Remote access giant AnyDesk resets passwords and revokes certificates after hack
techcrunch.com
techcrunch.com
> AnyDesk did not respond to questions asking if any customer data was accessed, though the company said in its statement that there is “no evidence that any end-user systems have been affected.”
> “We can confirm that the situation is under control and it is safe to use AnyDesk,” AnyDesk said. “Please ensure that you are using the latest version, with the new code signing certificate”.
Mmm. If I were an AnyDesk customer I'd definitively want more details on what actually happened before I used their software again.
In my experience, this answer is equivalent to "Yes, customer data was accessed".
If it wasn't, they'd say something like "We have no reason to believe customer data was accessed", instead of trying to shift the focus to whether or not end-user systems were caught up in the blast radius.
The last one, where both the domain name and password start with QR, makes me think the screenshots might actually be legit.
Go figure :)
But that "new code signing certificate" smells very bad. I would nuke anything signed by them ASAP.
You’re probably not in their target demographic to begin with, if you ask such questions.
I often use vnc myself but for end user it is way too hard to install.
It has a bunch of weird code smells that make me a bit hesitant to use it for supporting family members, but it seems to work well from what I read from others?
I use Teamviewer quite regularly, but that has some issues with Wayland. Free for personal use, but closed source with no self-hosting capabilities.
RustDesk works really well and is fast. I switched from TeamViewer because they wanted money. I switched from AnyDesk because it gave me more problems with disconnecting, has the worst UI of the three and sometimes my screen would be a minute or more behind what the host was seeing.
Can I ask why you mentioned this? It stands out.
For a while it used `sed` to disable Wayland on Linux in a way that only applies to Gnome (specifically on Ubuntu and a few other distros). The code also has a bunch of other exec()s with several commands piped into each other to parse the output.
None of it seems ill-intended, but it's code I would straight reject if I would be tasked to review it.
Sounds like a shakedown to me.
If you want a cloud thingy and it's just for personal, chrome remote desktop is decent enough.
If you need this to be highly performant (like accessing a crunchy 3d modeling rig from your ipad, or remote gaming) then Parsec is the best.
I mostly use it for family remote support and things tho, performance isn't amazing but it's plenty good.
Also supports things like relaying over an agent, hardware key authentication, file browsing. It's a little wonky in spots but overall it's such a great piece of software.
Not free, but I was using Remotix until they got bought out by Acronis who haven't really done much but increase the price and rebrand it (really long name "Acronis Cyber Protect Connect"). It does work on Linux and MacOS but I always found the performance to be lacking and the UI is workable but not great.
"Apache Guacamole is a free and open-source, cross-platform, clientless remote desktop gateway maintained by the Apache Software Foundation. It allows users to control remote computers or virtual machines via a web browser, and allows administrators to dictate how and whether users can connect using an extensible authentication and authorization system."
I can access the computer remotely without opening a port.