# RDP FIDO for Android — pre-beta 0.9.0

**Open pre-beta testing before the Google Play release.**
The app is free and works with any RDP-FIDO-GATE 1.15 or later (Windows or
Linux; the Free edition is enough). Anyone can join — below is what you
need, how to install, and what to send us.

Русский: [README.ru.md](README.ru.md)

| File | What it is |
|---|---|
| `RdpFido-0.9.0-prebeta.apk` | the app, signed with the Imobile developer key |
| `SHA256SUMS` | checksums |

SHA-256 fingerprint of the APK signing certificate:
`BF:FD:EA:D2:45:2E:D2:BD:1A:AD:02:E6:9A:0A:F9:5B:2C:A1:58:85:5A:AE:4F:CB:62:55:CA:0E:48:C2:60:BA`

## What it is

Same key, same gate — now from your phone. The app connects to Windows and
Linux machines protected by RDP-FIDO-GATE: the port stays closed to everyone
until you confirm with a FIDO2 key — and now the key can be the phone
itself. Nothing changes on the host: the gate accepts the phone like any
other client.

**Three ways to confirm**

- **The phone as the key.** A P-256 key pair is created in the phone's
  secure hardware (StrongBox or TEE) and signs only after your fingerprint
  or screen lock. To the gate it is the same hardware key as Windows Hello:
  the private key never leaves the chip, the signature counter grows with
  every login.
- **Security key over NFC.** A YubiKey or any FIDO2 key held to the back of
  the phone. The key's PIN is asked only when the gate requires user
  verification.
- **Security key over USB** through an OTG adapter — for phones without NFC.

**FIDO Stream — for games.** The same low-latency protocol as the desktop
client: UDP with AES-256-GCM, Reed–Solomon loss recovery, H.264, HEVC or AV1
straight into the phone's hardware decoder, 90 and 120 Hz panels, audio both
ways. Controls: physical gamepads over Bluetooth and USB (seen by the host as
an Xbox 360 controller, rumble comes back), an on-screen gamepad with a
draggable layout, a Bluetooth mouse with pointer capture, touchpad, direct
touch, keyboard and a quick-keys bar, Ctrl+Alt+Del to the host.

**RDP — for work.** A key touch opens the RDP port for 90 seconds and the
app hands the connection to your installed RDP client (Microsoft Remote
Desktop, for example) through an `rdp://` link — exactly as the desktop
client starts mstsc. The session password is placed on the clipboard.
Windows hosts and Linux hosts with xrdp are supported alike.

## What you need

- Android 9 or later. A fingerprint or screen lock for the phone-as-key;
  NFC for NFC keys; OTG for USB keys.
- A host with RDP-FIDO-GATE 1.15 or later — Windows or Linux
  (packages: https://new-imobile.com/download/rdp-fido-gate/linux/README.en.md ,
  Windows installer: https://accounts.new-imobile.com/updates/RdpFido-Setup.exe).
- For FIDO Stream over the internet, forward 7440/TCP and 7441/UDP on the
  host's router, as for the desktop client. For RDP — 7440/TCP and 3389/TCP.
- For the RDP mode — any RDP client on the phone that registers the `rdp://`
  scheme (Microsoft Remote Desktop does).

## Installation

1. Download `RdpFido-0.9.0-prebeta.apk` and open it. Android will ask to
   allow installation from this source (the browser or file manager) —
   allow it. Google Play Protect may warn about an app from outside the
   store — expected for a pre-beta.
2. Optionally verify the checksum against `SHA256SUMS`.
3. Open the app. It sends data nowhere except to your gate.

## First run

1. On the target machine get a one-time key enrollment code:
   `RdpFidoGate.exe code` (Windows, as administrator) or
   `sudo rdpfido-gate code` (Linux). The code is valid for 15 minutes.
2. In the app: “+” → the machine's address (for a gate in another network,
   its public address or DDNS), user name → protocol (FIDO Stream or RDP) →
   “Enroll key” → pick the key (phone / NFC / USB) → enter the code. The
   gate's certificate is pinned by thumbprint on first contact.
3. Tap the tile → pick the key → confirm with your fingerprint or a touch of
   the key. For FIDO Stream the stream screen opens; for RDP the external
   RDP client starts.

On the stream screen a thin bar at the top opens the panel: keyboard, quick
keys, control modes (touchpad / touch / gamepad), gamepad layout editing,
statistics, Ctrl+Alt+Del, key-frame request, disconnect. From a physical
keyboard the shortcuts are those of the desktop viewer: Ctrl+Alt+Shift+Q
disconnect, Ctrl+Alt+Shift+Z mouse capture, Ctrl+Alt+Shift+D Ctrl+Alt+Del,
Ctrl+Alt+Shift+M panel, Ctrl+Alt+Shift+O statistics.

## How to take part

So far the app has been verified on one phone (Mi Max 3, Snapdragon 636,
Android 10) against Linux and Windows gates. We need other devices and
scenarios. Especially valuable:

- phones and tablets on **other chips** (Exynos, MediaTek, Tensor, recent
  Snapdragon) and **other Android versions** (11–16);
- **90 and 120 Hz** screens, **HEVC and AV1** decoders;
- **NFC and USB keys** (YubiKey, Feitian and other FIDO2 keys);
- **physical gamepads** (Xbox, DualShock/DualSense, 8BitDo), a Bluetooth
  mouse and keyboard;
- connecting **over mobile data** and from behind NAT, through a relay;
- the **RDP** mode with different RDP clients on the phone;
- **Windows** hosts (NVENC, Quick Sync, AMF) and **Linux** hosts (xrdp, stream).

What to send: phone model and Android version, gate version and host OS,
what worked, what did not, and the **log from the app** — the “Log” screen
(button on the session list) → “Share”: the app version and phone model are
added to the text automatically. Where:

- the contact form on the site: https://new-imobile.com/contact
- e-mail: support@new-imobile.com

If you want a place in the **closed Google Play test** when it opens,
include the e-mail of your Google account in the message.

## Good to know about the pre-beta

- **Signing.** The pre-beta is signed with our developer key. The Google
  Play build will be signed differently, so the pre-beta will have to be
  uninstalled before installing it (the key and sessions are enrolled again).
- **The key in the phone** is bound to the app and the device: uninstalling
  the app or moving to another phone loses the key; on the gate it is
  removed with `RdpFidoGate.exe keys` / `rdpfido-gate remove-key`.
- **The app is free** and needs no activation; the Free/Pro licence applies
  to the gate only.

## Known limitations of 0.9.0

- The RDP transport is not built in: an external RDP client is used, as
  mstsc is by the desktop client. Without an RDP client on the phone the app
  says so and names the address and port — the grant is open anyway.
- Opus through MediaCodec rejects packets on the verified phone, so it is
  off by default — the host sends ADPCM. The microphone is sent as ADPCM.
- The relay and difficult NAT scenarios are implemented per the protocol but
  verified only logically — one of the main goals of the pre-beta.
- Old hardware decoders (OMX on Android 10) deliver a frame about two frames
  late.
- Shared FIDO Stream sessions (1.22) and file transfer are not yet
  implemented in the Android client.

## What comes next

Fixes from the pre-beta, then a closed Google Play test and the store
release. What is new in the gate and the desktop client:
https://new-imobile.com/download/rdp-fido-gate/CHANGELOG.en.md .
