What we can and can't see¶
What we (the roamd service) can see¶
| Yes, we can see | No, we can't see |
|---|---|
| Your email address | Your master password |
| That you have an account, and when you log in | What's inside your vault |
| The names of your computers, and whether they're online | Your browser key |
| When you connect to a computer, and for how long | Anything you type or see in a terminal |
| Your internet address (as any website does) | Your recovery key |
| What Voice says or hears (it all happens in your browser) |
what travels through us:
your typing --> [ LOCKED ] --> passes through us --> [ LOCKED ] --> your computer
^ ^
locked by your unlocked only by
browser your computer
Cloudflare, the network company in front of our website, handles the same traffic we do, so it can see the same things we can (the left column), and nothing in the right column.
If our servers were broken into¶
Someone who stole our database would get emails and locked vaults. To open a vault they'd have to guess your master password, and every guess is deliberately slow. A long, unique master password keeps you safe even then.
Limits¶
We'd rather you hear these from us.
- roamd is a website. Your browser runs code our server sends it. If someone took over our server, they could send changed code that captures your password as you type it. We block code from anywhere else, but the real fix is the downloadable apps we plan to make, whose code is signed and doesn't change behind your back.
- Emails aren't verified yet, and there's no check yet when you log in from a new device (coming: an emailed code, or Face ID / fingerprint).
- An open terminal stays open if you revoke a browser's access or remove the computer, until it's closed.
- Mac and Windows versions haven't yet been tested on real computers.
- This is a preview: don't rely on it for anything critical yet.
Data inventory (hub)¶
| Data | Stored as | Purpose |
|---|---|---|
| Plain, normalised | Account lookup | |
| Salt, Argon2 settings | Plain | Client key derivation |
| Login and recovery proofs | Hashed | Authentication |
| Vault key | Sealed twice (password key, recovery key) | Unlocked client-side only |
| Vault items | XChaCha20-Poly1305 ciphertext + revision | Sync (browser key, host pins, Voice settings) |
| Sessions and device tokens | Hashed | Web sessions, machine connections |
| Devices | Owner, name, host public key | Routing |
| Transient (memory only) | Login challenges, pending approvals, online tunnels, rate-limit counters | — |
| Logs | Startup and errors only: no request log, no bodies, no shell data | Operations |
The database is owner-only on the hub host. It contains no key that decrypts user data or logs in to a machine (tested: no raw proofs or tokens on disk).
Threat model¶
| Adversary | Protected | Not protected |
|---|---|---|
| Network attacker | TLS to the hub; SSH end to end; pinned host keys | Traffic analysis (timing, sizes) |
| Cloudflare (in front of the hub) | Shell traffic, vault contents, keys | The same metadata the hub sees |
| Hub database leak | Vault contents (Argon2id-bound); tokens and sessions (hashed) | Emails, device names; offline guessing of weak master passwords |
| Malicious or compromised hub (passive) | Shell traffic, vault, keys | Metadata: who connects to what, when |
| Malicious or compromised hub (active) | Machine authorisation (pairing codes), host impersonation (pins) | Serving modified web-app code (see below); denial of service |
| Stolen device token | Can't impersonate the machine (no host key) | Can connect to the hub as that device (disruption) |
| Copied machine settings | Sealed on Windows/macOS | Linux relies on file permissions |
| Malware on the user's machine or browser | — | Out of scope (as for any remote-access tool) |
Limits¶
- Web-delivered code: the web app (including its WebAssembly crypto) is served by the hub. An active hub compromise could serve code that captures the master password. Today's mitigations: a strict Content-Security-Policy (no third-party or inline script) and TLS. The structural fix is native apps or signed, pinned web bundles.
- Account security: no email verification and no new-device check yet (planned: emailed code, then passkeys).
- Revocation: revoking a key or removing a machine stops new logins at once; terminals already open stay open until closed.
- Platform coverage: the macOS and Windows agents haven't been tested on real hardware yet (Windows code paths are tested under Wine).
- Voice: Private mode never sends terminal text or audio off the device (see Voice). A planned cloud "Smart mode" would, and will be opt-in and labelled.
- Preview: not yet for critical use.