GUIDE
Pair two devices by sound when the sending PC has no camera
To send a file securely, the two devices first have to agree on a key. Normally the sending PC scans a code on the receiver's screen. A PC without a camera cannot do that, so until now someone typed a 12-character code. If the PC has a microphone, the receiving device can instead play its pairing offer as sound: about six seconds of tones, and nothing to type.
Written by Taha Bayar, a biologist working on laboratory data handover.
How to do it
- On the sending PC, open Kionel, choose the file and, under This PC has no camera?, press Listen for the receiver. The browser asks for the microphone.
- On the receiving device, choose Receive → Sender has no camera — show a code and press Pair by sound. Turn the volume up and hold its speaker near the PC's microphone. The sound repeats until it is heard.
- The PC shows a reply code on its screen. Point the receiving device's camera at it.
- Both screens now show the same six digits and symbols. Compare them, press Codes match on both, and the file is sent as usual.
- Business edition: when the file has arrived, the receiving device plays the signed delivery receipt as sound. On the PC press Listen for the delivery receipt; it shows Delivery verified and offers the receipt for download.
The sound stops by itself when the reply is read, and after 90 seconds in any case, because a pairing offer is only valid for two minutes.
What travels by sound, and what never does
The sound carries the receiver's pairing offer: its public keys, a random number, the time and a signature. It is the same 170-byte record that is otherwise shown as a QR code, and it contains nothing secret. Someone recording the room learns nothing they could use to read the file.
Someone could play a forged offer of their own, louder. Then the two screens would show different comparison codes, which is exactly what the comparison is for. Do not skip it.
The 12-character transfer code is different: it is a secret, and Kionel never plays it as sound. Sound reaches further than a screen can be seen, through an open door or into a phone in someone's pocket, so a secret has no place in it.
The file goes by light, the proof comes back by sound
A delivery receipt is the receiving device's signed statement that it received exactly this file. Normally the receiver shows it as a code and the sending PC scans it. A PC without a camera could not, so the proof stayed on the phone and the PC's own record ended at "sent".
The receipt has only two parts the PC does not already know: the receiver's signature and the moment it signed. The file's fingerprint, its size, both public keys and the dispatch record are already on the PC. So the receiving device plays just 77 bytes, the transfer number, the time and the signature, in about four seconds. The PC puts the receipt back together from what it knows and checks the signature. It is the same signature that the code on the screen would have carried; no new format is involved, and the receipt is checked like any other.
If the receiver got a different file, the signature does not fit the file the PC sent. A receipt recorded from an earlier transfer carries a different transfer number. An imitated sound has no valid signature at all. In each case the PC says what it heard, refuses it and keeps listening.
The sound repeats for a minute and can be played again. If it is never heard, nothing is lost: the file was delivered, and the signed receipt can be exported on the receiving device.
How the sound works
| Frequencies | 64 tones between 1.5 and 5.5 kHz, clearly audible; four tones at a time |
| Speed | 40 bytes a second; a pairing offer takes about 6 seconds, a delivery receipt about 4 |
| Error correction | Reed–Solomon: 16 damaged bytes in a frame are repaired |
| Measured in tests | Decoded with noise as loud as the signal, with room echo, at one hundredth of the volume, and between devices with different audio sample rates |
The idea is the acoustic modem of the telephone era, and open-source libraries such as ggwave use the same principle for short messages. It is far too slow for files, about a thousand times slower than the screen, which is why the file never uses it: sound carries the two short messages a PC without a camera cannot otherwise receive, the pairing offer and the delivery receipt.
When it will not work
- No microphone. Many desktop and instrument PCs have none. Type the code shown on the receiver instead; that always works.
- Microphone blocked. If the browser or a site policy refuses the microphone, Kionel says so and the typed code remains.
- Clocks more than two minutes apart. A pairing offer is refused when it looks older than two minutes. An isolated PC whose clock has drifted hears the sound and reports this; correct the clock or type the code.
- Headsets in call mode. Bluetooth headsets often pass only speech frequencies and process the sound; use the PC's own microphone.
- Receipt by sound without a business licence. Signed delivery receipts are part of the business edition, and the licence has to be on the receiving device. Without it the file is still delivered and checked, and nothing is played.
Privacy
The microphone is on only between pressing Listen for the receiver or Listen for the delivery receipt and the moment the sound is heard or you press Stop listening. The audio is decoded in memory on that page. It is not recorded, not stored and not sent anywhere; the offline package does the same without any network at all.
Other ways to send without a camera: a typed code, printed pages, or a one-way serial cable.