Zero-Knowledge Relay
A zero-knowledge relay (in Poket PC’s sense) is a network service that does not possess the cryptographic keys for your remote desktop session. It may know that two parties connected and how much data moved; it should not be able to read or forge screen or input data. The name is informal: it is not a zero-knowledge proof in the cryptographic sense.
Poket PC relay behavior
- Each side dials outbound to the relay (works on typical home and mobile networks).
- Both present the same rendezvous token; the relay matches and forwards ciphertext.
- Relay forwarding code does not decrypt; a test fails the build if that code ever depends on a crypto library.
Content confidentiality depends on end-to-end encryption between the phone and Mac, not on trusting the relay operator with keys.
If the relay is hostile
A compromised relay can block or delay traffic and observe metadata. It cannot decrypt payloads, and anything it injects or alters fails the authentication checks at the endpoints. Details: blog post and /security/.
Not the same as “zero logs”
We do not claim the relay stores zero bytes of metadata. App usage stats are separate: the iPhone app and the web client send a short list of events tied to a random ID created on your device, so the App Store privacy label counts them as data linked to you. You can turn them off with Share usage stats (called Share anonymous usage stats in iPhone 1.0). Details, including site analytics, are in privacy.
Frequently asked questions
Does zero-knowledge mean the relay operator learns nothing?
It means the relay does not learn session content. Metadata is still visible: IP addresses, timing, message sizes, and the random rendezvous token it matches connections by.
Is Poket PC's relay a VPN?
No. It splices two outbound connections; it does not assign VPN addresses.