FlashDesk భద్రత

Remote control కోసం అవసరమైన communication, connection approval, device verification మరియు operational management ను సురక్షితంగా నిర్వహించేందుకు FlashDesk రూపొందించబడింది.

ప్రతి session కు encryption

Screen video మరియు control data session ప్రారంభమైనప్పుడు సృష్టించే keys తో encrypted అవుతుంది. Key exchange ECDH P-256 ఉపయోగిస్తుంది, key derivation HKDF-SHA256 ఉపయోగిస్తుంది, encryption AES-256-GCM ఉపయోగిస్తుంది.
ప్రతి packet లో sequence number మరియు authentication tag ఉంటాయి; tampering మరియు పాత replay packets detect చేయవచ్చు.

ముందుగా P2P, అవసరమైతే relay

Session సమయంలో video మరియు control data సాధ్యమైనప్పుడు devices మధ్య direct గా పంపబడుతుంది. Direct connection సాధ్యం కాకపోతే FlashDesk relay routing కు మారుతుంది; అయినప్పటికీ media మరియు control payload session key తో encrypted గానే ఉంటాయి.

Destination side లో స్పష్టమైన permission

Destination side లో access manual approval లేదా password-based authorization ద్వారా allow చేయవచ్చు. Manual approval connection ను ఒక్కసారి మాత్రమే లేదా ఎంచుకున్న సమయానికి allow చేయగలదు. Time-limited sessions సమయం ముగిసినప్పుడు automatically disconnect అవుతాయి.

Device fingerprint verification

FlashDesk ప్రతి installation కు device identity key సృష్టించి, public key నుండి fingerprint పొందుతుంది. గతంలో trusted destination fingerprint మారితే FlashDesk warning చూపుతుంది, destination device మారిందా అని మీరు తనిఖీ చేయవచ్చు.

Signaling మరియు license communication

FlashDesk connections ప్రారంభించడానికి మరియు candidate information exchange చేయడానికి WebSocket over TLS (wss://) ఉపయోగిస్తుంది. License verification వంటి API communication HTTPS ఉపయోగిస్తుంది. Signaling server connection ప్రారంభించడానికి అవసరమైన సమాచారాన్ని relay చేస్తుంది; media communication established encrypted session లో జరుగుతుంది.

బాహ్య TLS సర్టిఫికేట్

FlashDesk సిగ్నలింగ్ కమ్యూనికేషన్ HTTPS / TLS పై WebSocket ను ఉపయోగిస్తుంది. క్రింద ఉన్న పబ్లిక్ TLS సర్టిఫికేట్ సమాచారం సర్వర్ నుండి పొందబడుతుంది మరియు సర్టిఫికేట్ మారినప్పుడు స్వయంచాలకంగా నవీకరించబడుతుంది.

డొమెయిన్లు
సర్టిఫికేట్ సమాచారం లోడ్ అవుతోంది...
జారీదారు
సర్టిఫికేట్ సమాచారం లోడ్ అవుతోంది...
SHA-256 ఫింగర్‌ప్రింట్
సర్టిఫికేట్ సమాచారం లోడ్ అవుతోంది...
గడువు
సర్టిఫికేట్ సమాచారం లోడ్ అవుతోంది...

సర్టిఫికేట్ సమాచారం తాత్కాలికంగా అందుబాటులో లేదు.

బాహ్య భద్రతా పరీక్ష

FlashDesk తన పబ్లిక్ వెబ్‌సైట్ మరియు సంబంధిత endpoints కోసం OWASP ZAP ఉపయోగించి భద్రతా పరీక్షను పూర్తి చేసింది. Mozilla Observatory, SSL Labs మరియు Security Headers లో A లేదా అంతకంటే ఎక్కువ రేటింగ్‌లను కూడా నిర్ధారించాము.

OS permissions మరియు local protection

FlashDesk ప్రతి OS కు అవసరమైన permission flows ను అనుసరిస్తుంది, ఉదాహరణకు macOS Screen Recording మరియు Accessibility permissions, Linux Wayland screen sharing permissions. Saved connection information మరియు passwords plaintext storage కాకుండా process చేయబడతాయి.

FlashDesk సర్వర్లు నిర్వహించే డేటా

FlashDesk servers may handle the following information as needed for service operation, abuse prevention, support, billing, and team administration.

