cofferFS vs. LUKS
Different layers, not competitors. Most setups want both.
LUKS is the standard way to encrypt storage on Linux — it is what the installer offers when it asks whether to encrypt the disk. Comparing it to cofferFS is comparing two different layers rather than two competing tools.
The short version
LUKS encrypts a block device: a partition, a logical volume, or a loop file. cofferFS encrypts a container that behaves like a folder. Most people want both, for different things.
Side by side
| cofferFS | LUKS | |
|---|---|---|
| Layer | file system over FUSE | block device via dm-crypt |
| Runs in | user space | the kernel |
| Mounting | no root | root required |
| Size | grows as you write | fixed; resizing needs LVM or care |
| Throughput | ~33 MB/s writing (measured) | near native disk speed |
| Covers the whole system | no | yes, including swap and root |
| Per-user containers | yes, trivially | awkward |
| Setup | coffer create |
partitioning, cryptsetup, fstab |
Where LUKS is the better choice
You want the whole machine encrypted. LUKS covers the root filesystem,
swap and temporary files. A stolen laptop gives up nothing. cofferFS
protects what you put inside the container and nothing else — your shell
history, caches and /tmp stay in the clear.
Speed matters. dm-crypt runs in the kernel with hardware AES and reaches close to raw disk performance.
It's already there. Every mainstream distribution sets up LUKS during installation. There is nothing to add.
Where cofferFS is the better choice
You want one folder private, not the whole disk. LUKS is all or nothing at the device level. A cofferFS container is one file among your normal files, opened when you need it and closed when you don't — even on a machine whose disk is already LUKS-encrypted, which is a sensible combination rather than a contradiction.
No root. Creating and mounting a LUKS loop file means cryptsetup,
losetup and a root password every time. coffer mount needs none of it,
which matters on a work machine where you do not have those rights.
No size decision up front. A LUKS loop file is created at a fixed size; growing it later means resizing both the file and the filesystem inside it. A cofferFS container just grows.
It travels. One file you can copy to an external disk or a backup
server, and coffer backup makes a consistent copy while it is mounted.
A LUKS volume is tied to its device.
Using both
They are not alternatives. A reasonable setup is LUKS for the disk, so a stolen machine reveals nothing, and a cofferFS container inside your home directory for the documents that should stay closed even while you are logged in and working.
Source of this page: compare/luks.md in the cofferFS repository.