Remote Desktop: how to use it without getting hacked
Updated 10/5/2026 · 4 min read
Remote Desktop (RDP) is incredibly useful — and one of the most common ways ransomware gets into home and business PCs. The problem is almost never RDP itself; it's RDP exposed directly to the internet.
The rule Never put Remote Desktop straight on the public internet. If you can reach port 3389 from outside, so can attackers — and they run automated tools that try millions of passwords.
Safer ways to use it - **Turn it off if you don't use it:** Settings → System → Remote Desktop → Off. - **Put it behind a VPN:** connect to your network first, then RDP. The port is never exposed. - **Require Network Level Authentication (NLA):** this blocks a lot of pre-login attacks. - **Use strong, unique passwords and MFA** on every account that can sign in. - **Limit who can connect** and watch for repeated failed logins.
How to check From outside your network, is port 3389 open on your public IP? A Keepvik scan checks this from the internet, so you see what an attacker would see — not just what the PC thinks.
Want to check your own PC?
The free Quick Scan looks for everything in this guide in about a minute.
Free Quick Scan