DataPurposeStored or temporaryNotes
FlashDesk ID / device identifierConnection start, device lookup, license associationStored where neededUsed to identify devices and route requests.
Device fingerprint public informationDevice verification and ID bindingStored as a hash where applicableThe server stores fingerprint-related hashes, not the private identity key.
App version and OS typeCompatibility, support, and operational analysisStored or updated with client statusShown in admin and support contexts where applicable.
Connection status and path statusConnection maintenance, seat control, admin visibilityTemporary during sessions; selected audit records for ProIncludes whether a session is direct, relay, or probing when reported.
IP address and network metadataService operation, abuse prevention, diagnosticsStored in operational records where neededMay include last seen IP, download tracking, and WebSocket diagnostic metadata.
License / subscription statusLicense verification, billing, seat managementStored where neededPayment card details are handled by the payment provider, not by FlashDesk.
Error logs or operational logsSupport, outage investigation, abuse preventionStored as operational logs; server logs are automatically deleted after 30 daysWebSocket logs redact ssh_tunnel_data payloads; other metadata may be logged for diagnostics.
Admin console activity for Pro usersTeam administration, license and session reviewStored as admin recordsIncludes organization, user, license, seat, and session audit records.

FlashDesk సర్వర్లు నిల్వ చేయని డేటా

FlashDesk servers do not store the following information during ordinary remote connections:

  • remote screen video contents
  • keyboard input contents
  • mouse operation contents
  • file transfer contents
  • SSH tunnel payload contents handled as ssh_tunnel_data
  • recorded session video contents

Network endpoints మరియు protocols

The following table summarizes communication that administrators may want to review before deployment.

PurposeProtocolPortTypical destinationNotes
Website / downloadHTTPS443/TCPFlashDesk official serversDownload pages show the version and SHA-256 checksum for official release files.
SignalingWebSocket over TLS (wss://)443/TCPflashdesk.io/wsUsed to start sessions and exchange candidate information.
API / license checkHTTPS443/TCPflashdesk.io/api/license/verifyUsed when checking a registered license key and seat status.
Update checkHTTPS443/TCPflashdesk.io/data/latest.json and package pathsThe app periodically checks the update manifest over HTTPS, downloads update packages from official servers, and verifies the expected SHA-256 hash before applying an update.
STUN / P2P candidate checkUDP3478/UDPFlashDesk official serversUsed to discover a reachable network endpoint before attempting direct P2P.
Direct P2P connectionUDP media/control pathDynamic UDP ports on peer devicesPeer device network endpointsDirect connection is preferred when NAT/firewall conditions allow it.
Relay connectionEncrypted media/control payloads over the relay path40020/UDP in the current desktop appFlashDesk relay serverUsed when a direct device-to-device path is not available. SDK relayws responses use 443/TCP.

Relay server behavior

FlashDesk first attempts a direct device-to-device path. Because NAT, firewall, VPN, and mobile-network conditions can prevent direct UDP communication, sessions may continue through a relay path when needed.

When relay routing is used, the relay server forwards packets for the session. Media and control payloads continue to be encrypted with the per-session key, and packets include authentication data used to detect tampering or replayed old packets.

ఇన్‌స్టాలేషన్ మరియు background behavior

FlashDesk can run in the background and can start automatically with the OS when the setting is enabled. The current default setting enables OS startup.

  • Windows: startup is managed through a user logon scheduled task named FlashDesk_Autostart, with a legacy Run-key fallback check.
  • macOS: startup is managed through a LaunchAgent plist.
  • Linux: startup is managed through XDG Autostart.

OS permissions are requested only as needed for features. macOS may require Screen Recording for screen capture and Accessibility for remote input control. Linux Wayland sessions use the desktop portal / PipeWire screen-sharing flow. FlashDesk periodically checks an HTTPS update manifest, downloads update packages from official servers, and verifies the expected SHA-256 hash before applying an update.

Local settings are stored under the user's application data folder in FlashDesk/flashdesk_settings.json. Local app logs are written under the user's local application data folder in FlashDesk/logs with a 7-day retention setting in the current app code. Local screen recordings, when enabled by the user, are stored under FlashDesk/recording on the user's device.

File authenticity మరియు code signing

Download pages show the version and SHA-256 checksum for official release files. Before installation, users can compare the downloaded file's SHA-256 checksum with the value published on the download page.

  • Windows: FlashDesk .exe files are signed with Authenticode. You can check the signature from file Properties > Digital Signatures, or run Get-AuthenticodeSignature .\FlashDesk.exe in PowerShell.
  • macOS: FlashDesk .pkg and .app distributions are signed with Apple Developer ID certificates and notarized by Apple.
  • Linux: verify the published SHA-256 checksum for .deb, .rpm, and AppImage downloads.

Vulnerability reporting

Security issues కోసం Contact page ఉపయోగించి subject లో [Security] చేర్చండి.

Please include the affected version, OS, reproduction steps, logs if available, and screenshots if relevant.

Operational recommendations

Shared PCs లో saved passwords నివారించండి, అవసరం లేని destinations delete చేయండి, గుర్తు లేని fingerprint changes approve చేయవద్దు, long-running sessions కోసం time limits లేదా automatic disconnect ఉపయోగించండి.