Show HN: P2P remote desktop – an alternative to TeamViewer / AnyDesk
github.com
github.com
A good chunk of NAT devices will pick external port based on [src ip/port, dst ip/port] combo, not just [src ip/port], so "WAN IP/port" you get from STUN will get you nothing useful. Not by itself.
STUNs should be used for discovering the pattern in NAT port overloading logic and then using it to predict which port your peer will use towards you if you were to try and connect now.
That is, you need to know the overloading pattern and then also time stuff correctly.
For that reason you will need a rendezvous server and it's also the best to let the server drive the whole process (as opposed to what STUN-based setups do, which is to let clients do it).
PS. In my past life I made a P2P VPN called Hamachi, which used all this stuff very extensively.
Don’t miss stuff listed under “peanuts”.
Unfortunately, there hasn't been much progress on that funtionality, as the ipfs team seems to focus more on "crypto" lately. But it mostly works: http://docs.ipfs.io.ipns.localhost:8080/reference/cli/#ipfs-... and I guess this gives more context on relays: https://github.com/ipfs/go-ipfs/issues/7433#issuecomment-640...
Otherwise, there is a useful library of firewall traversal libraries in any webrtc implementation.
https://syncthing.net/ https://github.com/hyperswarm/hyperswarm (whole family hypercore, hyperdrive, hyperswarm, ...)
All peers simply lookup their external port via STUN and publish this information.
What do you suggest as a learning resource for things like this? The STUN RFC's? The Stevens' networking book?
Stevens' book is a must read, yes, but it has nothing even on NAT (iirc), leave alone on working around it. Look at how NAT works, what types of it exist, etc. Then look at "hole punching". For bonus points skim through p2p-hackers mailing list archives from 2003 and thereabouts.
Very little has changed in this area since mid-00's, people just rediscover and re-implement the same thing over and over again. Few get it 100% right (IMO) due to sticking to prediction being done client-side. That's inferior to the server doing it, because it gets you more precise timing and better prediction rate.
I personally have been using Parsec most often these days and might even start paying money for it soon for some of their advanced features, as they've recently pivoted their marketing towards the productivity side, which is a move I'm happy to support with my wallet. I honestly don't see a reason why someone would use any of the traditional players in the space these days for personal use. Not sure how the tech in this project compares, but I think it should try to measure itself against something like Parsec/Rainway rather than TeamViewer/AnyDesk if it wants to compete at the state of the art.
Parsec and friends use more bandwidth and hardware resources to get a stream going, but that stream is of much higher quality. You probably won't be running a fully-staffed remote support company over DSL or basic cable with Parsec, but with Teamviewer you just might. I've made several remote support connections at the same time on ≤8Mbps down on a simple Core i3, you just can't get that done with a game streaming solution like Parsec. Modern streaming services also require hardware encoding support or their CPU requirements are huge, and the endpoints support software often connect to isn't that powerful.
Microsoft's RDP solution in excellent on all fronts, though. Normal H.264 encoding for moving content and static-optimized codecs for office machines, all with heuristics to switch codecs on the fly. Sadly, this is all locked away behind licenses for consumer devices, but the technology is there.
Is it? Even on gigabit LAN there's a noticeable amount of latency. For web surfing it's mostly passable, but for text/code editing it's very annoying.
We even ran our Dev machines in Azure over RDP/WAN. Only those on <30Mbps connections had noticable issues
i do excel, word, Libreoffice, firefox, heck employees even watch youtube on firefox over rdp and its "slightly" difficult to have it desync video and audio sometimes but it works.
my only problem is getting rdpwrap to patch every 3-4 months. i run ltsc so i should be getting less updates but what do you know, it messes up and all hell breaks loose.
terminal services.
people are stuck with either paying microsoft/citrix or using rdpwrap
But yeah, definitely. Parsec is far, far superior to TeamViewer et al.
It competes with RDP more than TeamViewer.
The core idea is simple: a video stream from one computer to another, with mouse and keyboard controls sent the other way. Connection negotiation can be done Magic Wormhole style, via basic STUN, encryption can be done in a number of ways. Add some clipboard and P2P file transfer features and you've got most of Teamviewer/Anydesk/whatever implemented. There's VNC, but that's horribly outdated and the UX is absolutely terrible.
I think there's a business to be built here; open source remote support with a Gitlab-style self-hosted option companies can put down in their own networks, or have them pay you for management and servers.
This project is a good starting place, as any. With some tweaks you could probably build this into a end-user friendly system with your usual numeric code and random password. There's a business to be built in this space, I'm sure of it. I wish I had the expertise to take advantage of that.
https://github.com/rustdesk/rustdesk-server/blob/master/id-r...
The rates for decent remote support software are terrible. For €150 per month, you can use three simultaneous connections across your entire organization, limited to a certain number of users who might possibly use the system. Teamviewer once offered lifetime licenses, but then they inserted ads for their subscription model into the lifetime customers to get even more money out of them.
