Skip to content

Security: alwkala/NETWATCH

SECURITY.md

Security Policy

Security Invariants

NETWATCH is engineered with strict local-first security boundaries:

  1. Loopback Only: The backend HTTP and SSE API binds strictly to 127.0.0.1 on an ephemeral port.
  2. Per-Session Bearer Token: Every API call requires an unguessable 192-bit cryptographic token generated per application startup.
  3. Anti DNS-Rebinding & Origin Isolation: All incoming requests are validated against strict Host and Origin allow-lists, isolating the daemon from malicious web pages open in local browsers.
  4. No Telemetry / No Cloud: Zero sensitive data (MAC addresses, IP configurations, network topologies) ever leaves the local machine.

Supported Versions

Version Supported
0.2.x ✅
0.1.x ✅
< 0.1.0 ❌

Binary Integrity & Unsigned Distribution Model

NETWATCH binaries are distributed as Unsigned Native Binaries. This architecture preserves independence, eliminates dependencies on commercial Certificate Authorities, and maintains an air-gapped, sovereign release pipeline.

Cryptographic Hash Verification

Every release publishes authoritative cryptographic hashes in SHA256SUMS.txt and directly within GitHub Release notes. Users and administrators should verify binary integrity prior to execution:

Windows (PowerShell):

Get-FileHash .\netwatch.exe -Algorithm SHA256

Linux / macOS:

sha256sum netwatch.exe

Compare the output hash against the published hash in the official release notes. If the hashes match, the binary has not been tampered with.

Windows Defender SmartScreen Transparency

Because NETWATCH is distributed unsigned without a costly commercial EV certificate, Windows Defender SmartScreen may display an "Unknown Publisher / Windows protected your PC" prompt on initial launch.

  • This prompt occurs for any executable without commercial certificate trust history.
  • To execute: Click "More info" -> Click "Run anyway".
  • NETWATCH requires no Administrator rights and runs completely unprivileged in user mode.

Reporting a Vulnerability

If you discover a security vulnerability or bypass in NETWATCH's loopback protection, token verification, or packet handling:

  1. Do not open a public issue.
  2. Report the vulnerability privately via GitHub Security Advisories.
  3. Provide detailed steps to reproduce, including environment details (OS, network configuration) and proof of concept if available.

Response SLA

  • Initial Acknowledgement: Within 48 hours.
  • Triage & Assessment: Within 5 business days.
  • Remediation & Patch Release: Disclosed responsibly once a patch is tested and published.

There aren't any published security advisories