Security & trust

What protects your credentials, and what does not

This page is written to be checkable. Every claim below matches the implementation, and where the honest answer is unflattering — an unsigned installer, no third-party audit — it says so rather than leaving you to find out.

Publisher identity

How it works

CySecTek is developed and published by an individual, not by an incorporated software vendor. There is no company registration to point you at, and this page is not going to imply one.

The authoritative download is cysectek.com. Some earlier releases are archived on GitHub. Anything offering CySecTek from another domain is not something we published, and the in-app updater will not download from one.

The updater rejects any URL that is not HTTPS on cysectek.com or the project's GitHub release archive before a request is made.

Code signing status

Read this

The installer is not code-signed. Windows SmartScreen shows a blue 'Windows protected your PC' screen for unsigned software it has not seen often, and you have to click 'More info' then 'Run anyway' to proceed. That is not a bug and not a false positive — it is Windows correctly telling you that nobody has vouched for this file.

A signing certificate requires a verified organisation or a validated individual identity. The usual cloud route, Microsoft's signing service, is not open to publishers in Jordan or Saudi Arabia, and no alternative has been settled — so there is no date to give, and this page will not invent one. While the installer is unsigned every release trips the same warning, and because SmartScreen reputation for unsigned software is tied to the file hash, it resets with each new release rather than improving over time.

In the meantime the honest mitigation is verification, not reassurance: check the SHA-256 of what you downloaded against the value published here before you run it. If the hashes do not match, do not run the file.

Be clear about what a match proves. It tells you the file is complete and identical to the one published on this site — not who published it. Establishing the publisher is exactly what a signature would add, which is why this page does not call the hash a substitute for one.

Do not get into the habit of clicking through SmartScreen for software generally. Verify the hash for this one.

Verifying your download

Implemented

Every installer's SHA-256 is published on the download page and in the release manifest the app itself reads. Compare it against the file you downloaded before running it. A match means the download is complete and identical to the published file; it does not identify who built it.

In PowerShell: Get-FileHash .\CySecTek_x.y.z_x64-setup.exe -Algorithm SHA256

PowerShell
Get-FileHash .\CySecTek_0.8.1_x64-setup.exe -Algorithm SHA256
CySecTek_0.8.1_x64-setup.exe · 7.4 MB
ad0ca1286fc2c4b59058de6952a978e4761f3690d39696fa93c5db0a96277ba2

Every published hash, including the MSI, is on the download page.

Update verification

Implemented

Nothing checks for updates on its own. The check runs when you press Check for updates on the About page — the app is used on client networks and must not phone home unprompted. That request fetches the release manifest from cysectek.com and carries the app's version in its User-Agent header, nothing else.

The updater refuses plain HTTP outright, and refuses any download host that is not cysectek.com or the project's own GitHub release archive — checked before the request is made, with the host parsed rather than pattern-matched, so a URL like https://cysectek.com.example.org does not get through. Redirects are held to the same hosts.

A downloaded package is hashed and compared against the SHA-256 in the manifest. It is only handed to the installer if it matches; a mismatch is deleted. Applying it is a separate, explicit click, after which the app closes so the installer can replace it. An installer you downloaded yourself can be checked the same way; if its hash does not match, the mismatch is shown and installing it takes two deliberate confirmations.

What this does not give you is a cryptographic signature. The hash and the download URL come from the same manifest, so the check protects against a corrupted or swapped download, not against a compromised cysectek.com. Closing that gap is what code signing is for.

Credential protection

Implemented

The app password is mandatory and is not a screen lock. A 32-byte key is derived from it with Argon2id at OWASP's floor — 19 MiB of memory, two passes, one lane — and that key encrypts saved SSH, SFTP and RDP passwords with ChaCha20-Poly1305.

The password itself is never written to disk in any form. That is the point: a credential file copied off the machine is useless without it, including to a process running as your own Windows account, which is exactly what credential-stealing malware is.

It also means the password cannot be recovered. Lose it and the saved credentials are permanently unreadable. Everything else in the app keeps working.

RDP is the exception by necessity: Windows' own client takes its credential through the Credential Manager, so an RDP password is handed over that way rather than on a command line where any process could read it — and removed from the Credential Manager again thirty seconds later.

Minimum length is 8 characters. The KDF parameters are stored alongside the file, so raising them in a future release will not lock existing users out. An optional idle lock, off by default, locks the vault again after a number of minutes you choose.

SSH host keys

Implemented

The first time you connect to a device its host key is recorded. On every reconnect the key is compared, and a connection presenting a different one is refused rather than offering a dialog that most people click through.

