All pages

How it is protected

  • No password is stored. Each account's password derives (scrypt) a key that unlocks the one key every saved KVM password is encrypted with (AES-256-GCM). Someone who copies the data folder gets nothing usable without an account's password. After QKVM restarts it cannot reach the KVMs until someone signs in. Note what this means: any account's password, a viewer's included, opens the saved KVM passwords to someone who also has a copy of the data folder, so give every account a good one.
  • Forgotten password: Forgot your password? on the sign-in page lists the ways back in.
    • The recovery key sets a new password for any account and keeps everything else as it was. It is shown once when QKVM is set up; an admin can make a new one under Settings → Security, which cancels the old one. Only a locked copy is stored. Whoever holds it can take over any account, so keep it like a password, and not on the computer QKVM runs on. It replaces the password only: an account with two-factor sign-in still needs its code.
    • Another admin can set a new password for you under Settings → Accounts.
    • Starting over: with neither, python -m qkvm --reset-password forgets every account and the recovery key, so the first account can be created again. The saved KVM passwords were encrypted for those accounts, so they are erased and must be entered again; the list of KVMs and the other settings stay.
  • Sign-in uses an HttpOnly, SameSite=Strict session cookie. Repeated wrong passwords lock the address out for 30 seconds, doubling up to 15 minutes.
  • First-run setup from another machine needs the setup code printed in QKVM's terminal (or container log), so nobody on the network can claim a copy you just started.
  • Each KVM's certificate is remembered the first time QKVM talks to it (like an SSH host key). If something else answers at that address later, QKVM refuses to send it the password and the tile says so; Settings → KVMs → Edit → Review certificate shows both fingerprints.
  • HTTPS for QKVM itself is one checkbox (a certificate is made on this computer; its fingerprint is shown so you can check the browser's warning). Turn it on whenever QKVM listens on the local network. Tailscale already encrypts its traffic.
  • Every change must come from QKVM's own page (cross-site requests are refused), the page runs under a strict Content-Security-Policy, and requests for unknown host names are rejected.
  • A KVM is not trusted either. What a device sends is read only up to a limit, only JPEG and PNG data is passed on to a browser as a picture, and what a device says about itself (name, model, numbers) is reduced to plain short text or a number before it is shown or logged. A broken or taken-over KVM can show a wrong picture; it cannot fill the memory of the computer QKVM runs on or put a page of its own in your browser.
  • Updates are installed only when signed by the publisher's release key (see Updates).
  • At start, QKVM says so if a library it runs on is older than the first version without a known vulnerability.