George Orwell — 1984
ãç§å¯ãå®ããããªããèªåèªèº«ãããé ããªããã°ãªããªããã
ç§ãã¡ã¯ããããŸãããããªãã®Identity Encryptionéµã¯ããã©ãŠã¶å ã§WebAuthnèªèšŒåšïŒæçŽãé¡ããŸãã¯ããŒããŠã§ã¢ããŒïŒããå°åºãããŸããç§ãã¡ã®ãµãŒããŒã¯ãããäžåºŠãèŠãããšããããŸãããããšãæãã ãšããŠããããªãã®ãã©ã€ããŒããã£ãŒã«ãã埩å·ããããšã¯ã§ããŸãããä»ã®èª°ã«ãã§ããŸããã
èªèšŒæ å ±ã®çºè¡ãšãã¹ã¯ãŒã管ç
2ã€ã®åé¡ã1ã€ã®è£œåã
AIãšãŒãžã§ã³ãã«ã¯èªèšŒæ å ±ãå¿ èŠ
ããªãã®ãšãŒãžã§ã³ãã¯ã³ãŒãããããã€ããéµãããŒããŒã·ã§ã³ãã2FAãå®äºããŸããããããçŸåšã®ãã¹ã¯ãŒããããŒãžã£ãŒã¯ãã¹ãŠãæž¡ããäœãæž¡ããªããã®ã©ã¡ããã§ããClavitorã¯åãšãŒãžã§ã³ãã«ã¹ã³ãŒããããèªèšŒæ å ±ã®ã¿ãçºè¡ããŸããVaultã®é²èЧãªããæ¢çŽ¢ãªãã
èªèšŒæ å ±ã«ã¯æ¬ç©ã®æå·åãå¿ èŠ
ãã¹ãŠã®ãã¹ã¯ãŒããããŒãžã£ãŒã¯ãã¹ã¿ãŒãã¹ã¯ãŒãã§æå·åããŸãããã®ãã¹ã¯ãŒãã匱ãããŸãã¯çãŸããå Žåããã¹ãŠã厩å£ããŸããClavitorã¯ããªãã®ããŒããŠã§ã¢ããéµãå°åºããŸããè§£èªãããã¹ã¯ãŒããªããç·åœããããããã¯ã¢ãããªãã
åé¡
ãã¹ãŠã®ãã¹ã¯ãŒããããŒãžã£ãŒã¯AIãšãŒãžã§ã³ããååšããåã«æ§ç¯ãããŸãããä»ã远ãã€ãå¿ èŠããããŸãã
å šãç¡ãã¯æ©èœããªã
ä»ã®ãã¹ãŠã®ãããŒãžã£ãŒã¯AIãšãŒãžã§ã³ãã«Vaultå ã®ãã¹ãŠãžã®ã¢ã¯ã»ã¹ãäžããããäœãäžããŸãããAIã«ã¯GitHubããŒã¯ã³ãå¿ èŠã§ã â ãã¹ããŒãçªå·ãŸã§èŠããå¿ èŠã¯ãããŸããã
ããªã·ãŒã¯ã»ãã¥ãªãã£ã§ã¯ãªã
ãAI察å¿ãVaultã§ãããµãŒããŒåŽã§ãã¹ãŠã埩å·ããŠããŸãããµãŒããŒãèªãããªããæ¬åœã®ãã©ã€ãã·ãŒã§ã¯ãããŸãããæ°åŠã¯åžžã«ããªã·ãŒã«åã¡ãŸãã
ãšãŒãžã§ã³ãã«ã¯èªèšŒæ å ±ãš2FAãå¿ èŠ
AIã¯ã¢ã¯ã»ã¹ãªãã§ã¯ãã°ã€ã³ããäºèŠçŽ èªèšŒã®ééããéµã®ããŒããŒã·ã§ã³ãã§ããŸãããclavitorã¯ãã®3ã€ãã¹ãŠãå¯èœã«ããŸã â ã¯ã¬ãžããã«ãŒããåããã€ãã©ã€ã³ã«æãããšãªãã
ä»çµã¿
ãã¢ã·ã¹ã¿ã³ãã¯ãã©ã€ããäºçŽã§ããŸãã
æ¥èšã¯èªããŸãããã
ãã¹ãŠã®ãã£ãŒã«ãã¯æå·åãããŠããŸãããã ããäžéšã«ã¯2ã€ç®ã®ããã¯ãããããŸãããã®2ã€ç®ã®éµã¯WebAuthnèªèšŒåšããå°åºããããã©ãŠã¶å ã«ã®ã¿ååšããŸããç§ãã¡ãé庫ãå®ããŸããéµãæã£ãŠããã®ã¯ããªãã ãã§ãã
AIãèªã¿åãå¯èœ
