Security

Only the Macs you approved ever receive anything.

What protects each step — and, in the same detail, where each protection stops.

A clipboard can hold a login code, a signed contract or an unfinished sentence, and all three travel the same way. Before you send one to another Mac, it is fair to ask where it goes, which devices can receive it, and what stays behind afterwards.

Deskferry answers that with local connections, devices an administrator has approved, an encrypted transport, and a history library that stays on the Mac that recorded it. The six sections below describe each protection and name the point where it ends.

Your Macs talk to each other, not to a cloud in between

Local networkWi-Fi / Ethernet

Mac A
Mac B
No cloud relay
Your content travels directly between trusted Macs over local Wi-Fi or Ethernet.

Two Macs on the same desk. Moving a paragraph from one to the other should not involve leaving a third copy with a cloud service somewhere. Supported clipboard content and selected files go directly between approved Macs on a local network both can reach.

The connection runs over local Wi-Fi or Ethernet. Shared content does not pass through a Deskferry developer server, and there is no Deskferry cloud clipboard that devices download from later. The receiving Mac gets the content over its own connection to the sending Mac. In protocol terms, that is peer-to-peer (P2P) LAN transport, with no Deskferry cloud relay in the path.

What that buys you day to day is one less place to keep tidy. Nothing accumulates in a cloud library you have to remember to clear, no uploaded archive to sort through later, no service account to connect before the first copy works. It matters most when the same laptop and desktop hand things back and forth twenty times a day.

Reachability is a real condition and not a formality, so be ready for it to bite. A guest network that isolates its clients blocks the connection outright, even while both Macs display the same Wi-Fi name. Nothing bridges home and the office. Local history on a single Mac is unaffected by any of this.

Sharing that does not run through one shared login

Apple Account A
Apple Account B

Approved device group

Mac A
Mac B

Device identity

No Deskferry login

Separate Apple Accounts. Sharing is authorized by the devices’ approved group membership.

Work Mac on the company account, personal Mac on yours. There is rarely a good reason to merge those, and connecting two machines should not force you to.

So there is nothing to register and no sign-in step before pairing or syncing. The two Macs can be on entirely different Apple Accounts. Permission comes from an approved device group rather than a shared login: device identity and group-scoped authorization do the job a service account would otherwise do.

In a household or a small team that means you invite one specific Mac. Nobody hands around credentials, personal and work sign-ins stay exactly where they are, and adding a device remains a decision somebody has to actually make.

Apple still handles Mac App Store downloads, purchases and any account requirement attached to them. What Deskferry avoids is a second product account, and it never asks the paired Macs to share one Apple Account.

Every new Mac joins by a decision someone makes

  1. Administrator invites
  2. Enter six-digit code120 seconds · up to 3 attempts
  3. SPAKE2TLS exporterBound to this connection
  4. Administrator approves
Invitation → six-digit code → SPAKE2 bound through a TLS exporter → administrator approval.

Being nearby says nothing about whether a Mac should receive your work. Discovery and permission are separate on purpose: turning up on the same Wi-Fi gets a device into no group and earns it nothing.

Pairing runs as a short sequence, so the administrator can look at the device before membership is granted:

  1. The administrator starts an invitation from their own group with Add Mac. The six-digit code is valid for 120 seconds and allows three authentication attempts.
  2. On the joining Mac, Join a Group selects that nearby invitation and takes the code. The encrypted pairing exchange uses SPAKE2 to verify both sides before the request reaches approval, and binds its result to the secure connection through a TLS exporter, so the short-lived code and the device session that follows belong to the same trust establishment.
  3. The administrator checks the joining Mac and approves it. If the code expires or the three attempts run out, the invitation has to be started again.

These checks belong to the moment access is granted. There is no code to retype for each copy — later connections verify the device identity that pairing established. Before the first transfer, select the same current group on both Macs and wait for the connection to be ready.

One part of this is not cryptographic at all: approve only a request you recognise. The code and the encrypted exchange protect the pairing process. Whether this is the device you meant to trust is the question only you can answer.

Protection for the transfer and for the copies you keep

In transitTLS 1.3 · mTLS

Mac A
Mac B

Mutual authentication

On each Mac

Mac A
Mac B
Encrypted historymacOS Keychain
TLS 1.3 protects the connection. Each Mac encrypts its own history content; its key stays in macOS Keychain.

A Wi-Fi password settles who gets onto the network. It does nothing about the content you then send across it. Both Macs have their identity verified and the connection between them is encrypted, which is what keeps copied text, images and files from being read in transit.

The transport uses TLS 1.3 with mutual authentication (mTLS), so each side proves who it is instead of trusting the network. Events are signed, and replay protection means an old but valid message cannot be accepted again as a new action. The connection also carries its context: it belongs to one approved group, not to whoever happens to be listening.

Retained history has its own protection. Bodies and attachments are encrypted on each Mac, and macOS Keychain holds the key. Index information such as times and status is stored separately, so encrypting the content does not mean that every field in the index is encrypted.

