German BSI withholds Truecrypt security report
1–10 of 86 posts
Re: German BSI withholds Truecrypt security report
#2> Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22
Re: German BSI withholds Truecrypt security report
#3I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the developers and many state entities that use the software and its successor.
The BSI is sadly often toothless when it comes to actually enforcing security standards on federal entities but to see them not even trying to educate on such matters, when they clearly know better, squanders a lot of trust one may have in them.
Re: German BSI withholds Truecrypt security report
#4Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22
Re: German BSI withholds Truecrypt security report
#5> The BSI knew all that. [...]
> The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published.
This is looking pretty terrible for Truecrypt. It means they ignored a vulnerability report and kept the vulnerabilities around for five years.
Re: German BSI withholds Truecrypt security report
#6Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22
They all have "geschwärzt" (blackened) in the file name, but it looks like only some author's name (and maybe working group name) have been removed -- I've scrolled through a few of these files, and didn't find anything else that might have been removed.
Re: German BSI withholds Truecrypt security report
#7It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them. I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the d…
The BSI actually did communicate the findings of the report to the TrueCrypt developers in 2010, which the developers ignored:
> The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published.
(From page 2 of the article)
Re: German BSI withholds Truecrypt security report
#8> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…
Re: German BSI withholds Truecrypt security report
#9It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them. I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the d…
> since this information would be relevant to the developers and many state entities that use the software and its successor. The BSI actually did communicate the findings of the report to the TrueCrypt developers in 2010, which the developers ignored: > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the result…
Re: German BSI withholds Truecrypt security report
#10> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…