惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
Recent Announcements
Recent Announcements
V
Visual Studio Blog
博客园 - 叶小钗
H
Help Net Security
aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享
U
Unit 42
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
D
DataBreaches.Net
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
A
About on SuperTechFans
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
tessera v0.1.1 — I Wasn't Done Yet
V G P · 2026-05-16 · via DEV Community

V G P

After shipping v0.1.0 I did what most developers do after a release — I opened my own app and started poking around.

The values were ciphertext. Good. But the keys were sitting right there in plain English. auth_state. cart_items. pending_payment. Anyone who opened DevTools knew exactly what I was keeping track of, even if they couldn't read the contents. That shouldn't have bothered me as much as it did. But I couldn't let it go.

So I kept going.


Your keys now mean nothing to anyone but you

tessera now runs every key name through HMAC-SHA-256 before it touches storage. What you call cart_items, tessera stores as t_3a9f7c2e. Close DevTools, reopen it, and all you see is:

t_3a9f7c2e  →  <ciphertext>
t_b2d4f110  →  <ciphertext>
t_03e8a5cc  →  <ciphertext>

Enter fullscreen mode Exit fullscreen mode

The mapping only exists in memory, derived from your passcode. Lock the vault — it's gone.


Some of those entries are fake

Here's the thing I'm most pleased with: not all of those entries are real. tessera automatically plants honey keys — decoys that look exactly like real values. Same key format, same ciphertext format. Completely indistinguishable.

Real code never touches them. Only something enumerating your storage and guessing would. That's the tripwire.

vault.on('honey-hit', (event) => {
  // something is probing your storage
});

Enter fullscreen mode Exit fullscreen mode


Values that delete themselves

Some data shouldn't outlive its purpose. A one-time code. A recovery token. A payment session. v0.1.1 lets values carry their own expiry:

vault.local.setItem('one_time_code', value, {
  ttl: 30_000,   // gone after 30 seconds
  maxReads: 1,   // gone after first read
});

Enter fullscreen mode Exit fullscreen mode

There's no background timer running. The check happens at read time — the moment something requests the value, tessera looks at the write timestamp and acts. If it's expired, it wipes before returning anything. A timer can be cleared by an attacker. A check on read cannot.

Don't want to configure every key manually? Sensitivity presets have you covered:

vault.local.setItem('recovery_code', value, { sensitivity: 'critical' });
// 5 minute TTL, 3 max reads, wiped at first sign of trouble

Enter fullscreen mode Exit fullscreen mode


It notices things that shouldn't be happening

The last thing I added was a suspicion engine. If reads start coming in faster than any human could trigger them, tessera notices. If an HMAC check fails on a read — meaning the value was touched outside the API — tessera notices that too.

You decide what happens:

Tessera.unlock('abc123', {
  suspicion: {
    rateLimit: { callsPerSecond: 10 },
    onSuspicion: 'lock',
  },
});

Enter fullscreen mode Exit fullscreen mode

lock, wipe, or throw. tessera just makes sure something happens.


The encryption in v0.1.0 was the obvious part. v0.1.1 is all the stuff I couldn't stop thinking about after — the layers that make it hard to learn anything useful from your storage even when someone already has full read access.

npm install @mrtinkz/tessera

Enter fullscreen mode Exit fullscreen mode

GitHub — feedback always welcome.