ทธ๋Œ€๋กœ ๊ฐ€์ ธ์™”์Šต๋‹ˆ๋‹ค. URL ๊ฒ€์ฆ ์™„๋ฃŒ. ์ถœ์ฒ˜ ๋ณด๊ธฐ →


๋ณผํŠธ๋Š” ๋‹น์‹ ์ด ์žˆ๋Š” ๋ชจ๋“  ๊ณณ์— ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ํ™ˆ ๋„คํŠธ์›Œํฌ์—์„œ๋งŒ ์ž‘๋™ํ•˜๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ด€๋ฆฌ์ž๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ๋…ธํŠธ๋ถ์€ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค. ํœด๋Œ€ํฐ์€ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค. ๋ธŒ๋ผ์šฐ์ € ํ™•์žฅ ํ”„๋กœ๊ทธ๋žจ์€ ์นดํŽ˜์—์„œ, ๋น„ํ–‰๊ธฐ์—์„œ, ๊ณ ๊ฐ ์‚ฌ๋ฌด์‹ค์—์„œ ๋ณผํŠธ๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์…€ํ”„ ํ˜ธ์ŠคํŒ…์€ ๊ณต์ธ IP๊ฐ€ ์žˆ๋Š” ์„œ๋ฒ„, DNS, TLS ์ธ์ฆ์„œ, ๊ฐ€๋™ ์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง, ๋ฐฑ์—…์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ์ฃผ๋ง ํ”„๋กœ์ ํŠธ๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค โ€” ์ธํ”„๋ผ์ž…๋‹ˆ๋‹ค.

์šฐ๋ฆฌ๋Š” ๋ชจ๋“  ๋Œ€๋ฅ™์˜ 21๊ฐœ ๋ฆฌ์ „์—์„œ clavitor๋ฅผ ์šด์˜ํ•ฉ๋‹ˆ๋‹ค. ์—ฐ $12. ๋‹น์‹ ์˜ Identity Encryption ํ‚ค๋Š” ๋ธŒ๋ผ์šฐ์ €๋ฅผ ๋– ๋‚˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค โ€” ์šฐ๋ฆฌ๋Š” ์ˆ˜ํ•™์ ์œผ๋กœ ๋‹น์‹ ์˜ ๋น„๊ณต๊ฐœ ํ•„๋“œ๋ฅผ ์ฝ์„ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.


30์ดˆ ๋งŒ์— ์‹คํ–‰

๋ช…๋ น์–ด ํ•˜๋‚˜. ์˜์กด์„ฑ ์—†์Œ.

Terminal

# Initialize the agent (one-time, token from web UI)
$ curl -fsSL clavitor.ai/install.sh | sh
$ clavitor
# Running on http://localhost:1984

Agent access โ€” scoped, encrypted

# Initialize the agent (one-time, token from web UI)
$ clavitor-cli init <setup-token>

# Agent fetches only what it's scoped to
$ clavitor-cli get "Vercel" --field password
tV3r...