ä¿åæã«æå·åãããVaultãµãŒããŒã埩å·å¯èœãAIãšãŒãžã§ã³ãã¯CLIçµç±ã§ã¢ã¯ã»ã¹ããŸãã
- API keys & tokens
- SSH keys
- TOTP 2FAã³ãŒã — AIãèªåçæ
- OAuth tokens
- æ§é åã¡ã¢
ããªãã®ããã€ã¹ã®ã¿
WebAuthn PRFã§ã¯ã©ã€ã¢ã³ãåŽæå·åããµãŒããŒã¯å¹³æãäžåºŠãèŠãŸããã絶察ã«ã
- ã¯ã¬ãžããã«ãŒãçªå·
- CVV
- ãã¹ããŒã & SSN
- ãã©ã€ããŒã眲åéµ
- ãã©ã€ããŒãã¡ã¢
æ ¹æ¬ããç°ãªãèšèš
AIãã§ãã¯ããã¯ã¹ä»ãã®ãã¹ã¯ãŒããããŒãžã£ãŒã§ã¯ãããŸãããã¢ãŒããã¯ãã£ãã®ãã®ãæ©èœã§ãã
ãã£ãŒã«ãã¬ãã«ã®AIå¯èŠæ§
åãã£ãŒã«ãã«ç¬èªã®æå·åã¬ãã«ãAIã¯ãŠãŒã¶ãŒåãèªããŸãããCVVã¯èªããŸãããåããšã³ããªãç°ãªãã¢ã¯ã»ã¹ã
WebAuthn PRF
Identity Encryptionã¯WebAuthn PRFã䜿çšããŸã â WebAuthnèªèšŒåšïŒæçŽãé¡ããŸãã¯ããŒããŠã§ã¢ããŒïŒããå°åºãããæå·éµãããªã·ãŒã§ã¯ãªãæ°åŠã§ããç§ãã¡ã«ã¯æåéã埩å·ã§ããŸããã
APIããŒãç¹å¥æ±ã
å°çšã®APIããŒã«ããŽãªãæã€å¯äžã®Vault â ãšãŒãžã§ã³ããã¢ã¯ã»ã¹å¯èœã§èŠèŠçã«åºå¥ãããŸããHostedãã©ã³ã¯ã€ã³ããŒãæã«APIããŒãèªåæ€åºããŸãããšãŒãžã§ã³ãã¯APIããŒãååŸã§ããŸããããã¹ããŒãã¯èŠããŸããã
Scoped agent tokens
ãšãŒãžã§ã³ãããšã«åå¥ã®ããŒã¯ã³ãäœæãåããŒã¯ã³ã¯å²ãåœãŠããããšã³ããªã®ã¿åç §å¯èœã1ã€ã䟵害ãããŠããæ®ãã¯å®å šã§ãã
åäžãã€ããªãåäžãã¡ã€ã«
DockeräžèŠãPostgresäžèŠãRedisäžèŠãGoãã€ããª1ã€ãSQLiteãã¡ã€ã«1ã€ãRaspberry Piã§åäœãæé¡$4ã®VPSã§ãåäœã
äœããã§ãç§»è¡
14ã®ãã¹ã¯ãŒããããŒãžã£ãŒãšãã©ãŠã¶ããã€ã³ããŒãããã¹ãŠã®ãã£ãŒã«ãããããã³ã°ããã¹ãŠã®ã¿ã€ããä¿æãã€ã³ããŒãæã«äºéæå·åããã¹ãŠã®ãœãŒã¹ãèŠã →
10åã®ãšãŒãžã§ã³ãã
ããããã«å¿
èŠãªãã®ã ããæäŸã
ãšãŒãžã§ã³ãããšã«ã¹ã³ãŒããããCLIããŒã¯ã³ãäœæã1ã€ã®ãšãŒãžã§ã³ãã䟵害ãããŠããå ¬éãããã®ã¯1ã€ã®ã¹ã³ãŒãã ã â Vaultå šäœã§ã¯ãããŸããã
ãªãMCPã§ã¯ãªãã®ãïŒ èªèšŒæ å ±ã¯Vaultå ã§æå·åãããŠãããCLIã§ããŒã«ã«ã«åŸ©å·ããå¿ èŠãããããã§ããMCPãµãŒããŒã«ã¯ãããã§ããŸãããCLIã¯ããªãã®ãã·ã³ã§åŸ©å·ããå¹³æãè¿ããŸããæ©å¯æ å ±ããµãŒãããŒãã£ã®ãããã³ã«å±€ãééããããšã¯ãããŸããã
