Remote desktop for Windows that is small, fast and actually secure.
JVNC is a two-piece VNC-compatible remote desktop: a tray Server on the PC you want to reach and a Client on the machine you sit at. No cloud, no account, no subscription — and unlike the classic free VNCs, encryption and modern authentication are built in.
One installer for both Server and Client. Windows 10/11 64-bit. Self-contained — nothing else to install. Free.
What it does
⊞The Windows key, remotely
Win+R, Win+E, Win+D, Win+arrows — every Win+key shortcut goes to the remote PC, not the one you're sitting at. JVNC captures the key with a low-level hook while its window is focused. It is the only VNC-style tool that does this out of the box.
⚡Change-driven updates
The server captures with DirectX Desktop Duplication (whole, tear-free frames, even over hardware-accelerated video) and sends only the 64-pixel tiles that changed, the moment they change, up to ~120 fps. No polling lag, no fixed frame rate. Scrolling is sent as CopyRect (a few bytes per tile), and on a slow link the server measures the connection, budgets each frame, sends the area around your pointer first and drops JPEG quality before it drops frames. The mouse cursor is drawn into the picture.
⇅File transfer both ways
Send a file to the remote PC or fetch one from it, any size, streamed straight to disk. Auto-accept into a folder or confirm each one — the screen and mouse keep working during transfers.
▭All your monitors — your way
See the whole remote desktop as one image, pick a single remote monitor (only that monitor is sent — less bandwidth), or go multi-head: one full-screen window per remote monitor, spread across your own monitors.
⎘Shared clipboard
Copy on one side, paste on the other — both directions, within half a second. Toggle it off in the toolbar whenever you want the two clipboards kept apart.
♪Hear the remote PC
Tick Audio and whatever the remote PC plays comes through your speakers — 48 kHz stereo at about 48 KB/s, or a 12 KB/s mono mode for slow links. No other free VNC does this either.
▣Tray server
Starts listening the moment it launches, lives in the tray, single instance, starts at sign-in if you like. Closing the window doesn't stop it; Exit does.
⤢Viewer that gets out of the way
Full screen on F11, scale-to-fit or 1:1, remembered hosts, live fps/bandwidth readout so you can tell the network from the machine.
✓Works with your phone's VNC app
Standard VNC underneath: any viewer connects with a VNC password, and viewers that speak VeNCrypt (bVNC, AVNC, TigerVNC) get TLS too. The JVNC client adds the rest. Everything is logged with the exact reason for every disconnect.
⇩Drag, drop, done
Drop files from Explorer onto the remote screen and they land on the PC. Print on the PC to the JVNC Remote Printer and the PDF appears at your side.
↺Wake it, reach it, keep it
Wake-on-LAN with the MAC learned automatically, auto-reconnect that keeps trying (and waking) for ten minutes, and a reverse mode where the PC dials you — no port forward on its side.
●Record and audit
Record any session and play it back inside JVNC. The server keeps a JSON audit trail of every connection, file, clipboard and print job.
◌No stuck drags
If a client drops mid-drag, the server releases every held button and key. Your window never ends up glued to the cursor.
Security you switch on, layer by layer
Every layer is independent. The password is required by default (the server asks you to set one on first start, and warns you every time you switch it off). Turn on more for a port that faces the internet.
The mechanisms, precisely
| Layer | How JVNC does it |
|---|---|
| Password at rest | PBKDF2-HMAC-SHA256, 100 000 iterations, 16-byte random salt, 32-byte verifier. Only the verifier is stored. |
| Password on the wire | Server sends salt + 16-byte nonce; client answers HMAC-SHA256(PBKDF2(password, salt), nonce). Constant-time check. The password never leaves your machine; a captured proof is useless elsewhere. |
| Encryption | TLS 1.2 / 1.3 (Windows SChannel), RSA-2048 self-signed X.509, SHA-256, created on first use. |
| Server identity | Trust-on-first-use pinning of the certificate thumbprint per host; a changed certificate triggers a warning and needs explicit re-acceptance. |
| Client identity | Mutual TLS: the client presents its own RSA-2048 certificate; the server accepts only approved thumbprints, inside the TLS validation callback — unapproved clients never reach the protocol. |
| One-time code | RFC 6238 TOTP (HMAC-SHA1, 6 digits, 30 s, 160-bit secret), current step ±1, sent as HMAC-SHA256(code, server nonce) — never the bare code. |
| Secrets at rest | Windows DPAPI (current-user scope, app entropy) for the TOTP secret and remembered passwords. |
| Network filtering | IP/CIDR allow list before any bytes are exchanged; optional single-interface bind; non-private source addresses refused unless mutual TLS is on. |
| Brute force | 5 failed handshakes → 15-minute ban per address; 1 s delay per failure. |
| Protocol | With any layer on: JVNC-000.01 greeting + flags, then TLS → password → TOTP, then standard RFB 3.8 inside the encrypted stream. With all layers off: plain, byte-for-byte RFB. |
The Security Guide in the manuals explains what each layer does and does not protect against, and recommends configurations for LAN, VPN and port-forwarded setups.
