JVNC

Remote desktop for Windows that is small, fast and actually secure.

JVNC is a two-piece VNC-compatible remote desktop: a tray Server on the PC you want to reach and a Client on the machine you sit at. No cloud, no account, no subscription — and unlike the classic free VNCs, encryption and modern authentication are built in.

One installer for both Server and Client. Windows 10/11 64-bit. Self-contained — nothing else to install. Free.

What it does

⊞The Windows key, remotely

Win+R, Win+E, Win+D, Win+arrows — every Win+key shortcut goes to the remote PC, not the one you're sitting at. JVNC captures the key with a low-level hook while its window is focused. It is the only VNC-style tool that does this out of the box.

⚡Change-driven updates

The server captures with DirectX Desktop Duplication (whole, tear-free frames, even over hardware-accelerated video) and sends only the 64-pixel tiles that changed, the moment they change, up to ~120 fps. No polling lag, no fixed frame rate. Scrolling is sent as CopyRect (a few bytes per tile), and on a slow link the server measures the connection, budgets each frame, sends the area around your pointer first and drops JPEG quality before it drops frames. The mouse cursor is drawn into the picture.

⇅File transfer both ways

Send a file to the remote PC or fetch one from it, any size, streamed straight to disk. Auto-accept into a folder or confirm each one — the screen and mouse keep working during transfers.

▭All your monitors — your way

See the whole remote desktop as one image, pick a single remote monitor (only that monitor is sent — less bandwidth), or go multi-head: one full-screen window per remote monitor, spread across your own monitors.

⎘Shared clipboard

Copy on one side, paste on the other — both directions, within half a second. Toggle it off in the toolbar whenever you want the two clipboards kept apart.

♪Hear the remote PC

Tick Audio and whatever the remote PC plays comes through your speakers — 48 kHz stereo at about 48 KB/s, or a 12 KB/s mono mode for slow links. No other free VNC does this either.

▣Tray server

Starts listening the moment it launches, lives in the tray, single instance, starts at sign-in if you like. Closing the window doesn't stop it; Exit does.

⤢Viewer that gets out of the way

Full screen on F11, scale-to-fit or 1:1, remembered hosts, live fps/bandwidth readout so you can tell the network from the machine.

✓Works with your phone's VNC app

Standard VNC underneath: any viewer connects with a VNC password, and viewers that speak VeNCrypt (bVNC, AVNC, TigerVNC) get TLS too. The JVNC client adds the rest. Everything is logged with the exact reason for every disconnect.

⇩Drag, drop, done

Drop files from Explorer onto the remote screen and they land on the PC. Print on the PC to the JVNC Remote Printer and the PDF appears at your side.

↺Wake it, reach it, keep it

Wake-on-LAN with the MAC learned automatically, auto-reconnect that keeps trying (and waking) for ten minutes, and a reverse mode where the PC dials you — no port forward on its side.

●Record and audit

Record any session and play it back inside JVNC. The server keeps a JSON audit trail of every connection, file, clipboard and print job.

◌No stuck drags

If a client drops mid-drag, the server releases every held button and key. Your window never ends up glued to the cursor.

Security you switch on, layer by layer

Every layer is independent. The password is required by default (the server asks you to set one on first start, and warns you every time you switch it off). Turn on more for a port that faces the internet.

Connection password default onStored as a salted PBKDF2-SHA256 hash; the wire uses a salt + nonce challenge, so the password is never sent and a captured login can't be replayed.
TLS 1.2 / 1.3 encryptionSelf-signed certificate created on first use. The client pins its fingerprint on first connect and shouts if it ever changes.
Approved client certificates (mutual TLS)Each client makes its own certificate; the server accepts only fingerprints you have approved. The strongest layer — the one that makes an internet-facing port reasonable.
One-time code (TOTP)Google / Microsoft Authenticator and friends. Proof is an HMAC over a server nonce — not replayable.
IP allow list & listen addressCIDR rules (e.g. your Tailscale range) and the option to bind only to a VPN interface.
Always on5 failed handshakes → 15-minute ban. Public (internet) addresses are refused unless a client certificate is required. Secrets at rest are DPAPI-encrypted.

The mechanisms, precisely

LayerHow JVNC does it
Password at restPBKDF2-HMAC-SHA256, 100 000 iterations, 16-byte random salt, 32-byte verifier. Only the verifier is stored.
Password on the wireServer sends salt + 16-byte nonce; client answers HMAC-SHA256(PBKDF2(password, salt), nonce). Constant-time check. The password never leaves your machine; a captured proof is useless elsewhere.
EncryptionTLS 1.2 / 1.3 (Windows SChannel), RSA-2048 self-signed X.509, SHA-256, created on first use.
Server identityTrust-on-first-use pinning of the certificate thumbprint per host; a changed certificate triggers a warning and needs explicit re-acceptance.
Client identityMutual TLS: the client presents its own RSA-2048 certificate; the server accepts only approved thumbprints, inside the TLS validation callback — unapproved clients never reach the protocol.
One-time codeRFC 6238 TOTP (HMAC-SHA1, 6 digits, 30 s, 160-bit secret), current step ±1, sent as HMAC-SHA256(code, server nonce) — never the bare code.
Secrets at restWindows DPAPI (current-user scope, app entropy) for the TOTP secret and remembered passwords.
Network filteringIP/CIDR allow list before any bytes are exchanged; optional single-interface bind; non-private source addresses refused unless mutual TLS is on.
Brute force5 failed handshakes → 15-minute ban per address; 1 s delay per failure.
ProtocolWith any layer on: JVNC-000.01 greeting + flags, then TLS → password → TOTP, then standard RFB 3.8 inside the encrypted stream. With all layers off: plain, byte-for-byte RFB.

