Rustdesk – Remote desktop software, an open source TeamViewer alternative
rustdesk.com
rustdesk.com
A quick glance at the code also reveals an almost complete lack of comments and copious use of unexplained `unsafe`.
This tool was clearly written by someone with a "make it work for the general public" mindset. And, to be honest, I'm not 100% opposed to this approach, although there should definitely be a giant warning system configuration is changed. When a piece of software says "You are using Wayland and this software requires X11, please change your desktop session type" then you're not helping most people. A simple button to fix the problem can be a lot better than an error message with a link to a complicated step-by-step guide.
As is often the case, this client seems to have been made for people running Ubuntu/Fedora, and a relatively recent version at that.
The copious amount of unsafe seems to revolve around operating system APIs being called. Interacting with X11 requires tons of unsafe operations, you can't really work around that. The best you can do is make your own wrappers to hide the fact you're calling unsafe code behind the scenes, but I can't see too much unnecessary unsafe code in there to be honest.
The user now has one app that works, potentially dozens that don't, doesn't know why it broke, and doesn't know how to fix it. Which is why destructive fix it's for a single app is not a great idea. If it was non-destructive, I would totally agree with you.
I'm sure there are some applications out there that rely on Wayland support, but Wayland is unusable for proper remote tech support without some extensions to the API that Wayland developers don't want to add (notably, the ability to send input to running applications).
There are workarounds (hooking directly into the input system, for example) but those work despite Wayland, not because of it.
I'm willing to go as far as to say that by clicking the "fix me" button, the end user will probably end up fixing more applications than it breaks.
Depends on what what you mean by "Wayland developers". Wlroots, and thus sway, support such extensions and I think KDE is open to standardizing such extensions. Gnome supports remote desktop through an xdg portal. The problem is that, as with several other things, all of the compositors haven't agreed on a single standard.
Which apps work on wayland but not x11 ?
Though people who want to avoid using toolkits would probably do that, as Wayland's API is much more sane for apps.
However for example Waydroid only supports running on Wayland, and somehow nobody has created a reverse XWayland yet (People that ask for this get constantly redirected to nested compositors which is absolutely the wrong thing, a proper reverse XWayland would seemlessly integrate the apps like Xwayland does, and you could drag them, transparency would work, and https://wayland.app/protocols/xdg-shell#xdg_surface:request:... would be converted to _GTK_FRAME_EXTENTS, etc)
I've used sway, as an example to Wayland only, and if you have specific things configured around Wayland as a compositor, they break too..
But that shouldn't really be the focus point of the discussion, what really is the point, you don't just yank a whole system wide config out from under an unsuspecting user, there's so many variables you just don't know or can account for. Creating a stable application, is also respecting other apps and the system it runs on, not just going in blazin' fixing things for yourself and then not caring about what side effect/consequences it can have. And worse, not informing about it properly.
This app probably should use libinput to emulate keyboard/mouse instead of tapping into X11. No need for crazy hacks as libinput supports Wayland. Applications that provide remote desktop-like functionality like Sunshine used it and runs well on Wayland.
Notably, the lack of a mouse cursor is kind of a big deal for remote support situations. You want the user to be able to indicate stuff with the mouse.
What is Gamestream ? What is Moonlight ?
Nvidia gamestream is the proprietary server from nvidia, sunshine is an opensource server compatible with gamestream protocol, and moonlight is an opensource gamestream client.
Hum I don't understand this, I've been injecting key strokes for a decade on any Linux-running system using uinput (which creates a new virtual /dev/input). Is this somehow broken by wayland? (I haven't ever really used wayland, nor do i understand how it works)
This is not well-written Rust; code like the below actually defeats the purpose of using Rust, and without any specific reason for doing so.
I personally discourage people from using this software.
static mut KEYBOARD_HOOKED: bool = false;
fn start_keyboard_hook(&self) {
if unsafe { KEYBOARD_HOOKED } {
return;
}
}
The build even requires an assembler (NASM), which is odd, in this context.Edit: Further, there's no such thing as "the purpose of using Rust". Different users can use the same tool for different purposes, and Rust is no different.
To keep in mind, on a pragmatic level, that this type of global can be trivially implemented, at a minimum, via atomics, so the cost to avoid the unsafe is near-zero.
