9 ms·
Show HN: 1-FPS encrypted screen sharing for introverts
I wanted to show you something I was hacking on for the last few weeks.
I tired of sharing screen via Google Meet with 1-hour limitation, with Zoom and 40-minute limitation, etc. With paid Slack subscription. And often times I just needed to screenshare with no audio.
So I ended up with my own solution - no registration, low memory, low CPU, low tek 1 fps encrypted screen sharing. Currently sharing only the main screen (good for laptop users).
It's very raw in terms of infrastructure, since I'm not counting bytes (yikes!), everything works on my own dedicated server. But the service itself has been tested, we've been sharing screens for countless hours. All sessions last for 48 hours, then it gets removed with all remaining info.
Every new frame replaces the other, and everything is end-to-end encrypted so even server owners and operators won't be able to see what are you sharing.
There is also no tracking, except the main page - and I use my own analytics. Sessions are not getting tracked and never will be, and observability currently is not in place.
Again, this is a true one-person side hacking project I hope (but I have serious doubts) I might need to scale if it's getting traction to support more users.
- popcalc 2y ago# github.com/go-vgo/robotgo In file included from go/pkg/mod/github.com/go-vgo/robotgo@v0.110.1/key.go:15: ./key/keypress_c.h:22:18: fatal error: X11/extensions/XTest.h: No such file or directory 22 | #include <X11/extensions/XTest.h> | ^~~~~~~~~~~~~~~~~~~~~~~~ compilation terminated. https://github.com/go-vgo/robotgo?tab=readme-ov-file#requirements https://github.com/go-vgo/robotgo?tab=readme-ov-file#require... There are some prereqs not listed your page. On Mint 22 I had to install the libxtst-dev package.
- RomanPushkin 2y agoThanks, I will update docs. "robotgo" has some issues on Windows, I am currently looking into some of them.
- burkaman 2y agoWhat is your use case for screensharing without audio? I can't figure out when that would be useful, you have to communicate with the other person somehow.
- kirykl 2y agoScammers use no audio screen sharing while on the phone with a mark
- deleted 2y ago[deleted]
- nottorp 2y agoAnd disgusting extroverts need full video and audio to ... feel complete?
- skulk 2y agoFrom TFA: > 1fps.video is perfect for introverts and remote workers who prefer sharing their screen without the pressure of audio or video calls. It's a versatile solution that works alongside any team chat application you're already using. It seems closer to "text chat while sending screenshots" than "share screen in a voice call." I can see why some would prefer this.
- burkaman 2y agoI get that, but it's also designed for sharing your entire laptop screen, so you'd have to either switch back and forth between code and chat, or take up half the screen with your chat app, both of which seem like they would be pretty disruptive to the actual screensharing. It seems like it would be better to just send a screenshot and then discuss, so the other person doesn't have to watch you typing messages to them instead of looking at the actual thing you want to share.
- theamk 2y agothat's what I thought as well, but then I read this part: > we use WebSocket-based cursor tracking, providing smooth, near 30 FPS pointer movement for precise demonstrations. This part does not seem to support that use case, you don't need 30 FPS pointer tracking for text chat.. Moreover, it'd be actively bad, as the cursor is likely to be pointing to the text chat window.
- Willingham 2y ago[flagged]
- popcalc 2y agoIt sounds like you're describing Windows Recall for Enterprise.
- imagetic 2y agoI love it. Our workflow is built around removing the need for an office and technical infrastructure. We have live streams of our timeline output (video editing) and an open comms channel. Most of our team is pretty introverted, so it's a push to talk system. We mostly just leave notes in the chat if it doesn't warrant a full discussion. Crude solutions are often the ones that get adopted.
- RomanPushkin 2y agoI'm happy to hear that. I've just open sourced the server part, so you can play with it a little bit more! I will improve docs over the time, so it's easier to follow.
- deleted 2y ago[deleted]
- zokier 2y agocould be interesting concept to try to make some heuristics for picking which frame to use; just blindly picking always the latest frame is unlikely to be ideal, instead you might want to pick frames where there is little movement, or no ongoing animations, or some other similar metrics. if you want to be super fancy, you could try to do this analysis per-window and then construct some sort of aggregate for the whole frame.
