TrueCrypt 7.0 released, now with hardware-accelerated AES support
1–10 of 20 posts
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#2Example supported processors include (select) ones from the i5/i7 desktop and mobile Intel processors, but anything which has that instruction set should work, apparently.
(from: "hardware acceleration" chapter, link near the top of the article)
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#3For FOSS-champions thing is that TrueCrypt developers are sneaky and don't accept contributions, so that in practice there is little outside control, and "given enough eyeballs are bugs are shallow" doesn't quite work.
For technical users, admins and frugal geeks TrueCrypt hides several unpleasant surprises, such as the encryption being undoable without a huge spare disk.
For casual users interface is cumbersome and counter-intuitive at times. It's almost as if developers have never considered usage scenarios. You have to type your passwords more often than strictly necessary, and sometimes you have to remember to do it, with risk of losing your data.
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#4There are several significant problems with TrueCrypt. Somehow, they fall into different domains, so for most users only one of them really matters. For FOSS-champions thing is that TrueCrypt developers are sneaky and don't accept contributions, so that in practice there is little outside control, and "given enough eyeballs are bugs are shallow" doesn't quite work. For technical users, admins and frugal geeks TrueCry…
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#5There are several significant problems with TrueCrypt. Somehow, they fall into different domains, so for most users only one of them really matters. For FOSS-champions thing is that TrueCrypt developers are sneaky and don't accept contributions, so that in practice there is little outside control, and "given enough eyeballs are bugs are shallow" doesn't quite work. For technical users, admins and frugal geeks TrueCry…
Is there any real alternative?
(If you look at Wikipedia's crypto-disk-software comparision page, http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_s..., you'll see that dm-crypt/cryptsetup/LUKS has pretty much all the features you would care about. Hidden containers would be nice, though.)
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#6There are several significant problems with TrueCrypt. Somehow, they fall into different domains, so for most users only one of them really matters. For FOSS-champions thing is that TrueCrypt developers are sneaky and don't accept contributions, so that in practice there is little outside control, and "given enough eyeballs are bugs are shallow" doesn't quite work. For technical users, admins and frugal geeks TrueCry…
If you're talking about an encrypted file container on a USB stick, the same problems exist with other encryption software. But I only remember typing in my password when mounting one, I'm not sure where it's asking you for your password over and over.
If you want a USB stick with decent usability, spend 99 bucks on an ironkey, and you'll get real hardware encryption as well.
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#7There are several significant problems with TrueCrypt. Somehow, they fall into different domains, so for most users only one of them really matters. For FOSS-champions thing is that TrueCrypt developers are sneaky and don't accept contributions, so that in practice there is little outside control, and "given enough eyeballs are bugs are shallow" doesn't quite work. For technical users, admins and frugal geeks TrueCry…
They accept contributions, you can even take the source and fork it. The only thing you can't do is call your version with added rootkit "Truecrypt"
System disk encryption in place is possibe and undoable. Data disks - I don't want to be able to do/undo this in place, I want them properly wiped.
You have to type in the passwd once to mount the disk? If you want to mount multiple disks with the same passwd (!!!) it will cache it
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#8There are several significant problems with TrueCrypt. Somehow, they fall into different domains, so for most users only one of them really matters. For FOSS-champions thing is that TrueCrypt developers are sneaky and don't accept contributions, so that in practice there is little outside control, and "given enough eyeballs are bugs are shallow" doesn't quite work. For technical users, admins and frugal geeks TrueCry…
If you use full disk encryption, it'll encrypt/decrypt on the fly, no extra hard drive needed. Type in password when you boot and you're done. If you're talking about an encrypted file container on a USB stick, the same problems exist with other encryption software. But I only remember typing in my password when mounting one, I'm not sure where it's asking you for your password over and over. If you want a USB stick…
Perhaps, or perhaps they just XOR your data with your passwd like a certain tape maker did for their super hardware AES mil-spec encryption.
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#9There are several significant problems with TrueCrypt. Somehow, they fall into different domains, so for most users only one of them really matters. For FOSS-champions thing is that TrueCrypt developers are sneaky and don't accept contributions, so that in practice there is little outside control, and "given enough eyeballs are bugs are shallow" doesn't quite work. For technical users, admins and frugal geeks TrueCry…
Edit: This is all common knowledge and has been for a few years. Wikipedia has all the details. The Czech Republic connection with the Trademark, the anonymous/unnamed developers, etc. The new (as of this year) mailing address in the US, the fake domain name registration, etc.
One last edit: TrueCrypt is probably fine protection against common thieves, but enough bits may have been knocked off of it to make it "acceptable" for export. If I was a Russian Spy, I would not touch it with a ten foot pole.
Re: TrueCrypt 7.0 released, now with hardware-accelerated AES support
#10Earlier quoted context omitted.
If you use full disk encryption, it'll encrypt/decrypt on the fly, no extra hard drive needed. Type in password when you boot and you're done. If you're talking about an encrypted file container on a USB stick, the same problems exist with other encryption software. But I only remember typing in my password when mounting one, I'm not sure where it's asking you for your password over and over. If you want a USB stick…
>ironkey, and you'll get real hardware encryption as well. Perhaps, or perhaps they just XOR your data with your passwd like a certain tape maker did for their super hardware AES mil-spec encryption.
https://www.ironkey.com/usb-flash-drive-flaw-exposed
Of course, like anything, they could have other unknown vulnerabilities. But like they say in the video on that link, they're a security company that makes a storage product, opposed to a storage company making a security product.