cofferFS

cofferFS vs. gocryptfs

The closest relative. One stores a tree, the other a single database.

gocryptfs is the closest relative to cofferFS: both mount through FUSE, both need no root, both are command-line tools for Linux. The difference is what sits on disk underneath.

The short version

gocryptfs encrypts a directory tree file by file. cofferFS puts everything into one encrypted database file. That single choice drives almost every other difference between them.

Side by side

cofferFS gocryptfs
On disk one container file a directory of encrypted files
File count visible no yes
File sizes visible no approximately
Directory structure visible no yes
Mounting FUSE, no root FUSE, no root
Cipher AES-256-CBC per page, HMAC-SHA512 AES-256-GCM, scrypt
Throughput ~33 MB/s writing (measured) considerably faster
Cloud sync whole file re-uploads per-file, sync-friendly
Reverse mode no yes

Where gocryptfs is the better choice

You sync to cloud storage. This is the big one. gocryptfs stores one encrypted file per plaintext file, so changing one document re-uploads one document. A cofferFS container is a single file — many sync clients will re-upload a large part of it after a small change. If your files live in Dropbox, Nextcloud or Syncthing, gocryptfs fits that model and cofferFS fights it.

Throughput matters. gocryptfs passes file data through with far less overhead than per-128 KiB SQL statements against an encrypted database.

You want reverse mode. gocryptfs can present an encrypted view of a plaintext directory, which makes encrypted backups of existing data straightforward. cofferFS has no equivalent.

You need the data readable without the tool. A gocryptfs directory can be decrypted by any compatible implementation. A cofferFS container needs coffer — or at least SQLCipher and knowledge of the schema.

Where cofferFS is the better choice

Metadata should stay private. gocryptfs encrypts file names, but the shape of your data is visible to anyone who sees the directory: how many files there are, roughly how big each one is, how deeply nested the tree goes, and when each file changed. For a folder of legal documents or medical records, that shape alone can be revealing. In cofferFS the entire structure is rows inside one encrypted database — an observer sees a single file and its total size.

One file is easier to handle. Moving, archiving or backing up means touching one object rather than a tree of thousands. coffer backup makes a consistent copy even while the container is mounted.

No size decision up front, and space comes back. The container grows as you write, and coffer compact returns space after large deletions.

Choosing between them

Ask where the files live. Synced to a cloud service, gocryptfs is the better fit. Sitting on your own disk, where you would rather not advertise how many documents you keep and how large they are, cofferFS is.

Source of this page: compare/gocryptfs.md in the cofferFS repository.