Security
A relay that cannot watch.
Remote access asks for more trust than almost any other category of software: permission to see and control the machine where your work, your accounts and your private life already live. The only answer that survives scrutiny is an architecture in which the people running the service are not in a position to abuse it.
End-to-end encrypted
Sessions are sealed between your device and your machine, under a key the two of them agree directly. The relay forwards ciphertext it has no key for.
Identity is a key you hold
Every device and agent holds a keypair generated on the device itself. Identity is something you possess, not a password a server checks on your behalf.
Paired once, physically
A machine is paired at the machine, by someone at the machine. After that it is a tap. Nobody can add themselves to your account remotely.
The relay cannot watch
The relay moves bytes between two endpoints that authenticated each other. It cannot decrypt a frame, inject a keystroke, or reconstruct a session.
Pinned certificates
Clients pin the relay they trust on first use and refuse a substitute. A network that can intercept traffic still cannot become the relay.
Revocation that propagates
A revoked device stops working in every region, not just the one it registered in. Revocations reach both regions in about a minute.
What end-to-end actually means
The key never reaches us
When you connect, your device and your machine agree a key directly with each other. That key is never sent to the relay, never stored on our infrastructure, and never derivable from anything we hold. Everything the session carries (screen frames, keystrokes, pointer movement, clipboard, files) is encrypted with it before it leaves the device that produced it.
This is the difference between a service that promises not to look and a service that cannot. Ours is the second kind, and that is a claim about architecture rather than about our intentions, which is the only kind of claim worth making.
What the relay can see
That two endpoints are connected, roughly how much data passes between them, and when. That is the irreducible minimum for a service whose job is to introduce two machines that both sit behind routers, and it is all of it. It cannot decrypt a frame, read a keystroke, reconstruct what was on the screen, or inject input into a live session.
What in-person pairing buys you
A machine is paired by somebody standing at that machine, scanning a code displayed on it. That single design decision removes the attack that matters most in this category: nobody can attach themselves to your account from somewhere else, because attaching requires physical presence at the machine being added.
What it does not cover
TETHERÆ secures the link between your device and your machine. It cannot defend a machine that is already compromised, and it cannot protect a session from someone looking over your shoulder at either end. If someone has your unlocked phone, they have your machines, the same trade every device you own already makes, and the reason the app lets you revoke a device from either side.
Reporting a vulnerability
Write to hello@tetherae.com. Please include enough detail to reproduce the issue. We would rather hear about a problem early than read about it later.
Your machines. 100% access.
Free while TETHERÆ is in beta. No card, no time limit, no strangers.