> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…
Truecrypt has been abandoned for ~seven years or so.
German BSI withholds Truecrypt security report
11–20 of 86 posts
Re: German BSI withholds Truecrypt security report
#12> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…
Re: German BSI withholds Truecrypt security report
#13Re: German BSI withholds Truecrypt security report
#14It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them. I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the d…
Perhaps BSI was merely attempting to provide such a service for free.
Re: German BSI withholds Truecrypt security report
#15"... in the simplest case a user can mount a Truecrypt volume that contains a file with suid root permission that will open a shell. Golem.de was able to replicate this scenario in a current version of Veracrypt."
Re: German BSI withholds Truecrypt security report
#16Re: German BSI withholds Truecrypt security report
#17Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22
Either they had to do that, or they had to be ready for the barrage of incoming requests for the documents.
Or more precisely, towards an organizational variety of Hanlon's Razor, where stupidity takes the form of the organizational failure mode of underlings not being authorized to do what would have been the right thing.
Curiously, a less colloquial formulation of Hanlon's Razor would replace stupidity with incompetence and this, when translated to German contains a hint of a precisely matching double entendre: in German, "Kompetenz" is used for two separate things. For being able to (like in English) and being authorized to. It's not a full double entendre because the negated form "Inkompetenz" is exclusive to the mental ability, just like the English counterpart, but what's a good aphorism without subtle extra layers?
Re: German BSI withholds Truecrypt security report
#18> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…
But did the VeraCrypt developers know about it?
Re: German BSI withholds Truecrypt security report
#19Earlier quoted context omitted.
> since this information would be relevant to the developers and many state entities that use the software and its successor. The BSI actually did communicate the findings of the report to the TrueCrypt developers in 2010, which the developers ignored: > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the result…
Yes, but they neglected to tell the veracrypt developers once truecrypt stopped being developed. Though they also do know many municipalities using both applications. They should have told the veracrypt developers and advised the municipalities to switch to the newer version. And the whole argument about the information being outdated by then when both are clearly in use seems negligent of their duties.
Re: German BSI withholds Truecrypt security report
#20Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22
Either they had to do that, or they had to be ready for the barrage of incoming requests for the documents.