Pairing: a key that only your devices have
When you set up a computer, the host creates a random 256-bit pairing key and shows it in a QR code. Your iPhone reads the key from the code and keeps it in the iOS Keychain (synced to your other Apple devices through iCloud Keychain, which Apple encrypts end to end). After pairing, the key never crosses the network.
Every connection is mutually authenticated
Before any screen data flows, your device and your computer each prove they hold the pairing key, using fresh random challenges (HMAC-SHA256). A computer that can't prove it has the key is rejected, and so is a device that can't.
End-to-end encryption
Each session derives its own keys from the pairing key (HKDF-SHA256). Every message, frame and keystroke is encrypted with AES-256-GCM and numbered, so replayed or reordered messages are rejected.
This is the same whether you're on your home network or connecting through the Farhand relay. The relay only pairs your device with your computer and passes ciphertext along. It can't decrypt it, because it never has the key.
Farhand on the web
A browser needs a computer's pairing key to connect, and we never have it to give. So you link the browser from your iPhone:
- The web page creates a new P-256 key pair and shows the public key in a QR code.
- Your iPhone scans it and encrypts your computers' pairing keys to that public key (ECDH, HKDF-SHA256, AES-256-GCM).
- Our servers pass the encrypted package to that browser, and only between two devices signed in to the same account. Then they delete it.
In the browser, keys are stored as non-extractable WebCrypto keys: the page can use them to connect, but can't read them back out. Signing out deletes them. The web app loads no third-party scripts apart from Apple's Sign in with Apple, and runs under a strict Content Security Policy.
Your account
| What | How it's protected |
|---|---|
| Sign-in | Sign in with Apple. We never see a password. |
| Sessions | Short-lived access tokens (15 minutes) and refresh tokens that rotate on every use. A reused refresh token ends the whole session. |
| Relay access | Signed tokens valid for two minutes, checked by each relay node. Removing a computer or ending a subscription cuts live connections immediately. |
| Computers | Each has its own credential, stored hashed. Removing it from your account revokes it. |
What we can't protect against
Anyone who can unlock your iPhone, or use a browser you've linked while you're signed in, can control your computers. Use a device passcode, sign out of the web app on shared computers, and remove devices you no longer use. If you think a pairing key has leaked, reset it from the host (it unpairs every device) and scan the new code.
Reporting a vulnerability
Please email security@farhandapp.com with the details, and give us a chance to fix the issue before sharing it publicly.