Authenticated encryption
Session packets use AES-256-GCM. Invalid authentication tags, replayed packets and unsupported message sizes or types close the connection.
The code controls access; encryption protects the connection. Keep both endpoints trusted.
Security measures implemented in the current app.
Session packets use AES-256-GCM. Invalid authentication tags, replayed packets and unsupported message sizes or types close the connection.
X25519 ephemeral keys provide forward secrecy. Password-derived proofs authenticate both sides and bind the key exchange.
Host generates a 12-character code. The password derivation uses 200,000 PBKDF2 rounds. Stop sharing before generating a new code.
This handshake is not a password-authenticated key exchange (PAKE). Captured handshakes allow offline code guesses. Keep the generated random code and share it only with the intended viewer.
There is no vendor relay in the session.
The PCs communicate directly over a reachable network. A VPN may add its own routing or relay. Encrypted traffic still travels through the network between the endpoints; direct does not mean it always stays on your LAN.
Normal app sessions do not upload screens to a cloud service or save recordings.
Choose a route that you can configure and verify.
No internet connection is required when the two PCs can reach each other on a LAN.
You need a suitable VPN or router configuration. Automatic relay-assisted connectivity is not included.
This beta targets Windows 10/11 x64. The host must be signed in and unlocked. UAC prompts, login screens, Ctrl+Alt+Delete and higher-privilege applications are not supported. Automated tests pass; native input on two separate PCs still needs verification.
Anyone who has the reachable host address and current secret code can connect while sharing is enabled. Stop sharing when the session is finished.
Download the free basic beta. Keep both desktops signed in and use the host’s generated code.