Files
HellCon/README.md
T
2026-09-07 18:55:05 +02:00

58 lines
2.5 KiB
Markdown

# HellCon
Peer-to-peer file sharing between two browsers. No server, no account, no
upload. The page you host is only a delivery mechanism for the JavaScript —
the files themselves travel directly from one browser to the other over
WebRTC, end-to-end encrypted (DTLS-SRTP) by the browsers themselves.
Built with Vite + Vue 3, toolchain is `bun`.
## How it works
1. **Sender** picks a file, chooses a STUN provider, and clicks
*Create code*. Their browser generates a WebRTC offer and the app presents
it as one copyable string.
2. The sender pastes that code to the receiver through **any channel they
already trust** — a chat app, email, a piece of paper read over the phone.
3. **Receiver** pastes the code; their browser answers and the app shows the
answer string. They send it back the same way.
4. The sender pastes the answer. Both browsers exchange the SDP fingerprints
as a two-line security check — if both sides see the same codes, no one
can have interposed on the exchange.
5. The connection opens and the file is transferred in chunks with
backpressure, reassembled on the receiver side and handed to the user as
a download.
**STUN**: if both peers are on the same network nothing external is needed
(pick "None"). For peers on different networks the browsers need one
stateless UDP lookup against a public STUN server (Google or Cloudflare, or
your own) to discover their public IP. That's the only third-party contact,
and it never sees connection or file data. Remove the `iceServers` entry in
`src/lib/webrtc.js` if you want to talk to nobody but your peers.
**MITM model**: the file data is end-to-end encrypted by the browsers and
cannot be MITM'd by a passive attacker. The only theoretical attack is
interposing on the *code exchange* itself; the built-in fingerprint
comparison ("Security check" after signaling) closes it — compare the codes
over a channel you trust.
## Commands
```sh
bun install
bun run dev # dev server
bun run build # static build -> dist/ (3 static files + favicon + robots.txt)
bun run preview # serve the production build
```
## Honest disclaimer
This is **vibe-coded throw-away software**. It was generated for fun, it
worked on the machines it was tried on, and it is roughly audited rather
than battle-tested. It may break on your browser, your NAT, or your use
case. If it works for you, great. If not, fixing it is now your hobby.
## License
MIT — do whatever you want with this. No warranty, see `LICENSE`.