Hacker News new | ask | show | jobs
by bArray 2290 days ago
An encrypted volume (fixed space) should even remove the white space. After all, knowing the size of a file contained within could leak information about its contents.

I imagine the only way to detect a volume would be to have it decrypted (enforced by law enforcement), to take the supposed volume type and files within and then re-encrypt with the same data. If your volume and the supposed clone are different, it would suggest that you have hidden another volume within.

1 comments

I think the defense is that (assuming IVs, nonces, etc... are held constant) that the files would encrypt identically. And the excuse for the rest of the disk is “it gets filled with random bytes to obscure how much disk space is actually being used.