Security

Security & encryption

A remote session shows someone's screen and lets you work on their computer. ShareDesk is built so that only the two computers in the session can see it, the customer decides who gets in, and every step can be checked.

  • End-to-end encrypted. Screen, sound, input, clipboard, chat, files, terminal and tunnels travel encrypted directly between the two computers. The keys never leave them.
  • Our server only connects. It helps the two computers find each other and passes on the connection request. It can't see or decrypt the session.
  • Verified devices. Every installation has its own key. Both sides prove who they are, and a security code lets you compare it on both screens.
  • The customer stays in control. Nobody gets in without a yes or a password the owner set, a banner shows every session, and one click ends it.
How a ShareDesk session is connected The technician's computer and the customer's computer exchange the encrypted session directly. The ShareDesk server is only used to set up the connection. If no direct path exists, a relay forwards the encrypted packets without being able to read them. ShareDesk server connection setup only (HTTPS) Technician Mac, PC or browser Customer Mac or PC end-to-end encrypted Relay (if needed) forwards encrypted packets How a ShareDesk session is connected ShareDesk server connection setup only (HTTPS) Technician Mac, PC or browser end-to-end encrypted Customer Mac or PC Relay (if needed) forwards encrypted packets
The session runs between the two computers. The server only introduces them; a relay, when a network needs one, only passes on encrypted data.

1. End-to-end encryption

Every session is encrypted from end to end with the open standards also used by video-call services (WebRTC). It's always on and can't be switched off:

2. What our server does – and doesn't

Before two computers can talk directly, they need to find each other. That is the only job of our server:

When a network doesn't allow a direct connection, the session goes through a relay. A relay only forwards the already encrypted data; it has no keys and can't read it.

3. Verified devices and the security code

Encryption is only worth as much as the certainty that you're talking to the right computer. ShareDesk checks this itself:

In the web viewer the connection is encrypted the same way, but a browser has no device key of its own. Such sessions are marked “unverified (browser)” on the customer's computer.

5. Unattended access

To reach your own computers without anyone at the screen, you set a password on them. ShareDesk never sends this password:

If you save an unattended password in your address book while signed in, the derived key is stored with your account and shared with the colleagues you share that computer with, so they can connect too. Use a strong password and share such computers only with people who should have access.

6. Technician accounts

Accounts are optional; they're for teams that want a shared address book, profiles and a session log.

7. Signed apps and updates

8. Data and location

9. Found a vulnerability?

Please tell us before you publish it: info@marketvision.ch. Describe what you found and how to reproduce it; we'll answer and fix it as fast as we can.