Personal cloud at home without opening ports: RustDesk straight over Tailscale

Once the public relay demanded a login, a user pointed RustDesk at Tailscale addresses; direct access inside the home network works with no open ports, yet dependence only changes hands.

The setup of a user who helps family with their computers over RustDesk changed recently: the public RustDesk server now requires a login, because that server was only ever meant for testing and demonstration, and growing botnet and scam abuse forced the gate. The handful of machines he connects to were already on his Tailscale network and could already reach each other, so the public server turned redundant; pointing RustDesk straight at a machine's Tailscale address cuts out the middleman. On the machine to be controlled, you open RustDesk, click the three-dot menu next to its ID, enter settings, unlock the Security section, and allow direct IP access. [1] [2]

I think the real story sits in that small checkbox in the three-dot menu: remote desktop no longer has to pass through a company's server; my network, my rules. For years we were taught that reaching a home machine from outside meant either opening a port or trusting someone else's relay; both reduced the owner to a guest. Direct IP access flips the equation: the cloud stops being the provider of the service and becomes the quiet background where my two machines find each other.

The setup has two more stops: a permanent password is set in the Security section, because otherwise RustDesk generates a rotating temporary password and reconnecting without someone sitting in front of the machine becomes impossible. Then the machine's stable address starting with 100 is taken from the Tailscale client's menu-bar icon or the machine list in the admin console and noted down next to the password; the address stays the same as long as the device remains part of the network. [3] [4]

To connect, the Tailscale address is pasted into the remote desktop box on the connecting machine, the permanent password is entered, and you are in. RustDesk warns at this point that the connection is direct and unencrypted, but since the traffic already flows inside the encrypted channel of the Tailscale tunnel, dismissing the warning is considered safe. The detail matters, because automated scanners, botnets, and targeted attackers routinely probe well-known ports on internet-facing addresses; what invites the uninvited guest is not how fast they knock, but whether the door faces the street. [5] [7]

The list of street-facing doors is short and memorizable: port 22 for SSH, 3389 for RDP, 23 for Telnet. Bound to internet-facing interfaces without adequate access controls, they become reachable from any machine on earth. RDP is cited as the primary initial access vector in a majority of enterprise ransomware incidents; with RDP access, attackers can switch off backups, encrypt data, and move laterally across the network. Opening a port is therefore not mere convenience; it sits in the same risk class as leaving the house key above the door. [6] [8]

The counter-view deserves a note too: not everyone has a machine to tend at home or a Tailscale network to manage; for one-off help, logging into a relay server is sometimes the more honest fix. Besides, dependence does not vanish in this arrangement, it only changes hands: instead of a relay company I now trust a mesh network provider, its account system, and its client. For someone unwilling to self-host a relay, the trade is sensible, provided it is remembered as a trade.

The question that intrigues me most is this: as the home computer quietly becomes the main machine again, what will the cloud's role shrink to? If my files, my backups, and occasionally the models I run sit at home while I drop by through my own tunnel from outside, what really distinguishes me from a rented monthly remote desktop? I do not know the answer, but I know what I will be watching in the coming months: how many of those who set this up are still connecting directly six months from now, and how many have quietly drifted back to the old relay. What endures will be the habit, not the setting.

Source passages

  1. RustDesk direct connections over Tailscale ↗
    I use RustDesk to help family with their computers from a distance. Out of the box it routes through the public RustDesk server, which is the path of least resistance when you’re getting started. But, that changed recently; a login is now required for the public server, and that’s because the public server was only ever meant for testing and demonstration apparently, and because of growing botnet and scam abuse. I didn’t want to have to self-host a relay server for the
  2. RustDesk direct connections over Tailscale ↗
    handful of machines I connect to. All of those machines are already on my Tailscale network, so they can already reach each other. That makes the public server redundant. I can point RustDesk straight at a machine’s Tailscale IP and skip the middleman! Enabling direct IP access On the machine you want to control, open RustDesk and click the three-dot menu next to its ID, then go to Settings. Under the Security section, click to unlock it, and tick Enable direct IP access.
  3. RustDesk direct connections over Tailscale ↗
    This is what lets a RustDesk client connect to this machine by its IP address rather than going via the relay. Setting a permanent password While you’re still in the Security section, scroll up to the Password area and set a permanent password. Without one, RustDesk generates a temporary password that rotates, which is no good when you want to connect again later without being sat in front of the machine. I store the password in 1Password so it’s there whenever I need it.
  4. RustDesk direct connections over Tailscale ↗
    Note: treat this like any other credential, since anyone with the password and network access to the machine can connect. Finding the Tailscale IP Each machine on your Tailscale network has its own stable IP in the 100.x.x.x range. You can grab it from the Tailscale client in the menu bar or system tray, or from the machines list in the admin console. That IP stays the same as long as the device is part of your network, so it’s worth noting down alongside the password.
  5. RustDesk direct connections over Tailscale ↗
    Connecting On the machine you’re connecting from, paste the Tailscale IP into the Control Remote Desktop field and connect. Enter the permanent password when prompted, and you’re in. RustDesk will warn that this is a direct and unencrypted connection. That warning is about RustDesk’s own transport, but the traffic is already running inside Tailscale’s encrypted tunnel, so it’s safe to proceed. That’s the whole setup. As long as both machines are on Tailscale, I connect
  6. Exposed Remote Access Services (SSH, RDP, Telnet) ↗
    CategoryExposed Service / Network Misconfiguration Typical SeverityHigh OWASPA05:2021 – Security Misconfiguration CWECWE-284 (Improper Access Control), CWE-16 (Configuration) Affected PortsTCP 22 (SSH), TCP 3389 (RDP), TCP 23 (Telnet) Also known asInternet-facing remote access, publicly exposed management interfaces Affected systemsLinux/Unix servers, Windows servers, network devices, embedded systems with management interfaces reachable from the public internet
  7. Exposed Remote Access Services (SSH, RDP, Telnet) ↗
    Overview SSH, RDP, and Telnet are administrative protocols designed to provide interactive remote shell or desktop access to systems. When these services are bound to internet-facing network interfaces without adequate access controls, they become directly reachable by any host on the internet. Automated scanners, botnets, and targeted attackers routinely probe all routable IP space for these well-known ports. Telnet is additionally dangerous because it transmits all data —
  8. Exposed Remote Access Services (SSH, RDP, Telnet) ↗
    malware, exfiltrate all data stored on or reachable from the host, and establish persistent backdoors. Ransomware deployment: RDP is the primary initial access vector cited in a majority of enterprise ransomware incidents. Attackers with RDP access can disable backups, encrypt data, and move laterally across the network. Data exfiltration and regulatory consequences: Unauthorised access to systems hosting personal data triggers breach notification obligations under GDPR,