cofferFS

cofferFS vs. LUKS

Different layers, not competitors. Most setups want both.

LUKS is the standard way to encrypt storage on Linux — it is what the installer offers when it asks whether to encrypt the disk. Comparing it to cofferFS is comparing two different layers rather than two competing tools.

The short version

LUKS encrypts a block device: a partition, a logical volume, or a loop file. cofferFS encrypts a container that behaves like a folder. Most people want both, for different things.

Side by side

cofferFS LUKS
Layer file system over FUSE block device via dm-crypt
Runs in user space the kernel
Mounting no root root required
Size grows as you write fixed; resizing needs LVM or care
Throughput ~33 MB/s writing (measured) near native disk speed
Covers the whole system no yes, including swap and root
Per-user containers yes, trivially awkward
Setup coffer create partitioning, cryptsetup, fstab

Where LUKS is the better choice

You want the whole machine encrypted. LUKS covers the root filesystem, swap and temporary files. A stolen laptop gives up nothing. cofferFS protects what you put inside the container and nothing else — your shell history, caches and /tmp stay in the clear.

Speed matters. dm-crypt runs in the kernel with hardware AES and reaches close to raw disk performance.

It's already there. Every mainstream distribution sets up LUKS during installation. There is nothing to add.

Where cofferFS is the better choice

You want one folder private, not the whole disk. LUKS is all or nothing at the device level. A cofferFS container is one file among your normal files, opened when you need it and closed when you don't — even on a machine whose disk is already LUKS-encrypted, which is a sensible combination rather than a contradiction.

No root. Creating and mounting a LUKS loop file means cryptsetup, losetup and a root password every time. coffer mount needs none of it, which matters on a work machine where you do not have those rights.

No size decision up front. A LUKS loop file is created at a fixed size; growing it later means resizing both the file and the filesystem inside it. A cofferFS container just grows.

It travels. One file you can copy to an external disk or a backup server, and coffer backup makes a consistent copy while it is mounted. A LUKS volume is tied to its device.

Using both

They are not alternatives. A reasonable setup is LUKS for the disk, so a stolen machine reveals nothing, and a cofferFS container inside your home directory for the documents that should stay closed even while you are logged in and working.

Source of this page: compare/luks.md in the cofferFS repository.