HellCon
Peer-to-peer file sharing between two browsers. No server, no account, no upload. The page you host is only a delivery mechanism for the JavaScript — the files themselves travel directly from one browser to the other over WebRTC, end-to-end encrypted (DTLS-SRTP) by the browsers themselves.
Built with Vite + Vue 3, toolchain is bun.
How it works
- Sender picks a file, chooses a STUN provider, and clicks Create code. Their browser generates a WebRTC offer and the app presents it as one copyable string.
- The sender pastes that code to the receiver through any channel they already trust — a chat app, email, a piece of paper read over the phone.
- Receiver pastes the code; their browser answers and the app shows the answer string. They send it back the same way.
- The sender pastes the answer. Both browsers exchange the SDP fingerprints as a two-line security check — if both sides see the same codes, no one can have interposed on the exchange.
- The connection opens and the file is transferred in chunks with backpressure, reassembled on the receiver side and handed to the user as a download.
STUN: if both peers are on the same network nothing external is needed
(pick "None"). For peers on different networks the browsers need one
stateless UDP lookup against a public STUN server (Google or Cloudflare, or
your own) to discover their public IP. That's the only third-party contact,
and it never sees connection or file data. Remove the iceServers entry in
src/lib/webrtc.js if you want to talk to nobody but your peers.
MITM model: the file data is end-to-end encrypted by the browsers and cannot be MITM'd by a passive attacker. The only theoretical attack is interposing on the code exchange itself; the built-in fingerprint comparison ("Security check" after signaling) closes it — compare the codes over a channel you trust.
Commands
bun install
bun run dev # dev server
bun run build # static build -> dist/ (3 static files + favicon + robots.txt)
bun run preview # serve the production build
Honest disclaimer
This is vibe-coded throw-away software. It was generated for fun, it worked on the machines it was tried on, and it is roughly audited rather than battle-tested. It may break on your browser, your NAT, or your use case. If it works for you, great. If not, fixing it is now your hobby.
License
MIT — do whatever you want with this. No warranty, see LICENSE.