13 ms·
IronRDP: a Rust implementation of Microsoft's RDP protocol
- fadedsignal 2y ago[flagged]
- kvdveer 2y agoGiven the number of devastating memory unsafety issues we've seen in RDP, I kinda welcome this effort. Let's see more $foo implemented in rust.
- gwervc 2y agoI swear it's forbidden by the language licensing to write any novel software with it. Actually I'm also pretty sure it disproves writing software by oneself in favor of asking others to (re)write their software in it.
- nindalf 2y agoIt's nearly impossible to have an idea that is truly novel and has no prior art. Even if it isn't the exact same thing, you can see the ideas that inspired this one. All of us are standing on the shoulders of giants all the time. But you've missed a couple of reasons why Rust rewrites are popular. Rewriting in Rust is proven path to better performance (Python codebases pandas -> polars, black -> ruff) or better security. C/C++ codebases like FreeType being rewritten in Rust for security (https://developer.chrome.com/blog/memory-safety-fonts https://developer.chrome.com/blog/memory-safety-fonts). What should people looking for performance or security do to mollify you? You are asking why aren't completely new ideas being implemented in Rust? They are. Check out https://rerun.io https://rerun.io. I could be mistaken, but I haven't seen anything similar to rerun. And that was implemented in Rust. Maybe these aren't visible because there genuinely are so few things that are completely novel.
- knowitnone 2y agoyet another complaint for no good reason
- pixelpoet 2y agoThey were annoyed by something, and made a post about it. Aren't you doing the same?
- geenat 2y agoDoes this implement a server? or client only? Linux?
- jeroenhd 2y agoThis code seems to be part of some kind of cloud offering for enterprise cloud environments. A lot of RDP code seems to concentrate on a React component for connecting to an RDP server. Edit: I've juist built the code on Linux and the demo video is recorded on Windows, so this seems multi-platform. There's also code for a .NET client in Avalonia (a cross-platform GUI library) so I'm guessing the entire thing should work on any modern OS. There's a basic skeleton for an RDP server in the code, but the README is a bit short.
- hulitu 2y ago> React component > code for a .NET client in Avalonia So is this written in Rust or not ?
- steveklabnik 2y agoGithub's languages analysis says 87.7% Rust, 9.3% C#, 1.3% TypeScript.
- awakecoding 2y agoYes, IronRDP is written entirely in Rust, but we also have bindings for .NET and the web. We originally developed it for our RDP web client for Devolutions Gateway (https://github.com/Devolutions/devolutions-gateway https://github.com/Devolutions/devolutions-gateway) but now also support it as an option in Remote Desktop Manager (https://devolutions.net/remote-desktop-manager/ https://devolutions.net/remote-desktop-manager/). Devolutions Gateway implements the RDCleanPath extension used to bridge WSS to RDP, making the connection from a web client possible. The same IronRDP core can be compiled to a native client for regular RDP connections outside the browser. There is also some work done for the server, but it's not as advanced as XRDP.
- jeroenhd 2y agoThe demo in the README is pretty impressive for an independent implementation, but I also noticed the repo includes server code (https://github.com/Devolutions/IronRDP/tree/master/crates/ironrdp-server https://github.com/Devolutions/IronRDP/tree/master/crates/ir...). I wonder if tools like Proxmox could use this as a more efficient alternative to VNC (which is slow and weird) or SPICE (for which there are very few non-Linux tools).
- tlamponi 2y ago> I wonder if tools like Proxmox could use this as a more efficient alternative to VNC (which is slow and weird) or SPICE (for which there are very few non-Linux tools). Yeah, we at Proxmox are actually evaluating such things, and we hope that IronRDP and QEMU display [0] can be part of a stack that replaces SPICE in the long term, but it will need a bit more time to see how this play out and what exact role it can play in Proxmox VE. Another experiment is to see if we can add a more modern video encoding to QEMU, as the recently released noVNC 1.6 gained support for H.264 [1]; albeit we naturally would prefer something more open like AV1. [0]: https://gitlab.com/marcandre.lureau/qemu-display/ https://gitlab.com/marcandre.lureau/qemu-display/ [1]: https://github.com/novnc/noVNC/releases/tag/v1.6.0 https://github.com/novnc/noVNC/releases/tag/v1.6.0
- nemanja 2y agoCompute overhead of H.264 encoder is non-negligible for a VM host where I want all my CPU cycles to go to user VMs. Datacenter-class Intel CPUs (Xeon) don't include H.264 encoders in hardware. QuickSync circuitry is generally limited to consumer-grade CPUs. Not to mention MPEG licensing issues. AV1 eliminates MPEG licensing issues, but encoding in hardware is even more limited. Also, AV1 is great for encode-once use cases (e.g. YouTube) since it's heavily geared towards reducing bandwidth requirements vs. encode speed. It's workable for real-time streaming in the lowest settings, but H.264 is still better overall.
