65 lines
2.8 KiB
Markdown
65 lines
2.8 KiB
Markdown
# Security and privacy
|
|
|
|
The default posture is local inference, explicit writes, and fail-closed
|
|
computer use. No telemetry or cloud inference is required. Model endpoints
|
|
stay on localhost. Public `web_search`, `google_search`, `fetch_page`,
|
|
`web_fetch`, `wiki_search`, `hn_search`, `code_search`, and `browser` are allowed
|
|
by default without a confirmation prompt and without extra API keys. They run in
|
|
a Jarvis-owned Chromium window. Private, loopback, and metadata URLs are
|
|
blocked before the browser starts. There is no SearXNG dependency. Shell
|
|
commands that open public HTTP (curl, wget) remain blocked by the runtime; use
|
|
the web tools instead.
|
|
|
|
```mermaid
|
|
flowchart TD
|
|
R[User request] --> P{Permission gate}
|
|
P -->|read| X[Execute locally]
|
|
P -->|write / dangerous| C{Explicit confirmation?}
|
|
C -->|yes| X
|
|
C -->|no| B[Block and explain]
|
|
X --> A[Audit metadata]
|
|
X --> D[Return result]
|
|
L[Lock screen] --> K[Revoke CU + webcam + mute HUD]
|
|
```
|
|
|
|
## Protected assets
|
|
|
|
- Microphone audio remains in a RAM ring buffer unless transcript retention is
|
|
explicitly enabled.
|
|
- Screen frames remain in memory or temporary storage and are wiped on
|
|
computer-use revoke by default.
|
|
- Webcam stills stay under `/tmp/jarvis-webcam` and are wiped on camera
|
|
revoke, lock screen, cancel, or `WipeComputerTraces()`. Camera access is
|
|
off by default and needs Settings plus Allow now.
|
|
- Computer-use audit logs store action metadata and screenshot hashes, not
|
|
screenshots.
|
|
- Voice references, memory, and model caches are user-owned files.
|
|
- QVAC binds to localhost; bearer tokens, when used, come from user-owned
|
|
configuration and are not logged.
|
|
|
|
## Filesystem access
|
|
|
|
Path tools default to the Jarvis workspace (`~/.local/share/jarvis-qvac` when
|
|
installed). Settings can widen that to your home directory or the entire
|
|
filesystem. This is still your user account: Jarvis does not gain root, and
|
|
writes plus shell commands still go through the confirmation gate.
|
|
|
|
## Computer-use controls
|
|
|
|
Computer use requires a spoken or HUD grant, shows a visible cursor/target, and
|
|
stops on revoke, Escape, lock screen, or grant expiry. It refuses password
|
|
fields, dangerous actions without confirmation, and actuation when the portal
|
|
or EIS backend is not ready. Legacy input is opt-in.
|
|
|
|
Camera access is a separate fail-closed grant. Enable it in Settings, press
|
|
Allow now, then the agent may call `webcam`. Revoke, lock screen, cancel, and
|
|
grant expiry wipe captured stills.
|
|
|
|
## Threat model boundaries
|
|
|
|
The daemon assumes the local user account and installed desktop libraries are
|
|
trusted. A malicious local process with access to the user's session bus or
|
|
filesystem is outside the protection boundary. Keep the repository and model
|
|
cache user-owned, use a restrictive token file mode, and avoid running the
|
|
daemon as root.
|