Plausible deniability is simply not a useful defense against someone that would decide to torture you for a mere suspicion.
It is also worth pointing out that the number of passwords you deny having is completely irrelevant. You could claim to have forgotten the one password you use for non-deniable encryption and the effect would be the same (and your story is equally plausible). It is much easier to claim to have forgotten one password than to try to maintain an innocent partition, so you might as well just do that.
I never thought I'd feel the need to offer this as serious advice, rather than just a novelty toy, but SpyCoin is a way to get data across borders.
I have a pound coin and it's pretty good.
- Tomás de Torquemada, 2011
Is it possible to hide the fact that you have a Truecrypt volume? Or are there always headers or signatures that give it away?
You can't really hide the fact that you're using encryption, because it doesn't really look like anything else apart from random data & people don't usually go around piping /dev/random into large files for no good reason. Compressed data is high entropy, but can be decompressed to something lower entropy, so you can easily eliminate png filess, zipped files etc.
But if you had truecrypt installed and 1 drive that wasn't formatted... Yea
Btw: there's no explicit restriction on N-level deep of hidden volumes, but TC won't automatically make the outer ones read-only.
At least that was Julian Assange's vision when he invented the Rubberhose filesystem[1] in 1997.
[1] https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29
The rational thing for the government to do would be to ignore the computer (after forensics), and work on the person. If the information turns out not to be productive, escalate the torture. When the suspect dies and/or fools you into a significant expenditure or public failure, you lose and the suspect wins. Same as it's always been.
edit: of course, faced with the fact that there's no reason not to torture you to death, you may just become a willing collaborator.
I hoped this would b a technical article explaining a flaw in TrueCrypt, but it is just flawed logic based on a misconception that "plausible" means "full-proof".
Zerobin gives an idea: http://sebsauvage.net/wiki/doku.php?id=php:zerobin
If you don't have a hidden volume and the government decides to keep torturing you,
you're screwed. You have no way of stopping the torture even if you wanted to, and you
probably get killed. So your reward is -100. The government's reward is 10 because
although they may have wasted some time torturing you, they have your plans, can prove
your guilt, and arrest your accomplices.
I don't understand why the government's reward is 10. How do "they have your plans" if there is no hidden volume? Are the plans in the "outer" partition in this scenario?It's a very useful mechanism to protect information important to you in other situations. Perhaps you don't want your spouse, kids, boss or employees to have access to some data. Or you need to hide sensitive data in plain sight for preservation purposes.
And your irrefutable logic for picking that ordering is what, exactly?
The reasoning behind the 9 and 10 on the 'no hidden volume' side is especially flawed, and seems to be a backwards argument made to support the number, rather than to derive it.
Somehow being wrong and wasting resources costs no points, but uncertainty and being correct costs points.
Also, there is no strictly dominant strategy in the prisoners dilemma like he says.
I guess that means I'm not a true crypto nerd?
(I think it is unfortunate how dismissive that comic is, exactly because of this use case...)
Look at it this way, if the US government could get Glenn Greenwald's laptop, which in this scenario is TrueCrypt-encrypted, do you think they would simply give it back to him and say, "I guess he didn't have anything after all" if the first password he gave them turned up nothing but pictures of his cat?
Of course, the goal of TrueCrypt may be to provide a small amount of extra security, which it does. As others have said, a regime that would torture you to death likely doesn't need your laptop anyway. But the point is reasonably valid that a hidden volume is only enormously valuable if no one thinks you might have it, which isn't the case with TrueCrypt anymore.
That's "magic bullet" security/magic thinking if I've ever heard it...
Rather, this article argues something different, which is that in some (extreme) circumstances, plausible deniability won't help you much (though it's still optimal in that it's a "strictly dominant" strategy) . To which i would say "no duh".
I get that this is a big deal though, from a "is truecrypt" usable standpoint though...I just think that people should base their security procedures on more practical measures.