- concerndc1tizen 2y agoWouldn't it also be a problem that, IIUC, a CPU only has one encoding engine, so you could only have one active stream (at full speed), in a multi-tenant scenario?
- kayson 2y agoThis is very cool. I still think MS RDP is the best remote desktop client and protocol. The performance is just insanely good, and the client is easily available on 95% of computers. The multi-monitor support is also awesome. The only downside is that it's Microsoft...
- DaiPlusPlus 2y ago> The performance is just insanely good, It's still artificially capped to a really awkward framerate (maybe 24fps or ~32fps?), even today.
- rcarmo 2y agoYou can set that to 60fps - https://taoofmac.com/space/protocols/rdp https://taoofmac.com/space/protocols/rdp
- DaiPlusPlus 2y agoThat article instructs readers to use H.264 rendering and to set DWMFRAMEINTERVAL - thing is, DWMFRAMEINTERVAL is a host-side parameter and apparently all it does is set an upper-limit on the possible refresh rate [1], rather than force the entire RDP system (client and server) to run at a specific frane-rate. This also conflicts with a personal experience of mine: possibly around 2007-2009 I remember using a FOSS RDP client meant for Linux but ported to Windows for some reason, and I preferred using it to connect to a shared WS2003 TermSrv box on the LAN because it sure felt like 60fps, despite everything else wrong with a barely-complete Win32 port (I don’t think they even used MINGW; mad lads…). It was my own TermSrv box and I know I didn’t do anything server-side to make it work so buttery-smooth. …which tells me that the compromised user-experience caused by the artificially capped frane-rate of the RDP session is entirely at the direction of the client, not the server. But that was… 15+ years ago (…fuck), it’s possible the protocol has changed and maybe it’s something both host and client negotiate, but clearly its possible and clearly someone in the Windows Server group at MSFT enjoys cinema too much because they seem to think 24fps is good enough for everyone. Also, when you use H.264 in RDP, it defaults to 4:2:0 chroma subsampling[2] which is going to ruin fine-details and make text ugly if not unreadable - there’s a reason we use H.264 for movies but not text documents. I remember around 2013 when a bunch of competing remote-access companies all launched hardware-accelerated-video-based remote-desktop products and being impressed with how they handle remote-Netflix over a pre-LTE mobile tether, but reeling and gasping to throw-up after their aggressive codec motion-estimation, subsampling, and YUV colorspace absolutely butchered a 100% zoom Word document with ClearType enabled. Using the system instilled oneself with a strong discipline against ever moving or resizing a window on the desktop, lest the smears of low-bitrate macroblocks start to appear, warning you the text-on-screen is about to become painfully unreadable for the next few seconds while you curse the DSL connection you’re still forced to use because your apartment complex’s HOA got a sweet deal on satellite TV from the incumbent telco by blocking the local cableco, with their sweet sweet DOCSIS 4, from adding service to the building and I’m done. [1] https://learn.microsoft.com/en-us/troubleshoot/windows-server/remote/frame-rate-limited-to-30-fps#setting-frame-rates https://learn.microsoft.com/en-us/troubleshoot/windows-serve... [2] https://learn.microsoft.com/en-us/azure/virtual-desktop/graphics-encoding#chroma-subsampling-support-for-420-and-444 https://learn.microsoft.com/en-us/azure/virtual-desktop/grap...
- nailer 2y agoFedora recently ditched VNC support in their installer for RDP. https://docs.fedoraproject.org/en-US/fedora-server/installation/interactive-remote/ https://docs.fedoraproject.org/en-US/fedora-server/installat... (which may be a Wayland think, I just know more about Fedora than general Linux distros). RDP seems to have taken the zeitgeist in the open source world.
- IshKebab 2y agoIt is a lot more advanced than VNC, and the open source world doesn't seem to have come up with any alternatives.
- InsideOutSanta 2y agoRustDesk is intended to be a TeamViewer alternative but works quite well as a simple remote desktop application: https://github.com/rustdesk/rustdesk https://github.com/rustdesk/rustdesk
- raphinou 2y agoI thought to have seen some negative comments about its security, anyone knowing more about it?
- InsideOutSanta 2y agoI haven't heard anything negative about it, and I can only find one CVE: https://www.cvedetails.com/cve/CVE-2024-25140/ https://www.cvedetails.com/cve/CVE-2024-25140/ Personally, I'm not exposing my installations to the Internet, so I feel relatively secure regardless.
