Things are banned, implicitly, only if you get caught, so I don't think this is a philosophical argument.
The final cyphertext of an encryption system should be indistinguishable from noise - the less random the output looks, the more information an attacker gains.
The output of your 512-bit encryption should therefore look like noise already. Converting noise to noise should therefore result, predictably, in more noise. So I'm going to say "no, you can't tell".
Proper encryption, maximum compression, and random bytes are all indistinguishable, as they have maximum entropy.
I only failed 9th grade three times, so feel free to correct me.
without additional information!
I can prove to you that you're seeing an encrypted message by giving you the decryption key, and I can prove to you that you're seeing compression by giving you the decompression algorithm.
However, there is no way to prove that random bytes are _really_ random.
well of course, because the opposite is true, any string of bytes can by XOR'd to something meaningful.
Instead of auditing the code/file format, it may be less error prone to just re-encrypt the entire file thereby hiding any metadata that the encryption program attaches.
And that is before you get into less than perfect encryption.
In cryptanalysis it is normally assumed that the attacker knows the algorithm and encryption parameters aside the key.
I’m not interesting so not an issue for me, but I would also assume that they can break much more than this and wouldn’t actually reveal their limit in such a policy. Kind of like how your boss quadruples your time estimate. If their policy says nothing over 256, then they likely have capability for more.
But I’d expect that usually these pass phrases can be any length as they are all getting beaten out of us when needed.
There are several degrees of interest. Essentially they are interested in everyone trying to hide anything from them and they probably understand people of real danger to them will do their best to look ordinary and mediocre.
> If their policy says nothing over 256, then they likely have capability for more.
Sounds reasonable but breaking 512 obviously is much harder than 256 and will take significant time and resources they don't really want to waste. They will rather force you to reveal the key and only break 512+ if they can't easily reach you physically or identify you in the first place.
This can be done covertly or overtly, the former being plain old spying, the latter may be as simple as detaining the people involved and seizing computers (especially in China...).
Note that there's a huge difference between "until proven guilty" and "until considered suspect": suddenly obscurity cannot be shrugged off at all, quite the opposite.