Security

Security you can actually understand

Remote access is powerful, so we designed Pocketlid to need as little trust in us as possible. Here’s how it works — no buzzwords.

What goes where

Directly between your devices, encrypted

  • Screen video
  • Mac audio
  • Keyboard and pointer input
  • Files and clipboard
  • Terminal sessions

Through the Pocketlid server

  • Your account email
  • Your device list: names and public keys
  • Connection setup messages, such as the network addresses your devices use to reach each other
  • Wake requests and whether a Mac is online

If a direct connection isn’t possible, an encrypted relay (TURN) forwards the traffic. It only ever sees encrypted packets.

Encrypted, peer to peer

Your phone and Mac connect with WebRTC, the same standard used for video calls in browsers. Everything is encrypted between the two devices.

Our server is only a meeting point. We treat it as untrusted by design: even if someone took control of it, they couldn’t pose as your phone to your Mac, or as your Mac to your phone.

Every connection is signed

Each phone creates a signing key in Android Keystore. The key is backed by hardware and can’t be exported. Your Mac has its own key in the macOS Keychain.

When you connect, the phone signs a challenge tied to that exact encrypted session. The Mac checks that the key belongs to a phone it trusts and that the phone is still active on your account. Then the Mac signs back, and your phone checks it against the key it saved for that Mac. If anything doesn’t match, the connection is closed.

The PIN, done right

The first time a phone connects to a Mac, it enters the Mac’s PIN (at least six digits) once. The PIN is checked with CPace, a password-authenticated key exchange: the PIN never leaves the Mac, and someone watching the traffic learns nothing they could use to guess it offline.

An attacker gets one guess per attempt. After five wrong attempts in a row, the Mac locks for increasing periods of up to an hour.

Lost phone, no problem

Remove a phone from your account in Settings › Phones on this account. From then on, your Macs refuse it — even though it still has its key.

You can also remove it from the Mac’s list of trusted phones, so it would need the PIN again.

Controls on your Mac

Approve each connection

Someone at the Mac must click Allow within 30 seconds.

Ask for the PIN every time

Even trusted phones must enter the PIN on each connection.

Choose what’s allowed

Turn terminal access and file transfer on or off.

Know who’s connected

Notifications on connect and disconnect, plus a connection history.

Lock when done

Lock the Mac’s screen automatically when the connection ends.

Curtain and input lock

Keep the screen dark and the keyboard locked while you’re away.

On your phone

  • Lock Pocketlid with your fingerprint.
  • A saved Mac password requires your fingerprint every time it’s used.
  • Your phone’s signing key stays in Android Keystore and can’t be copied.

Good to know

  • Anyone who can open the app on your unlocked phone can use your Macs. Turn on app lock.
  • macOS asks you to grant Screen Recording and Accessibility. Pocketlid only accepts input from authenticated sessions.
  • Our server holds your account and device list. See the Privacy Policy for details.

Found a security issue?

Please email support@pocketlid.com with “Security” in the subject. We’ll respond as quickly as we can and keep you posted.