Skip to content

Security

  • The pairing QR code contains the Mac’s node ID, the server public key and a one-time pairing code.
  • A pairing code is valid for 10 minutes and is invalidated after one use, after 5 wrong attempts, or when you close the pairing window.
  • Each device’s identity is its iroh node key (Ed25519), kept in the Keychain on the phone and excluded from backups. iroh authenticates both sides on every connection, and the Mac only accepts nodes of paired devices.
  • A removed device is disconnected immediately.

The phone and the Mac connect directly on the same network. When they’re apart, they try to punch through NAT and fall back to a relay only if that fails. The public relays run by n0 are used by default; you can enter a self-hosted relay (iroh-relay) in the Mac’s Settings › Network. There are no Nohup servers in between, and no port forwarding is needed on the Mac.

  1. Transport: iroh’s QUIC connection (TLS 1.3), with both sides authenticated by their node keys.
  2. Application: an extra end-to-end layer on top of QUIC, so a relay forwarding the traffic can’t read it.
    • X25519 handshake (server static key + ephemeral keys on both sides); HKDF derives two ChaCha20-Poly1305 keys per direction.
    • Length headers are encrypted separately and every record carries random padding, so there’s no plaintext structure or fixed length on the wire.

The server public key is in the pairing QR code, so the phone pins it when pairing. If it ever changes, the connection is refused and you’ll see “Server Identity Changed”. Compare fingerprints in the Mac’s Settings › Network.

Pages sent to the phone load via the nohup-page:// scheme; every request is read over the same encrypted connection. The Mac doesn’t open any HTTP port.