Show HN:Entropy——在SaaS时代,共享屏幕令人恐惧
Show HN: Entropy – Sharing screen is scary in SaaS age

原始链接: https://entropysec.io/

Entropy是一款Chrome扩展程序,旨在保护屏幕共享期间的敏感信息(密钥和个人身份信息)。它提供三种定价方案: * **基础版(免费):** 使用正则表达式、熵值和通用过滤器提供实时密钥和个人身份信息检测。 * **专业版(每月3.99美元):** 包含所有基础版功能,此外还包括自动启用屏幕共享检测、自定义设置、复制粘贴警报、检测历史记录和审计功能。 * **企业版:** 提供团队同步、集中策略执行、审计跟踪、Slack/SIEM集成和基于大型语言模型的检测。请联系他们了解价格。 Entropy能够检测各种密钥和个人身份信息,而不会显著降低浏览器速度。它允许自定义要检测或忽略的内容。该扩展程序强调主动安全,确保在演示或共享屏幕时模糊处理和保护密钥。旨在在GitHub密钥扫描或TruffleHog可能不足时提供额外的安全措施。

Entropy是一款Chrome扩展程序,旨在防止在屏幕共享期间意外泄露敏感信息,它已在Hacker News上发布。该程序能够实时识别API密钥、令牌和电子邮件,并应用模糊遮盖。扩展程序在本地使用正则表达式和编译到WASM的熵启发式算法运行,最大限度地减少CPU使用率。用户可以为专有的令牌格式添加自定义规则。 反馈指出,初始登陆页面未能清晰地传达扩展程序的目的。同时也有人担心使用模糊处理而不是实心的黑色遮挡条,因为模糊的数据可能被重建。一些用户对向一个封闭源代码的扩展程序授予访问所有网站数据的权限表示担忧。一个潜在的改进建议是面向需要在性能报告中隐藏客户数据的广告公司。功能需求包括可自定义的遮挡方法(例如,黑色遮挡条、菊花图案)以及专注于替换不太敏感的私人信息以用于演示屏幕录制。

原文

Entropy

Share Screens, Not Secrets.

Hide your Secrets and PIIs from



|

Share Screens, Not Secrets.

Hide your Secrets and PIIs from



|

Pricing Plans

Pricing Plans

Essential

Free.

Real-time secret/PII detection

Regex + entropy detection

Generic detection filters

Pro

$3.99 / month

Auto-enabled in screen share

Custom regex & entropy settings

Copy-paste alert for secrets

Detection history & audits

Get Pro

Get Pro

Get Pro

Get Pro

Enterprise Browser Security

Let's Talk

Team sync of detection rules

Centralized policy enforcement

Audit trail for secret reveals

')" class="framer-qfjqf5" aria-hidden="true">

Integration with Slack/SIEM alerting

LLM-based detection

Enterprise Browser Security

Let's Talk

Team sync of detection rules

Centralized policy enforcement

Audit trail for secret reveals

')" class="framer-qfjqf5" aria-hidden="true">

Integration with Slack/SIEM alerting

LLM-based detection

Enterprise Browser Security

Let's Talk

Team sync of detection rules

Centralized policy enforcement

Audit trail for secret reveals

')" class="framer-qfjqf5" aria-hidden="true">

Integration with Slack/SIEM alerting

LLM-based detection

Enterprise Browser Security

Let's Talk

Team sync of detection rules

Centralized policy enforcement

Audit trail for secret reveals

')" class="framer-qfjqf5" aria-hidden="true">

Integration with Slack/SIEM alerting

LLM-based detection

FAQ

FAQ

What types of secrets and PII can it detect?

Will it slow down my browser or affect my workflow?

Is my data sent to a server?

Can I customize what’s detected or ignored?

Why wouldn’t I just use GitHub secret scanning or TruffleHog?

What types of secrets and PII can it detect?

Will it slow down my browser or affect my workflow?

Is my data sent to a server?

Can I customize what’s detected or ignored?

Why wouldn’t I just use GitHub secret scanning or TruffleHog?

What types of secrets and PII can it detect?

Will it slow down my browser or affect my workflow?

Is my data sent to a server?

Can I customize what’s detected or ignored?

Why wouldn’t I just use GitHub secret scanning or TruffleHog?

Your Secrets -

secured, and

blurred!

Take charge of your secrets with Entropy browser extension – your browser security tool, when you meet, present, and share your screen to the world.

Your Secrets -
secured, and
blurred!

Take charge of your secrets with Entropy browser extension – your browser security tool, when you meet, present, and share your screen to the world.

联系我们 contact @ memedata.com