The Stack Overflow Podcast · The Stack Overflow Podcast

Prevent agentic identity theft

March 27, 2026·25 min·1 clip
1Password says its zero-knowledge architecture means the company cannot see inside a credential vault.
The risk starts on the developer machine. Ryan Donovan sets up the episode around local agent security, then Nancy Wang pulls it back to the credential systems developers already use every day. She starts with engineering, not security theater. Her story begins with a father in northwestern rural Wisconsin who fixed cars, worked as a metallurgist, and made machines and broken parts feel real early on. The biographical detour earns its place because the rest of the conversation keeps treating agent security as a systems problem. The hard part is what these agents can touch. Wang is most worried about credential access. If an agent can call skills tied to malware packages, ordinary automation starts looking a lot like an identity and access issue. Donovan keeps the threat model easy to picture with the disposable agent reaching into a credential store. Wang comes back to the choke point: API keys and SSH keys. Developers need them for production work, and now their agents may need them too. She thinks the guardrails are late. Agent use in production is already moving faster than the controls many teams expected would shape it. OpenClaw is the example she uses for why open source agent projects will not stay on a tidy path. 1Password's answer is local and signal heavy. Because it already sits on customer endpoints through device trust, it can read runtime behavior, user behavior, locally running software, and package context. That changes the ask from whether a secret exists to whether the access looks permitted or strange enough to stop. Passkeys and biometrics sit nearby as extra checks. The close returns to agent identities, with Wang asking listeners to send the questions on their minds.

As heard by us

A practical discussion of agent security as a credential, endpoint signal, and identity problem.

Agent security becomes concrete here: local software agents are already reaching for the same credential stores, packages, API keys, and SSH keys developers use every day.

Read the full review in PlayNext →

Why you'd press play

You need the security model before local agents start touching your keys.

Read the full recommendation in PlayNext →
Listen to the show on