{
  "id": 13353721,
  "title": "Building a True Zero-Knowledge File Sharing Tool with Client-Side Encryption",
  "url": "https://urgent.news/2026/10/10/building-a-true-zero-knowledge-file-sharing-tool-with-client-side",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T07:23:07.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/pyaephyomaungdev/building-a-true-zero-knowledge-file-sharing-tool-with-client-side-encryption-1mej"
  },
  "original_language": "en",
  "account": "The article outlines the creation of a new file sharing tool called SendShield Files, which aims to provide a truly zero-knowledge service. Traditional file sharing tools often retain the encryption keys or have the capability to decrypt files on their servers. SendShield Files seeks to eliminate this vulnerability by ensuring that even the tool's operator cannot access the contents of the shared files.\n\nAt its core, SendShield Files encrypts files entirely on the user's browser before they leave their device. The encryption key remains solely on the user's machine and never reaches the server. The process involves the browser generating a random file key, splitting the file into 16 MiB chunks, and then encrypting each chunk using AES-256-GCM with the Web Cryptography API.\n\nThe decryption key is placed in the URL fragment, which, according to RFC 3986, is not sent to the server in the HTTP request. This ensures that the server only stores the ciphertext, resulting in a zero-knowledge architecture where the provider cannot decrypt the files, even if they desired to do so.\n\nThe tool offers two main ways to share files: by directly sending a file or by requesting files through a drop portal. In the first method, users choose a file, optionally set an expiration time (between 10 minutes and 90 days), and add an optional Argon2id passphrase. The browser then encrypts the file and shares the link, with the key stored in the URL fragment. In the second method, users create a request link that uploaders can use to send sensitive documents. The uploaders encrypt their files using the provider's X25519 public key on their own browsers, and only the provider can decrypt the submissions.\n\nSendShield Files uses AES-256-GCM for chunked encryption, Argon2id for passphrase wrapping, and X25519 for file requests. The crypto library is open source for those who wish to review the implementation: https://github.com/SendShield-Files/crypto\n\nHowever, the tool is still in the early stages and has a few limitations. It is not yet self-hostable, large files may strain the browser's memory, there are no team or workspace features, and the user experience can still be improved for non-technical users. The author is currently seeking feedback from developers, particularly regarding any red flags in the crypto approach, the potential friction of the UX for normal users, and what would make users prefer this tool over existing alternatives.\n\nThe article provides several links for further information: a Product Hunt post at https://producthunt.com/products/sendshield-files, the main site at https://sendshieldfiles.com, and security details at https://sendshieldfiles.com/security.",
  "summary": "Building a True Zero-Knowledge File Sharing Tool with Client-Side Encryption Most “secure” file sharing tools still hold the encryption keys or can decrypt your files on their servers. I wanted something different — a tool where even I, as the operator, mathematically cannot access the contents. So I built SendShield Files . The Core Idea Files are encrypted entirely in the browser before they…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}