If I compress a single file or a folder together with a random.txt file of random size, and then encrypt it with Cryptomator, could someone still find out how big the file/folder is?
Sounds a bit cumbersome in daily usage, but the answer is “no”.
No to if I can hide the file size or no to if someone can know the file size?
If you have a file with size x. And you compress this file together with another file of size y, and then place this compressed package (eg zip or rat) into a vault, nobody can find out x. Or y.
As far as I know there’s also no need to have 2 files. Just the compressing of file one will hide its original file size in the vault. (But I’m not an expert with file compression)
Isn’t compression a determistic proccess?
Meaning that an attacker could just reproduce it and get the real file size?
Therefore I add a file of random size (and probably also random content)
I’m no security expert but I think you don’t need two files.
Yes, if you encrypted the file first then zipped the encrypted file, unzipping it would reveal the size of the encrypted file because, as you say, the compression is reversible - if it wasn’t it wouldn’t achieve the purpose for which zip compression exists. But if you do it in the other order - zip first, then encrypt - the person obtaining the file couldn’t get at the unencrypted file to unzip it. What they see is the size of the encrypted file and they can’t unzip unless they can decrypt it first.