Skip to Main Content
Back to blog

Don’t bring exposed developer credentials to Black Hat

by Eric Eddy

July 9, 2026 - 3 min

Isometric illustration of the 1Password logo at the center of a network, connected by lines to floating icons representing SSH keys, API keys, an AI agent, and credential surfaces, set against a deep blue grid background.

Related Categories

Black Hat is where the security industry gathers to compare notes on current cybersecurity topics. It brings together a diverse group of security experts, from C-suite executives to black-hat hackers. Some attendees see it as a target-rich environment for testing their latest hacks. 

Many hackers and supply chain attacks rely on the fact that local credentials are stored in predictable locations with standardized file names, in clear text. For example, AWS credentials usually live in ~/.aws/credentials because the CLI writes them there by default. SSH keys live in ~/.ssh. 1Password developer tools can secure these credentials.

It’s never a bad time to secure locally-stored developer credentials, but if you’re attending Black Hat, this might be an especially good time. Secure your credentials in 1Password before the conference, and find us at the booth to get an exclusive sticker. 

Find and secure SSH keys

Developer watchtower discovers SSH keys that are stored in plaintext or use outdated cryptography. Follow the documentation to discover and secure your local SSH keys, which you can then access from the terminal using biometrics, just the same way you do for your passwords. 

Secure environment variables (Beta)

1Password Environments make your Environment’s variables available via locally mounted .env files, without writing your credentials to disk. You can securely share them with team members and access them programmatically in your terminal via our CLI or via our SDK in Go, JavaScript, or Python integrations. Follow the documentation to secure and mount your environment variables.

Find us at booth 4735

Located in the main exhibit hall near the Bayside C escalators.

If you’re attending the conference please come say hello, pick up some stickers, and ask us all your questions about 1Password developer tools! Play our developer challenge, Credential Sprawl Capture the Flag to win exclusive swag and get your name on our leaderboard.

We’ll be running live demos and having technical discussions throughout the conference that cover our developer and AI tools, including: 

  • Developer Watchtower scans your local disk for exposed SSH keys, flags what’s vulnerable, and walks you through remediation. By Black Hat, we will enhance Developer Watchtower to discover and vault even more developer secrets.

  • 1Password Credential Broker, currently in private beta with Github Actions, eliminates standing pipeline credentials so workloads get access when they need it and lose it when the job is done. 

  • Secure Agentic Autofill delivers credentials in memory, scoped to the task for AI-coding agents, while the local MCP server connects directly to 1Password Environments, keeping raw values out of the AI context window.

Not attending Black Hat?

If you’re not going to the conference, find us online! We just shipped a new version of our Developer documentation site, 1password.dev, with new workflow-based getting-started guides, instructional videos, and tools to build with AI coding assistants, including llms.txt files, Markdown rendering by appending .md to any URL. Cursor, Copilot, Windsurf, and Claude can pull 1Password documentation directly. Enter Ctrl+K on any page, ask in plain language, and get a direct answer with links to the relevant pages.

Find us at Mandalay Bay

We will be in Las Vegas from August 1st through 6th. Bring your hardest supply chain scenario from the past year. That is the conversation we came to have.

The attacker knows what's on your disk. Do you?

Every 1Password plan includes a free 14-day trial. Run Developer Watchtower before Black Hat, vault what you find, and come share your experience in our booth 4735 to claim your prize.