> Contains private account data.
> It's a JSON compressed and encrypted file.
> The JSON byte-stream is compressed using gzip algorithm.
> Then the gzip-stream is encrypted using AES-GCM-256 symmetric cipher with a 256-bits key.
Does this compress-then-encrypt combination introduce a security weakness? It's certainly a problem on the Web, since attackers can learn what's in an encrypted response by getting the server to insert their own strings; e.g. trying the same request many times with different query strings, and seeing which ones result in smaller responses, indicating that the given query string matches somewhere in the document.
It would require the attacker to be able to get their own strings in the payload, but since this JSON contains things like contact info that might be possible.