58 lines
2.5 KiB
Markdown
58 lines
2.5 KiB
Markdown
# HellCon
|
|
|
|
Peer-to-peer file sharing between two browsers. No server, no account, no
|
|
upload. The page you host is only a delivery mechanism for the JavaScript —
|
|
the files themselves travel directly from one browser to the other over
|
|
WebRTC, end-to-end encrypted (DTLS-SRTP) by the browsers themselves.
|
|
|
|
Built with Vite + Vue 3, toolchain is `bun`.
|
|
|
|
## How it works
|
|
|
|
1. **Sender** picks a file, chooses a STUN provider, and clicks
|
|
*Create code*. Their browser generates a WebRTC offer and the app presents
|
|
it as one copyable string.
|
|
2. The sender pastes that code to the receiver through **any channel they
|
|
already trust** — a chat app, email, a piece of paper read over the phone.
|
|
3. **Receiver** pastes the code; their browser answers and the app shows the
|
|
answer string. They send it back the same way.
|
|
4. The sender pastes the answer. Both browsers exchange the SDP fingerprints
|
|
as a two-line security check — if both sides see the same codes, no one
|
|
can have interposed on the exchange.
|
|
5. The connection opens and the file is transferred in chunks with
|
|
backpressure, reassembled on the receiver side and handed to the user as
|
|
a download.
|
|
|
|
**STUN**: if both peers are on the same network nothing external is needed
|
|
(pick "None"). For peers on different networks the browsers need one
|
|
stateless UDP lookup against a public STUN server (Google or Cloudflare, or
|
|
your own) to discover their public IP. That's the only third-party contact,
|
|
and it never sees connection or file data. Remove the `iceServers` entry in
|
|
`src/lib/webrtc.js` if you want to talk to nobody but your peers.
|
|
|
|
**MITM model**: the file data is end-to-end encrypted by the browsers and
|
|
cannot be MITM'd by a passive attacker. The only theoretical attack is
|
|
interposing on the *code exchange* itself; the built-in fingerprint
|
|
comparison ("Security check" after signaling) closes it — compare the codes
|
|
over a channel you trust.
|
|
|
|
## Commands
|
|
|
|
```sh
|
|
bun install
|
|
bun run dev # dev server
|
|
bun run build # static build -> dist/ (3 static files + favicon + robots.txt)
|
|
bun run preview # serve the production build
|
|
```
|
|
|
|
## Honest disclaimer
|
|
|
|
This is **vibe-coded throw-away software**. It was generated for fun, it
|
|
worked on the machines it was tried on, and it is roughly audited rather
|
|
than battle-tested. It may break on your browser, your NAT, or your use
|
|
case. If it works for you, great. If not, fixing it is now your hobby.
|
|
|
|
## License
|
|
|
|
MIT — do whatever you want with this. No warranty, see `LICENSE`.
|