Here is what none of that decides: what a trusted recipient does afterwards. A Mac that received your content can keep it indefinitely, and an unlocked Mac belongs to whoever sits down at it. Picking recipients, and locking the machines themselves, is work that stays with you.

A current group with a defined audience and defined roles

Current group

Administrator
Signed membership list
Member
Mac C · Future access revoked
Other group · not current
The current group defines the audience. Removing a member revokes future access, not copies already received.

Once more than two Macs are involved, knowing who can receive a copy starts to matter more than how fast it gets there. The current group is the audience — not every nearby Mac, and not every group you have ever joined. Underneath, group-bound v2 frames keep messages in their intended group context, while a signed membership list and signed revocation record who is still authorized. Each Mac then applies its own sync policy on top of that.

The controls split membership decisions away from everyday use:

  • Administrators manage membership. Approving a new Mac is theirs, and so is removing a member from a group they own, including a device that happens to be offline at the time. Members cannot remove each other.
  • Each Mac controls its own sharing. Which group is current, whether sync is paused, which content types this machine may send — all local decisions. Glance at the group before a copy that matters.
  • Personal history stays personal. Being in a group with someone gives them no route into your history library, and that includes the administrator. What a recipient does keep is its own local record of whatever you allowed to sync.

A home group and a work group can sit side by side, and you pick before you share. Switching changes the active audience; having both does not mean every new copy goes to both.

Removing a member revokes future authorized access through that pairing, and stops there. It does not reach back into files, pasted content or history the other Mac already stored. Access control governs who receives the next copy, never what became of the last one.

A local check that keeps supported secrets out of readable history

Check on this Mac
  1. Copied content
  2. Supported format matched
  3. Sensitive placeholderNo body, names or thumbnails retained

Supported formats only; detection can miss content.

History exclusion ≠ blocking sync

A supported format match leaves a placeholder, not a recoverable secret. Detection and sync settings remain separate.

You paste a password and forget about it. It is now an entry in a list you will scroll past for weeks. A local check for supported sensitive formats exists so that some of those copies never become readable history in the first place.

The rules cover credentials with explicit fields, certain private-key formats and supported recovery phrases, matched by structure rather than by treating every random-looking string as a secret. Recognition is deterministic: it uses the format's own structure, NFKD normalization and checksums where the format defines them, including supported BIP39 and SLIP39 phrases, BIP32, BIP38 and WIF private keys, and PEM or OpenSSH containers. The check runs on your Mac, and the clipboard content is not uploaded for inspection.

When a supported format matches, the whole event is stored as a sensitive placeholder. Its readable body, attachment names and thumbnails are not kept in that entry, so it cannot be opened later to recover the secret.

Now the distinction that actually catches people out: keeping something out of history and keeping it off the network are two different settings. Sensitive-content sync is on by default, and each Mac applies its own settings independently. If private material should not reach the current group at all, turn that setting off or pause sync before you copy it. A placeholder sitting in history is not evidence that nothing was sent.

FAQ

Questions, answered

Can another Mac on the same Wi-Fi read my clipboard?

Being on your network does not make a Mac a member of anything. Content reaches devices with approved group membership, over an authenticated connection, and a Mac nobody approved has nothing waiting for it. Which means the decision that protects you is not a network setting — it is which devices, and which people, you invite.

Do the two Macs need the same Apple Account?

No, and that is rather the point. Pairing and sync run on the approved group, so the two Macs can sign in to different Apple Accounts and keep doing so. Apple handles App Store downloads and purchases separately, and there is no Deskferry account anywhere in this.

What happens if the pairing code expires or pairing fails?

You start over, which takes about ten seconds. The six-digit code lasts 120 seconds and allows three authentication attempts; once either runs out, the administrator issues a new invitation and then checks and approves the joining Mac. See both sides of first-time pairing.

Can Deskferry reach my office Mac from home over the internet?

No. The two Macs need a local Wi-Fi or Ethernet network they can reach each other on, and there is no developer relay standing by to bridge two locations. What does still work with no network at all is local history on a single Mac.

Does joining a group expose my existing history?

No. Your history library stays on your Mac and the group has no way to query or search it. What can travel is new copies that you allow to sync, and each Mac on the receiving end keeps its own local record of what it received.

Will removing a Mac delete the files it already received?

No, and nothing could. Removal revokes future authorized access; files, pasted content and history already stored over there stay exactly where they are. So the judgement to make is whether you trust a recipient with the content afterwards, not only during the transfer.

Does sensitive detection stop every password from being sent?

No, on two counts. It covers supported formats only, and what it governs is readable history rather than transmission. Sensitive-content sync is on by default, so if something private must not leave this Mac, turn that off or pause sync before copying. See privacy controls and first-time pairing.

Guides

Your next useful read

Deskferry

Keep the next step simple.

Continue on another Mac, hand off a file, or find an earlier copy.

macOS 14+ · One Mac for history · Reachable LAN for sync