Skip to content

Releases: stoatworks-labs/peephole

Release list

Peephole 0.1.0

Choose a tag to compare

@stoatworks-labs stoatworks-labs released this 22 Sep 09:12

Peephole has been live as a web page since September. This is the same tool as
a desktop application — for a machine on a show network with no route out, or
one that simply should not be talking to anything.

https://peephole.stoatworks-labs.com is still there and still free of any
install.

Which file

Every platform gets a build that runs anywhere and a smaller single-architecture
one. If you would rather not think about it, take the first column.

Runs on anything Smaller
macOS macos-universal.dmg macos-arm64.dmg — Apple Silicon only
Windows windows-setup.exe windows-x64-setup.exe, or -arm64-
Linux linux-x86_64.AppImage .deb and .rpm, x64 and arm64

The Windows -portable.exe files are the same builds without an installer, for
running from a USB stick. macOS also has .pkg installers and .zip archives
of the app bundle.

The macOS builds are Developer ID signed and notarised by Apple, so they
open normally — no quarantine step and no right-click-Open. Windows installers
are unsigned, so SmartScreen warns on first run.

What the app has that the tab does not

  • Full screen is the window, not an element inside it, so nothing of the
    application is left around the picture. Esc leaves it.
  • The mode list always comes from the device, on all three platforms. In a
    browser that is true only in Chrome and Edge — getCapabilities() is
    Chromium-only, and the app brings its own Chromium.
  • The screen stays awake properly, through a power-save blocker held by the
    process rather than the Screen Wake Lock API, which Firefox does not have and
    which every browser drops the moment the window is hidden. It also keeps
    painting when the window is behind something else, which is the normal state
    of a confidence monitor.
  • No permission theatre. No https requirement, no padlock, and a refusal
    names the operating system's own setting rather than an address bar the app
    does not have.

It does not use the network

Not to install, not to run, not ever. There is no updater, no telemetry, no
analytics and no crash reporting. The page is served to the window over an
app:// scheme from inside the application, with a Content-Security-Policy of
connect-src 'none', and the main process cancels every http/https/ws request
besides. Both halves are verified in the test run.

Still unproven

No real camera or capture card has run through Peephole yet, in either
shape.
The desktop app was driven end to end against Chromium's fake capture
device — Start, the picker built from real device labels, a mode change to
1920 × 1080 confirmed at the video element, the readout, full screen, settings
persisting, and the network refused. But a fake device always gives you the mode
you ask for, which is exactly what a real capture card does not, so the
downscale warning — the reason the tool exists — has not been exercised.

If you run it against a card, the thing to watch is the readout: it should name
the card's real mode, and warn when you are handed something smaller than you
asked for. Reports welcome on the issue tracker.

Nobody has launched the Windows or Linux builds on Windows or Linux either.
They package cleanly and CI builds them on their own runners; that is all that
can be claimed so far.