Agent workflow
# Agent fetches exactly what it's scoped to $ clavitor-cli get "GitHub Deploy" --field password ghp_a3f8...
Claude Code
# Install the skill â Claude Code learns your vault $ clavitor-cli skill > ~/.claude/skills/clavitor.md # Then just ask: # "get me the AWS credentials" # "store this API key as 'Stripe Prod'"
ãšãŒãžã§ã³ããšããªã â åãVaultãé©åãªã¢ã¯ã»ã¹
4ã€ã®ã¢ã¯ã»ã¹æ¹æ³ãããããç°ãªãã³ã³ããã¹ãåãããã¹ãŠåãæå·åã¹ãã¬ãŒãžãåç §ã
CLI
AIãšãŒãžã§ã³ãåã
ãšãŒãžã§ã³ãã¯CLIã§èªèšŒæ å ±ãååŸ â ãšãŒãžã§ã³ãããšã«ã¹ã³ãŒããåãšãŒãžã§ã³ãã¯ä»äžããããã®ã ããåç §ãVaulté²èЧãªããæ¢çŽ¢ãªãã
Extension
ãã©ãŠã¶ã®ãŠãŒã¶ãŒåã
ãã¹ã¯ãŒãã®èªåå ¥åã2FAã³ãŒãã®ã€ã³ã©ã€ã³çæãèªèšŒåšã«ããIdentityãã£ãŒã«ãã®ããã¯è§£é€ â ããŒãžãé¢ããããšãªãã
CLI
ã¿ãŒããã«ã¯ãŒã¯ãããŒåã
èªèšŒæ
å ±ãã¹ã¯ãªãããCIãã€ãã©ã€ã³ã«çŽæ¥ãã€ããvault get github.token â å®äºã
API
ãã®ä»ãã¹ãŠåã
ã¹ã³ãŒãä»ãããŒã¯ã³ã«ããREST APIããããã€ãã€ãã©ã€ã³ã«ã¹ããŒãžã³ã°éµã®èªã¿åãã¢ã¯ã»ã¹ãä»äžããã以å€ã¯ãªãã
ãªããããéèŠã
2022幎ã«äŸµå®³ã幎ã被害ã¯ç¶ãã
2022幎ãLastPassã¯æå·åãããVaultããã¯ã¢ãããæµåºãããŸãããåVaultã¯é¡§å®¢ã®ãã¹ã¿ãŒãã¹ã¯ãŒãã§æå·åãããŠããŸãããæ°å¹ŽåŸãæ»æè ã¯ãŸã è§£èªãç¶ããŠããŸã â 匱ããã¹ã¯ãŒãããé ã«ããã匷ããã®ãžãFBIã¯ãã®1åã®äŸµå®³ãã$150Mã®æå·è³ç£çé£ã远跡ããŸããããããæå·è³ç£ã¯ç®ã«èŠãã被害ã®äžéšã«éããŸãã â åãVaultã«ã¯éè¡ã®ãã°ã€ã³ãäŒæ¥VPNèªèšŒæ å ±ãå»çããŒã¿ã«ãçšåã¢ã«ãŠã³ããå«ãŸããŠããŸããã
1åã®äŸµå®³ãã確èªãããæå·è³ç£çé£ãFBI远跡æžã¿ããŸã å¢å äžãKrebs on Security â
çé£ã¯ä»ãç¶ããŠããŸããæå·åã¯é¡§å®¢ããšã§ããããéµã¯ãã¹ã¯ãŒãã§ããããã¹ã¯ãŒãã¯è§£èªãããŸããSecurity Affairs â
Clavitorã®ããŒããŠã§ã¢ããŒãæ¯ç§1å åã®æšæž¬ã§ç·åœããããŠããå®å®ã®å¹Žéœ¢ã®1å × 1å × 1å × 1å åã®æéãããããŸããããã¯æ¯å©ã§ã¯ãããŸãããæ°åŠã§ãã