Atomics are not supported by all the platforms, but based on my understanding of their targets (x86-64), they're supported.
AFAIK on any typical platform there's no way you'd have "tearing" for a single byte ie: this will never store an invalid boolean representation.
(Since I use sway on Ubuntu, rather than gdm, I’d argue it’s a capital offense, but YMMV.)
> "Warning" > "Current Wayland display server is not supported" > `Fix it` => a button triggers system gdm config change > A 'Help' link to github, showing how to change the config manaully.
I wouldn't count it as malware. But I don't think it's OK to change the system configuration by pressing a button of a remote desktop software. It should simply provide a link to user instead.
[1] https://github.com/rustdesk/rustdesk/blob/45375517b960add901...
I wonder if the fact that the original author comes from the largest non-English-speaking population in the world [1], a population large enough to have its own distinct software development culture, is relevant. I'm guessing that they don't routinely participate in our English-speaking software development communities. If that's so, then they're not exposed to our norms or the constant negativity of our online discourse. Perhaps that's liberating. Perhaps we need more independent cultures, doing their own thing with no regard for what we think. In any case, for me, software developed in China, such as this project and Zoom (particularly the Windows client), provides an interesting peek into what Jimmy Maher called a mirror world [2]. It may trigger our natural discomfort with foreignness, but some of the differences from the typical American commercial software culture, such as a continued willingness to develop bloat-free native Windows apps, are refreshing.
[1]: https://news.ycombinator.com/item?id=31457771
[2]: https://www.filfre.net/2017/06/tales-of-the-mirror-world-par...
Edit: If anyone thinks what I said is offensive, please let me know, either publicly or privately. I tried to approach a delicate topic without offending, but I'm not sure if I succeeded.
I am a native English speaker living in the USA.
I constantly feel belittled, undermined, and shunned by the technically literate - especially the hyper technically literate - because of the exact negativity you’re talking about. I can only imagine the level of shock someone who hasn’t built up calluses to the mentality would feel.
The negativity is most often this kind of discourse. How gizmo x wont possibly fly because of some rules and general ideas, and how this person’s other gizmo is really the bar to meet, and everything else is not worth their time.
I cannot impart to you how terrible I felt for months thinking that I was such a bad engineer that I couldn’t stand up a simple web server on a droplet. I felt like “it’s just so easy and obvious” and I gave up multiple times.
This may be crusty software by some people’s standards, but I challenge those same people to put down their high projects, spend 10 minutes writing an issue, or even a weekend with a PR, and dropping this whole schtick of “lol look at the bad developers doing bad things.”
This comes off as damning and condemning, and it is by intent, but it’s also a cry for help.
If you are technically literate enough to identify issues in something technical.. be the person that shares that understanding freely, instead of holding it like a bar of achievement.
I have to say, this phrase just struck me as pure arrogant xenophobia.
Like most people on here, I'm sure I can safely speak for the majority when I say there is plenty of shit American commercial software out there. The patriotic US flag waving and "made in US" does not automatically make it the best software.
Also many organisations, especially in Europe, will almost bend over backwards to avoid being tied too much to the US because of what the three-letter-agencies get up to, and the anti-foreigner legislation that supports them.
The recipe to get rid of that "natural discomfort with foreignness" that yanks have is simple: Most Americans just need to get out more ... get that passport that so few of you have and spend some proper time outside US borders (and no, trips to Canada don't count, and likely neither does Mexico).
Edit: However:
> Like most people on here, I'm sure I can safely speak for the majority when I say there is plenty of shit American commercial software out there. The patriotic US flag waving and "made in US" does not automatically make it the best software.
As someone who happens to be American, I emphatically agree. I regret that I didn't make this clear in my original comment. I meant to say that I think projects like Rustdesk and the Zoom Windows app are better than a lot of American crap in some important ways. I was trying not to be arrogant, but clearly I failed.
Edit 2: As for xenophobia, yes, I'm prone to it. I thought that was a natural human tendency, not peculiarly American, but I could be wrong.
I think the "trample the users gdm config" issue for example might be a small influence from the Chinese proprietary software world. A quick and dirty fix. At least there was some message in this case. Usually, proprietary Chinese software doesn't even ask. There was some wild stuff going on in the XP days.
I would not put any faith in the security of this software, which for remote desktop, is a problem.
