drift v0.1.0
Encrypted file transfer over WebSocket — a single binary, zero configuration.
Highlights
-
Single binary, batteries included — The React frontend is embedded right in the Rust binary. No install steps, no Docker, no config files. Just run
drift --port 8000and open your browser. -
End-to-end encrypted — Every session performs a fresh X25519 Diffie-Hellman key exchange. File data is encrypted with ChaCha20-Poly1305 with forward secrecy. Optional password authentication via HMAC challenge-response.
-
Two-pane file browser — A web UI shows your local files on the left and remote files on the right. Select and copy in either direction.
-
CLI direct send — Skip the browser entirely with
drift --target host:8000 --file video.mp4. Transfers the file, prints progress, and exits. -
Folders just work — Directories are compressed to tar.gz on the fly, streamed over the wire, and extracted on the other side. No zipping by hand.
-
Bidirectional — Push files to a remote machine or pull files from it. Both directions work from the browser UI and from connected servers.
Quick Start
# Machine A
drift --port 8000
# Machine B — connects and shows both file trees
drift --port 9000 --target 192.168.0.2:8000
# Or just send a file
drift --target 192.168.0.2:8000 --file report.pdfSecurity
| Property | Implementation |
|---|---|
| Key exchange | Ephemeral X25519 (forward secrecy) |
| Encryption | ChaCha20-Poly1305 AEAD, monotonic nonces |
| Key derivation | HKDF-SHA256, separate keys per direction |
| Authentication | Optional HMAC challenge-response (--password) |
| Path safety | All paths canonicalized and jailed to root dir |
Install
git clone https://github.com/aeroxy/drift.git
cd drift
cargo build --release
# Binary at target/release/driftRequires Rust 1.82+ and bun.
Full documentation: README