The press will go along with the government and talk about you as a "hacker who is using sophisticated message hiding techniques to disguise their secret communications with conspirators." Even if you were just talking about dinner plans.
Technical solutions to lawfare are pointless.
I do understand what you're trying to refer to — to things like "you can't tell it was me who connected to that darknet market" / "but we can tell that your IP address originated a Tor connection, and we now consider that illegal in-and-of-itself, even if it wasn't you doing it but you were just acting as an exit node for others."
But again, we've spent a long time building various different cryptosystems that make different sets of guarantees that are useful in different situations. Tor is useful under one particular set of constraints, but that set of constraints is not "staying long-term under an oppressive regime that will arrest you for emitting Tor fingerprintable traffic."
For a cryptosystem that is useful under this use-case, see: Freenet. Or NNTP numbers groups. Or MixMaster.
(Though also, even Tor does work here, with modification. This is why Tor added bridges — precisely so that people in oppressed regimes could forward their traffic, in an innocuous-looking way, through bridge nodes hosted by people in non-oppressed regimes, where the IPs of these nodes are only handed out as needed to Tor users, one or two at a time, and so can't be blacklisted by country-level firewalls in advance.)
(I've read enough cyberpunk to be sufficiently prepared for this dark future.)
What's benefit to `steganography` and the current encryption tools, I'll admit I don't know a lot about steganography but I've always seen it as the receiver still needing the handshake.
The theoretical idea is that the information could be hidden in a random location, e.g. extracting every Nth bit, such that the information would be indistinguishable from random noise. In practice, both parties need to agree on the location, so it has the same flaw as 'perfect encryption' methods like a one-time-pad, you need to transfer information IRL.
One could make a case for a group/app using a custom scheme to add a layer of security until someone infiltrates the group / RE the app, but you'd get the same security by just encrypting everything with the same password.
That was my 'playground' conclusion too. It has to be clandestine to work.
> In practice, both parties need to agree on the location
That is still a key by another term..
> but you'd get the same security by just encrypting everything with the same password.
Right, it feels like just a level of obfuscation at that point. Ironically what I was interested in was encypted payloads that could be `called` when loaded. Involves a ridiculous amount of 0days, but the idea of opening an image and having your browser/os touched.. It's interesting given today's lifestyle.
Not if the obfuscated payload is encrypted using end to end methods. This way obfuscated layer starts to look like trash.
To decrypt such a message you need to seize the control over message receiving computer with user and no encryption has protection from this.