Security

What protects your phones from other people on the network, from relay operators and from web pages, and what is out of scope.

Droidline can read the screen of a paired phone and act on it. These are the protections around that, and their limits.

Pairing decides who may control a phone

A phone accepts commands only from the PC it paired with, and a PC accepts only phones it paired with. Pairing happens one of two ways:

  • QR code. It carries the PC's public key and a one-time token. The token is valid for 10 minutes and for one phone, and it never travels in plaintext: the phone proves it has the token by deriving the right keys.
  • 6-digit code. The phone shows a code derived from both sides' keys, and you type it on the PC. A device sitting in the middle would produce a different code on each side.

droidline revoke <device> removes a phone's key; it has to pair again to connect.

Everything after the handshake is encrypted

Every line between a phone and the PC is encrypted with AES-256-GCM. The keys come from two P-256 key exchanges, one with fresh keys per connection (so a key stolen later cannot decrypt old traffic) and one with the long-term keys (so both sides know who they talk to). This holds on every route, including the same Wi-Fi. A tunnel or relay, Cloudflare included, sees only device IDs, sizes and timing.

The design composes standard primitives (P-256, HKDF-SHA256, AES-GCM) in a pattern close to Noise KK, but it is not a Noise implementation and it has not been audited. The protocol and its test vectors are public.

Your code's side

  • The client port listens on 127.0.0.1. Other machines cannot reach it unless you change client.listen, and then every connection needs a client token (droidline token create). Tokens are stored as hashes.
  • The HTTP interface refuses requests from web pages (any Origin header not in client.allowed_origins), requests whose Host is not localhost (DNS rebinding), and POST bodies that are not JSON. A page you visit cannot drive your phones.

Secrets on the PC

The server's private key, the TLS key, the relay token and saved proxy passwords are stored with DPAPI under your Windows account, or in a file only your user can read on macOS and Linux. The phone keeps its private key encrypted with a key from the Android Keystore.

Out of scope

  • Anyone who can use your PC account can drive your phones, as with any automation tool you run.
  • The accessibility service can read whatever is on screen. Install the app only on phones you control.
  • Droidline does not unlock PIN, pattern or password lock screens.

Reporting a problem

Report vulnerabilities privately through GitHub: Security, then Report a vulnerability, on the repository. Please do not open a public issue.