- Arrowmaster 2y agoThey installed a root certificate on windows computers that could have been used to MITM all traffic. I personally had issues with the project years before that when I tried to install their Linux .deb and they ran `pip install` as root in the pre install script inside the .deb. That caused so much havoc to clean up I was pissed at them for years. Now that idiocy is blocked by default in current versions of pip.
- zelon88 2y ago[flagged]
- InsideOutSanta 2y agoI wonder if that comment is a result of vibe coding. LLMs often fill their code with comments that restate the literal behavior of a line of code rather than explaining it in a way that adds value.
- 999900000999 2y agoIt being FOSS means you can fork and customize it. Maybe instead use it as a headless automation tool.
- kasajian 2y ago"I shouldn't have to read code to understand comments" That's fair, but that's not universally agreed. Some say comment the "why" not the "what" because you can always read the code to understand the what. Also, code will likely be more correct than the comments if code is modified, and the comment isn't. And finally an entirely different school of thought is that you don't need comments if you name your functions right, breaking every few lines, the thing you would have otherwise commented on, into its own function with a good name. I think all of these are good suggestions to some degree. I'm somewhere in between, leaning toward more comments to help the AI
- pizzafeelsright 2y ago"I read comments to understand code" I read some of your repo. You write a lot of comments. Your response also describes reasons why I avoid reading comments. I think your preference comes off as an attack on different approaches. I attempt to code so clearly that I do not need to document as the code is self documenting. And the code you're talking about is probably AI written. I don't let AI comment on my code unless told to. fyi your website is down or too slow.
- jeroenhd 2y agoThis isn't a public project to write an open source Rust RDP client, it's the result of a company selling cloud software open sourcing their RDP stack. It stands to reason that things like comments and documentation aren't as extensive, because the goal isn't to attract maintainers per se, but to provide context to employees working on the code. I find the READMEs to be more than informational enough for that purpose. The RDP implementations I've seen are in unsafe languages like C. With the history of memory exploits in RDP (targeting both servers and clients), I think RDP code written in a language where memory bugs don't immediately lead to security issues are an advantage here. The code also readily compiles to WASM and can be used from within a web browser, which isn't as easy when you need to bundle all the dependencies for a project like freerdp. As for the comments, they're not great, but the style isn't that uncommon. Documentation is rarely written to explain the program to you, most developers I know write comments to explain the things that may not necessarily be clear by code alone. The expectation for most software developers is that you're ready to read the code if the docs aren't clear immediately. I much prefer extensive documentation, but I have to admit that I've run into issues more than once because nobody bothered to update the extensive documentation above a function after several changes, leading to inconsistent behaviour. A failure of the code review process for sure, but these things happen in software projects, unfortunately. In my experience these are often generated by IDEs, AI or, the result of including comment coverage in KPIs. They can sometimes be useful, though, like when you write a Rust function declaration with lifetimes and generic types, where notation becomes quite difficult to read.
- graynk 2y agoI get the whole Rust -> Iron thing, but when I see Iron prefix I think of dotnet because of https://github.com/ironlanguages https://github.com/ironlanguages and https://ironsoftware.com/ https://ironsoftware.com/
- TheRealPomax 2y agoGiven that it's an implementation of Microsoft's RDP, not sure that's a "but" in this very specific case =)
- badlibrarian 2y agoI think of IronPython and IronRuby and IronScheme, early attempts at Microsoft trying to combine cornmeal with .NET and open source and calling it a burrito. https://ironpython.net/ https://ironpython.net/ https://en.wikipedia.org/wiki/IronRuby https://en.wikipedia.org/wiki/IronRuby https://en.wikipedia.org/wiki/IronScheme https://en.wikipedia.org/wiki/IronScheme
- tracker1 2y agoThat was my first thought as well. Surprised to see they're still seeing updates. Also surprised to never see an IronJS or IronTypescript or similar really.
- snoman 2y agoIt be weird to see MS make an IronTypescript given that they created typescript.
- 38 2y agocannot build for windows ironically https://github.com/Devolutions/IronRDP/issues/709 https://github.com/Devolutions/IronRDP/issues/709
- stodor89 2y agoIRONically, hehe
- jeroenhd 2y agoThe error says cmake is missing, not that it doesn't build on Windows.
- 38 2y agoJust what I want, a C requirement for a Rust project
- paulddraper 2y agoSounds like it's not your Rust project. But cmake is required by Rustls (or more precisely, aws-lc-rs).
