Skip to content
Subfile

Choosing a carrier file: why video beats photos for large vaults

A photo makes the better demo. A video makes the better vault. The difference is entirely about what size looks normal.

5 min readThe Subfile team

When you create a vault with Subfile you pick a carrier: an existing file that the encrypted volume is written into. The carrier keeps working — it plays, previews and opens exactly as before — and the vault rides along inside it. The question people ask first is which type of file to choose, and the honest answer is that it depends almost entirely on how big the vault needs to be.

The reason is simple. Concealment does not come from clever bit-twiddling. It comes from the file being unremarkable, and a file is unremarkable when its size matches what a person would expect from its type. Every carrier format has a size range that reads as normal, and the moment you leave that range the file starts asking questions on your behalf.

The size story each format can tell

video
mp4, mov, mkv — comfortable into the tens of gigabytes
audio
wav, aiff, flac — a few hundred megabytes to a few gigabytes
photo
jpeg, png, heic — tens of megabytes before it looks odd
container
zip, iso, pdf — whatever the surrounding folder makes plausible

Video wins on large vaults because video is the one file type where enormous is boring. A twenty-minute 4K export from a phone is already several gigabytes. Nobody double-takes at a 12 GB .mov in a folder of footage, and nobody has an instinct for what a given clip should weigh — the number depends on codec, bitrate, resolution and length, so a wide range of sizes is defensible without any explanation at all.

Photos are the opposite. People have a strong, if unspoken, sense of what an image file costs. A JPEG from a phone is a handful of megabytes. A large raw scan might be a few hundred. A 4 GB JPEG is not a photograph with a lot of detail in it; it is a file that has something else in it, and anyone who glances at a size column will notice. Photos make the best demonstration of the idea — you can open one in Preview, see the picture, and know a vault is inside it — but they are the most fragile carrier in practice.

Fragility is the second axis

Size is what gets noticed. Handling is what gets things destroyed. A carrier survives being copied, renamed, moved, backed up, put on a USB stick or synced as a file. What it does not survive is anything that re-encodes it.

  • Uploading a photo to a social platform or most messaging apps. These recompress images by policy, usually silently, and the vault is gone the moment the file is re-derived from the pixels.
  • Transcoding a video, or letting an editor re-export it. Same bytes in, different bytes out.
  • Converting audio between formats, including a well-meaning “optimise library” feature.
  • Repacking an archive, or letting a tool rewrite a PDF to linearise or compress it.
  • Cloud services that store a re-derived version rather than the original file. File-level sync is fine; anything that processes your media is not.

This is why photos carry more risk than their size limit alone suggests. Photos are the file type people share most casually, and sharing is exactly the operation that recompresses them. A video sitting in a project folder is far less likely to be casually sent through a pipeline that rewrites it.

Making the file believable

A carrier has to fit its surroundings as well as its type. Two files can be identical in every technical respect and only one of them looks natural.

  1. 01Use a real file you actually have. A clip you shot, a session you recorded, a scan you made. Provenance is the cheapest form of plausibility, and a file with real content that opens and plays normally survives any amount of casual inspection.
  2. 02Put it where its type belongs. Footage lives with footage. A lone video in a folder of invoices is a flag.
  3. 03Match the name to the neighbours. If everything around it is dated and descriptive, be dated and descriptive.
  4. 04Let the size be ordinary for the folder it sits in. If every other export is between two and eight gigabytes, land inside that band.
  5. 05Do not create the carrier and the vault on the same day the file claims to be from, if timestamps are part of the story you are telling. Copying resets metadata in ways that are easy to forget.

A rough decision rule

If the vault is going to hold documents, keys, contracts, scans, correspondence — the things that are small and matter — almost any carrier works, and audio is a good middle choice: a single uncompressed session is already large enough to hide a meaningful vault without looking strange.

If the vault is going to hold client work, project archives, raw media or years of accumulated material, use video. It is the only carrier where the file can grow to the size the job actually requires and still look like nothing in particular.

And if the file does not need to look like media at all — a vault on your own external drive, in your own project folder, where a dull archive is the least interesting thing present — a plain container is often the quietest option of the four. Not everything has to be a disguise. Sometimes it just has to be uninteresting.

pick the size story first · the format follows from it

next

What a hidden volume actually protects you from

Steganographic containers buy you a specific kind of quiet. Here is where the quiet holds, and where it does not.

5 min read

An ordinary file. A private drive inside.

Subfile writes an encrypted volume into a file you already have and mounts it in Finder. Offline, no account, macOS.

See how it works