I'm not sure if the entropy analysis of that free space can suggest that there's something funky about that free space or not.. Because usually free space is either actual info just marked as deleted, or info reset to zeros by some pro active wiping of the free space. So, having a bunch of whacky data that doesn't look like any kind of file, can probably be used as a tell tale sign? No?
Unless you're thinking your attacker would exclude you from torture for "yielding" the password.
I would think if they are capable of torturing you than they wouldn't stop at a polite confession.
The idea is that they’ll stop torturing you because they don’t know of the existence of the hidden volume.
(In practice I suspect it leaves some subtle queues, but maybe perfect for a border crossing )
~"Do you have any encrypted data we can't see?"
"Yes. The entire drive is encrypted"
~"What is the key?"
"iloveapplesauce6969"
~"Well, that worked and I see your data here. What a lovely family.. is that Disney world?"
"Yes it was Timmy's 5th birthday"
~"I'm going to waterboard you"
You: "This was everything!"
Them: "We don't believe you" -rubber hose-
You: "Stop it! I planned to blow up the world trade center!"
Them: "We knew you were a liar."
To themselves: "Wow, torture works."
Rinse, repeat.
But as sibling commenters describe, if sufficiently motivated, there's no reason that an authoritarian state wouldn't just keep torturing you anyway. :(
Sure, but it helps to make it look like you're someone not worth torturing in the first place. The same look would happen when you decrypt your TrueCrypt partition.
Large unused sections on the laptop with random data is a bad look for someone trying to say they're not a spy.
If it were me, I would do something more like bring a laptop with a bunch of biblical research and ask everyone in the checkpoint, if they've taken Jesus Christ into their heart.
This of course assumes that in this instance the authoritarian regime just finds these sorts of religious people annoying and not dangerous. I wouldn't do this coming into Iran, say.
I imagine the only way to detect a volume would be to have it decrypted (enforced by law enforcement), to take the supposed volume type and files within and then re-encrypt with the same data. If your volume and the supposed clone are different, it would suggest that you have hidden another volume within.
(Good) Encryption is a (secure) mechanism for obscuring data, surely?
In comparison, which particular password I use can be very highly decoupled from the rest of the world and my architecture, which makes it vastly more (reliably) obscure.
Somewhere inbetween "you have to know my server exists to send 'login:admin password:pass' to it" and "the volume's encrypted with a 2048-bit cypher generated from atmospheric entropy" is, maybe, a useful middle ground.
Hidden volumes seem like more of a defensive meta-obscurity, in that they obscure your metadata (your ownership of a particular piece of encrypted data).
Also, there are plenty of historical ciphers that fall foul of Kerckhoff, I don't think we can say retrospectively that they weren't done for security, and in many cases were probably totally adequate for some time, if not their lifespan.
Specifically- there's no limit to the number of decoys that could be on a disk. So you can get into the situation where you've decrypted every volume that exists, under coercion, but your adversary believes there are more volumes remaining.
By design, you have no way to prove that there isn't more hidden data on that disk. This is unlikely to end very well for you.
If you have a VeraCrypt partition that they can detect, it makes you look like a spy. Lots of random data in unused sectors on your hard drive is a bad look if you're trying to convince the border agent you're not a spy.
If you have a plain old laptop with some mildly embarrassing information on it that's not encrypted, you might still be a spy, but they wouldn't be able to tell from the laptop itself.
If your decoy only lists 5GB of space on a 5TB drive, then it isn't a very good decoy.
This is intentional.
If you could prove that there wasn't more hidden data, then the incentives would be to torture you until you did that.
Since you can't, there is no incentive to reveal a further hidden volume, since the attackers will either keep torturing you or not, and revealing more will most likely not help you.
This exact topic was discussed in the Rubber Hose documentation that I read 20 years ago. I think this is an archive of the document I'm thinking of: https://web.archive.org/web/20100820175505/http://iq.org/~pr...
Of course if you really worry about such things you shouldn't be trusting the other people you are working with either...
That's a double edged sword though - imagine you give up, surrender the password and are then being asked to unlock a hidden volume, which you don't have.
1) they might not believe you, and
2) that’s still true even if the reason you don’t have a key is because you don’t actually have a secret encrypted partition — or whatever — to supply a decryption key for
So the best thing to do is avoid being in a situation where someone is allowed to do that in the first place.
I'm sure advanced configurations with well-crafted decoys and steganography can help combat that, but as we can see, encryption can only take you so far and it's only one element of the picture.
At this point setting up a secure connection to a device in a secure location is way easier than trying to protect your data against someone with physical access.
You can also get your collaborators to revoke access if you fear you might be 'compromised', although ultimately it's hard to protect a system against yourself.
Otherwise, no. When they have you they can just torture you to death for whatever reason or no reason at all.
Then you position your friends over multiple jurisdictions so that they cannot legally compel all of them to play along.
[0] https://en.wikipedia.org/wiki/Rubberhose_(file_system) [1] https://en.wikipedia.org/wiki/Deniable_encryption