- eddd-ddde 2y agoI think this may defeat the purpose of minimal compute utilisation. It definitely sounds like a great idea and an interesting problem.
- RomanPushkin 2y agooh, I like it actually! I had idea to scan the screen with 5-10 pixel sparse 100x100 matrix at the point where the change has been found previously to detect a possible screen change.
- philsnow 2y ago> you could try to do this analysis per-window and then construct some sort of aggregate for the whole frame This seems like it could get into the area of smartphone "cameras" that do so much computation on the output of the light sensors that it can hardly be called photography [0]. It's a cool idea (in chess I've heard a similar idea called "quiescence search"[1]), but probably not worth the trouble. [0] https://old.reddit.com/r/Android/comments/11nzrb0/samsung_space_zoom_moon_shots_are_fake_and_here/ https://old.reddit.com/r/Android/comments/11nzrb0/samsung_sp... [1] https://en.wikipedia.org/wiki/Quiescence_search https://en.wikipedia.org/wiki/Quiescence_search
- KomoD 2y agoI'm having issues with the cursor tracking, I don't know if it's because I have multiple monitors or something like that? Here's a pic, the ring is where my cursor actually is https://i.imgur.com/TvzskjS.png https://i.imgur.com/TvzskjS.png
- RomanPushkin 2y agoThanks, you have my promise that for every major use case there is going to be a fix. Feel free to check out at a later time if has been fixed or not. I appreciate the feedback
- vngzs 2y agoGood job releasing your project! It's a cool idea and surprisingly minimalist. That said, I've found a number of cryptographic flaws in the application source. This should not be used in instances where the encryption is mission-critical. 1) You generate a random key [0] and then feed it into PBKDF2 [1] to generate a 32-byte AES-GCM key. If you can generate 32 random bytes instead of 10 reduced-ASCII characters and a key stretch, just do that. PBKDF2 is for turning a password into a key, and it's far from the recommended algorithm nowadays; prefer scrypt if you need to do this sort of thing. 2) AES-GCM with random 12-byte nonces. Never use random IVs with GCM; this breaks the authentication [2] [3]. Given the pitfalls of AES-GCM with respect to random nonces, you might prefer switching to XSalsa20+Poly1305. The advantage of XSalsa is it has an extended nonce length, so you can use random nonces without fear. 3) Random key derivation with a restricted character set can make brute force attacks easier. You should have a 256-bit random key, and if you want that key to be within a certain character set, then encode the byte output from the CSPRNG using that character set. 4) 1fps achieves symmetric key distribution via a URL with a fragment identifier ("#") which IIRC is not sent to the server. Therefore it assumes you have a secure key distribution channel - the link contains the key, so it's important that only the intended recipient can view the part after the "#". If the server is truly malicious, it can deploy client-side Javascript to send the fragment to the server, allowing the server to access the key (and thus cleartext communication). [0]: https://github.com/1fpsvideo/1fps/blob/main/1fps.go#L99 https://github.com/1fpsvideo/1fps/blob/main/1fps.go#L99 [1]: https://github.com/1fpsvideo/1fps/blob/main/1fps.go#L287 https://github.com/1fpsvideo/1fps/blob/main/1fps.go#L287 [2]: https://eprint.iacr.org/2016/475.pdf https://eprint.iacr.org/2016/475.pdf [3]: https://soatok.blog/2020/05/13/why-aes-gcm-sucks/ https://soatok.blog/2020/05/13/why-aes-gcm-sucks/
- RomanPushkin 2y agoThat's pretty cool and this is exactly why I am here :) To have this kind of advice. I'll implement these changes as soon as I can.
- mass_and_energy 2y agoThis is such a healthy interaction, it makes me so happy to see people lifting each other up like this
- rustcleaner 2y ago>limited proprietary GNU-nonfrenly screensharing Was Rustdesk on-radar?
- andrea76 2y agoDoes it support wayland?
