DEV Community

Cover image for Building a True Zero-Knowledge File Sharing Tool with Client-Side Encryption
Pyae Phyo Maung
Pyae Phyo Maung

Posted on

Building a True Zero-Knowledge File Sharing Tool with Client-Side Encryption

Building a True Zero-Knowledge File Sharing Tool with Client-Side Encryption

Most “secure” file sharing tools still hold the encryption keys or can decrypt your files on their servers. I wanted something different — a tool where even I, as the operator, mathematically cannot access the contents.

So I built SendShield Files.

The Core Idea

Files are encrypted entirely in the browser before they ever leave the user’s device. The decryption key never reaches the server.

How it works

  1. The browser generates a random file key.
  2. The file is split into 16 MiB chunks and encrypted with AES-256-GCM using the Web Cryptography API.
  3. The decryption key is placed only in the URL fragment (#key=...).
  4. According to RFC 3986, the fragment is never sent to the server in the HTTP request.
  5. The server only stores ciphertext.

Result: zero-knowledge architecture. We cannot decrypt your files even if we wanted to.

Two Main Flows

1. Send a File

  • Choose a file + optional expiration (10 minutes to 90 days).
  • Optionally add an Argon2id passphrase.
  • Browser encrypts → share the link (key stays in the fragment).

2. Request Files (Drop Portal)

  • Create a request link.
  • Uploaders encrypt files with your X25519 public key in their own browsers.
  • Only you can decrypt the submissions.
  • Useful when you need people to send you sensitive documents without sharing a password.

Crypto Choices

  • AES-256-GCM — chunked encryption (16 MiB)
  • Argon2id — passphrase wrapping
  • X25519 — sealing for file requests
  • Keys isolated in the URL fragment

The crypto library is open source if you want to review it:

https://github.com/SendShield-Files/crypto

Current Limitations

This is still early. Some things I’m aware of:

  • Not self-hostable yet
  • Large files depend on browser memory
  • No team/workspace features
  • UX can still be improved for non-technical users

Looking for Feedback

I launched it on Product Hunt today and would love honest feedback from developers, especially on:

  • Any red flags in the crypto approach?
  • Is the UX too friction-heavy for normal users?
  • What would actually make you use this over existing tools?

Links:

Thanks for reading. Brutal feedback is welcome.

Top comments (1)

Collapse
 
suppdevbot profile image
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to