- nsteel 2y agoEven more precisely would be that it's a requirement for the default rustls backed on some platforms for some features. aws-lc-rs is a pain, but fortunately ring is just a feature flag away. Sorry, it's not the point of what you were saying. You can tell I've been stung supporting users with this.
- iJohnDoe 2y agoIs this available for Linux? Linux desperately needs RDP. Any Linux distros with RDP built-in?
- mhurron 2y agoXRDP? Only real problem I know of there is it doesn't support Wayland.
- allanrbo 2y agoYes, Gnome on Ubuntu and Debian has had a built in rdp server for the last several releases: settings -> sharing -> Remote Desktop -> on
- Saris 2y agoFor some reason the performance with those is never on par with windows RDP, it feels a lot more like VNC.
- rcarmo 2y agoLook into installing xorgxrdp-glamor and openh264. I have zero issues in Fedora, at least, and most of my Debian machines (even ARM) have equivalent packages (although sometimes without full acceleration).
- alexpadula 2y agoThat is mighty impressive. Thank you for sharing!
- shravankumar8 2y agoamazizng
- paulddraper 2y agoThat's...a confusing name. Given that IronPDF, IronXL, IronQR, IronBarcode, IronZIP, IronPPT, IronRuby are written in C#/.NET.
- awakecoding 2y agoMy apologies for the name choice, I actually didn't know "Iron" was taken for a lot of C#/.NET projects. We were looking for something that meant "hardened" because it's written in Rust, and went for "IronRDP". This being said, we're generating .NET bindings to IronRDP which we use in Remote Desktop Manager.
- KomoD 2y ago> We were looking for something that meant "hardened" because it's written in Rust, and went for "IronRDP" Hardened means hardened, hope that helps.
- password4321 2y agoThis is great. I'll have to look into spinning up a client for out of support Mac OS editions via macports -- the last version of the official client sometimes crashes eating up GB of RAM. I also would like to integrate smart card support into the client instead of passing through the hardware to the host... entering PINs through the normal remote UI always gives me the heebie-jeebies.
- MasterYoda 2y agoWhich good free open source alternatives for remote desktop on win 11 are there where you can install both a server ()for win11 home that have the rdp server) and have a client you connect with? Knows only about VNC, but never liked it? And ironrdp just looks like the client. Whant to selfhost the server.
- theragra 2y agoI bought sketchy Serial number upgrade go windows 11 pro to solve that
- TiredOfLife 2y agoChrome remote desktop for over internet and sunshine/moonlight for local lan
- shmerl 2y agoHow does it compare to freerdp feature wise?
- eitland 2y agoBased on what I see under https://github.com/Devolutions/IronRDP?tab=readme-ov-file#how-to-enable-remotefx-on-server https://github.com/Devolutions/IronRDP?tab=readme-ov-file#ho... it seems like the server part is Windows only?
- seritools 2y agoIt's instructions for the Windows RDP server to enable RemoteFX support so that the Rust client can make use of it. Maybe I'm missing something, but for the server side it's only crates that help you build your own server, no direct integration with any system, be it Windows or otherwise.
- eitland 2y agoOk, so there is a server for Linux as well?
- inetknght 2y ago> 1. Julia has two sisters. That means there are three girls in total (Julia + two more). False. Julie could be the name of a boy. > 2. Julia also has one brother, named Martin. OK > 3. Altogether, there are four siblings: three girls and one boy (Martin). Where did you identify the third girl? > 4. From Martin’s perspective, his sisters are all three of the girls (Julia and her two sisters). Here's where the answer comes from (Julia and her two sisters). More directly: "How many sisters does her brother Martin have?" > 5. Therefore, Martin has three sisters. OK. So the reasoning might have come to the "right" answer but the way it arrived at the answer was incorrect.
- inetknght 2y ago(derp, I just now realized this is in the wrong post and meant to post it here https://news.ycombinator.com/item?id=43439186 https://news.ycombinator.com/item?id=43439186 )
- stuaxo 2y agoOoh.. if this could support GfxRedir, then it could open up various interesting virtualisation things.
- reneberlin 2y ago"With a focus on security" was the punchline and i had to smile. While i encourage the great intention and the work that has been done, it seems an oxymoron to create a secure client to connect to unsecure clients. I will never forget that blazing speed of the BlazeRDP-implemetation that i used in the past that is now long forgotten. I never saw such an speed-optimized RDPish implementation. I knew i was connecting to unsecure clients and used a propietary fix to a MS-based protocol, but it was insanely fast. I never had such a fast remotedesktop since then regardless of the OS. This is not an ad, i'm not affiliated, it's simply a fact in my life, that i recall.
