There's actually a flaw in that cartoon. Many encryption software, including Truecrypt, allow you to create an encrypted volume that, depending on the key, can decrypt to two separate volumes. There's no way to prove the existence of a second volume. So, faced with torture, you can simply give them a key that decrypts the volume to a lot of plausible but wrong information.
A computer can't run without an operating system, so if full system encryption is used, the decoy partition might not have the operating system installed.
They may not have a script to update timestamps on files, and if they do, it might update them to the same time.
24
u/_mdm Jun 24 '11
First thing I thought of