Clavitorã®åçïŒ 21ãªãŒãžã§ã³ â ãã¹ãŠã®Vaultã¯ç¬ç«ããããŒã¿ããŒã¹ã§ãããå ±æããŒãã«ã®è¡ã§ã¯ãããŸããããã¹ãŠã®èªèšŒæ å ±ãšIdentityãã£ãŒã«ãã¯ãWebAuthnèªèšŒåšïŒæçŽãé¡ãYubiKeyããŸãã¯ãã®ä»ã®FIDO2ããã€ã¹ïŒããå°åºãããç¬èªã®æå·åéµãæã¡ãŸããããªããéžãã ãã¹ã¯ãŒãã§ã¯ãããŸãããéžã¹ãã¯ãã®ãã¹ã¯ãŒãã§ããããŸããããµãŒããŒã«ååšããããšããªããããã¯ã¢ããã«ååšããããšããªããããããæååã§ã¯ãªãããç·åœããã§ããªãéµã§ãã
ãã®åã«ã¯è²¬ä»»ã䌎ããŸãã åžžã«æäœ2ã€ã®ããã€ã¹ãç»é²ããŠãã ããïŒã¹ããŒããã©ã³ + ããŒãPCïŒãããã«è¯ãã®ã¯ïŒãªã«ããªãŒããŒãå°å·ããPINã§ä¿è·ããèªå® å€ã«ä¿ç®¡ããããšã§ãããã¹ãŠã®ããã€ã¹ãçŽå€±ããå Žåããã®å°å·ç©ãå¯äžã®åŸ©åž°ææ®µã§ããç§ãã¡ã¯å©ããããŸãã â èšèšäžãããªã£ãŠããŸãã
ç«¶å
声ãèããŸããããã¹ãŠã«å¯Ÿå¿ããŸããã
1PasswordãBitwardenãLastPassã«å¯Ÿããå®éã®ãŠãŒã¶ãŒããã®å®éã®äžæºããã©ãŒã©ã ãGitHub issuesãHacker Newsããåéãèªç€ŸãŠãŒã¶ãŒããã®éžå¥ã§ã¯ãããŸããã
1PASSWORD â Community Forum
"The web extensions are laughably bad at this point. This has been going on for months. They either won't fill, wont' unlock, or just plain won't do anything (even clicking extension icon). It's so bad"
â notnotjake, April 2024 â
- clavitor: ãã¹ã¯ãããã¢ããªãžã®äŸåãªããæ¡åŒµæ©èœã¯ããŒã«ã«ã®Vaultãã€ããªãšçŽæ¥éä¿¡ â IPCãªããåæãªããã¢ã³ããã¯ãã§ãŒã³ãªãã
BITWARDEN â GitHub Issues
"Every single website loads slower. From Google, up to social media websites like Reddit, Instagram, X up to websites like example.com. Even scrolling and animation stutters sometimes. javascript heavy websites like X, Instagram, Reddit etc. become extremely sluggish when interacting with buttons. So for me the Bitwarden browser extension is unusable. It interferes with my browsing experience like malware."
- clavitor: content scriptsãŒããæ¡åŒµæ©èœã¯ããŒãžã«äœãæ³šå ¥ããŸãã â ãã©ãŠã¶ã®autofill APIã®ã¿ã䜿çšããããªããèŠæ±ããæã ãå ¥åããŸãã
LASTPASS â Hacker News
"The fact they're drip-feeding how bad this breach actually was is terrible enough... Personally I'm never touching them again."
