ComingUp ComingUp
Fylex.io

Fylex.io

Post-quantum, zero-knowledge decentralized file sharing & Monero payments.

Sep 2, 2026 Security & Privacy
decentralized file sharing post_quantum privacy zero_knowledge

Gallery

Fylex.io

About

Fylex - Zero-Knowledge, Post-Quantum Decentralized File Sharing & Sovereign MonetizationFylex is an enterprise-grade, native cross-platform privacy engine and decentralized file-sharing platform engineered under strict zero-trust and anti-forensic principles. Fylex operates on the core assumption that every layer of communication is adversarial: the network, the database, the ISP, browser extensions, and even local operating system clipboards. Fylex ensures that zero plaintext bytes, file names, metadata, or keys never touch centralized servers.🖥️📱 True Native Multi-Platform SupportFylex is engineered from the ground up for seamless, high-performance deployment across desktop, mobile, and web environments:• Windows: Native desktop client built with Wails v3 and Go 1.26+. Packaged with Inno Setup into a standalone wizard (`Fylex-Setup.exe`), featuring embedded PE resource manifests, custom taskbar integration, and full binary string/symbol obfuscation via Garble.• Android: High-performance mobile build utilizing native NDK Clang cross-compilation, JNI bridging (`libwails.so`), API 35 SDK support, ProGuard/R8 optimization, and dual-ABI targeting (`arm64-v8a` + `armeabi-v7a`).• Linux: Portable native ELF 64-bit binaries and Debian/Ubuntu `.deb` packages generated via `nfpm`, complete with system desktop integration, WebKitGTK bindings, and custom app icons.• Modern Web: Zero-install web client powered by Go WebAssembly (WASM), Web Crypto API, and embedded Tor Hidden Services (`.onion`).⚛️ Post-Quantum & Hybrid Cryptographic ArchitectureFylex is built to resist both contemporary supercomputing attacks and future cryptanalytically relevant quantum computers (CRQCs):• Quantum-Resistant Key Exchange: Hybrid ML-KEM-768 (NIST FIPS 203 / Kyber) combined with classical ECDH (secp256r1 / P-256).• Quantum-Resistant Signatures: Hybrid ML-DSA-65 (NIST FIPS 204 / Dilithium) + classical ECDH (P-256 / secp256r1) via HKDF-SHA256 to sign server handshakes, ephemeral session tokens, and Data Encryption Key (DEK) updates.• Symmetric Cipher: XChaCha20-Poly1305 featuring 256-bit keys and 192-bit nonces, immune to AES cache-timing side-channels and nonce-collision limits.• Large-File STREAM Construction: Nonces are derived per chunk using sequence offsets and base nonces with an explicit 24th-byte end-of-stream flag, preventing chunk reordering, dropping, or tampering.• Password Security: Client-side OPAQUE aPAKE (Asymmetric Password-Authenticated Key Exchange) and Argon2id / PBKDF2-SHA256 (600,000 rounds) master key stretching.• Encrypts the Data Encryption Key (DEK) against a future round of the League of Entropy’s distributed Drand randomness beacon using Identity-Based Encryption (IBE) on the BLS12-381 curve. The file mathematically cannot be decrypted by anyone including the uploader or anyone until the network collectively produces the designated round's signature.🛡️ Deep Anti-Forensics & Endpoint Defense• RAM-Only Ephemeral Decryption: Plaintext streams are reconstructed strictly in isolated RAM buffers (0 bytes touch the SSD/hard drive), bypassing swap file indexing and auto-destructing upon tab/window closure.• Pre-Encryption Metadata Scrubber: An integrated WASM engine automatically parses and strips binary EXIF data, GPS tags, camera profiles, and author metadata prior to encryption.• Anti-Reverse Engineering & Obfuscation: Binaries are compiled with Garble for stripped symbols and encrypted string tables. The WASM enclave actively benchmarks execution timing to detect debuggers/breakpoints and executes an immediate memory wipe (`zeroize()`) upon tampering.• "DOM Vault" & Closed ShadowRoot: Renders sensitive content inside `mode: 'closed'` Shadow DOM boundaries and sucks the DOM tree into a detached `DocumentFragment` the instant window focus is lost.• Input & Clipboard Protection: Features a randomized HTML5 Canvas virtual pinpad to defeat hardware USB/software keyloggers and auto-overwrites OS clipboards with decoy links after 45 seconds.• On Android, Fylex executes all cryptographic routines inside a native C/Go shared library (`libwails.so`) compiled with the Android NDK (Clang). Memory transfers between the UI and backend occur strictly via in-process JNI DirectByteBuffers that bypass system networking and zeroize their heap space immediately upon ret🌐 Decentralized Storage & Traffic Obfuscation• Fetch Stream Uploading (`duplex: "half"`): Streams 32MB encrypted chunks directly to the IPFS distributed network via with zero backend disk caching, supporting 20GB+ transfers with flat browser RAM.• PURB (Padded Uniform Random Blobs): Automatically pads encrypted payloads to standardized bucket boundaries to defeat file-size fingerprinting.• Embedded Tor Hidden Service: Directly bundles the `bine` orchestrator to generate ephemeral `.onion` v3 hidden services automatically on boot.• Traffic Padding (Chaffing): Exchanges continuous randomized dummy heartbeat packets to smooth out temporal bandwidth spikes against ISP surveillance.💰 Sovereign Monetization & Access Controls• Automatically generates unique, disposable Monero subaddresses for every upload. Polls the mempool to unlock downloads trustlessly while automatically routing fees to uploaders without KYC.• Timelock Capsules: Encrypts DEKs against future rounds of the Drand distributed threshold BLS randomness beacon, making decryption mathematically impossible before a set date/time.• Steganography & Duress Modes: Hides encrypted keys inside ordinary cover images (LSB steganography) and supports panic passwords that visually simulate decryption failures while silently incinerating encrypted bob.More feature:• Zero-Knowledge URL Routing: URL fragments are hashed client-side with SHA-256 before requesting the record.• Tokens are consumed via server-side atomic Lua scripts; expiration is passive and strict. Prevents Race Conditions and TOCTOU attacks. A single-use token can never be claimed by two concurrent requests.• Ephemeral Single-Use APIs. Every endpoint URL contains a short-lived, unpredictable token that is immediately invalidated. • Disposable XMR Subaddresses. Generates a mathematically unique Monero address for every single file transfer.• Burn After Reading feaures• Zero-padded buffers for PoW checks. Prevents timing attacks where an adversary could guess tokens or hashes by measuring nanosecond differences.and Lots More

Comments (2)

Mia Daniel Mia Daniel 6 days ago

enterprise adoption seems unlikely with monero's regulatory baggage

Deven Dicki Deven Dicki 5 days ago

post-quantum AND zero-knowledge... someone really went all in on buzzwords