Back

RustDesk now supports true unattended remote access on Wayland

99 points3 hoursrustdesk.com
inktype1 hour ago

RustDesk still does not support encrypted connections when self hosting: https://github.com/rustdesk/rustdesk/issues/3714

SubiculumCode41 minutes ago

I think you bring up a fine point. Most applications have encryption built in and transparent to the user. While technical IT people in charge of infrastructure will not make this assumption, it is not unreasonable, at the same time, for small business / individual users, to not understand or know of this limitation.

VNC does not, for example, and you need to set up port forwarding through ssh. X2Go does....but I don't trust it terribly. So, RustDesk..what do you need to wrap it in? ssh?

I really want a better solution that VNC/X2Go..especially since I use hardware accelerated apps that need to use VGL to operate correctly (but underwhich operation is quite buggy).

dj0k3r1 hour ago

Tailscale, or any encrypted mesh overlay is perfect for this. Infact I prefer it that way. Rustdesk can do what it does best at its core.

wooben43 minutes ago

Your statement is not entirely accurate. This only applies when using Direct IP Access on local networks, which is off by default. Their justification and invitation to PRs is the final comment [1] on the issue you linked. Why are you leaving this information out of your comment?

1 - https://github.com/rustdesk/rustdesk/issues/3714#issuecommen...

SubiculumCode37 minutes ago

It may only apply to Direct IP Access, but isn't that what many would expect (not trusting middleman to be secure?)

andai2 hours ago

Menu css looks a bit dodgy with the notification at the top:

https://files.catbox.moe/d5ztxi.jpg

ChocolateGod2 hours ago

How does this work on a technical level?

Does it framebuffer grab the current session and inject input events?

hparadiz58 minutes ago

Yea I need to know this before I even consider something like this. I'm guessing it's a daemon that runs as root in the background.

throwaway274482 hours ago

What is rustdesk and how is it distinct from vnc?

Edit: i appreciate the explanations; thank you.

pizza23460 minutes ago

VNC and RustDesk are both remote desktop solutions, however, Rustdesk is considerably more performant than the VNC family, because the latter primarily sends framebuffer updates, while the former can use modern video codecs and temporal compression to encode screen changes much more efficiently.

shock14 minutes ago

> Rustdesk is considerably more performant than the VNC family

It consumes, on the client, 800%-1200% CPU AND 8%-10% GPU decode on my NVIDIA card. I opened a bug and they transformed it into a discussion, without any response.

rcxdude1 hour ago

VNC is one way of doing remote GUI access (well, more a family of different protocols and products with different capabilities and tradeoffs). RustDesk is just another product that does the same thing but doesn't have a specific connection to VNC as a protocol so e.g. doesn't have to handle legacy authentication modes and stream formats. In my experience most remote access solutions beat VNC for performance, for example.

vablings2 hours ago

Well first there was TeamViewer which was VNC with more bells and whistles then it became enshittified. Then anydesk came along and ate up teamviewer then that became enshittified, Now we have rustdesk which seems to hopefully be a bit more immune to being enshittified.

If you already use VNC this is not something for you

mschild14 minutes ago

RustDesk is also open source including the server so you can fully self-host.

topspin23 minutes ago

I've noticed that RealVNC has hidden their formerly free VNC desktop client, now called RealVNC Classic Viewer, behind an enterprise subscription login, and replaced it with a different cloud first thing, RealVNC Connect Viewer, that requires a login to at least obtain, and is anemic in terms of features.

Not that RealVNC is VNC. However, enshittification has clearly taken another scalp.

Kelteseth30 minutes ago

Funny that the video in the blog post still needs X. I will see myself out....

Fidelix8 minutes ago

No need to announce

aspbee55549 minutes ago

RustDesk works so much better and easier than vnc and other vendored solutions. No need to open ports, no need for vpn, it just works, no account BS, no vendor lock in BS.

I have used RustDesk for years, also run my own lookup/relay server so I do not need to rely on the public lookup server

While everything else gets enshitified RustDesk just keeps getting better

SubiculumCode20 minutes ago

Without self-hosting, how can I be sure that the middleman server layer won't affect my security?

wartywhoa2348 minutes ago

Definitely a lifesaver for tech support!

And the fact it's self-hosted is priceless.

manav2 hours ago

Does my screen have to be on?

LoganDark2 hours ago

RustDesk should fix their password requirements: https://github.com/rustdesk/rustdesk/discussions/2888

applfanboysbgon2 hours ago

It's open-source, so just build it yourself with the tiny change. Something this trivial could be done with a 30 second prompt at this point, so there's not even an excuse of "too much effort".

I will note that the XKCD password scheme being proposed there is, in fact, completely insecure. A modern consumer GPU can crack "four random English words" in a day. You can argue that it's the user's choice to be allowed to use insecure passwords, but arguing that that scheme is actually secure is just wrong.

tredre32 hours ago

> A modern consumer GPU can crack "four random English words" in a day. [...] but arguing that that scheme is actually secure is just wrong.

Let me do just that!

This is a networked service. You send your password (or a hashed form) to it, and it validates it. You don't have the local hash to bruteforce it offline.

Even if we only consider the top 10k english words, it's 10000^4. It's going to take years to bruteforce this over a network because you'll go through so many rate-limits, cooldown periods, and outright bans that it's questionable whether it's even possible.

applfanboysbgon1 hour ago

Virtually any password other than "password123" is fine if you're rate limited to a few guesses per day by a networked service. Passwords should be secure against the inevitable data breach when the service you're using loses their hashed password database, which happens on a routine basis.

strbean20 minutes ago

Seems like the only real issue here is that rustdesk uses SHA256 instead of argon2.

tialaramex1 hour ago

> This is a networked service. You send your password (or a hashed form) to it

Hopefully neither. But given everybody involved in VNC seems to be the same batch of clueless morons who built all those PHP web forums twenty years ago with MD5 as the password hash, who knows what they cobbled together. Maybe an expert can chime in about what actually happens here?

Yes, for a sensible scheme this can't work.

throwaway274482 hours ago

> A modern consumer GPU can crack "four random English words" in a day.

Sure, if you can rely on users using a specific format. The joy of the xkcd technique is you don't need to tell other people what yours is.

But, people just aren't going to remember strings of gibberish. Expecting users to do this is just silly.

applfanboysbgon2 hours ago

The "joy of the XKCD technique" is that it prescribes a specific format millions of people will use, and it's so trivial to break that you can throw in similar variations of it into your cracking algorithm at virtually no cost.

If you were willing to use a bespoke, more secure variation of it, you could include a capital letter and a number rather than filing an issue on a repo insisting that you be allowed to use exactly the insecure variation.

+1
throwaway274481 hour ago
7bit2 hours ago

Okay. The feature I'm waiting for is the self-hosted web client.

zuzululu2 hours ago

so this means I can be on a vacation, turn on my ubuntu desktop remotely, login and control it ? I have a strong need for this as my desktop is also a server

VorpalWay2 hours ago

For a remote Linux system you can also do a lot over plain SSH as well.

amelius2 hours ago

You can already do this with VNC or Xpra (the latter is a screen/tmux for graphical applications).