â intunderflow, January 2023 â
- clavitor: ã»ã«ããã¹ããŸãã¯Identity Encryptionä»ãã®Hostedãå©çš â ç§ãã¡ã¯ããªãã®ãã©ã€ããŒããã£ãŒã«ããæ°åŠçã«èªããŸãããæŒæŽ©ããVaultããŒã¿ã¯ãããŸããã
1PASSWORD â Community Forum
"Since doing so, it asks me to enter my password every 10 minutes or so in the chrome extension"
â Anonymous (Former Member), November 2022 â
- clavitor: WebAuthn-firstãèªèšŒåšãäž»èŠãªã¢ã³ããã¯æ¹æ³ãã»ãã·ã§ã³ã¯ããŒã«ã«ã«ååš â åèªèšŒã匷å¶ãããµãŒããŒåŽã®æå¹æéãªãã
BITWARDEN â Community Forums
"the password not only auto-filled in the password field, but also auto-filled in reddit's search box!"
"if autofill has the propensity at times to put an entire password in plain text in a random field, autofill seems like more risk than it's worth."
- clavitor: LLMãã£ãŒã«ãèªèãæ¡åŒµæ©èœããã©ãŒã ãèªã¿åããã¢ãã«ã«ã©ã®ãã£ãŒã«ããäœããåãåãã â CSSã»ã¬ã¯ã¿ã§ã¯ãªãæå³ã«åºã¥ããŠå ¥åã
BITWARDEN â Community Forums
"Bitwarden REFUSES to autofill the actual password saved for a given site or app...and instead fills an old password. It simply substitutes the OLD password for the new one that is plainly saved in the vault."
- clavitor: LLMãã£ãŒã«ãèªèãæå³ã§ãããã³ã°ããšã³ããªã¯URLã§ã€ã³ããã¯ã¹ â æ£ãããµã€ãã«æ£ããèªèšŒæ å ±ãæ¯åã
ãã¹ãŠã®åŒçšã¯å ¬éæçš¿ãããã®ãŸãŸåŒçšãURLã¯æ€èšŒæžã¿ããœãŒã¹ãèŠã →
ããªãã®Vaultã¯ãããªãããããã¹ãŠã®å Žæã«å¿ èŠã§ãã
èªå® ãããã¯ãŒã¯ã§ããåããªããã¹ã¯ãŒããããŒãžã£ãŒã¯ããã¹ã¯ãŒããããŒãžã£ãŒã§ã¯ãããŸãããããŒãPCã¯ç§»åããŸããã¹ããŒããã©ã³ã¯ç§»åããŸãããã©ãŠã¶æ¡åŒµæ©èœã¯ãã«ãã§ã§ãé£è¡æ©ã§ãã¯ã©ã€ã¢ã³ãã®ãªãã£ã¹ã§Vaultãå¿ èŠãšããŸãã
ã»ã«ããã¹ããããšããããšã¯ããããªãã¯IPãDNSãTLSèšŒææžã皌åçç£èŠãããã¯ã¢ãããåãããµãŒããŒãå¿ èŠãšããããšã§ãã鱿«ãããžã§ã¯ãã§ã¯ãããŸãã â ã€ã³ãã©ã§ãã
ç§ãã¡ã¯clavitorãå šå€§éžã®21ãªãŒãžã§ã³ã§éå¶ããŠããŸãã幎é¡$12ãããªãã®Identity Encryptionéµã¯ãã©ãŠã¶ã®å€ã«åºãããšã¯ãããŸãã â ç§ãã¡ã¯ããªãã®ãã©ã€ããŒããã£ãŒã«ããæ°åŠçã«èªããŸããã
30ç§ã§çšŒå
ã³ãã³ã1ã€ãäŸåé¢ä¿ãªãã
Terminal
Agent access â scoped, encrypted
# Initialize the agent (one-time, token from web UI) $ clavitor-cli init <setup-token> # Agent fetches only what it's scoped to $ clavitor-cli get "Vercel" --field password tV3r...