Then read this:
> "... with no concerns about security"
Nevermind. Might be the cynic or skeptic inside me, but it tells me these people are either careless, naive or ill intentioned.
"... with no concerns about security" seems to be a bad maschine translation.
The Chinese version says "(you) don't have to worry about security".
Nevertheless, it still doesn't change my impression. I read it like "(you) don't have to worry about security". The other interpretation "we didn't worry about security" seemed too unlikely.
It doesn't inspire confidence if they want me to be in a relaxed position. I'd expect them to raise concerns about security and take the initiative to show how secure their system is...
I can't read anything on the front page though, the website shows up light-grey-on-white. Is that just me? Did the CSS fail to load somehow? Edit: never mind, the CSS sets the text color to #999 and a font weight of 200 for many elements. Apparently that's intentional. Going by the font list, I'm guessing the theming was tested on macOS and made to look nice without testing if the fallback fonts were even readable in the slightest.
I can’t remember the name (it was just two letters, like ‘SD’ or such) and I forgot to bookmark it as well…
Update: Found the thread https://news.ycombinator.com/item?id=31444913
i think some frontend engineers/designers might have misconfigured screens
otherwise i can’t understand why setting right contrast is so difficult
Open home page, "please set up your own server" Click link, second line "Note: You need buy license When using this software" Click link, "Currently we are not selling server licenses as we are working on a new version of the server. "
Combine this with the default server being slow and it’s unusable.
This is really great.
I dare say the performance is "better" than anydesk, nothing objective or I could measure. Maybe its me wishing it be as prevalent and more than anydesk/tw
Pretty typical imo
The cynical side of me wonders when the scammers are going to set-up their own servers for this though and start using it instead of AnyDe(x/sk)/TeamViewer. No way of being reported then other than the IP to the server host themselves.
I don't believe that reporting scammers to remote support companies has ever been effective in the fight against these people, especially with the local police departments near the scammers' offices taking their sweet time to respond to any outcry about them.
The sad reality is that less than a week after scammers find out about this tool, the Windows binary will probably be flagged by every single AV engine out there.
The biggest challenge for this group is getting them to: Find the website for the tool
Find the download button
Find the file in their downloads
Run it so they can give me the connect number
What the tool can do to help is make the website very distinct so I can be sure from a verbal description they’re on the right domain, have an in-your-face download button, and have 0 install or configure steps upon launch.
I have struggled with this very same problem, and finally using some short url for downloads. Helps a little bit.
But one funny story related to this: I was helping one gentleman and i told him on the phone that he should go to "www dot teamviewer dot com" . He had not used that before and his English skills were non-existent.
He had trouble finding Download -button from the site and that time Teamviewer.com had young female model stock photo there. I asked him - to confirm that he is on the right website - like "Do you see there that brown haired cute girl?". He answered: "Yes, and few blondes.".
I asked him to read address line for me and it was "teenviewer.com".
After few corrections to the url we finally got Teamviewer installed.
I use AnyDesk - it was the first one I found which requires no installation (and when I got access, I added a link on the desktop and start menu). However, it requires extra clicks to access sensitive things (device manager at least).
The only real problem I face is macOS requires these screen recording/accessibility permissions for the connections to work on some versions and it's extremely tedious to walk someone through setting those verbally.
Rustdesk refused to install because the macOS version was too old. Until Rustdesk runs on many OSes, especially older OS versions, it will be hard to use.
Mind you, it's not entirely clear what OS versions are supported from the website, so I went through a lot of trouble to get my dad to try and install it, only to then be disappointed.
I have hope though! It looks great so far.
In the past I found I was able to play some games on a windows machine remotely across campus from a terrible netbook running arch at like ~30 fps. Every other tool I tried had too much latency or was too poor quality of a connection to make that viable.
Edit. I may have been using the windows client through wine, I don't think they had an official Linux client at the time.
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
No, I don't know where that's documented. I pulled it out of the manifest of an existing installer.Who knows what other essential features they might put behind a paywall. Their licensing fees aren't even released yet.
Seems sketchy to me. I'd stick to meshcentral.
And maybe some code comments?
Sincerely,
metadat
I.e. encryption and self-hosting capable setver and FW hole-puncher.
also, it has shrink feature to make bigger screen fit on the local screen
Hold me.