Ci

Cifer, zero-key custody using threshold cryptography

Hacker News

Cifer, zero-key custody using threshold cryptography

I built CIFER, a distributed encryption + access-control system designed so that no component ever holds a complete decryption key at rest. Core idea: each “secret” (per user or per dataset) has its own independent post-quantum keypair. There is no master key. Architecture summary: Control plane: verifiable ownership, delegation, revocation, and append-only audit records (tamper-evident authorization history) Custody plane: 5 custody nodes running in TEEs, each storing 1 key fragment Orchestration: validates authorization then collects fragments to reconstruct keys only when needed Key custody model: Private key is generated in a TEE then immediately split via Shamir secret sharing into 5 fragments Fragments are distributed to independent custody nodes Original private key is destroyed Threshold is 3-of-5 for reconstruction Each custody node independently verifies authorization against the control plane before releasing its fragment Clusters are disabled if membership changes (node exits disable the cluster) Encryption scheme (hybrid PQ + symmetric): Fetch ML-KEM-768 public key from content-addressed storage, verify integrity ML-KEM-768 encapsulation per message/file/chunk to derive a fresh shared secret Derive one-time AES key + IV via HKDF-SHA256 Encrypt payload with AES-256-GCM Output includes a fixed-size envelope: ML-KEM ciphertext (1088 bytes) + GCM tag (16 bytes) Decryption flow: Requester signs a decryption request Orchestrator checks owner/delegate status + freshness window (replay defense) Orchestrator requests fragments in parallel, accepts the first 3 valid fragments Reconstructs the private key and decrypts Audit logs record the operation Reconstructed keys may be cached in memory for 36 hours (availability vs exposure tradeoff) Design goal: reduce blast radius from insider threats and single-node compromise, and address long-term confidentiality via post-quantum KEM. I would love feedback on: TEE trust assumptions and practical hardening for custody nodes Whether 36h key caching is acceptable, and safer alternatives Control plane failure modes (partition, reorg) and best practices for “deny by default” behavior Metadata strategy for large-file workflows (I currently keep filename/size in plaintext metadata) Better approaches for custody node independence and anti-collusion guarantees

Share card

Actual performance

2points
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: model, user, single · Missing: mac, agents, macos
83%83% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Strong signals: para · Missing: supports, reddit linkedin, podcasting
65%65% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsStrong engagement from HN community · Strong signals: ide, io · Missing: https docs, excited, just released
52%52% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
AppSumoMay struggle as an AppSumo deal · Missing: plus, platform, intuitive
44%44% predicted probability of success on AppSumo, based on ML models trained on real launch data.
TrustMRRLess likely to generate early MRR · Strong signals: para · Missing: mobile apps, ios, personal
32%32% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
19%19% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Strong signals: crypto · Missing: web3, chat, cryptocurrency
1%1% predicted probability of success on BetaList, based on ML models trained on real launch data.

Incorrect prediction on native model

Similar products

Ga
Gact/Key39%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Gact/Key

Hacker News1
Cr
Crypto Wallet using any FIDO2 key (as Yubikey)45%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Crypto Wallet using any FIDO2 key (as Yubikey)

Hacker News2
Su
Subscribable Key Value store using NATS50%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Subscribable Key Value store using NATS

Hacker News1
Ke
Key Value store using HFS+ extended attributes38%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Key Value store using HFS+ extended attributes

Hacker News3
No
Nooot – Share text using the key phrase, access it from anywhere45%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Nooot – Share text using the key phrase, access it from anywhere

Hacker News42
Pu
Public Key Login Using Keybase42%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Public Key Login Using Keybase

Hacker News3
Ze
Zero-configiration systemd containers57%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Zero-configiration systemd containers

Hacker News2
Ze
Zero-configiration systemd containers57%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Zero-configiration systemd containers

Hacker News28
k3
k3sup – Zero to kubectl56%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

k3sup – Zero to kubectl

Hacker News1
Co
Courier Primal – Courier Prime with a slashed zero48%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Courier Primal – Courier Prime with a slashed zero

Hacker News2