Security at Farhand

Remote control is powerful, so we built Farhand so that nobody but you, including us, can see or control your computer.

Pairing: a key that only your devices have

When you set up a computer, the host creates a random 256-bit pairing key and shows it in a QR code. Your iPhone reads the key from the code and keeps it in the iOS Keychain (synced to your other Apple devices through iCloud Keychain, which Apple encrypts end to end). After pairing, the key never crosses the network.

Every connection is mutually authenticated

Before any screen data flows, your device and your computer each prove they hold the pairing key, using fresh random challenges (HMAC-SHA256). A computer that can't prove it has the key is rejected, and so is a device that can't.

End-to-end encryption

Each session derives its own keys from the pairing key (HKDF-SHA256). Every message, frame and keystroke is encrypted with AES-256-GCM and numbered, so replayed or reordered messages are rejected.

This is the same whether you're on your home network or connecting through the Farhand relay. The relay only pairs your device with your computer and passes ciphertext along. It can't decrypt it, because it never has the key.

Farhand on the web

A browser needs a computer's pairing key to connect, and we never have it to give. So you link the browser from your iPhone:

  1. The web page creates a new P-256 key pair and shows the public key in a QR code.
  2. Your iPhone scans it and encrypts your computers' pairing keys to that public key (ECDH, HKDF-SHA256, AES-256-GCM).
  3. Our servers pass the encrypted package to that browser, and only between two devices signed in to the same account. Then they delete it.

In the browser, keys are stored as non-extractable WebCrypto keys: the page can use them to connect, but can't read them back out. Signing out deletes them. The web app loads no third-party scripts apart from Apple's Sign in with Apple, and runs under a strict Content Security Policy.

Your account

WhatHow it's protected
Sign-inSign in with Apple. We never see a password.
SessionsShort-lived access tokens (15 minutes) and refresh tokens that rotate on every use. A reused refresh token ends the whole session.
Relay accessSigned tokens valid for two minutes, checked by each relay node. Removing a computer or ending a subscription cuts live connections immediately.
ComputersEach has its own credential, stored hashed. Removing it from your account revokes it.

What we can't protect against

Anyone who can unlock your iPhone, or use a browser you've linked while you're signed in, can control your computers. Use a device passcode, sign out of the web app on shared computers, and remove devices you no longer use. If you think a pairing key has leaked, reset it from the host (it unpairs every device) and scan the new code.

Reporting a vulnerability

Please email security@farhandapp.com with the details, and give us a chance to fix the issue before sharing it publicly.