cofferFS

cofferFS vs. VeraCrypt

Both put everything in one file. They differ in sizing, privileges and scope.

VeraCrypt is the successor to TrueCrypt and the tool most people reach for when they want an encrypted container file. cofferFS covers the same basic idea — one file that holds everything — but makes different trade-offs.

The short version

Use VeraCrypt if you need Windows or macOS, a graphical interface, or hidden volumes. Use cofferFS if you are on Linux, want the container to grow with your data instead of being sized up front, and want to mount without root.

Side by side

cofferFS VeraCrypt
Container size grows as you write fixed at creation
Mounting FUSE, no root needs root or admin rights
Platforms Linux Windows, macOS, Linux
Interface command line GUI and command line
Hidden volumes no yes
Cipher AES-256-CBC per page, HMAC-SHA512 AES, Serpent, Twofish, cascades
Reclaiming space coffer compact, manual shrink is involved
Throughput ~33 MB/s writing (measured) close to disk speed

Where VeraCrypt is the better choice

You use more than Linux. cofferFS is Linux-only and will stay that way. VeraCrypt containers open on Windows and macOS too, which matters if the file travels on a USB stick between machines.

You need plausible deniability. VeraCrypt's hidden volumes let you reveal one password while a second volume stays invisible inside the free space of the first. cofferFS has nothing comparable and does not try to.

You move large files constantly. VeraCrypt works at the block level and reaches close to disk speed. cofferFS writes through per-128 KiB SQL statements; a benchmark over 95,000 files and about 12 GB reached 260 files per second and 33 MB/s, against 4027 files per second on plain ext4. For documents, photos and source trees that is unnoticeable. For routinely shuffling multi-gigabyte video files it is not.

You want a graphical interface. VeraCrypt has one. cofferFS does not.

Where cofferFS is the better choice

You don't know how large it will get. A VeraCrypt volume is sized when you create it. Guess too small and you create a second one; guess too large and the space is gone from the start. A cofferFS container starts tiny and extends as you write. --max-size sets a ceiling if you want one.

You don't want to type a root password to open your own files. FUSE mounts belong to the user who created them, so coffer mount needs no privileges at all. On Linux, VeraCrypt needs root to attach its volume.

You want metadata hidden too. Everything — file contents, names, directory structure, sizes — lives as rows in one encrypted SQLCipher database. There is no file layout to observe from outside.

You want it in a script. cofferFS is a single command-line binary with registered aliases, --password-command for a password manager, and optional idle auto-unmount. It fits into systemd units and backup jobs without a GUI in the way.

Honest limitations

By default cofferFS does not enforce the Unix permissions it stores — the password is the only gate, which matches how an encrypted container is normally used. coffer mount --enforce-permissions turns the stored mode, owner and group into real checks if you want them. One container is mounted by one process at a time. Deleted space comes back only when you run coffer compact. The technical reference spells all of this out.

Source of this page: compare/veracrypt.md in the cofferFS repository.