End-to-End Encryption (Remote Desktop)
End-to-end encryption (E2EE) in remote desktop means only the controller (your iPhone) and the host (your Mac) can read and write session content: screen frames, pointer events, keyboard input, and Ask messages. Infrastructure in the middle may route traffic but cannot decrypt it, because the keys exist only on the two endpoints.
How Poket PC applies E2EE
- Each device creates a long-term X25519 identity key and keeps the private half in its Keychain, on that device only and never synced. Pairing gives each side the other’s public key.
- Each session runs a Noise IK handshake to authenticate the paired devices and derive fresh session keys (forward secrecy).
- Every record is sealed with ChaCha20-Poly1305; replays and tampering fail verification on the Mac or phone.
The relay matches two connections with the same rendezvous token and copies bytes. Its forwarding path does not hold session keys. See zero-knowledge relay and the full security model.
What E2EE does not hide
The relay and your ISP can still see metadata: IP addresses, connection times, and traffic sizes, and the relay also sees the random rendezvous token it matches connections by. E2EE protects content, not traffic analysis.
E2EE covers the path between your two devices. When Ask uses a cloud model, the prompt, the assistant’s memory and the screenshots it needs also go from the Mac to that provider (Anthropic or xAI) under your account. With a local model in Ollama they stay on the Mac.
Further reading
Frequently asked questions
Is TLS to the relay enough?
No. TLS protects the hop to the relay and ends there. Poket PC also encrypts between your devices, so the relay forwards ciphertext it has no keys for.
What algorithm does Poket PC use?
A Noise IK handshake with X25519 keys and SHA-256, then ChaCha20-Poly1305 records.