Everything you've read about "VNC is insecure" — answered
Those warnings are about stock VNC. Here's each one, and what JVNC does about it.
| The classic danger | How JVNC answers it |
|---|---|
| Bots scan the port and brute-force the password | Per-address lockout (5 tries → 15-min ban, 1 s delay each). And the public-address rule refuses internet-address connections unless they present an approved client certificate — a bot is dropped before it can try one password. |
| The password can be captured in transit | It never crosses the wire — a PBKDF2 challenge/response, nothing to sniff or replay. |
| VNC is unencrypted; Wi-Fi can read your screen & keystrokes | Built-in TLS 1.2/1.3 encrypts everything; the client pins the server certificate against man-in-the-middle. |
| An open port is inherently unsafe | Approved client certificates (mutual TLS): without a key from one of your own devices the handshake can't complete — an open port only answers your machines. Add a one-time code for a second factor. |
| Opening a port means juggling modem + router + firewall + a changing home IP | Don't open one. Reverse connection has the PC dial out (no inbound rules), or a VPN (Tailscale/WireGuard) puts both machines on a private network — nothing faces the internet, nothing to maintain. |
How it compares
Against the usual suspects, out of the box on Windows. Green column is JVNC.
Security
| JVNC | TightVNC | UltraVNC | TigerVNC | RealVNC Connect (paid) | |
|---|---|---|---|---|---|
| Password | PBKDF2 verifier, challenge–response, any length | DES challenge, 8-char max | 8-char VNC auth or Windows accounts | VNC auth, or user/pass over TLS | System / cloud accounts |
| Encryption | Built in TLS 1.2/1.3, pinned | None (needs SSH/VPN) | Plugin (AES) | VeNCrypt TLS / X.509 | Always, AES-256 |
| Device certificates | Yes, approved list | No | No | Manual PKI | Cloud device auth |
| Two-factor (TOTP) | Yes | No | No | No | MFA |
| IP allow list + lockout | Yes + yes | Yes + basic | Yes + yes | Firewall + basic | Cloud policy |
| Refuses public IPs without a device cert | Yes, by default | No | No | No | n/a (brokered) |
| Secrets at rest | DPAPI-encrypted | Obfuscated in registry | Same | Config file | Cloud |
| Runs as service / shows lock screen | No — signed-in session only | Yes | Yes | Yes | Yes |
| Maturity / audits | New, unaudited | 20+ years | 20+ years (several CVEs) | Active security releases | Commercial, audited |
Features
| JVNC | TightVNC | UltraVNC | TigerVNC | |
|---|---|---|---|---|
| Windows key & Win+key shortcuts to the remote PC | Yes — hook keeps your own PC quiet | No | Partial (menu tricks) | No |
| Change-driven updates | Yes, ~120 fps cap | Hook/poll driver | Mirror driver optional | Poll |
| File transfer (both ways, unlimited size) | Yes | Yes | Yes | No (server) |
| Multi-monitor as one desktop | Yes | Yes | Yes | Yes |
| Single-monitor view / multi-head windows | Yes / Yes | Single only | Single only | Single only |
| Drag-and-drop files · reverse connection · Wake-on-LAN · session recording · audit log · printer redirection | All built in | Reverse only | DnD, reverse, log | Reverse only |
| Remote audio | Yes (built in) | No | No | No |
| Stuck-drag protection on disconnect | Yes | — | — | — |
| Installer needs nothing pre-installed | Yes | Yes | Yes | Yes |
| Size on disk | ~300 MB (bundled .NET) | ~5 MB | ~10 MB | ~10 MB |
| Price | Free | Free (GPL) | Free (GPL) | Free (GPL) |
Quick start
- Install on both machines. Run the installer; pick Server on the PC you want to control and Client on the one you sit at (or both on both). It adds the firewall rule and can start the server at sign-in.
- Set the password. The server asks for one on first start and then sits in the tray, listening on port 5900. Its window lists the PC's IP addresses.
- Connect. In the client, type the server's address and port, click Connect, enter the password. Click the picture once to give it keyboard focus — from then on, everything you type (Windows key included) goes to the remote PC.
- Harden it if the port faces the internet. Server → Security…: turn on TLS, approve your client's certificate, add a one-time code. Or skip the port forward entirely and connect over Tailscale.