Plausible deniability is simply not a useful defense against someone that would decide to torture you for a mere suspicion.
Plausible deniability is simply not a useful defense against someone that would decide to torture you for a mere suspicion.
It is also worth pointing out that the number of passwords you deny having is completely irrelevant. You could claim to have forgotten the one password you use for non-deniable encryption and the effect would be the same (and your story is equally plausible). It is much easier to claim to have forgotten one password than to try to maintain an innocent partition, so you might as well just do that.
I never thought I'd feel the need to offer this as serious advice, rather than just a novelty toy, but SpyCoin is a way to get data across borders.
I have a pound coin and it's pretty good.
- Tomás de Torquemada, 2011
Is it possible to hide the fact that you have a Truecrypt volume? Or are there always headers or signatures that give it away?
You can't really hide the fact that you're using encryption, because it doesn't really look like anything else apart from random data & people don't usually go around piping /dev/random into large files for no good reason. Compressed data is high entropy, but can be decompressed to something lower entropy, so you can easily eliminate png filess, zipped files etc.
But if you had truecrypt installed and 1 drive that wasn't formatted... Yea
Btw: there's no explicit restriction on N-level deep of hidden volumes, but TC won't automatically make the outer ones read-only.