Use case · for VNC refugees

Encrypted remote desktop without VNC setup

Classic VNC often ships with no built-in transport encryption and needs per-server config. Scry is end-to-end encrypted (DTLS-SRTP) over WebRTC with zero per-server setup, on Mac, Windows, Linux and the browser. Try every feature free for 24 hours with no card, or start the monthly or annual plan with 7 days free.

Mac · Windows · Linux · browser

If you've run classic VNC — TightVNC, UltraVNC, TigerVNC and friends — you know two things. First, it's lightweight, free, and deployed on millions of machines. Second, getting it secure and reachable is its own project: many classic VNC servers ship with no built-in transport encryption (you're expected to tunnel it over SSH yourself), plus per-server configuration, password legacy, and firewall/port wrangling for every machine.

If you searched encrypted remote desktop and you're a VNC refugee, this page is about removing both problems at once — honestly, including exactly how the end-to-end encryption works.

The two VNC problems Scry removes

  • 1. Transport encryption you don't have to bolt on

    Classic VNC like TightVNC ships without built-in encryption; securing it traditionally means setting up an SSH tunnel per connection. Scry's connection is end-to-end encrypted by default over WebRTC — DTLS/SRTP is part of the standard, not something you configure. There is no “now set up the SSH tunnel” step.

  • 2. No per-server setup

    With VNC you install and configure a server on every machine, manage passwords, and open ports. Scry uses one account: sign in on each computer and it shows up in your list. No port forwarding, no per-server config.

The encryption boundary — how it actually works

Scry's connection is end-to-end encrypted using WebRTC's standard DTLS-SRTP. That is a real, named, verifiable property and it's exactly the security gap classic VNC leaves open.

Your two devices negotiate the encryption keys in the DTLS handshake: the host and the device you're viewing from. Our relay only exchanges connection details to get the two devices talking and, when a direct path isn't possible, forwards already-encrypted packets it cannot read. The relay in the middle can't decrypt your screen, your input or your clipboard. End to end, direct when the network allows and through an encrypted relay otherwise.

What you give up vs classic VNC

Be clear-eyed: classic VNC is free, open-source, ultra-lightweight, and has decades of deployment behind it. Scry has none of that heritage. Scry does now ship a native Linux host for X11 and Wayland desktops (on Wayland only after sign-in, one screen, with no lock screen), but if you specifically want open-source you can audit and self-host, classic VNC (or an OSS tool built on it) is still the honest choice, not Scry.

Honest limits

  • Sessions stream one display at a time. Got more than one? Flip between them mid-session and keep working.
  • End-to-end encrypted (DTLS-SRTP), direct when the network allows (covered above).
  • Linux host is new: Scry reaches Linux on X11 and Wayland desktops; on Wayland only after sign-in, one screen, with no lock screen. If you need a deeply field-hardened Linux deployment, classic VNC or RealVNC is the honest pick.

Encrypted by default. No SSH tunnel. No per-server config.

Mac, Windows, Linux and the browser. One account, end-to-end encrypted (DTLS-SRTP) over WebRTC.

Free for 24 hours: every feature, no card.

Related