An easy way to share files P2P, and how it works
torrentfreak.com
torrentfreak.com
* Generate the URL like sharefest.me/roomid#randomstring
* Sharefest encrypts the file contents before and after transmission with randomstring as key using the SJCL.
* Send the URL/key out of band, over a secure channel.
* Voila, end-to-end crypto.
I don't know if anything became of it, though.
EDIT: Oh, here it is: https://github.com/Peer5/ShareFest/issues/24
The short answer is that so long as the page is loaded entirely over TLS, and the TLS isn't stripped or subverted in any way, it's safe from MITM. Sharefest doesn't currently support TLS, so they would need to set that up prior to enabling end-to-end encryption.
https://github.com/Peer5/ShareFest/issues/30#issuecomment-20...
You can download ShareFest, audit it and store it locally so you can run your known-good version. It's just an HTML page and a few JS files (or at least it was, last time I looked).
I was going to create a version of this that was a single webpage and had as little code as possible (for auditability and ease of saving/deployment), but other projects got in the way (plus it's easier to improve ShareFest than write it from scratch).
Developers can extend this platform with as many plugins as they wish - as an open-source solution, it's totally open. (I believe fragmentation, more specifically increasing the number of less advanced solutions doesn't help...)
Being a live webpage also give us, as the developers, much less headaches in terms of protocol compatibility -- We maintain just one "version" of Sharefest client at the same time.
If someone is interested I share a list of similar approaches:
https://www.getshareapp.com/v2 (from BitTorrent, requires a plugin):
(It's not just file sharing, though: it aims to address your entire encrypted p2p communication needs.)
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: OpenPGP:SDK v0.9
xsBNBFHUtg4BCACvWPNRhEGm/n3o+1tr1ye71SWwiCYDdC8cTn7t38Gmo/E/HG4q
hgOJvRp8kAStwryzggAwRrE8rfEsJEP6YaGw+vTQVQffwKw6C4MlGx3TJ5OgklLl
93eAw0hfTVNZCcQ42g/wzEjigAcmb+Kd15M8wCKKNX0VR96SJjJMS+z7Fv0UGKSo
MJnqS+6HLyR6SrgbIsRrGOziHDIz03ycH2T3Ckc66zmwvzi6uwcQFpVoqmtQZIiE
nFzNJHLrtr+SlXQLw4rJgNixsUgiCBzm7nM2548ygk3OEOVFQA2HfSvrG8PlhdKo
KtJBimYkov6eEgyDFrwBwUaqLUeSxHaH563JABEBAAHNJHBocmVlemEgKEdlbmVy
YXRlZCBieSBSZXRyb1NoYXJlKSA8PsLAXwQTAQIAEwUCUdS2DgkQ7F/6kYGHq0IC
GQEAAMNmB/9SOQFld2G8roNu+VOX5L0h0u6Hl4IsOpdxRkMofO0LFzH7n7+6EkBS
sXOdBvcLo3UL2cJxCf3bI/u2MJrrRbIdls2id2g4egAtnupXtLVu6q6S1vRg40PB
2ab4iJKe4Siz5QedsZd6HGfaV46fEWl6Tfu/sbIVH+5vHqc9A/CYUW8HjGQRFm0Z
Q4P1jwHkMTt/o6fUWWmja6/2Wz3j4v8HtkAuvusVqlPXmdDDNpyOt9L3stTQF1XQ
XskJaegiNhp8j7MlMEb9TGNFRaim1G/w8EwCauO8j+fjHJxvXmmqCzL/pG1cxKik
WYWfKn3+Q5MUfPpGltj0HdOkEw/yuu35
=37ck
-----END PGP PUBLIC KEY BLOCK-----
--SSLID--a71db6edde2788ece31c3437098be374;--LOCATION--mba;
--LOCAL--192.168.0.4:33395;--EXT--92.229.126.245:44003;It's of course the exact same logic as with encrypted email ("public key encryption" or "asymmetric encryption").
