FlashDesk নিরাপত্তা
রিমোট কন্ট্রোলের জন্য যোগাযোগ, অনুমোদন, ডিভাইস যাচাই ও পরিচালনা নিরাপদে সামলাতে FlashDesk তৈরি। স্ক্রিন ভিডিও ও কন্ট্রোল ডেটা প্রতি সেশনে এনক্রিপ্ট হয়।
প্রতি সেশনে এনক্রিপশন
মিডিয়া ও কন্ট্রোল ডেটা সেশন শুরুর সময় তৈরি হওয়া কী দিয়ে এনক্রিপ্ট হয়। FlashDesk ECDH P-256, HKDF-SHA256 ও AES-256-GCM ব্যবহার করে।
সিকোয়েন্স নম্বর ও অথেন্টিকেশন ট্যাগ পরিবর্তন বা পুরনো প্যাকেট পুনরায় পাঠানো শনাক্ত করতে সাহায্য করে।
আগে P2P, দরকার হলে রিলে
সম্ভব হলে ভিডিও ও কন্ট্রোল ডেটা সরাসরি ডিভাইসের মধ্যে যায়। সরাসরি সংযোগ সম্ভব না হলে রিলে ব্যবহৃত হয়, তবে ডেটা এনক্রিপ্টেড থাকে।
গন্তব্য পাশে স্পষ্ট অনুমতি
অ্যাক্সেস ম্যানুয়াল অনুমোদন বা পাসওয়ার্ড দিয়ে দেওয়া যায়। অনুমোদন একবারের জন্য বা নির্দিষ্ট সময়ের জন্য হতে পারে, সময় শেষ হলে সংযোগ স্বয়ংক্রিয়ভাবে বন্ধ হয়।
ডিভাইস ফিঙ্গারপ্রিন্ট যাচাই
FlashDesk প্রতিটি ইনস্টলের জন্য ডিভাইস পরিচয় তৈরি করে। বিশ্বাসযোগ্য গন্তব্যের ফিঙ্গারপ্রিন্ট বদলালে যাচাইয়ের জন্য সতর্ক করে।
সিগন্যালিং ও লাইসেন্স যোগাযোগ
FlashDesk সংযোগ শুরুতে WebSocket over TLS (wss://) এবং লাইসেন্স API-তে HTTPS ব্যবহার করে। প্রতিষ্ঠার পর মিডিয়া এনক্রিপ্টেড সেশনে চলে।
বাহ্যিক TLS সার্টিফিকেট
FlashDesk সিগন্যালিং যোগাযোগ HTTPS / TLS-এর উপর WebSocket ব্যবহার করে। নিচের পাবলিক TLS সার্টিফিকেট তথ্য সার্ভার থেকে নেওয়া হয় এবং সার্টিফিকেট বদলালে স্বয়ংক্রিয়ভাবে আপডেট হয়।
- ডোমেইন
- সার্টিফিকেট তথ্য লোড হচ্ছে...
- ইস্যুকারী
- সার্টিফিকেট তথ্য লোড হচ্ছে...
- SHA-256 ফিঙ্গারপ্রিন্ট
- সার্টিফিকেট তথ্য লোড হচ্ছে...
- মেয়াদ শেষ
- সার্টিফিকেট তথ্য লোড হচ্ছে...
সার্টিফিকেট তথ্য সাময়িকভাবে পাওয়া যাচ্ছে না।
বহিরাগত নিরাপত্তা পরীক্ষা
FlashDesk OWASP ZAP ব্যবহার করে তার পাবলিক ওয়েবসাইট এবং সংশ্লিষ্ট এন্ডপয়েন্টগুলোর নিরাপত্তা পরীক্ষা সম্পন্ন করেছে। Mozilla Observatory, SSL Labs এবং Security Headers-এ A বা তার বেশি রেটিংও নিশ্চিত করা হয়েছে।
OS অনুমতি ও স্থানীয় সুরক্ষা
FlashDesk macOS, Linux Wayland ও অন্যান্য OS-এর অনুমতি প্রবাহ অনুসরণ করে। সংরক্ষিত সংযোগ তথ্য ও পাসওয়ার্ড প্লেইনটেক্সট এড়াতে প্রক্রিয়াকরণ করা হয়।
FlashDesk সার্ভার যে ডেটা পরিচালনা করে
FlashDesk servers may handle the following information as needed for service operation, abuse prevention, support, billing, and team administration.
