DeskRemote DeskRemote

Security安全

Last updated: 2026-07-23 · English primary · consent-based personal remote desktop最後更新:2026-07-23 · 英文為主 · 以同意為前提的個人遠端桌面

Product posture: DeskRemote is authorized remote access software, not spyware. Sessions require explicit authorization or local unattended opt-in. This website does not process card payments. 產品定位:DeskRemote 是經授權使用的遠端存取軟體,不是間諜軟體。工作階段需要明確授權,或在主機本機明確啟用無人值守。本網站不處理卡片付款。

1. Consent model1. 同意模型

You may access only computers you own or are explicitly authorized to access, and only with informed consent from the person whose device, screen, files, audio, or input you control.您只能存取自己擁有或獲得明確授權的電腦,且必須取得裝置、螢幕、檔案、音訊或輸入受您控制之當事人的知情同意。

2. Pairing and device enrollment2. 配對與裝置註冊

Devices join an owner account / personal workspace through an explicit enrollment or pairing path (sign-in, support code, or local unattended setup). Silent host enrollment without local awareness is not a supported product path.裝置透過明確的註冊或配對流程(登入、支援代碼或本機無人值守設定)加入擁有者帳號/個人工作區。在本機使用者不知情的情況下暗中註冊主機,並非本產品支援的方式。

3. Visible session indicator3. 可見的工作階段指示

When a remote session is active, the host client is designed to show a visible session indicator where the platform allows it. Operators and local users should be able to tell that a remote viewer is connected. Hidden or covert sessions are prohibited by product policy and the Acceptable Use Policy.遠端工作階段進行時,主機用戶端在平台允許的情況下會顯示可見的工作階段指示。操作者與本機使用者應能察覺有遠端檢視者連線中。隱藏或隱密的工作階段依產品政策與合理使用政策均屬禁止。

4. Unattended access is opt-in only4. 無人值守存取僅限主動啟用

5. Kill switch and session stop5. 緊急停止與結束工作階段

Active control can be stopped from the host using the on-screen disconnect / emergency stop control, and from the viewer by ending the session. Ending a session is expected to stop further remote input on that connection path. For account-level compromise, also sign out other sessions, rotate the password, and review 2FA / device trust.主機端可用畫面上的中斷連線/緊急停止控制項停止進行中的控制;檢視端則可直接結束工作階段。結束工作階段即應停止該連線路徑上的後續遠端輸入。若帳號層級遭入侵,另請登出其他工作階段、更換密碼,並檢查 2FA/裝置信任。

6. Revoke access6. 撤銷存取

7. Audit trail7. 稽核紀錄

DeskRemote may store session and security metadata such as start/end time, participant or device identifiers, route category, quality state, and security events. That audit trail supports abuse investigation and operator awareness. It is not a substitute for local host awareness or a kill switch.DeskRemote 可能儲存工作階段與安全性的中繼資料,例如開始/結束時間、參與者或裝置識別碼、路由類別、品質狀態與安全事件。該稽核紀錄用於濫用調查與操作者掌握狀況,並不能取代主機本機知悉或緊急停止機制。

8. What the server does not store by design8. 伺服器依設計不儲存的內容

Remote screen contents, keystrokes, transferred-file contents, audio, and clipboard payloads are not intended to be persisted as ordinary server records. Explicit user-requested features (for example session recording or file transfer to a chosen endpoint) may create files at the endpoint or configured storage location — not as default cloud “always-on screen history.”遠端螢幕內容、按鍵輸入、傳輸檔案內容、音訊與剪貼簿內容,依設計不會作為一般伺服器紀錄持續保存。使用者明確要求的功能(例如工作階段錄影,或將檔案傳輸至選定端點)可能在端點或設定的儲存位置產生檔案——而非預設的雲端「隨時記錄的螢幕歷史」。

By design, the control-plane server is not treated as a trusted holder of remote desktop media or control payload secrets. Session media is encrypted end-to-end on supported paths so the control plane does not hold media keys for ordinary sessions. Peer identity is not fully machine-authenticated on every path yet — viewers may still need to compare a safety number (SAS) out of band; authenticated host identity, device attestation, and active-relay MITM closure remain pre-GA residual work. Do not read “E2EE” as “the host is cryptographically proven without any human check.”依設計,控制層伺服器不被視為遠端桌面媒體或控制內容機密的受信任保管者。在支援的路徑上,工作階段媒體採端對端加密,一般工作階段的媒體金鑰不會由控制層持有。對端身分在各路徑上尚未全部完成機器自動驗證 — Viewer 仍可能需要以離線方式比對安全碼(SAS);已驗證的 Host 身分、裝置證明與主動中繼 MITM 閉環仍屬 Pre-GA residual。請勿把「E2EE」理解成「無需人工核對即可密碼學證明 Host 身分」。

