Live data from Hacker News

German BSI withholds Truecrypt security report

golem.de

1–10 of 86 posts

Re: German BSI withholds Truecrypt security report

#2
Note, the title is no longer accurate. There's an update at the end of the article, along with a download link:

> Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22

Re: German BSI withholds Truecrypt security report

#3
It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them.

I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the developers and many state entities that use the software and its successor.

The BSI is sadly often toothless when it comes to actually enforcing security standards on federal entities but to see them not even trying to educate on such matters, when they clearly know better, squanders a lot of trust one may have in them.

Re: German BSI withholds Truecrypt security report

#4
post #2

Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22

Either they had to do that, or they had to be ready for the barrage of incoming requests for the documents.

Re: German BSI withholds Truecrypt security report

#5
> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...]

> The BSI knew all that. [...]

> The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published.

This is looking pretty terrible for Truecrypt. It means they ignored a vulnerability report and kept the vulnerabilities around for five years.

Re: German BSI withholds Truecrypt security report

#6
post #2

Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22

The documents seem to be available here: https://fragdenstaat.de/anfrage/untersuchungen-zum-verschlus...

They all have "geschwärzt" (blackened) in the file name, but it looks like only some author's name (and maybe working group name) have been removed -- I've scrolled through a few of these files, and didn't find anything else that might have been removed.

Re: German BSI withholds Truecrypt security report

#7

It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them. I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the d…

> since this information would be relevant to the developers and many state entities that use the software and its successor.

The BSI actually did communicate the findings of the report to the TrueCrypt developers in 2010, which the developers ignored:

> The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published.

(From page 2 of the article)

Re: German BSI withholds Truecrypt security report

#8
post #5

> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…

Truecrypt has been abandoned for ~seven years or so.

Re: German BSI withholds Truecrypt security report

#9
post #7

It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them. I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the d…

> since this information would be relevant to the developers and many state entities that use the software and its successor. The BSI actually did communicate the findings of the report to the TrueCrypt developers in 2010, which the developers ignored: > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the result…

Yes, but they neglected to tell the veracrypt developers once truecrypt stopped being developed. Though they also do know many municipalities using both applications. They should have told the veracrypt developers and advised the municipalities to switch to the newer version. And the whole argument about the information being outdated by then when both are clearly in use seems negligent of their duties.

Re: German BSI withholds Truecrypt security report

#10
post #5

> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…

You should no longer use TrueCrypt, if you want an alternative I suggest https://www.veracrypt.fr
Post reply on HN