-----BEGIN PGP PUBLIC KEY BLOCK----- Version: OpenPGP:SDK v0.9
xsBNBFG0XDIBCADiHErShXdFVj8+XSsmYfVaeYwr3nykLVbfDQbQvYx2gNO23iXv UyGOqTqx7UtC3EP3oAoJqAAs7sK5OjklivV4WqxVQUwX9sqEYn2ht0u20K3rBXhh /c9TfcFFeGi9SwTkiA/754sQYu7Lz5iR4q6xmrb+Ki4CCuoxl06/7MBLoKOhS4ZO 2bkegwynbx5oMHAgfvR1Ov6au9IxFrm7W6HIC1IDRLisEQZnKg6PYE8KXTV1NbsU wikQ6hSIrnrlPvbkimbiVUTX8NwRSRXrDPW1YYw5oqU/HgNUA78Y9LIkTLwmdFrz 0LWs+gDTN3eethggEGrAkKVlQOPFg/3lUIdDABEBAAHNJGF3ZXNvbWUgKEdlbmVy YXRlZCBieSBSZXRyb1NoYXJlKSA8PsLAXwQTAQIAEwUCUbRcMgkQTx3tq5dI1QoC GQEAABbhCADSG2iosMirYi6MDJYvY7cwPluxpWYXkzNdW/fMJI+2iIWs39lGUDBY //tBZLwUW1zh5Bb1w+I0Ms8R35zgKH4f59pMpNTTeKTttQ8CQFekW3dCwKbNQRIc 6bdyafSilnI6jNrn4sYiMOmflqGurSVYFmQ8DUVg+pNHKGh909Gs3IahsWxpaGux NSPZ43h5oz/mDObJV9DUUxO8zpT011Fcx7/pqBfnZ39cArNCHs4SNMwwCyrfAo7F 0HgmrYZ5szRwXBROqInBNUdiNa3U/7FDBiw1NHRkWXEtPgkynO73Jl+NKngzxFb9 M6zkGiKprN4RnetC0JBWJIYq3y4GLew8 =vojG -----END PGP PUBLIC KEY BLOCK----- --SSLID--6786bb2895fc63074c4623ca891c851a;--LOCATION--Earth;
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: OpenPGP:SDK v0.9
xsBNBFHYH2QBCAChckyg3kkChkKonezTlhUgeXMVqPP3Pn8W5LJrRsRTWG6VnMa4
L5lB71dPLKRKZt68ZHTY/s2FC/W6fR32me2pKb1IKZGZlnbrWEIEAtonqgjR9dJo
VkEEHFe+an2HLbfIxFXFRDKeBCfcP+cnOoehSDvsuopoVy6MKSnjd/OHOiV2k5jC
tCGQiJN1L1rIq+0S6YyouHUrLCMgMu1PM37vhRhXR0Y3XIgwaCqmtyiiiu3Kck9s
kvI7E8Tk/3HqscgfwUPg9anT6gHWGrUY3iqIvTFfuNOiW2EuEj4SYxNBLhXgJ+9J
styxRQMTp2z2G1/9pqEcObBBrURGwdGwImLjABEBAAHNSVN0YXZyb3MgS29yb2tp
dGhha2lzIChHZW5lcmF0ZWQgYnkgUmV0cm9TaGFyZSkgPHN0YXZyb3NAa29yb2tp
dGhha2lzLm5ldD7CwF8EEwECABMFAlHYH2QJEK4oESk9rbCrAhkBAAAOcAf+KeGg
dDVoBYcJbtjIZQr/HbU0cDajv03nbq41n5Kcx+zR8FIIEK7s0bzimqFmfKlZnIlR
I3Jh+WPTY/k0AKP8BX6ykP2VkzK0zj7St+HB9rHhTjff4ImdAjRz7sL7SDSlyk2V
YcvnthVPENKF7qMPePC9agU7M8E+xQ76VAcIpL5TE9tDg0BhSBk89aejvNwMWwxO
fVYc8BT8XrWKe8Y4Ln3qHQl9SoD8ab3jzed7ZhyYxwgFDcEouRlsx4XfcPfWvXTz
oHbfOHxpYVpp2hpcuiRvgJKde3fwt81WZ+WRN7bHT1u22Ojc/rBNCJ0A4wvGiRJS
jqophn2OYb5W7Dcp3Q==
=5kYc
-----END PGP PUBLIC KEY BLOCK-----
--SSLID--ad7dd0f6c5b84fe6cabf3ac62bb2618a;--LOCATION--Laptop;
--LOCAL--192.168.1.102:62835;--EXT--0.0.0.0:0;As of now, the easiest, best, fastest, and most secure way to transfer files is by using BTSync. (http://labs.bittorrent.com/experiments/sync.html)
Create a shared folder, give out the secret or read only key, done.
It's a great way to get files from one place to the other. The (encrypted) data does not go via a server, making this potentially the fastest, most scalable and safest type of file transfer available in a browser. One of the extra perks is that sharing files on a local network becomes really really fast. It's miles ahead
Props to the devs for making this! :)
Maybe I'm just not in the target group.
Like djim said, storage space and bandwidth are non-issues.
May I suggest trying to get Sharefest popular within a niche? You may have to adapt to that particular niche, but I think it'll help you a lot.
I think there's something in your product, but it doesn't have any selling points for me. Even if you make it as good as Dropbox or any other service, I won't change. For that, you need to be better than existing solutions.
Either be better or be different. Generic user facing file sharing - been there, done that.
Plus all the security/privacy issues...