Reference
Security
How Burrow protects your data, what it can’t protect against, and how to report a problem privately.
On this page
On disk
vault.enc, encrypted with AES-256-GCM.
Every save uses a fresh random IV, and GCM detects any change to the file. The scrypt settings stored in the file are checked against upper limits, so a tampered vault can’t make unlocking eat gigabytes of memory. Files are written atomically with 0600permissions, so only your user account can read them.When the vault locks, the key in memory is overwritten with zeros.
Locking
Inside the app
Chromium’s sandbox and context isolation are on, and the interface has no Node.js access. A strict Content Security Policy only allows the app’s own scripts. There is no inline script, evalor remote code.The main process only accepts messages from the app’s own window and checks the type of every argument. Navigation and new windows are blocked. Only httpandhttpslinks open, and they open in your normal browser.Camera, microphone, location, notifications and every other web permission are denied, except clipboard access for copy and paste. Packaged builds have no DevTools and refuse to start with remote debugging switches. Electron fuses turn off ELECTRON_RUN_AS_NODE,NODE_OPTIONSand--inspect, and the app only loads from its integrity-checkedapp.asar.The spellchecker is off, so no dictionaries are downloaded and nothing you type is sent anywhere.
SSH
The first connection to a host shows its key fingerprint for you to confirm. If a known host’s key changes, you get a warning, and the connection only goes ahead if you accept the new key. Key exchange, host key and MAC algorithms based on SHA-1 or MD5 are turned off. Servers that only support those are refused instead of being connected insecurely. Agent forwarding is not used.
Sync
The login key is sent to the server to prove who you are. The server only stores its SHA-256 hash. The encryption key encrypts your data with AES-256-GCM before it leaves the device. It is never sent anywhere.
localhost, for development), refuses redirects, and times out stuck requests. Data coming back from the server is decrypted, checked and validated field by field before anything is saved.
Updates
api.github.com and carries nothing about you except your IP address. Download links from the answer are only used if they point to this repository’s releases.
AppImage: updates are downloaded and installed by electron-updater. Every download is checked against the SHA-512 hash in the release’s latest-linux.ymlbefore it replaces the app.macOS and rpm: the app never downloads or installs anything itself. It opens the download in your browser.
Verify what you run
git clone https://github.com/zukotuutori/burrow-client.git
cd burrow-client
npm ci
npm run build:macgit clone https://github.com/zukotuutori/burrow-client.git
cd burrow-client
npm ci
npm run build:linuxKnown limitations
The code has not been audited by an independent security firm. Release builds are not signed or notarized. Only the AppImage installs updates itself. On macOS and with the rpm, security fixes only reach you when you install the new version by hand. Update checks don’t run on their own unless you turn that on. Since builds aren’t signed, updates are only verified against the hash published in the same GitHub release, not against a signature. Plain JSON files (hosts, snippets, known hosts, settings) are not encrypted. Only secrets are. After the vault locks, the key is wiped, but decrypted secrets can stay in memory until JavaScript’s garbage collector frees them. Malware running as your user account can read everything the app can see while the vault is unlocked. No app can fully protect against that. Hiding the window from screenshots and screen recordings works on macOS but not on Linux. Whoever runs a sync server can see user names, IP addresses, and when and how much data is uploaded. They can’t read or change your data, but they can delete it or hand out an older copy. The sync salt is derived from the user name, so a new device can log in with just the user name and password. This means someone with a copy of the server database can try to guess account passwords offline. Every guess costs a full scrypt run and account passwords have the same rules as the master password, but a weak password is still a risk. A forgotten master password or sync account password cannot be recovered.
Supported versions
Report a vulnerability
the version or commit you tested your operating system steps to reproduce, or a proof of concept what an attacker could do with it