Files
HellCon/README.md
T
2026-09-07 18:55:05 +02:00

2.5 KiB

HellCon

Peer-to-peer file sharing between two browsers. No server, no account, no upload. The page you host is only a delivery mechanism for the JavaScript — the files themselves travel directly from one browser to the other over WebRTC, end-to-end encrypted (DTLS-SRTP) by the browsers themselves.

Built with Vite + Vue 3, toolchain is bun.

How it works

  1. Sender picks a file, chooses a STUN provider, and clicks Create code. Their browser generates a WebRTC offer and the app presents it as one copyable string.
  2. The sender pastes that code to the receiver through any channel they already trust — a chat app, email, a piece of paper read over the phone.
  3. Receiver pastes the code; their browser answers and the app shows the answer string. They send it back the same way.
  4. The sender pastes the answer. Both browsers exchange the SDP fingerprints as a two-line security check — if both sides see the same codes, no one can have interposed on the exchange.
  5. The connection opens and the file is transferred in chunks with backpressure, reassembled on the receiver side and handed to the user as a download.

STUN: if both peers are on the same network nothing external is needed (pick "None"). For peers on different networks the browsers need one stateless UDP lookup against a public STUN server (Google or Cloudflare, or your own) to discover their public IP. That's the only third-party contact, and it never sees connection or file data. Remove the iceServers entry in src/lib/webrtc.js if you want to talk to nobody but your peers.

MITM model: the file data is end-to-end encrypted by the browsers and cannot be MITM'd by a passive attacker. The only theoretical attack is interposing on the code exchange itself; the built-in fingerprint comparison ("Security check" after signaling) closes it — compare the codes over a channel you trust.

Commands

bun install
bun run dev       # dev server
bun run build     # static build -> dist/ (3 static files + favicon + robots.txt)
bun run preview   # serve the production build

Honest disclaimer

This is vibe-coded throw-away software. It was generated for fun, it worked on the machines it was tried on, and it is roughly audited rather than battle-tested. It may break on your browser, your NAT, or your use case. If it works for you, great. If not, fixing it is now your hobby.

License

MIT — do whatever you want with this. No warranty, see LICENSE.