How remote access works
Reaching your own PC from a browser, end-to-end encrypted. Coming soon.
Remote access is coming soon. This page explains how it is built, so you can judge it for yourself.
Linking your PC
On home.gliros.com, Devices > Link a new device gives you a one-time code (valid for 10 minutes). You enter it in the desktop app. The app makes its own key pair and sends only the public key to your account. The private key never leaves your PC.
Opening it from a browser
On app.gliros.com your linked PCs are listed. Open connects your browser and your PC through the GlirOS relay:
- Your PC keeps a connection to the relay and proves who it is with its key.
- Your browser gets a one-time ticket, valid for 30 seconds, that works only for your own device.
- The browser and the PC then agree on a fresh encryption key between themselves (X25519), and the PC signs it with its device key (Ed25519), so nobody in between can pretend to be your PC. The page shows the device's key fingerprint so you can compare it with the one in the desktop app.
- Everything after that is encrypted with XChaCha20-Poly1305. The relay only passes encrypted data on. It can't read it, and it keeps nothing of it.
Revoking
Revoke on home.gliros.com cuts the device off at once, including a session that is open right now.