A paired phone can type into a terminal on your computer, so it can run anything you can. That is the whole point, and also the whole risk. Pairing is where we make sure only your phones get that power.
No open port
Your computer does not listen for connections from the internet. Both your phone and your computer connect out to a relay, which passes messages between them. So there is no port to forward, no VPN to set up and no address to scan.
A one-time token
When you choose Pair a phone, the computer creates a random 256-bit token and shows it as a QR code and a short code. The token works once and expires after 5 minutes. After repeated wrong guesses the pairing window closes.
Until a window is open, an unpaired device cannot do anything on your computer except send the pairing token.
Keys made on your devices
During pairing, your phone and your computer set up encryption keys between themselves. The keys are made on those two devices and the private halves never leave them. After pairing, everything about a session travels end-to-end encrypted: terminal output, what you type, commands, approvals and answers.
Allow, on the computer
In the Mac app, a valid code is still not enough. The owner must press Allow on the computer, seeing the phone’s name and code. If someone got hold of your code in the five minutes it was valid, they would still be waiting on a prompt only you can answer.
Taking a phone away
A lost phone is cut off from Devices on the computer, within a second and including live connections. The computer also limits how fast a phone may send, so a bug or a hostile phone cannot flood it.
What this does not cover
- A compromised computer or an unlocked, compromised phone. Either one has full control by design.
- Metadata. The relay sees when a device connected and how big a message was.
- Denial of service by someone who can reach the relay.