NETWATCH is engineered with strict local-first security boundaries:
- Loopback Only: The backend HTTP and SSE API binds strictly to
127.0.0.1on an ephemeral port. - Per-Session Bearer Token: Every API call requires an unguessable 192-bit cryptographic token generated per application startup.
- Anti DNS-Rebinding & Origin Isolation: All incoming requests are validated against strict
HostandOriginallow-lists, isolating the daemon from malicious web pages open in local browsers. - No Telemetry / No Cloud: Zero sensitive data (MAC addresses, IP configurations, network topologies) ever leaves the local machine.
| Version | Supported |
|---|---|
0.2.x |
✅ |
0.1.x |
✅ |
< 0.1.0 |
❌ |
NETWATCH binaries are distributed as Unsigned Native Binaries. This architecture preserves independence, eliminates dependencies on commercial Certificate Authorities, and maintains an air-gapped, sovereign release pipeline.
Every release publishes authoritative cryptographic hashes in SHA256SUMS.txt and directly within GitHub Release notes. Users and administrators should verify binary integrity prior to execution:
Windows (PowerShell):
Get-FileHash .\netwatch.exe -Algorithm SHA256Linux / macOS:
sha256sum netwatch.exeCompare the output hash against the published hash in the official release notes. If the hashes match, the binary has not been tampered with.
Because NETWATCH is distributed unsigned without a costly commercial EV certificate, Windows Defender SmartScreen may display an "Unknown Publisher / Windows protected your PC" prompt on initial launch.
- This prompt occurs for any executable without commercial certificate trust history.
- To execute: Click "More info" -> Click "Run anyway".
- NETWATCH requires no Administrator rights and runs completely unprivileged in user mode.
If you discover a security vulnerability or bypass in NETWATCH's loopback protection, token verification, or packet handling:
- Do not open a public issue.
- Report the vulnerability privately via GitHub Security Advisories.
- Provide detailed steps to reproduce, including environment details (OS, network configuration) and proof of concept if available.
- Initial Acknowledgement: Within 48 hours.
- Triage & Assessment: Within 5 business days.
- Remediation & Patch Release: Disclosed responsibly once a patch is tested and published.