- deleted 2y ago[deleted]
- cornholio 2y agoDoes it use WebRTC? The last time I've looked at this - and what stopped me from releasing a more polished MVP of the same low impact continuous meeting-not-a-meeting concept - is that the only way to scale WebRTC is to use your own paid infrastructure. The only peer to peer topology available WebRTC clients support is a star, so without a multiplexing server you are practically limited to a handful of peers in any session. So you are either offering a slow and very limited free service, or you need to pay hand over fist and burn venture capital to basically compete with Zoom and WebRTC. Slowing the video stream to very low FPS does help somewhat with scaling, but makes for a niche product. If you can crack P2P multiplexing and offer an unlimited free service, and tack on some fremium model on that, that this thing can take off like a rocketship, if for no other reason that every team leader in the world wants a continuous feed of their remote worker's desktop. A free and capable screen sharing app can become THE tool for collaboration, disrupting things like Slack if the right features are there. I'm seriously interested to cofound something like that, let me know if anything I've said makes sense to you.
- walterbell 2y ago> every team leader in the world wants a continuous feed of their remote worker's desktop. "every" -- why? Do high-performance teams have low or high trust?
- cornholio 2y agoI'm not sure what you are arguing here: that low performance teams do not exist, or that they do not need to be managed, or that we should provide free educational resources to their managers instead of selling them the tools they want? It's a real problem real companies face, look at r/overemployed for a taste.
- chfritz 2y agoWould YOU like to work with your manager looking over your shoulder at all times? A good manager builds trust, rather than needing to rely on control.
- deleted 2y ago[deleted]
- JS-Sound 2y ago[flagged]
- formerly_proven 2y ago1 FPS screen sharing? Isn't that just MS Teams on a tuesday?
- rjsw 2y agoTeams does the no-audio part too.
- andriamanitra 2y agoFrom reading the code it looks like it's just taking a screenshot (.jpg) and sending it once a second. Does doing it that way actually save on bandwidth compared to modern video compression (that re-use information from previous frames)? I recorded a one minute video clip of me editing some code in VS Code (1440p 10fps, using AV1 encoding) and it was about half the size of 60 JPEG screenshots of the same screen. I would be curious to see your numbers if you've done any tests.
- AndrewKemendo 2y agoSeems like is preventing data persistence (replace, delete) was chosen over minimize bandwidth (no optimization) But could easily do both if you wanted to - though I’m not sure it’s worth the hassle. I agree that this might struggle if used at scale on the same IP
- nine_k 2y agoNot only that. JPEG works best on natural-looking images, with gradients, curves, constant and wide color variation, etc. Computer screens very often show entirety different kinds of images, dominated by few flat colors, small details (like text) and sharp edges. That is, exactly by "high-frequency noise" JPEG is built to throw away. JPEG either makes "smeared" screenshots or low-compression screenshots. PNG often works better. A proper video codec mostly sends the small changes between frames (including shifts,like scrolling), and relatively rare key frames. It could give both a better visual quality and better bandwidth usage. What's interesting in the "screenshot per second" solution is that it can be hacked together from common existing pieces, like imagemagic, netcat, and bash; no need to install anything. (Imagine you've got privilege-limited access to a remote box, and maybe cannot even write to disk! Oh wait...)
- kijin 2y agoThe problem with the JPEG vs. PNG debate for screenshots, is that screenshots can contain anything from photos to text to UI elements to frames of video. Just open any website and you'll see text right beside photos, or text against a photographic backdrop, often in the middle of being moved around with hardware-accelerated CSS animations. I think we need an image container format that can use different compression algorithms for different regions or "layers" of the image, and an encoder that quickly detects how to slice up a screenshot into arbitrary layers. Both should be possible with modern tech. I just hope the resulting format isn't patent-encumbered.
- AndrewKemendo 2y agoI was looking for something like this today because we’re remote monitoring a physical test event and having an open google meet with recording is a mess - however we would still want to be able to have text chat for the interface Seems like this is a really good minimal interface - if I’m feeling wonky I might extend it with chat persistence somehow I am assuming any additional synchronized text or voice is done elsewhere like calling someone on the phone or clarification via text on slack right?
- RomanPushkin 2y agoThis is what I sometimes do with a friend of mine: WhatsApp phone call and a simple screen sharing between my laptop and his PC.
- CyberDildonics 2y agoI was looking for something like this today Earlier today you were thinking you specifically needed exactly 1 fps?
