cofferFS vs. VeraCrypt
Both put everything in one file. They differ in sizing, privileges and scope.
VeraCrypt is the successor to TrueCrypt and the tool most people reach for when they want an encrypted container file. cofferFS covers the same basic idea — one file that holds everything — but makes different trade-offs.
The short version
Use VeraCrypt if you need Windows or macOS, a graphical interface, or hidden volumes. Use cofferFS if you are on Linux, want the container to grow with your data instead of being sized up front, and want to mount without root.
Side by side
| cofferFS | VeraCrypt | |
|---|---|---|
| Container size | grows as you write | fixed at creation |
| Mounting | FUSE, no root | needs root or admin rights |
| Platforms | Linux | Windows, macOS, Linux |
| Interface | command line | GUI and command line |
| Hidden volumes | no | yes |
| Cipher | AES-256-CBC per page, HMAC-SHA512 | AES, Serpent, Twofish, cascades |
| Reclaiming space | coffer compact, manual |
shrink is involved |
| Throughput | ~33 MB/s writing (measured) | close to disk speed |
Where VeraCrypt is the better choice
You use more than Linux. cofferFS is Linux-only and will stay that way. VeraCrypt containers open on Windows and macOS too, which matters if the file travels on a USB stick between machines.
You need plausible deniability. VeraCrypt's hidden volumes let you reveal one password while a second volume stays invisible inside the free space of the first. cofferFS has nothing comparable and does not try to.
You move large files constantly. VeraCrypt works at the block level and reaches close to disk speed. cofferFS writes through per-128 KiB SQL statements; a benchmark over 95,000 files and about 12 GB reached 260 files per second and 33 MB/s, against 4027 files per second on plain ext4. For documents, photos and source trees that is unnoticeable. For routinely shuffling multi-gigabyte video files it is not.
You want a graphical interface. VeraCrypt has one. cofferFS does not.
Where cofferFS is the better choice
You don't know how large it will get. A VeraCrypt volume is sized when
you create it. Guess too small and you create a second one; guess too large
and the space is gone from the start. A cofferFS container starts tiny and
extends as you write. --max-size sets a ceiling if you want one.
You don't want to type a root password to open your own files. FUSE
mounts belong to the user who created them, so coffer mount needs no
privileges at all. On Linux, VeraCrypt needs root to attach its volume.
You want metadata hidden too. Everything — file contents, names, directory structure, sizes — lives as rows in one encrypted SQLCipher database. There is no file layout to observe from outside.
You want it in a script. cofferFS is a single command-line binary with
registered aliases, --password-command for a password manager, and
optional idle auto-unmount. It fits into systemd units and backup jobs
without a GUI in the way.
Honest limitations
By default cofferFS does not enforce the Unix permissions it stores — the
password is the only gate, which matches how an encrypted container is
normally used. coffer mount --enforce-permissions turns the stored mode,
owner and group into real checks if you want them. One container is mounted
by one process at a time. Deleted space comes back only when you run
coffer compact. The technical reference spells all of
this out.
Source of this page: compare/veracrypt.md in the cofferFS repository.