first commit
This commit is contained in:
@@ -0,0 +1,57 @@
|
||||
# HellCon
|
||||
|
||||
Peer-to-peer file sharing between two browsers. No server, no account, no
|
||||
upload. The page you host is only a delivery mechanism for the JavaScript —
|
||||
the files themselves travel directly from one browser to the other over
|
||||
WebRTC, end-to-end encrypted (DTLS-SRTP) by the browsers themselves.
|
||||
|
||||
Built with Vite + Vue 3, toolchain is `bun`.
|
||||
|
||||
## How it works
|
||||
|
||||
1. **Sender** picks a file, chooses a STUN provider, and clicks
|
||||
*Create code*. Their browser generates a WebRTC offer and the app presents
|
||||
it as one copyable string.
|
||||
2. The sender pastes that code to the receiver through **any channel they
|
||||
already trust** — a chat app, email, a piece of paper read over the phone.
|
||||
3. **Receiver** pastes the code; their browser answers and the app shows the
|
||||
answer string. They send it back the same way.
|
||||
4. The sender pastes the answer. Both browsers exchange the SDP fingerprints
|
||||
as a two-line security check — if both sides see the same codes, no one
|
||||
can have interposed on the exchange.
|
||||
5. The connection opens and the file is transferred in chunks with
|
||||
backpressure, reassembled on the receiver side and handed to the user as
|
||||
a download.
|
||||
|
||||
**STUN**: if both peers are on the same network nothing external is needed
|
||||
(pick "None"). For peers on different networks the browsers need one
|
||||
stateless UDP lookup against a public STUN server (Google or Cloudflare, or
|
||||
your own) to discover their public IP. That's the only third-party contact,
|
||||
and it never sees connection or file data. Remove the `iceServers` entry in
|
||||
`src/lib/webrtc.js` if you want to talk to nobody but your peers.
|
||||
|
||||
**MITM model**: the file data is end-to-end encrypted by the browsers and
|
||||
cannot be MITM'd by a passive attacker. The only theoretical attack is
|
||||
interposing on the *code exchange* itself; the built-in fingerprint
|
||||
comparison ("Security check" after signaling) closes it — compare the codes
|
||||
over a channel you trust.
|
||||
|
||||
## Commands
|
||||
|
||||
```sh
|
||||
bun install
|
||||
bun run dev # dev server
|
||||
bun run build # static build -> dist/ (3 static files + favicon + robots.txt)
|
||||
bun run preview # serve the production build
|
||||
```
|
||||
|
||||
## Honest disclaimer
|
||||
|
||||
This is **vibe-coded throw-away software**. It was generated for fun, it
|
||||
worked on the machines it was tried on, and it is roughly audited rather
|
||||
than battle-tested. It may break on your browser, your NAT, or your use
|
||||
case. If it works for you, great. If not, fixing it is now your hobby.
|
||||
|
||||
## License
|
||||
|
||||
MIT — do whatever you want with this. No warranty, see `LICENSE`.
|
||||
Reference in New Issue
Block a user