- fitsumbelay 2y agovery cool idea, and the pro-introverts pitch is very interesting I really appreciate the discussion about the tech involved, especially non-go lang info and advice. peak HN imo
- jpeeler 2y agoOpenDNS is reporting this domain as malware :( https://malware.opendns.com/main?url=1fps.video&server=nyc4&prefs=&tagging=&nref https://malware.opendns.com/main?url=1fps.video&server=nyc4&... - not sure if that's viewable elsewhere, but if so there's a report link there.
- Dwedit 2y agoMoonlight Game Streaming has pretty much displaced VNC for my uses. It just needs some better features for things like file transfer, clipboard sharing, etc...
- nicman23 2y agoi just need the clipboard to be honest and maybe a service that can nat punch
- 38 2y agodoes not work on windows
- RomanPushkin 2y agoSee updated docs for Windows users: https://github.com/1fpsvideo/1fps?tab=readme-ov-file#windows-users https://github.com/1fpsvideo/1fps?tab=readme-ov-file#windows... Please understand the Windows toolchain is often broken, and binaries are preferable. I will roll out binaries soon for all platforms. I also noticed some cursor coordinates issues on Windows machine (I have high resolution). I'm wondering if you have any issues with that as well. Good news is that there are steps to workaround and we're aware of these issues :) I guess check back later, I hope we gonna fix it soon!
- samstave 2y agoThis is awesome - and you've got some great advice. The following was just inspired by the idea of yours "1fps screen sharing": If you do 1FPS screen sharing - then create a private gallery on imgur.com - and have a thing update screenshots in a single gallery with a garbage collecting thread deleting a screenshot every 30 seconds/interval... then have user have hidden gallery url and auto refresh browser tab. This might work well actually if you have a small data connector and a device that can upload like only when event occurs. Just upload that to replace the file in the imgur gallery - and you have a free cloud cam.
- WatchDog 2y ago> I tired of sharing screen via Google Meet with 1-hour limitation, with Zoom and 40-minute limitation, etc. FWIW, jitsi[0] is an open source[1] WebRTC based, full featured, video conference/meeting alternative to zoom, google-meet, slack, etc. You can use it via the main site, or self-host it if you like. [0]: https://meet.jit.si/ https://meet.jit.si/ [1]: https://github.com/jitsi https://github.com/jitsi
- unnouinceput 2y agoI prefer https://talk.brave.com/ https://talk.brave.com/ over jitsi. Same idea but I find it better than jitsi
- throwaway5070 2y agoThis is literally a themed Jitsi instance. Even fetches its assets from Jitsi's CDN, lol
- unnouinceput 2y agoI used jitsi for a long time. Then they started throttling and then they demanded user registration. I ditched them at that point and started using this. What you say it's maybe true, didn't checked, but for above reasons I gave up on them. Each to their own I suppose
- amelius 2y agoThe maximum of 4 users can be a bit limiting.
- arendtio 2y agoNextcloud Talk is another option, but you probably need the Golang High-Performance backend [1] for more than three people simultaneously. [1] https://github.com/strukturag/nextcloud-spreed-signaling https://github.com/strukturag/nextcloud-spreed-signaling
- goldielox 2y agoCool! Been working on some automation bots in golang lately, so could I use your program to monitor my screen on the go over the phone? cheers
- RomanPushkin 2y agoYes, you can do that. There is a session limitation of 48 hours. Curious if it works for you?
- goldielox 2y agoYes that's more than enough, cool man, will give this a try soon! I'm not that sure I can trust my bots fully yet haha, need a simple way to monitor them on my phone when I'm AFK haha
- account42 2y ago> You need Golang installed for this command to work. What makes all these newfangled language ecosystems think this is an acceptable way to distribute your software. No, I don't want to install yet another giant tree of language specific crap. Learn to distribute self-contained binaries please.
- Cyberdog 2y agoFor most professional software, I agree. For hobby projects like this, I can certainly understand the appeal of asking users to compile it themselves rather than trying to provide binaries for all of the possible OS and hardware combinations in use today, most of which you might not even have access to for testing. That said, certainly there does seem to be a weird glib assumption by some hobby/OSS projects that of course I already have the same developer ecosystem/toolchain installed on my system as they do - of course I have a Rust toolchain or can install dependencies with Homebrew or am using Linux with systemd/Wayland. This project at least kindly asks me to install Go first if I haven't already.