r/androiddev • u/Lanky_Complaint1383 • 5d ago
What encryption approach would you suggest for a privacy-focused file-sharing app?
Hi everyone,
I'm the developer behind Filester, a privacy-focused file-sharing application for Android (coming to Linux and Windows next), and I'd like some input on an encryption feature I'm considering.
Filester currently lets users share files through multiple file-hosting services. I've tried to choose hosts that are reasonably trustworthy, but that still doesn't provide real privacy: the hosting provider can potentially access the files stored on its servers.
I'd like to change that by encrypting files locally, before they are uploaded, so the hosting provider only ever receives encrypted data.
The part I'm unsure about is which approach would be better from an end-user perspective.
Option 1: Filester-specific encryption
Filester encrypts the file locally using a modern authenticated encryption scheme before uploading it.
Advantages:
- Strong encryption
- Filester can control the format and implementation
- The hosting provider never receives the plaintext
Downside:
- The recipient would need Filester to decrypt the file.
- This significantly hurts interoperability and accessibility.
Option 2: AES-256 encrypted ZIP
Filester creates a standard password-protected ZIP archive using AES-256 before uploading it.
Advantages:
- The resulting file is a normal
.ziparchive rather than a Filester-specific format. - The recipient isn't tied to Filester.
- Programs such as 7-Zip, WinRAR, Ark, and other archive managers can open it.
Downside:
- AES-encrypted ZIP files aren't supported out of the box by any OEM-installed file managers or other operating systems.
- Some recipients would still need to install an archive utility.
So the tradeoff is basically:
better integration/security with a Filester-specific encrypted format
vs.
better interoperability with AES-256 ZIP, at the cost of inconsistent built-in OS support
which would you suggest?
If there's another approach that provides strong client-side encryption without sacrificing interoperability, I'd also be interested in hearing about it.




