3 ms·
We've tried to make sure the host and clients don't completely trust our cloud servers. For example the "Jump Desktop Connect" app on the host always requires c
by nonane 10y ago
We've tried to make sure the host and clients don't completely trust our cloud servers. For example the "Jump Desktop Connect" app on the host always requires credentials for a valid local account on the computer before it allows incoming connections through. It won't let accounts with blank passwords through. Also the credential transfer always happens over an end-to-end encrypted connection between the two devices - which means our cloud servers don't get to see or have access to your local computer's creds. This way, if someone gets a hold of your Jump Desktop account, they won't be able to get through unless they also know your local computer's creds.
Another way we protect hosts is by not allowing random hosts and clients to communicate with each other unless you've given explicit permission to each host/client. This means that Bob can't load up the Jump Desktop client and try to randomly brute force Alice's local account password by trying to connect repeatedly. The cloud server will drop Bob's connection requests to Alice unless Alice has explicitly given Bob permission to connect.
The above applies to our zero setup app, Jump Desktop Connect. Jump Desktop is also a full blown RDP and VNC client (with SSH support) - so you don't really have to use the Jump Desktop Connect app if you don't want to. You can use traditional RDP / VNC-over-SSH to establish secure connections as well.
- swozey 10y agoDo you have a system to block, mitigate or monitor for "strange" IP blocks accessing systems they've never accessed before? It's a great idea if not. We have, unfortunately, had to do this in webhosting/billing for a long time due to the amount of fraud from specific blocks. Not as dynamic, but for instance LastPass will allow you to blacklist or whitelist entire country IP blocks. A system that also monitors (on your end, or maybe alerts the customer) that their machine in Kansas all of a sudden has multiple IPs from China/whatever accessing it (on your end seeing this globally through the network as well) would be great to mitigate events like this. If you go on vacation, you can remove the block. So far every report I've seen has been Guangzhao/Yangzhao in the access reports. Could easily, easily nip that in the bud. Obviously other proxies could be used but something like a remote access system is something people should be locking down tightly.