✓

Sensor — Security Review

The CloakwireX Sensor companion (Windows · macOS · Linux) was assessed with an internal Red / Blue / Purple team review, and the findings were remediated.

Status Reviewed & remediated Date 30 Sep 2026 Reviewer X Technologies LLC Scope CloakwireX Sensor v1

Method

🔴 Red team

Attacked the Sensor as an adversary — LAN attacker, malicious website, on-path/MITM, local user, and supply-chain paths.

🔵 Blue team

Reviewed the defensive posture — secure defaults, credential handling, data minimization, and honesty of claims.

🟣 Purple

Merged and ranked both by real-world severity, then resolved every confirmed Critical/High/Medium finding.

What was assessed

The local pairing API and its authentication, network exposure and cross-origin protection, credential storage, the data the Sensor reads and returns, resource limits, the iPhone-side client's handling of responses, and the integrity of the downloads. Two facts held up under attack and are worth stating: the Sensor runs no shell commands from untrusted input (no command injection), and its pairing code is generated by a cryptographic random source with ~80 bits of entropy (not guessable).

Findings & remediation

Confirmed findings and their resolution. Exploit details are intentionally omitted; each item is described by category.

AreaOutcomeStatus
Cross-origin / DNS-rebinding protectionThe local server now validates the request Host and refuses browser-origin requests, so a web page cannot reach it.Resolved
Credential storageThe pairing code is written owner-only (not readable by other users on the computer).Resolved
Information exposureThe status endpoint no longer reveals the computer's name or OS to the network.Resolved
AuthenticationHigh-entropy token, constant-time comparison, and the code now expires when the Sensor is idle.Resolved
Dependency isolationThe Sensor imports code only from its own folder — never a writable shared location.Resolved
Resource limitsPer-request timeouts and automatic idle shutdown; the phone caps and validates every response.Resolved
Client-side validationThe iPhone validates each response's shape and size, so a rogue responder can't feed it bad data.Resolved
Download integrityEvery download publishes a SHA-256 you can verify (below). Code-signing / notarization is planned.Checksums live · signing on roadmap
Local-network transportThe link between phone and computer is local and unencrypted — pair on a network you trust. TLS on the LAN is planned.Disclosed · TLS on roadmap

Security posture

Verify your download

Confirm you're running the genuine Sensor. On Windows PowerShell: Get-FileHash .\CloakwireX-Sensor-Windows.zip — on macOS/Linux: shasum -a 256 <file>. It should match:

Windows: 540964871c80bbf444353789f4ea4a8c5bccf89a7642163be355f7f21b2fe786
Cross-platform: ba3aeb4a299cfae9bfcd957f7ca2e8b2e76db811abf64db99ca4ecdcadef1758

The current checksums are always shown on the download page.

About this review. This is an internal security review conducted by X Technologies LLC — it is not a third-party audit or a formal certification. We publish it for transparency. Found something? Please report it privately to support@cloakwirex.com; we practice responsible disclosure and will not publish working exploit steps.