When a device has genuinely been rebuilt, a panel shows the stored fingerprint and the new one side by side so you can compare them against what the device itself reports before choosing to accept the change.

Private key handling

Implemented

Choosing a private key stores the path to it, not the key. The file stays where it is, under whatever permissions you have already given it.

If the key has a passphrase and you ask for it to be saved, the passphrase is encrypted exactly as a password is — under the app password, with ChaCha20-Poly1305. If you do not save it, nothing is stored at all.

Keys are read in OpenSSH format, including encrypted ones. PuTTY's .ppk is not read directly; the app says so and names the PuTTYgen steps rather than failing with a parse error.

Session transcripts

Implemented

Session logging is opt-in and off until you turn it on. When it is on, a transcript is written per session, named for the host and the moment it opened.

Transcripts are encrypted with the same key as saved credentials and carry a .clog extension. This matters more than it sounds: a switch session routinely prints running-config, SNMP communities and pre-shared keys, and a plain-text log of that sitting in a folder is a credential file by another name. If the vault is locked while a session is open, the transcript stops rather than continuing in clear.

The Npcap dependency

How it works

Port Finder and Packet Capture need Npcap, the packet-capture driver from the Nmap project. Nothing else in the app requires it, and the app does not bundle, install or update it.

It is a kernel driver, so installing it is a real decision about what runs on your machine. Get it from npcap.com — the project's own site — rather than from a mirror.

Administrator rights

How it works

The app runs as a normal user and never asks for elevation: there is no elevated helper, no service, and the .exe installs per-user. Scanning, ping and traceroute, SSH, file transfer, serial, and the TFTP and DHCP servers all run as you.

Packet Capture and Port Finder open network adapters through Npcap. Whether that needs administrator rights is decided by Npcap, not by the app: its installer has an option to restrict the driver to administrators, and with that on — or when every adapter refuses to open — CySecTek has to be run as administrator. The app says so when it happens.

Releasing or renewing a DHCP lease and flushing the DNS cache from the Diagnose page run ipconfig, which Windows only allows from an elevated process. Reading the configuration needs nothing.

Telemetry

Implemented

The application collects nothing about you and sends nothing about how you use it. There is no account, no licence check, no crash reporting and no analytics library in the app. The only thing that identifies it on the wire is the User-Agent header on the two updater requests, which carries the app's version.

It makes outbound requests in three situations, none of them hidden. On launch, the Overview screen asks api.ipify.org for your public address and pings 1.1.1.1 to check the path out — the one thing it does unprompted, once, when that screen opens. When you press Check for updates on the About page, it fetches the release manifest from cysectek.com, and an update you choose to download comes from cysectek.com or the project's GitHub release archive. When you run Diagnose, Speed Test or a Site Report survey, it resolves google.com, cysectek.com and microsoft.com through your resolver and 1.1.1.1, requests Google's and Microsoft's connectivity endpoints, and downloads from and uploads a throwaway buffer to speed.cloudflare.com — which is what measuring reachability and speed means.

Beyond those, it talks only to the equipment you point it at. Scan results, transcripts, credentials, reports and exports stay on your machine. Nothing is uploaded.

This website uses privacy-preserving analytics for page views. The application does not.

Reporting a vulnerability

How it works

Report security issues to info@cysectek.com. Include what you found, how to reproduce it and what you think the impact is. If you would like a reply encrypted, say so and we will arrange a key.

Please give a reasonable window to fix an issue before publishing it. In return: an acknowledgement that it was received, an honest assessment of severity, and credit in the release notes if you want it.

There is no bug bounty. This is one person's project and pretending otherwise would waste your time.

Dependency practices

How it works

The application is Rust and TypeScript. Dependencies are pinned by lockfile so a build is reproducible, and updated deliberately rather than automatically.

The cryptography is not hand-rolled: Argon2id, ChaCha20-Poly1305 and the SSH implementation are established libraries, used as intended.

Security limitations

Read this

The installer is unsigned, as explained above.

There has been no third-party security audit and no penetration test. Nobody independent has reviewed this code, and this page does not imply otherwise.

TFTP and DHCP have no authentication or encryption. That is the protocols, not the implementation — run them on an isolated or trusted link and stop them afterwards.

Anything that decrypts your credentials runs on your machine as you. The app password protects credentials at rest against a copied file; it cannot protect against malware already running with your privileges while the vault is unlocked.

The app does not manage or rotate the credentials it stores. It keeps them; the policy around them is yours.

Found something wrong on this page?

If a statement here does not match what the software actually does, that is a bug in its own right. Tell us and it gets corrected.