# HellCon Peer-to-peer file sharing between two browsers. No server, no account, no upload. The page you host is only a delivery mechanism for the JavaScript — the files themselves travel directly from one browser to the other over WebRTC, end-to-end encrypted (DTLS-SRTP) by the browsers themselves. Built with Vite + Vue 3, toolchain is `bun`. ## How it works 1. **Sender** picks a file, chooses a STUN provider, and clicks *Create code*. Their browser generates a WebRTC offer and the app presents it as one copyable string. 2. The sender pastes that code to the receiver through **any channel they already trust** — a chat app, email, a piece of paper read over the phone. 3. **Receiver** pastes the code; their browser answers and the app shows the answer string. They send it back the same way. 4. The sender pastes the answer. Both browsers exchange the SDP fingerprints as a two-line security check — if both sides see the same codes, no one can have interposed on the exchange. 5. The connection opens and the file is transferred in chunks with backpressure, reassembled on the receiver side and handed to the user as a download. **STUN**: if both peers are on the same network nothing external is needed (pick "None"). For peers on different networks the browsers need one stateless UDP lookup against a public STUN server (Google or Cloudflare, or your own) to discover their public IP. That's the only third-party contact, and it never sees connection or file data. Remove the `iceServers` entry in `src/lib/webrtc.js` if you want to talk to nobody but your peers. **MITM model**: the file data is end-to-end encrypted by the browsers and cannot be MITM'd by a passive attacker. The only theoretical attack is interposing on the *code exchange* itself; the built-in fingerprint comparison ("Security check" after signaling) closes it — compare the codes over a channel you trust. ## Commands ```sh bun install bun run dev # dev server bun run build # static build -> dist/ (3 static files + favicon + robots.txt) bun run preview # serve the production build ``` ## Honest disclaimer This is **vibe-coded throw-away software**. It was generated for fun, it worked on the machines it was tried on, and it is roughly audited rather than battle-tested. It may break on your browser, your NAT, or your use case. If it works for you, great. If not, fixing it is now your hobby. ## License MIT — do whatever you want with this. No warranty, see `LICENSE`.