The Security Guide in the manuals explains what each layer does and does not protect against, and recommends configurations for LAN, VPN and port-forwarded setups.

Everything you've read about "VNC is insecure" — answered

Those warnings are about stock VNC. Here's each one, and what JVNC does about it.

The classic dangerHow JVNC answers it
Bots scan the port and brute-force the passwordPer-address lockout (5 tries → 15-min ban, 1 s delay each). And the public-address rule refuses internet-address connections unless they present an approved client certificate — a bot is dropped before it can try one password.
The password can be captured in transitIt never crosses the wire — a PBKDF2 challenge/response, nothing to sniff or replay.
VNC is unencrypted; Wi-Fi can read your screen & keystrokesBuilt-in TLS 1.2/1.3 encrypts everything; the client pins the server certificate against man-in-the-middle.
An open port is inherently unsafeApproved client certificates (mutual TLS): without a key from one of your own devices the handshake can't complete — an open port only answers your machines. Add a one-time code for a second factor.
Opening a port means juggling modem + router + firewall + a changing home IPDon't open one. Reverse connection has the PC dial out (no inbound rules), or a VPN (Tailscale/WireGuard) puts both machines on a private network — nothing faces the internet, nothing to maintain.
In short: the scary articles describe the old way. Behind a VPN (or reverse connection), with password + TLS + client certificate on, none of those exposures apply.

How it compares

Against the usual suspects, out of the box on Windows. Green column is JVNC.

Security

JVNCTightVNCUltraVNCTigerVNCRealVNC Connect (paid)
PasswordPBKDF2 verifier, challenge–response, any lengthDES challenge, 8-char max8-char VNC auth or Windows accountsVNC auth, or user/pass over TLSSystem / cloud accounts
EncryptionBuilt in TLS 1.2/1.3, pinnedNone (needs SSH/VPN)Plugin (AES)VeNCrypt TLS / X.509Always, AES-256
Device certificatesYes, approved listNoNoManual PKICloud device auth
Two-factor (TOTP)YesNoNoNoMFA
IP allow list + lockoutYes + yesYes + basicYes + yesFirewall + basicCloud policy
Refuses public IPs without a device certYes, by defaultNoNoNon/a (brokered)
Secrets at restDPAPI-encryptedObfuscated in registrySameConfig fileCloud
Runs as service / shows lock screenNo — signed-in session onlyYesYesYesYes
Maturity / auditsNew, unaudited20+ years20+ years (several CVEs)Active security releasesCommercial, audited

Features

JVNCTightVNCUltraVNCTigerVNC
Windows key & Win+key shortcuts to the remote PCYes — hook keeps your own PC quietNoPartial (menu tricks)No
Change-driven updatesYes, ~120 fps capHook/poll driverMirror driver optionalPoll
File transfer (both ways, unlimited size)YesYesYesNo (server)
Multi-monitor as one desktopYesYesYesYes
Single-monitor view / multi-head windowsYes / YesSingle onlySingle onlySingle only
Drag-and-drop files · reverse connection · Wake-on-LAN · session recording · audit log · printer redirectionAll built inReverse onlyDnD, reverse, logReverse only
Remote audioYes (built in)NoNoNo
Stuck-drag protection on disconnectYes———
Installer needs nothing pre-installedYesYesYesYes
Size on disk~300 MB (bundled .NET)~5 MB~10 MB~10 MB
PriceFreeFree (GPL)Free (GPL)Free (GPL)
The honest bit. JVNC's authentication is ahead of every free VNC here — they still default to an 8-character DES password with no encryption unless you add SSH, a VPN or a plugin. Its track record is behind all of them: the code is new and has not been independently audited, and it runs in the signed-in session rather than as a service. Best practice is the same for all of them: put the server behind a VPN (Tailscale, WireGuard) and use these layers as defense in depth.

Quick start

  1. Install on both machines. Run the installer; pick Server on the PC you want to control and Client on the one you sit at (or both on both). It adds the firewall rule and can start the server at sign-in.
  2. Set the password. The server asks for one on first start and then sits in the tray, listening on port 5900. Its window lists the PC's IP addresses.
  3. Connect. In the client, type the server's address and port, click Connect, enter the password. Click the picture once to give it keyboard focus — from then on, everything you type (Windows key included) goes to the remote PC.
  4. Harden it if the port faces the internet. Server → Security…: turn on TLS, approve your client's certificate, add a one-time code. Or skip the port forward entirely and connect over Tailscale.

Manuals