9. Encryption honesty9. 誠實描述加密

DeskRemote uses modern transport and session-media encryption practices appropriate for a personal remote-desktop product. We do not use exaggerated encryption marketing labels, and we do not claim absolute invulnerability. No software product can guarantee protection against every future attack, endpoint compromise, social engineering, or misconfiguration.DeskRemote 採用適合個人遠端桌面產品的現代傳輸與工作階段媒體加密作法。我們使用誇大的加密行銷標語,也不宣稱絕對無法被攻破。沒有任何軟體產品能保證抵禦所有未來的攻擊、端點入侵、社交工程或設定錯誤。

10. Multi-factor authentication (MFA / 2FA)10. 多因素驗證(MFA/2FA)

Account two-factor authentication (TOTP) is available on the Free floor and is not a paid-only feature. Enable it from account security settings when available. MFA reduces risk from stolen passwords; it does not replace host consent or unattended opt-in controls.帳號雙因素驗證(TOTP)在 Free 方案即可使用,並非付費限定功能。功能提供時可在帳號安全設定中啟用。MFA 可降低密碼遭竊的風險,但不能取代主機端同意或無人值守主動啟用等控制。

11. Abuse prevention11. 濫用防範

12. Vulnerability reporting12. 弱點回報

If you believe you have found a security vulnerability in DeskRemote, email [email protected] with subject line Security vulnerability.若您認為在 DeskRemote 中發現安全弱點,請寄信至 [email protected],主旨註明 Security vulnerability

13. Implemented vs planned13. 已實作與規劃中

Honest status for merchant and customer review. “Implemented” means present on the current product line; “Planned / hardening” means roadmap or partial coverage that must not be over-claimed.供商家與客戶審閱的誠實狀態。「已實作」代表目前產品線已具備;「規劃/強化中」代表屬於路線圖或僅部分涵蓋,不得誇大宣稱。

Control控制項Status狀態Notes備註
Consent-based remote sessions以同意為前提的遠端工作階段Implemented已實作Authorized use only; Terms / EULA prohibit unauthorized access僅限授權使用;條款/EULA 禁止未經授權的存取
Device pairing / enrollment裝置配對/註冊Implemented已實作Account-bound devices; revoke from workspace surfaces裝置綁定帳號;可從工作區介面撤銷
Visible host session indicator可見的主機工作階段指示Implemented已實作Where platform UI allows; release requirement for host safety在平台 UI 允許的情況下;屬主機安全的出貨要求
Host kill / stop control主機緊急停止/中斷控制Implemented已實作Emergency stop / disconnect on host and viewer end-session主機端緊急停止/中斷連線;檢視端可結束工作階段
Unattended opt-in only無人值守僅限主動啟用Implemented已實作Local host configuration required; revocable需在主機本機設定;可撤銷
Session / security audit metadata工作階段/安全稽核中繼資料Implemented已實作Metadata events; not ordinary screen recording storage中繼資料事件;非一般螢幕錄影儲存
E2EE session media (default)端對端加密的工作階段媒體(預設)Implemented已實作Control plane not trusted holder of media keys by design依設計,控制層不是媒體金鑰的受信任保管者
Account 2FA (TOTP)帳號 2FA(TOTP)Implemented已實作Available on Free; enable in account settingsFree 方案即可使用;於帳號設定啟用
Login rate limit / lockout登入頻率限制/鎖定Implemented已實作Anti-bruteforce on auth paths驗證路徑防暴力破解
No default server screen archive伺服器預設不保存螢幕內容Implemented (by design)已實作(依設計)Privacy Notice: screen not ordinary server records隱私聲明:螢幕內容非一般伺服器紀錄
Store-first entitlements (no website card checkout)商店優先權益(本網站不進行卡片結帳)Implemented policy已實作之政策websiteCheckout remains disabled for production public site正式公開網站維持停用 websiteCheckout
Cross-platform host parity (every OS path)跨平台主機對齊(所有作業系統路徑)Planned / partial規劃中/部分Windows-first host maturity; other hosts follow capability truth以 Windows 主機優先成熟;其他主機依實際能力如實跟進
Enterprise SSO / fleet policy企業 SSO/機群政策Out of personal scope不在個人版範圍Not part of Personal Free / Pro launch不屬於 Personal Free/Pro 上市範圍
Third-party Merchant of Record portal第三方 Merchant of Record 入口Implemented, gated已實作,受 Gate 管制Online subscription lane via third-party processor (Paddle preferred MoR) is implemented and stays closed until the merchant and checkout gates pass經第三方金流服務商(Paddle 為優先 MoR)的線上訂閱通道已實作,在商家與結帳 Gate 通過前維持關閉

14. Related pages14. 相關頁面