Only the latest commit on the main branch is actively supported with security updates.
| Version / Branch | Supported |
|---|---|
main |
✅ |
| Older releases | ❌ |
We take the security of PC Remote Sentinel & Multi-PC Fleet Commander seriously. If you discover a security vulnerability, please report it responsibly rather than opening a public issue on GitHub.
- Open a Private Security Advisory via the GitHub repository's Security tab, or contact the maintainer directly.
- Include in your report:
- Description of the vulnerability and attack vector.
- Step-by-step reproduction guide or proof-of-concept (PoC).
- Potential impact on users, hardware, or API resources.
- Initial Acknowledgement: Within 48 hours.
- Assessment & Fix: Typically within 7 business days depending on severity.
- Public Disclosure: Coordinated after a patched version has been deployed.
- Protect your Telegram Bot Token: Anyone with access to your bot token can control your bot. Never share it or commit it to public repositories.
- Configure
AUTHORIZED_USER_IDS: Always set your numeric Telegram ID in.envanddeploy_config.env. Unlisted users are automatically rejected and logged. - Keep Live Config Files in
.gitignore: The files.env,deploy_config.env, andfleet.jsoncontain active secrets and must remain in.gitignore. Use the provided.examplefiles as public templates. - Choose a Strong
FLEET_SECRET: Set a long, random string forFLEET_SECRETto ensure your cross-network relay packets cannot be decrypted or forged.
PC Remote Sentinel implements defense-in-depth security mechanisms:
- All remote telemetry, heartbeats, and commands transmitted across the Cloud Relay are encrypted using AES-256-GCM with a 12-byte random cryptographic nonce generated per message.
- Cryptographic verification tags ensure that message payloads cannot be tampered with in transit.
- Topic Hashing: MQTT topic paths are derived from
SHA-256(FLEET_SECRET)to prevent eavesdropping or topic enumeration on public brokers.
- Any message, callback query, or button interaction from an unauthorized Telegram account is rejected instantly.
- Authorized owners receive an immediate notification alert containing the intruder's numeric Telegram ID, username, and attempted action.
- Built-in cooldown timers prevent notification flooding.
- Terminal command execution via
/cmdstrictly blocks inspection of.env,deploy_config.env, and credential files. - Telegram Bot API tokens are masked automatically from terminal stdout, stderr, and logs.
- Incoming file drops are restricted to the local
downloads/directory with strict basename sanitization. - Remote file fetching (
/get) blacklists sensitive system, SSH, registry, SAM, and git configuration files (.env,id_rsa,sam,.git, etc.).
- Camera and screen recording routines utilize mutex locking to prevent hardware race conditions or device driver crashes.