Skip to content

Safety on your machines

roamd runs on your computer, so it's built to be careful there.

 +----------------------- your computer -----------------------+
 |                                                             |
 |  roamd                                                      |
 |   - runs as YOU, never as the all-powerful admin            |
 |   - only lets in browsers you approved at this computer     |
 |   - writes down every login attempt (access.log)            |
 |   - refuses to start if other users could read its files    |
 |   - its secret files only work on THIS computer             |
 |   - offers a command line, and nothing else                 |
 |                                                             |
 +-------------------------------------------------------------+

It won't run as the administrator. Anyone you approve gets the powers of the account roamd runs as, so roamd stays in your normal account unless you deliberately say otherwise.

It only offers a terminal. It refuses the extra tricks remote-login programs sometimes allow (tunnelling other connections through, forwarding keys and so on), which attackers like to abuse.

You can see and control who gets in.

  • roamd keys lists the approved browsers.
  • roamd keys revoke … removes one, immediately.
  • access.log records every attempt, allowed or refused.

Its secrets are sealed to this computer. The computer's ID key and its connection token are locked so that a copy of roamd's folder (in a backup, a synced folder or an email) is useless anywhere else. Windows and Mac use their built-in secure storage; on Linux the files are private to your user, the same way SSH keys are kept.

Removing it is clean. Remove the computer in My devices or run roamd logout: it's deleted from your account, its token stops working, and roamd stops.

Process and privilege

Control Detail
No root / Administrator Refuses to run as root (Unix) or elevated (Windows) unless --allow-root is given; the service installer always refuses
Settings permission check (Unix) Refuses to start unless the settings folder and its secret files belong to the user, are private (0700 / 0600) and aren't symlinks. New files are created private, written atomically
Autostart Per-user only: systemd user unit (NoNewPrivileges), LaunchAgent, or least-privilege logon task; no system services

SSH server policy

Setting Value
Authentication Public key only, from the approved list; a few failures end the connection
Timeouts and limits Unauthenticated connections are dropped quickly; sessions and connections are capped; dead connections are detected by keepalives
Refused Port forwarding (both directions), agent forwarding, X11, subsystems (including SFTP), environment variables
Offered An interactive terminal (PTY / Windows ConPTY), and nothing else

Secrets at rest

 host key, device settings
    |
    +-- Windows: DPAPI (per user), stored in local, non-roaming AppData
    +-- macOS:   XChaCha20-Poly1305 under a key held in the login Keychain
    +-- Linux:   owner-only files (no universal keystore on servers)

Each sealed file is bound to its name. A sealed file copied to another machine or user, or edited, fails with a clear "sealed on another machine or user" error. DPAPI is tested under Wine; the macOS Keychain path is not yet run on a real Mac. Malware running as the same user can usually still reach the keystore: sealing protects copies, not a compromised account.

Audit and control

  • access.log: UTC timestamp, event (login accepted or refused, connection closed or refused), key fingerprint. Owner-only, rotated automatically.
  • The approved-keys list is re-read on every attempt, so roamd keys revoke applies to a running agent immediately. A damaged list admits nobody.
  • Removing a machine (from the web app or roamd logout) deletes it on the hub. Its token stops working and roamd run exits.

Known gap: revoking a key or removing a machine doesn't yet close terminals already open.