The safe way to reach your machines
An open Remote Desktop port is the single most brute-forced thing on the internet, and the most common way ransomware gets its first foothold. The trouble is that almost nobody who has one open knows it — a port-forward set up years ago for one evening, a router default, a setting that survived a firmware update. It sits there answering strangers, and the first sign of trouble is usually the trouble itself.
This happened to us
While building Rooster Wake's remote-connection features we went looking at our own setup, and found a Remote Desktop port on one of our machines open to the whole internet — forwarded by a router rule nobody remembered making, and already being hammered by the automated login attempts that sweep every address on the internet looking for exactly this. The account defences held and nothing got in, but the exposure was real and it had been there quietly for a long time. If it can happen to the people writing the security page, it can happen to anyone.
The uncomfortable part was how invisible it was. Nothing on the machine looked wrong. The only way to know was to check the machine's door from the outside — which is precisely the check we built in.
Why an open Remote Desktop port is the risk it is
Remote Desktop was built to be reached across a trusted network, not across the open internet. Exposed directly, it is a login prompt facing four billion addresses, and automated tools try millions of username-and-password combinations against those prompts continuously. One reused or guessable password, one unpatched flaw in the protocol itself, and a stranger has an interactive session on your machine — which is why this exact exposure is the entry point behind a large share of ransomware cases.
"No port forwarding" is the answer, and it is why nothing about Rooster Wake asks you to open a port. But knowing the theory does not help if a forward you forgot is open right now. That is the gap this feature closes.
What Rooster Wake does about it
Install the free agent on a machine and it reports that machine's own connection posture back to your dashboard — including whether its Remote Desktop port is answering from the public internet. When it is, your machine's card says so plainly, names the port, and tells you how to close it. This runs on every plan, free included: knowing your own front door is unlocked is not a feature we would put behind a price.
One promise about how that check works, because it is the whole basis of trusting us with it: we only ever look at the machine's own address — the one its own agent is reporting from — and never anything else. The system is built so that it is structurally incapable of scanning any other address; it is a mirror held up to your own machine, not a scanner pointed at the network.
The safe pattern: keep it asleep, wake it, connect with your own tools
The reason so many machines end up with an open port is that people leave a PC on and reachable so they can get to it later. Rooster Wake removes that reason. Keep the machine asleep — drawing a couple of watts, exposing nothing — and wake it the moment you need it, from anywhere, with nothing forwarded and no software required on the machine you are waking. The agent that runs the exposure check above is optional: waking never needs it, and what it adds is that posture report on every plan, and sleep, restart and shutdown on the paid plans.
Once it is awake, reach it the safe way: over a mesh network that needs no open ports, or a zero-setup remote tool that connects out to you rather than waiting for the internet to connect in. The dashboard hands you that connection at the moment the machine is up. Nothing about the path leaves a door open when you are done — the machine goes back to sleep, and there is no port for anyone to find.