7-Zip Header Encryption Explained for Privacy
Header encryption in 7-Zip is a security feature that encrypts not just the contents of your files, but also their metadata—including file names, sizes, directory structures, and file extensions. While standard archive encryption leaves file names visible to anyone who opens the file, header encryption conceals the entire directory tree behind a password prompt. This article explains how header encryption works, why it is essential for personal privacy, and how it differs from conventional archive encryption.
What Is Header Encryption?
When you compress files into an archive, the software creates two distinct components: the file data (the compressed payloads) and the header (the table of contents). The header contains metadata, such as:
- File and folder names
- Directory paths
- Uncompressed and compressed file sizes
- Timestamps (date modified, created, accessed)
- File attributes and permissions
Under standard encryption, only the actual contents of the files are encrypted with an algorithm like AES-256. Anyone without the password cannot extract or view the contents of the files, but they can still double-click the archive and view the complete list of files and folders inside.
When you enable header encryption—labeled as "Encrypt file names" in 7-Zip—the entire header is encrypted using the same key as the data. Without the correct password, 7-Zip cannot read the table of contents, meaning the software cannot display what files exist inside the container.
Why Header Encryption Is Vital for Privacy
File contents are not the only sensitive data stored on a computer. Metadata alone can expose confidential information, making header encryption crucial for robust privacy.
1. Eliminating Metadata Leakage
File names often reveal highly sensitive details. For instance, file
names such as Divorce_Settlement_Draft.docx,
2024_Tax_Return_SSN.pdf, or
Medical_Biopsy_Results.png tell an observer exactly what
kind of information is contained in the archive, even if the files
themselves cannot be opened. Header encryption ensures that an
unauthorized observer learns nothing about the contents.
2. Preventing Targeted Cryptanalysis and Tampering
When an attacker can see the names, sizes, and extensions of files inside an archive, they gain structural clues about the data. In targeted attacks, knowing that an archive contains specific software executables or standard document templates gives adversaries known plaintext structures, which can aid in targeted analysis or verification. Hiding the headers leaves the attacker with an opaque block of raw ciphertext.
3. Immediate Access Denial
With standard archive encryption, a user is prompted for a password only when attempting to open or extract a specific file. With header encryption enabled, the password prompt appears immediately upon opening the archive. If the user cancels the prompt or enters the wrong password, 7-Zip refuses to open the archive entirely.
Technical Requirements in 7-Zip
Header encryption is not supported by all compression formats:
- Supported Formats: It is natively supported in the .7z format.
- Unsupported Formats: Standard .zip archives do not natively support header encryption; standard ZIP specifications require directory headers to remain plaintext for backward compatibility.
To use header encryption in 7-Zip, the archive format must be set to
.7z, a password must be provided under the Encryption
section, and the checkbox labeled "Encrypt file names"
must be checked before creating the archive.