termique
Blog
Feature2 min read

termique v0.6.1 – shared credentials are now end-to-end encrypted

termique v0.6.1 wraps shared credentials with the recipient’s own key before they ever reach termique’s servers, closing a gap where we could technically decrypt what you share wit

termique v0.6.1 – shared credentials are now end-to-end encrypted

termique v0.6.1 wraps shared credentials with the recipient’s own key before they ever reach termique’s servers, closing a gap where we could technically decrypt what you share with a teammate. A few related edge cases in the sharing flow are fixed too.

Update from the in-app updater, or grab a fresh build from the download page.

What changed under the hood

Sharing a host in termique has always encrypted the credential on your device before it ever leaves the app. What changed is how the key to that encryption reaches the person you’re sharing with. Previously, termique’s servers held a secret capable of decrypting that key on request, so a recipient’s device could fetch it back during sync. Now the key is wrapped with the recipient’s own public key instead, generated and stored on their device the same way their other keys are. termique’s servers pass the wrapped key along without ever holding the means to open it.

Why this closes a real gap

A host you’ve never shared has always been genuinely zero knowledge: its credential is encrypted with a key derived from your master password, which never reaches termique at all. A shared host used to work differently, because sharing requires a server to relay a key between two devices with no other channel between them. This release covers desktop first, with mobile following in a later update. Once both people involved on a share are on an updated build, termique has no technical ability to read what’s been shared, not just a policy against doing so.

Also fixed

  • A revoked share could be reactivated by the person it was revoked from
  • Revoking a share only changed its status. The credential stayed on our servers and remained retrievable by the revoked recipient until this fix.
  • A share could be pushed into an accepted state without the recipient actually consenting to it

None of this needs any action from you. Existing shares, and any device that hasn’t updated yet, keep working exactly as before while the rollout completes.

Keep reading

Try termique free.

SSH manager with end-to-end encrypted credentials, AI assistant, and cross-device sync.

Download free

Keep reading

All articles ⟶