9 ms·
Show HN: I built a website to share files and messages without any server
NeighborHoodShare: It is a p2p files and messages sharing platform without involvement of any server. It has end-to-end encryption, ensuring your messages and files remain confidential.
These are some features:
- Share photos, documents, videos, and more with ease, no matter the size.
- Connect instantly with anyone for speedy and reliable file transfers, bypassing the need for centralized servers.
- Get started in minutes with our intuitive interface designed for seamless communication. No registration.
- Easily connect with others using QR codes, simplifying the sharing process further.
The inspiration behind NeighborHoodShare stemmed from a common dilemma: the reluctance to share personal contact details like phone numbers or email addresses when sharing photos or messages with strangers. With NeighborHoodShare, you can share content securely without compromising your privacy.
I would be happy to hear your feedback and suggestions for improving NeighborHoodShare.
I had written a blog on how p2p networking in browsers work: https://dikshantraj2001.medium.com/nat-stun-turn-and-ice-466dabbc2fdb https://dikshantraj2001.medium.com/nat-stun-turn-and-ice-466...
- Vinnl 2y agoA bit off-topic, but since I was looking at doing a side project with a P2P feature, would appreciate if I could pick your brain for a bit: don't you still need to run the STUN and TURN servers? Can you run those using Vercel's serverless functions?
- vmfunction 2y agolook at https://peerjs.com https://peerjs.com that this the project is using.
- BrandoElFollito 2y agoThis looks like an implementation of STUN - there are no miracles, if two machines are behind NATs someone need to broker the connection.
- Vinnl 2y agoHmm thanks, so that says: > To broker connections, PeerJS connects to a PeerServer. Note that no peer-to-peer data goes through the server; The server acts only as a connection broker. > If you don't want to run your own PeerServer, we offer a free cloud-hosted version of PeerServer. So I suppose there's still a server, but it's shared and run by two folks based on donations: https://peerjs.com/peerserver https://peerjs.com/peerserver
- cl3misch 2y agoWithout data going through the server it should be pretty cheap to host, right?
- dkraj 2y agoThat is why there are public STUN servers available by google that any one can use: stun.l.google.com:19302 stun1.l.google.com:19302 stun2.l.google.com:19302 stun3.l.google.com:19302 stun4.l.google.com:19302
- llmblockchain 2y agoI used peerjs years ago (2013~). It was a whole lot of pain back then... I assume things have gotten better, but damn was it painful! I ended up forking and fixing/maintaining my own fork because it was too slow to get things fixed in master.
- dkraj 2y agoA STUN server is required for discoverability and if still ICE candidates are not found or a negotiation can not take place, I just shows an error for now. About vercel I am not sure need to check whether it provides or not
- deleted 2y ago[deleted]
- James_K 2y agoHow can this work without a a server? You surely need a third party to traverse NAT.
- NayamAmarshe 2y agoIt's using WebRTC's P2P. It does require internet but the middleman is absent in file-sharing.
- dkraj 2y agoWe need a STUN server to traverse NAT and get IP addresses but it does not use server to store or share the file. Only ice candidates are gathered, discovered and a handshake is facilitated by a STUN server. If that is not possible it shows error.
- cynicalsecurity 2y agoIf at least one party is behind NAT, it's a dead end. I wouldn't trust anyone who makes a false claim it's possible.
- roeles 2y agoPlease Google udp hole punching
- wickedsickeune 2y ago
- NayamAmarshe 2y agoLooks good but any plans to make it open source? Similar open source solutions exist like: - https://pairdrop.net/ https://pairdrop.net/ - https://wormhole.app/ https://wormhole.app/ - https://www.snapdrop.net/ https://www.snapdrop.net/ How does this compare?
- INTPenis 2y agoI've been hosting my own pairdrop for a year now, very easy and quick to share a file between my smartphone and laptop without digging out a usb cable.
- p4bl0 2y agoI use KDE Connect for that. Have you given it a try?
- INTPenis 2y agoNo, I did try the Gnome equivalent a long time ago but these days I use a more minimal setup. So I'd prefer a CLI tool.
- jimbobthrowawy 2y agoWhat is the Gnome equivalent? If you mean GSconnect, that's an implementation of kde connect. I think kde connect has some CLI tools, but they're not super ergonomic. For CLI stuff, I usually just run the python http server or woof and make a QR code with the URL.
- d-z-m 2y agoI looked around and couldn't find a description of the protocol by which two peers authenticate to each other/transfer files. Also, is the E2EE encryption referred to simply whatever is being used to encrypt the transport(DTLS/SRTP/etc)? or are you doing additional encryption/decryption of files? Also I'm curious like others, does this only work if no nat traversal is required? or are you leveraging public stun/turn infrastructure?
- meiraleal 2y agoIt's webrtc, no?
