Secrets 2.6, for both macOS and iOS, is now available. This release delivers on some of the most commonly requested features.
When you open Secrets you’ll find a new built-in filter called Favorites. Simply tap the ★ button on the item detail to add it to your favorites. Tap again to remove it.
You can mark any item as a favorite, be it a Login, Credit Card, Note, etc. Quickly access them by selecting the Favorites filter.
One interesting thing to note is that this feature is actually built upon the tagging feature we introduced in version 2.4, and it serves as an example of what you can do with Custom Filters.
Previously, Secrets added the ability to tag your items. By tagging your items Secrets could surface more relevant results when searching.
With this update, you don’t even need to search. If you have a group of related items you access frequently, you can create custom filter and have those items at a click distance.
You can use much more than tags to create your custom filters. Want to see all Logins you’ve created using a specific e-mail as username? Sure. Want to see which Logins have a One-Time Password set? You can do that too!
Some of our users have asked for folders. This is our answer to that. Custom filters are much more flexible than folders and can easily achieve the same effect. Simply tag your items with what the folder name would be and create a filter based on that. With the advantage that the same item can belong to more than one “folder”.
Last but not least, you can check your Logins against the popular Have I Been Pwned service.
This service collects data, such as usernames and passwords, exposed on the internet from various service breaches. It then makes this data publicly available and easily queryable.
Secrets will check both if your username is contained in any of the breaches collected, and if your password was leaked. Worth noting, is that your password is never sent to the service, only the first 5 characters of the SHA1 hash of your password is sent. If you want to know more about how this works, the author Troy Hunt, does a great job explaining it in this blog post.
One final remark, is that Secrets will never consult this service without you explicitly telling it to do so. We don’t want Secrets to do anything behind your back, even if it could potentially find vulnerable logins for you.
Setapp is an innovative service providing access to a curated list of first-class Mac apps. It’s a subscription service with a simple an enticing value proposition: $9.99/month to access the entire collection of hand-picked apps. And now, Secrets is part of that collection.
Secrets for Mac is still and will continue to be available on the Mac App Store with a one-time In-App Purchase. But starting today, it’s also available on Setapp.
As users, we’re highly reluctant to paying a subscription for an app… but with Setapp you’re not paying for one app, but an ever-growing list of already over 100 apps. If you’re only interested in Secrets that one-time In-App Purchase is still there for you 😉. If you find you can put some of the apps on that list to good use, perhaps you should consider signing up!
We believe Setapp to be another great distribution channel, and we’re very excited to have Secrets in the hands of even more users.
Once you commit to it, using a password manager is liberating. Having unique and strong passwords for all your logins creates warm fuzzy feeling inside. You feel like you are in control of your digital life.
This is only possible because there’s a trust relationship between you and your password manager. And your passphrase is the link in between.
Any serious password manager will derive encryption keys from your master passphrase. This means that your passphrase is the only way to access your data. If your password manager can recover your data without your passphrase or some secret only you know, then they can access your data without your consent.
But this presents a challenge to that warm fuzzy feeling. Forgetting your passphrase means loosing access to your data. The passphrase is both the basis for trusting the security of your data and also something you must remember… and remembering a long passphrase can be hard. So hard that most of us avoid changing it.
That’s why with Secrets 2.4 for Mac you can create a Recovery Key.1 A Recovery Key is a 128 bit random value that can also be used to unlock your secrets. You can use this key if you ever forget your master passphrase. And because it’s not tied to your passphrase, you can change it reassured by the fact you can recover your data in case you forget it.
To create a Recovery Key, simply go to File -> Recovery Key -> Create… and follow the steps2. You will be asked to print your key. It will look something like this:
The included QR Code allows you to use your Mac’s camera to scan the key instead of typing all those characters.
You should print the recovery key and test it by selecting File -> Recovery Key -> Test… Finally, store it some place safe.
You can also entrust a copy of your Recovery Key to someone you trust in the event something happens to you. This isn’t something most of us ever think about. But our digital selves grow bigger everyday. And in the event that, for some drastic reason, you are unable to access your passwords… your next of kin will be able to with as little friction as possible.
This feature will eventually make its way to Secrets for iOS. ↩
Recovery keys are per device and are not synced via iCloud. You can only use a recovery key on the device that created it. ↩
The great team at Panic just launched Transmit 5, a great update to an already awesome file transfer app for Mac. The news prompted this post about a little-known feature built into Secrets for Mac.
Since the first version of Secrets if you hover over a service associated with a Login you can quickly connect to that service by clicking the button. For example, if you have https://www.icloud.com associated with your Apple ID Login clicking that button will open that page on Safari.
This feature works out of the box for http and https services using Safari or Chrome, and ssh, sftp, ftp, telnet using Terminal. But if you have Transmit installed on your Mac, Secrets will prefer to use it for all service types it supports, includings services such as Amazon S3 and WebDav!
This site, for instance, is hosted on Amazon s3. I have a Login item in Secrets with the credentials for accessing the S3 bucket and an associated service with the URL s3://s3.amazonaws.com/outercorner.com. Everytime I need to update the site, I can just click the button and it will open a Transmit window already connected to the bucket.
Go ahead, give it a try. This integration works with both Transmit 5 and Transmit 4.
When you first run Secrets the main window will open with an item list on the left and a detail pane one the right. This layout is very common on the Mac, Apple’s Mail and Contacts applications use it also. You select an item on the left to view its details on the right. For the majority of users it’s a well-known concept.
This layout works very well when you need to view or edit your item’s details. However, when designing Secrets, it was clear that most of the time the interaction with the application would be a quick and simple information retrieval, such as getting a password, a credit card number or filling a login in the web browser. In this scenario, a smaller window focused on searching would be a better fit.
That’s why you can hide the detail pane since the very first version of Secrets. You can try this yourself by selecting View and then Hide Detail Pane in Secrets’ menubar, or by using the keyboard shortcut ⇧⌘D.
You may be wondering how do you retrieve a password or credit card number if the detail is closed… Well, you just select the item you want and press ⌘C to copy the most relevant information for that item type to the clipboard. For Logins this will be the password, for Credit Cards the card number and for Bank Accounts the account number. Also, if you use the alternate ⌥⌘C keyboard shortcut you’ll copy the username for Logins and the PIN for credit cards.
This collapsed mode also works great for when your filling logins in Safari. And if you have a small screen on your Mac you can make use of the Split View feature introduced in El Capitain to have Secrets and Safari open side by side in fullscreen.
If need to access some other information or edit an item you can open the detail pane again, obviously, or simply double click the item to show the item’s details without expanding the detail pane.