| Data | Purpose | Stored or temporary | Notes |
|---|---|---|---|
| FlashDesk ID / device identifier | Connection start, device lookup, license association | Stored where needed | Used to identify devices and route requests. |
| Device fingerprint public information | Device verification and ID binding | Stored as a hash where applicable | The server stores fingerprint-related hashes, not the private identity key. |
| App version and OS type | Compatibility, support, and operational analysis | Stored or updated with client status | Shown in admin and support contexts where applicable. |
| Connection status and path status | Connection maintenance, seat control, admin visibility | Temporary during sessions; selected audit records for Pro | Includes whether a session is direct, relay, or probing when reported. |
| IP address and network metadata | Service operation, abuse prevention, diagnostics | Stored in operational records where needed | May include last seen IP, download tracking, and WebSocket diagnostic metadata. |
| License / subscription status | License verification, billing, seat management | Stored where needed | Payment card details are handled by the payment provider, not by FlashDesk. |
| Error logs or operational logs | Support, outage investigation, abuse prevention | Stored as operational logs; server logs are automatically deleted after 30 days | WebSocket logs redact ssh_tunnel_data payloads; other metadata may be logged for diagnostics. |
| Admin console activity for Pro users | Team administration, license and session review | Stored as admin records | Includes organization, user, license, seat, and session audit records. |
FlashDesk সার্ভারে সংরক্ষণ করা হয় না এমন ডেটা
FlashDesk servers do not store the following information during ordinary remote connections:
- remote screen video contents
- keyboard input contents
- mouse operation contents
- file transfer contents
- SSH tunnel payload contents handled as ssh_tunnel_data
- recorded session video contents
Network endpoint ও protocol
The following table summarizes communication that administrators may want to review before deployment.
| Purpose | Protocol | Port | Typical destination | Notes |
|---|---|---|---|---|
| Website / download | HTTPS | 443/TCP | FlashDesk official servers | Download pages show the version and SHA-256 checksum for official release files. |
| Signaling | WebSocket over TLS (wss://) | 443/TCP | flashdesk.io/ws | Used to start sessions and exchange candidate information. |
| API / license check | HTTPS | 443/TCP | flashdesk.io/api/license/verify | Used when checking a registered license key and seat status. |
| Update check | HTTPS | 443/TCP | flashdesk.io/data/latest.json and package paths | The app periodically checks the update manifest over HTTPS, downloads update packages from official servers, and verifies the expected SHA-256 hash before applying an update. |
| STUN / P2P candidate check | UDP | 3478/UDP | FlashDesk official servers | Used to discover a reachable network endpoint before attempting direct P2P. |
| Direct P2P connection | UDP media/control path | Dynamic UDP ports on peer devices | Peer device network endpoints | Direct connection is preferred when NAT/firewall conditions allow it. |
| Relay connection | Encrypted media/control payloads over the relay path | 40020/UDP in the current desktop app | FlashDesk relay server | Used when a direct device-to-device path is not available. SDK relayws responses use 443/TCP. |
Relay server behavior
FlashDesk first attempts a direct device-to-device path. Because NAT, firewall, VPN, and mobile-network conditions can prevent direct UDP communication, sessions may continue through a relay path when needed.
When relay routing is used, the relay server forwards packets for the session. Media and control payloads continue to be encrypted with the per-session key, and packets include authentication data used to detect tampering or replayed old packets.
ইনস্টলেশন ও background behavior
FlashDesk can run in the background and can start automatically with the OS when the setting is enabled. The current default setting enables OS startup.
- Windows: startup is managed through a user logon scheduled task named FlashDesk_Autostart, with a legacy Run-key fallback check.
- macOS: startup is managed through a LaunchAgent plist.
- Linux: startup is managed through XDG Autostart.
OS permissions are requested only as needed for features. macOS may require Screen Recording for screen capture and Accessibility for remote input control. Linux Wayland sessions use the desktop portal / PipeWire screen-sharing flow. FlashDesk periodically checks an HTTPS update manifest, downloads update packages from official servers, and verifies the expected SHA-256 hash before applying an update.
Local settings are stored under the user's application data folder in FlashDesk/flashdesk_settings.json. Local app logs are written under the user's local application data folder in FlashDesk/logs with a 7-day retention setting in the current app code. Local screen recordings, when enabled by the user, are stored under FlashDesk/recording on the user's device.
File authenticity ও code signing
Download pages show the version and SHA-256 checksum for official release files. Before installation, users can compare the downloaded file's SHA-256 checksum with the value published on the download page.
- Windows: FlashDesk .exe files are signed with Authenticode. You can check the signature from file Properties > Digital Signatures, or run
Get-AuthenticodeSignature .\FlashDesk.exein PowerShell. - macOS: FlashDesk .pkg and .app distributions are signed with Apple Developer ID certificates and notarized by Apple.
- Linux: verify the published SHA-256 checksum for .deb, .rpm, and AppImage downloads.
Vulnerability reporting
Security issues-এর জন্য Contact page ব্যবহার করুন এবং subject-এ [Security] দিন।
Please include the affected version, OS, reproduction steps, logs if available, and screenshots if relevant.
পরিচালনা পরামর্শ
শেয়ার করা PC-তে পাসওয়ার্ড সংরক্ষণ এড়ান, অপ্রয়োজনীয় গন্তব্য মুছুন, অচেনা ফিঙ্গারপ্রিন্ট পরিবর্তন অনুমোদন করবেন না, দীর্ঘ সেশনে সময়সীমা ব্যবহার করুন।