ShareTunnel is a file transfer service built on a sophisticated combination of web standards and a decentralized protocol: WebRTC + Nostr + PWA/OPFS.
It is designed around a zero-knowledge architecture, so that no third party, including the service operator, can access your data.
- Encryption
- Files travel PC to PC over a WebRTC DataChannel, encrypted with DTLS.
Keys are agreed afresh with ECDHE for every connection, so a key leaked later cannot decrypt past transfers (forward secrecy).
- Authentication
- The share URL holds the share’s public key and a 128-bit secret.
The receiver checks the sender’s replies against that key’s signature, and the sender only answers someone who presents the secret.
The DTLS certificate fingerprints travel the same way, so a relay cannot sit in the middle.
- Signaling
- Connection info is encrypted to the other side’s key with NIP-44, signed, and exchanged through public Nostr relays.
Anything with a bad signature, older than 60 seconds, or seen before is dropped.
Relays see only ciphertext, public keys, timestamps and the connecting IP address, and the events are of the ephemeral kind that is not stored.
- Share URL
- The secret sits after the “#”, which is never part of an HTTP request, so it does not reach servers or access logs.
Anyone with the URL can receive the files, so pass it over a channel you trust and add a password when needed.
- Access control
- The receiver’s browser turns the password into a key with PBKDF2-SHA256 (600,000 iterations, salted), and the sender’s PC checks it.
The password itself is never sent or stored.
Every 5 wrong attempts double how long attempts are refused unchecked (from 1 minute up to 1 hour).
Expiry and download limits are also enforced on the sender’s PC, and ended shares refuse connections.
- IP addresses
- Being peer to peer, the sender and receiver learn each other’s IP address.
STUN servers (Cloudflare, Google) and Nostr relays also see the connecting IP address.
There is no relay server (TURN), so networks that block direct connections cannot transfer.
- Receiving
- Incoming file names and paths are checked, and nothing is written outside the chosen folder.
Partial data is kept in browser storage (OPFS) and moved to the folder, then deleted, once complete.
- Local storage
- Share private keys and password hashes are stored only in the sender’s browser (IndexedDB).
To reconnect, receiving a sync stores the share URL and a key derived from the password in the receiver’s browser.
This storage is kept apart for each site, so other sites cannot read it, and nothing is sent out.
Passwords are only kept in a form that cannot be turned back, so the password itself cannot be learned from it.
On a shared PC, end shares and remove syncs when you are done.
Ended shares are deleted after 7 days and removed syncs right away. Clearing the site data in your browser deletes everything.
- App delivery
- The app is only served as static files from Cloudflare over HTTPS, and no server ever receives your files or keys.
Text from the other side is always escaped, and a CSP lets only the site’s own scripts run.