Repository navigation
Security
Flashback runs next to your games all day, so it is built to be trustworthy on a gaming PC: it stays out of game processes, verifies every update twice before installing it, and keeps Cloud accounts passwordless. This page explains how, in plain terms, and how to report a vulnerability.
| Protection | How it works |
|---|---|
| No injection into games | Flashback records a display, not a game process. It never injects code or DLLs into a game and never reads game memory. That keeps it away from anti-cheat-sensitive game hooks. |
| No keyboard hooks | Global shortcuts use the Windows RegisterHotKey API. The optional input overlay uses Windows Raw Input only while it's enabled, never low-level hooks or input injection. |
| No administrator rights | Flashback installs for your Windows user only and never asks for administrator access. |
| Capture kept in its own process | The recorder runs in a separate capture worker with no network access, no updater and no Cloud session. It talks to the main app over a private local channel restricted to your Windows user and authenticated with a random secret for each launch. |
| Your Cloud session is encrypted | Cloud sign-in and the anonymous-status secret are protected for your Windows user with Windows DPAPI. |
An update to Flashback has to pass two independent locks. Each is held by a different key, and neither key alone can ship code to your PC.
Release published
|
+------------+-------------+
| |
Lock 1: signed manifest Lock 2: verified publisher
(an offline key signs (Microsoft Artifact Signing
exactly which version, signs the programs, plus a
file, size and SHA-256) catalog binding the whole
package's name, size and
SHA-256)
| |
+------------+-------------+
|
Flashback checks both, the file's
hash, and the publisher identity
|
Both pass? Install.
Anything off? Refuse.
In more detail:
- The manifest lock. Each release has a manifest signed with an offline key. It names the exact version, update feed, package and installer, including size and SHA-256 hash. A file that doesn't match is refused.
-
The publisher lock. Since 0.7.41, installers and programs are signed through Microsoft Artifact Signing, so Windows shows Flashback's verified publisher. The app pins that publisher identity and requires the certificate chain to end at Microsoft's identity-verification root. A separately signed catalog binds the whole update package (its name, size and SHA-256), so a genuine signed
Flashback.exesitting next to a tampered DLL still fails. - Built in, not downloaded. The keys and rules the app checks against are compiled into Flashback. A release that requires the publisher signature can't quietly fall back to checking the manifest alone.
- Whole packages only. Updates are always full packages, never partial "delta" patches, because a delta could replace the updater itself before the publisher check ran.
- No downgrades. Flashback remembers the newest release it has accepted and refuses an older one, even if it's genuinely signed. That stops a compromised website, CDN or mirror from serving you an old release. (It can't protect against malware that's already running on your PC; nothing in an app can.)
- Checked again at the last moment. Interrupted downloads resume, and what was already downloaded is verified first. Right before installing, Flashback fetches and verifies the manifest and package again and holds the file so it can't change underneath.
- Long-lived signatures. The catalog carries a trusted timestamp, so it stays valid after the short-lived signing certificate expires, and revocation is checked online.
- Roll forward only. A bad release is fixed by a newer one, never by pushing an older build.
Flashback checks for updates once when you open its window, never while it sits in the tray, and never downloads without your click. If your PC's clock is far off, the check tells you to fix the date and time rather than failing silently.
The full technical design is on Update Security Chain.
Download Flashback only from flashbk.gg or this repository's Releases. To confirm an installer is genuine, compare its SHA-256 hash with the one on flashbk.gg/faq and in the release's SHA256SUMS.txt, and check the signature in the file's properties. Verifying Downloads walks through both, step by step.
- No passwords. You sign in through Discord, or Google where offered, in your normal browser. Flashback never stores a password.
- Standard, safe app sign-in. The app uses the native-app sign-in flow (OAuth with PKCE), with the browser handing the result straight back to Flashback on your PC.
- Short-lived, rotating tokens. Access tokens expire quickly and refresh tokens rotate each time they're used. If an old refresh token is ever reused, the whole session is cut off.
- Sign out everywhere. On the web, Sign out of all browsers and apps ends every session at once, the app's included.
- No secrets in the app. The Flashback app contains no Discord, Cloudflare, storage or Stripe secrets.
| Protection | Details |
|---|---|
| Encrypted in transit | Every connection uses HTTPS with strict transport security (HSTS). |
| Encrypted at rest | Cloud data and clips are stored on Cloudflare, which encrypts them at rest. |
| Private means private | Only me and Friends media is kept off the public media host and served only through expiring links checked for each viewer. |
| Unguessable links | Share links use long random identifiers with at least 128 bits of randomness and aren't listed anywhere. Uploaded videos are served from a separate domain from the website and account pages. |
| Verified uploads | Uploads use short-lived permissions, each part is checked, and the finished file is verified before it's published. |
| Payments by Stripe | Plans are sold through Link, Stripe's checkout. Card details go to Stripe and never reach Flashback's servers. |
| Defense in depth | Strict content security policies, rate limits on every public endpoint, and abuse checks on uploads and forms limit the damage any single mistake could do. |
| Limited, logged staff access | The internal control center requires multi-factor sign-in, each person sees only what their role needs, and every change is recorded in an audit log. There is no routine browsing of users' clips. |
If you find a security problem in Flashback, the website or Flashback Cloud, please report it privately:
- Use the support form with the Security type, or email support@flashbk.gg.
- Include what you found, how to reproduce it, and the version you tested.
- Keep it private until it's fixed.
You'll get confirmation of receipt within three business days and updates until it's resolved.
Safe harbor. Flashback won't take legal action against good-faith research that follows the security page: don't access or change other people's data, don't degrade the service, and allow reasonable time for a fix before sharing details. There is no paid bug bounty yet. A machine-readable contact is published at flashbk.gg/.well-known/security.txt.
For abusive clips or profiles rather than security bugs, see Reporting and Safety.
Related pages: Privacy · Update Security Chain · Verifying Downloads · Cloud Account and Data
Flashback for Windows 11 · flashbk.gg · Discord · Support · Docs describe Flashback 0.8.0. Live version, checksum and policies are on flashbk.gg.
Start here
- System requirements
- Getting started
- Installing and updating
- Verifying downloads
- Shortcuts
- Settings reference
Features
- Instant replay
- Recording quality and presets
- Screenshots
- Audio
- Voice commands
- Editor and montage
- Overlays (input overlay)
- Library
- Storage limit
- Naming and organization
- Per-game profiles
- Ghost Mode
- Discord integration
Cloud and social
- Flashback Cloud
- Plans and billing
- Sharing and visibility
- Automatic and voice uploads
- Profiles and friends
- Web and phone
- Account and data
Privacy and security
Under the hood
- Why Flashback is light
- Architecture overview
- Capture pipeline
- Hardware encoding
- Isolated capture worker
- Replay buffer and segments
- Resource guards and recovery
- Audio and video sync
- FFmpeg build
- Built on .NET 10
- Update security chain
- Performance and benchmarks
- Release qualification
Help
Community and support
Links