That’s not true. The original DNS request, for youtube.com, may not have been encrypted, but any URL parameters afterwards are kept encrypted. As long as HTTPS is used, if hypothetically Google wasn’t going to give it to them, “the government,” or your ISP for that matter, can tell you’re watching YouTube, but can’t tell which video you’re watching.
file.pizza if this is a one off or rare occurrence. If you’re doing this regularly, there are better options, provided the person at the “source” computer is competent. A significant question is whether or not these computers are on the same network. I would recommend running a HTTP server if you don’t care about privacy, HTTPS if you do. There’s no need to buy an SSL certificate, self-signed is more than adequate for this purpose.
It’s more complicated to set up, but the advantage is that when you’re done you can send the receiving party a link they can open in any web browser, no hassle.