The CloakwireX Sensor companion (Windows · macOS · Linux) was assessed with an internal Red / Blue / Purple team review, and the findings were remediated.
Attacked the Sensor as an adversary — LAN attacker, malicious website, on-path/MITM, local user, and supply-chain paths.
Reviewed the defensive posture — secure defaults, credential handling, data minimization, and honesty of claims.
Merged and ranked both by real-world severity, then resolved every confirmed Critical/High/Medium finding.
The local pairing API and its authentication, network exposure and cross-origin protection, credential storage, the data the Sensor reads and returns, resource limits, the iPhone-side client's handling of responses, and the integrity of the downloads. Two facts held up under attack and are worth stating: the Sensor runs no shell commands from untrusted input (no command injection), and its pairing code is generated by a cryptographic random source with ~80 bits of entropy (not guessable).
Confirmed findings and their resolution. Exploit details are intentionally omitted; each item is described by category.
| Area | Outcome | Status |
|---|---|---|
| Cross-origin / DNS-rebinding protection | The local server now validates the request Host and refuses browser-origin requests, so a web page cannot reach it. | Resolved |
| Credential storage | The pairing code is written owner-only (not readable by other users on the computer). | Resolved |
| Information exposure | The status endpoint no longer reveals the computer's name or OS to the network. | Resolved |
| Authentication | High-entropy token, constant-time comparison, and the code now expires when the Sensor is idle. | Resolved |
| Dependency isolation | The Sensor imports code only from its own folder — never a writable shared location. | Resolved |
| Resource limits | Per-request timeouts and automatic idle shutdown; the phone caps and validates every response. | Resolved |
| Client-side validation | The iPhone validates each response's shape and size, so a rogue responder can't feed it bad data. | Resolved |
| Download integrity | Every download publishes a SHA-256 you can verify (below). Code-signing / notarization is planned. | Checksums live · signing on roadmap |
| Local-network transport | The link between phone and computer is local and unencrypted — pair on a network you trust. TLS on the LAN is planned. | Disclosed · TLS on roadmap |
Confirm you're running the genuine Sensor. On Windows PowerShell: Get-FileHash .\CloakwireX-Sensor-Windows.zip — on macOS/Linux: shasum -a 256 <file>. It should match:
Windows: 540964871c80bbf444353789f4ea4a8c5bccf89a7642163be355f7f21b2fe786
Cross-platform: ba3aeb4a299cfae9bfcd957f7ca2e8b2e76db811abf64db99ca4ecdcadef1758
The current checksums are always shown on the download page.