All the rest seem to copy the terrible design of on demand code signing and that doesn’t work. If you get an EV certificate for instant SmartScreen reputation the key is on a HSM. If you get an OV certificate that is easier to automate with you need to build SmartScreen reputation which is brutal.
The RuskDesk project mentioned below was the most interesting to me. It’s a small executable and works pretty good. That’s enough to tell me that someone should be able to build a great product if they have instant support executables signed with an EV certificate.
What it comes down to though is that everyone needs their own code signing certificate or someone needs to run a matchmaking service. I’m sure you could build something that works well with Cloudflare Workers/KV by sending hashed (+salted) IDs to a matchmaking Worker. When a customer reads me the ID I know the secret and can tell the matchmaker “here’s the secret, please redirect the client to my self hosted server, relay, etc. at support.example.com.”
Also, Screego is another interesting project to check out.
A possible solution would be to distribute the client through something like the Windows Store on Windows, and a URL connection handler. The support-receiving website (or intranet support page) could work by opening a URL like remote-support://internal.domain.eu/listen from a web page and if that fails, link to the Windows Store and install directions instead. An unsigned, backup download of unsigned executables can be added to that download page if you so desire.
Theoretically, you could also set up some kind of DHT or TOR-like network where nodes can just find each other. You wouldn't want to send standard Bittorrent or TOR traffic without warning in corporate networks, of course, but the technology exists.
For businesses, the unsigned executable with config could just be distributed by the IT department with their own certificate or the necessary exemptions, and launch an autoconnect daemon, if necessary.
The _real_ challenge, I think, for building such a tool is that if it works well, scammers will use it and slander your product. Some might even patch out any warnings or alerts that you add to protect innocent people from scams. Scammers aren't intelligent enough to make their own RAT, but just one tech-savvy criminal could make loads of money with some slight modifications.
There's more nuance here which OP is alluding to. If you form a corporation and get an EV cert, you will not get a SmartScreen block, not even on your very first download. Immediate SmartScreen reputation is the point of getting an EV cert for this; Microsoft says this explicitly. If you get an OV cert (the only kind that an individual developer can get!), you will get blocked and will have to build reputation.
As an individual open source developer, I have an OV signing cert :( At least it shows my name on the SmartScreen prompt.
I’ve never done it myself but there was a posting here about 8 years ago about how Dropbox distributed their installer and I took a quick look at it: https://news.ycombinator.com/item?id=8204454
It pairs well with Tactical RMM https://github.com/wh1te909/tacticalrmm
I'd really like to replicate this, even in a really simple CLI way but I haven't found all the right blocks to fit together. Naturally I don't have TeamViewer's account servers to rely on, and ideally I'd not use any centralised/third-party service at all (e.g. Zerotier or Tailscale).
My current idea is to make a GNUnet VPN and then use avahi to discover SSH or VNC servers, then I can use Remmina as a fancy GUI. This will probably be slow and difficult.
There are plenty of FOSS tools that do almost what I want, but none I've found quite gets there yet.
;) that's what an MVP is used for - prove key business assumptions.
as I see it, space is hardly the issue, nor build/engineering - as a species we are pretty apt at abstracting around them.
I've not had need to use VNC, remote desktop etc for years.
That's because it's not only a matter of software but also a matter of service (STUN is not enough, TURN is required in many situations. And someone has to pay for the servers and bandwidth...). If IPv6 had succeded instead of IPv4+NAT, maybe the situation would be different.
In terms of software, the open-source x2go (based on nomachine NX libraries and protocol, see https://wiki.x2go.org/doku.php) has been very efficient in my cases when bandwidth was limited and when I had no big NAT issues.
I agree that STUN/TURN servers are a necessity, but they're not _that_ expensive to self-host. You could stuff the STUN/TURN feature behind rate limits for the hosted version or put them behind a pay wall entirely so companies don't have to mess around with that stuff themselves.
ssh -v -L 5900:localhost:5900 user@remotehost 'DISPLAY=":0" xterm -e "x11vnc -localhost"'
And then krdc vnc://localhost
or whatever VNC client you like.For linux-to-linux this has replaced TeamViewer for me, together with zerotier.com for getting through NAT.
TeamViewer / Anydesk (and the rest) regularly take actions to disable accounts of fake call (scam) centers.
For examples of this check out the youtube channels of:
Jim Browning / Kitboga / Perogi and lots more
take a look at the way this type of software is used to abuse and scam older people who have no clue about how computers (and the associated scams work)
Take a look at any single video on any single one of those youtube channels and you will see that this is a problem that needs to be at least considered. It could be as simple as a massive warning detailing the scam on the installer.
Edit: In fact heres a link Its both hilarious and depressing all at the same time.
Also 100% FOSS, but more advanced.
Gratitude is the fairest blossom which springs from the soul. (Henry Ward Beecher)
Is there session recording and MSI deployment?