- dkraj 2y agoyes it is using webRTC. will open source the repo soon. BTW there are all information about it in different threads
- dkraj 2y agoWebRTC it is: https://webrtc.org/ https://webrtc.org/ Yes only the network layer encryption. No file encryption as it will cost client browsers a lot in case of encrypting and then decrypting that at other end. I have written more about it here: https://dikshantraj2001.medium.com/nat-stun-turn-and-ice-466dabbc2fdb https://dikshantraj2001.medium.com/nat-stun-turn-and-ice-466... Currently, I am using the public STUN servers only. If the IPs are not reachable, it would show an error and won't work as setting up TURN server would mean same as a third party server saving in file and serving it over network
- porridgeraisin 2y agoYou can use https://npmjs.com/e2ee.js https://npmjs.com/e2ee.js (disclaimer: I am the author) for basic end to end encryption in the browser (uses the webcrypto api). It supports encrypting and decrypting a web stream as well which you could use.
- d-z-m 2y agoIdeally I would not have to trust the signalling server to ensure I'm transferring files to who I think I am[0]. Not as much of a knock against your project as a knock against webRTC in general. [0]: https://webrtchacks.com/webrtc-and-man-in-the-middle-attacks/ https://webrtchacks.com/webrtc-and-man-in-the-middle-attacks...
- ramchip 2y ago> without involvement of any server > bypassing the need for centralized servers I don't follow this part... it's using a centralized server to serve the web app, which could easily serve JS code that steals confidential data right?
- dkraj 2y agoDidn't get the part of steals confidential data? It can not do anything without your permissions. All websites are well scoped and run in their private environment in a web browser.
- ramchip 2y agoI mean the data people send through the app. You say: > It is a p2p files and messages sharing platform without involvement of any server. It has end-to-end encryption, ensuring your messages and files remain confidential. However the clients get the JS code from the web server. Since you control that server, you can change the code to disable the encryption, or send a copy of the messages somewhere else. You can even make the server give specific people / IPs one copy of the code and others a different copy. Hence my point is there is a trusted centralized server involved.
- dkraj 2y agoGot you so you want to say that the place where I have hosted is a centralised place and yes you are right. But I won't do that ~~~
- supportengineer 2y agoSure “you” won’t do that. But who are you? What if “you” changes? “You” could be the CIA or a Nigerian scammer. Nobody knows. And it can change at any moment.
- scrose 2y agoAh yes, we should completely trust the anonymous person who registered to the site 23 days ago and has done nothing other than submit half a dozen chrome extensions to the site since then
- anonu 2y agoI'm curious about the effectiveness of your other app, NoFap, a browser extension. You might need something a bit less easy to control to make it useful. Just my two cents.
- dkraj 2y agoCan you please elaborate
- aster0id 2y agoObligatory callout to the excellent server-free CLI file transfer tool magic wormhole which is open source and battle tested
- matheusmoreira 2y ago> This program uses two servers > the mailbox server, and the transit relay. The dream of the P2P internet died with NAT.
- wickedsickeune 2y agoI hoped that it would relive with IPv6 but apparently this will not happen while I'm alive.
- siamese_puff 2y agoNo offense, but why would people use this without associated source code for anyone to scrutinize? Why keep it private? WebRTC based tools like this exist so it’s only a red flag IMO to keep it private.
- dkraj 2y agoHad open sourced it. You can check it at: https://github.com/dikshantrajput/neighborHoodShare https://github.com/dikshantrajput/neighborHoodShare
- deleted 2y ago[deleted]
- fenesiistvan 2y agoTURN and P2P are incompatible things.
- deleted 2y ago[deleted]
- gradientsrneat 2y agoOP reply says they use STUN, not TURN.
- nrvn 2y agoThere have been plenty trusted battle tested open source implementations of WebRTC-based p2p transfer. Why would I use this one instead of them?
- deely3 2y agoCould you please name these implementations?
- mikae1 2y agohttps://file.pizza/ https://file.pizza/ https://github.com/kern/filepizza https://github.com/kern/filepizza Is one. But I've seen more.
- nrvn 2y agoJust a few that are both open source and have the hosted public versions available: https://github.com/RobinLinus/snapdrop https://github.com/RobinLinus/snapdrop https://github.com/jchorl/sendfiles https://github.com/jchorl/sendfiles https://github.com/szimek/sharedrop https://github.com/szimek/sharedrop
- scrose 2y agoYou’ve done nothing but submit half a dozen random extensions in the 3 weeks that all collect different personal information on browsing history at a minimum. Your README’s look AI generated, and you’re a completely anonymous account. Additionally, your responses on how files are encrypted here is severely lacking. All I can say is: There are a lot of red flags here.
- dkraj 2y agoYes you are absolutely right. I had replied on other threads. Files are not encrypted. WebRTC provides encryption on all sessions
- johnea 2y agoThere's a website... but no server? Language sure is weird...
- dkraj 2y ago"Share files and messages without server"
- dkraj 2y agoHere is the source code: https://github.com/dikshantrajput/neighborHoodShare https://github.com/dikshantrajput/neighborHoodShare