- Fidelix 2y agoAny links to share? I don't care about security for my use case.
- reneberlin 2y agohttps://sc.ericom.com/ericom-blaze/ https://sc.ericom.com/ericom-blaze/
- reneberlin 2y agoAnd i forgot to mention something: the mobile client was also the best that i ever used, too. Absolutely intuitive back in the days - but i don't know how it is today. But i expect it to be even better, not degraded.
- RandyOrion 2y agoJust a random note. As someone in this thread already stated, if you want smooth remote desktop experience with security requirements, you may try sunshine + moonlight for streaming with tailscale / zerotier for connection.
- znpy 2y agoJust a quick note from somebody who's been tinkering with RDP: RDP is so much more than remote desktop, and this ironrdp thing looks cool but is also severely limited. xrdp supports forwarding audio (playback and microphone forwarding, both ways) as well as local folder forwarding. And I think i also got webcam working (webcam on my laptop forwarded to the browser running on the remote host). for reference: https://www.xrdp.org/ https://www.xrdp.org/ I hope this implementation gets to a maturity level to make it actually usable for realistic remote desktop usage :)
- noAnswer 2y agoDoes someone know why folder forwarding is so slow? Browsing forwarded directories is not production ready at all! (I'm not talking about xrdp, but the original RDP.) Even SMB2 over WAN is faster. If a program has a deep link and has to process one file, ok. Everything above that and it turns into a waiting game.
- gHA5 2y agoRemote Desktop Protocol protocol
- buybackoff 2y agoIs it feature-complete with RDP and then some? As someone who has spent, over the last ~15 years, probably equal amount of screen time on RDP vs local (even in the office it's usually RDP to a blade, and at home a laptop to a powerful workstation; with remote work recently it's so much more and often nested), and someone who tried Linux on Desktop regularly and gave up because of inferior RDP alternatives (even GNONE 47 is a joke for RDP, but getting closer), - I learned to appreciate all the tiny details that make the RDP proper great.
- kuon 2y agoDo you know a good client on linux with Wayland support? I have artefacts with all clients I tried.
- jdadj 2y agoProbably coincidentally, in a blog post today, Cloudflare announced clientless, browser-based support for RDP. It seems they're using IronRDP under the hood. https://blog.cloudflare.com/browser-based-rdp/ https://blog.cloudflare.com/browser-based-rdp/
- EthanHeilman 2y agoCloudflare person who did some of the very early prototyping on this. I posted about our use of IronRDP here. https://news.ycombinator.com/item?id=43441709 https://news.ycombinator.com/item?id=43441709 I would strongly recommend IronRDP, excellent open source project.
- lxe 2y agoInteresting to see a Rust implementation of RDP. The protocol has a lot of quirks and edge cases that make it challenging to implement correctly, especially around authentication and session management. The focus on security is good, but I'm curious how they handle RemoteFX and other proprietary extensions that often require licensing. Would be great to see this become a solid foundation for cross-platform RDP implementations that don't rely on the official Microsoft stack.
- hackerbrother 2y agoI love RDP! It really is an impressive technology. I work in-office somewhere, and when I'm on campus, RDPing into my desk laptop from a conference room client has native performance, with audio even. What is the best remote desktop server for Linux?
- tgtweak 2y agoRemotefx is a really big feature addition. I still think modern alternatives like parsec are better in almost every regard but RDP is extremely mature.
- londons_explore 2y agoRDP has a huge array of features. It can be everything from server side rendered and just sending a video stream over the network to client side rendered and sending openGL commands over the network. There is a massive difference between a basic implementation that works and a fully featured implementation which works reasonably over a 56k modem.
- apatheticonion 2y agoWow! It would be amazing if this also supported high performance streaming codecs for local game streaming as the latency/fps of RDP is too low for that - though its ergonomics are unmatched (screen resolution, resizing, etc).
- sushidev 2y agoI’m using kasm/webtop containers to work remotely via the browser. Is there something similar using rdp/ironrdp?
- codecraze 2y agoWhat would you use to Remote Desktop between 2 mac without latency? I tried several tools but it was lagging (screen sharing, vnc, spashtop, anydesk, …)
- htk 2y agoNative screen sharing with the high performance* feature works great for me. (requires the native client to work) *[https://support.apple.com/en-gb/guide/remote-desktop/apdf8e09f5a9/mac https://support.apple.com/en-gb/guide/remote-desktop/apdf8e0...]
- codecraze 2y agoAh thanks. I missed that part. Will give it a try!
- szundi 2y ago[dead]