This is only half-true. Any secure encryption is going to result in ciphertext that is indistinguishable from random data.
In cases where the ciphertext is designated by a header or file format, then it's trivial to know that something is encrypted. Then there are cases where we can try to forensically determine that there's encrypted data via the existence of an encryption tool (e.g. VeraCrypt).
If you wipe a disk with random data, for example, then it would be relatively difficult to determine whether or not the disk is encrypted (implying that there are no headers on it). In fact, one method of wiping disks is to generate a random encryption key and encrypt a stream from /dev/zero to fill the disk (https://wiki.archlinux.org/index.php/Dm-crypt/Drive_preparat...).
This tool is making use of a VeraCrypt hidden volume which is a rather really interesting application of plausible deniability in cryptography. Essentially, this let's you have two volumes where both are encrypted, but each has a different key. In this setup, you'd put some files on one of the volumes to make it appear that it's your "used" volume. On the other "hidden" volume, you'd place the real files you want to keep safe.
In a case where the government is demanding that you release your encryption keys, you would give up the keys to the "fake" volume. Unless you divulge the keys to the "real" volume, the attackers wouldn't necessarily know that it exists.
Unless there's evidence of you using one (maybe chat logs or google searches asking for help on using it, for example), there's no reason for anyone to suspect you use it.
The VeraCrypt documentation explains the technical details (https://www.veracrypt.fr/en/Hidden%20Volume.html) well enough.
A new SSD with very little data in the filesystem isn't going to have many, many sectors filled with random bytes. They're going to be blank instead.
A used drive will have free sectors (not used by the filesystem) containing unencrypted contents of old files that have since been deleted or something. This is also not random data. Chunks of movies, pictures, applications and music will be identifiable, easily.
Yes, and that is suspicious. Random data is suspicious.
But from the authorities' point of view, they will beat you until they're convinced you don't have anything of interest you can give up. That could last quite a while...
There are legitimate reasons for wiping data...can't believe we're having this discussion, here of all places.
We're just talking about drawing attention to yourself from governmental agencies that probably don't have your well-being as their highest concern.
Using state-of-the-art encryption to keep your files safe is good. But if it leaves any evidence that you are indeed using encryption, you are potentially drawing attention to yourself. And people should be aware of that.
If you wanted to hide data in an encrypted partition that looks like random data, that's not going to work.
While that's technically true it feels a bit like a moot point because if you have random data that cannot be attributed to any other application (such as large volumes of randomness) then it's a reasonable conclusion that you've just detected an encrypted volume.
> In a case where the government is demanding that you release your encryption keys, you would give up the keys to the "fake" volume. Unless you divulge the keys to the "real" volume, the attackers wouldn't necessarily know that it exists.
Unless they inspect the storage properties (either physically or how it registers itself on the host) and see that it's a 1TB drive with only a 500GB mountable volume. Again, it wouldn't be a forgone conclusion that the individual has other hidden volumes but it would be suspicious enough to warrant further investigation / interrogation.
As always though, it really depends on the risk level you're trying to protect yourself against.
It's possible Tor and Tails is dangerous software to use in certain states. But if they can safely use it, it's here for them.
I am not sure what you mean here - properly encrypted data is indistinguishable from random data ...