Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

51–60 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#52

Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

If their site/dns/whatever was compromised than there's no way you can trust the GPG signature at this point. I'll await a proper press release.

Re: TrueCrypt suggesting migration to BitLocker?

#53

I missed the part where this document lists the vulnerabilities in TrueCrypt.

exactly. This makes no sense. Security Audit. XP support ended in April not May. Also Truecrypt is open source... when it is not secure why not fix it? And why care of XP support? There are more open questions than answers.

Re: TrueCrypt suggesting migration to BitLocker?

#54
post #6

I'm really confused. Which isn't unusual really, but in this case I think it is understandable.

I'm with you. This seems like an odd move, given that most likely only a minority of their users used XP for some time. Why haven't they been warning Windows Vista, 7 and 8 users to use Bitlocker for years (not to mention Mac OS X and Linux users)? Perhaps I just missed the warnings, but I am really puzzled. I suppose the developers could have just found a massive vulnerability (perhaps they're doing their own audit…

If you scroll to the bottom, you'll find this link: http://truecrypt.sourceforge.net/OtherPlatforms.html

Re: TrueCrypt suggesting migration to BitLocker?

#55

Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

If this is a hack, then the truecrypt.org site (or dns) and sourceforge site are both compromised, suggesting a dev got hacked who would have had access to both, and perhaps the TC signing key as well (not everyone practices good signing key hygiene, like keeping it offline, even for important software projects).

Even if it's a legit announcement, I wouldn't run that 7.2 binary. Anyone running truecrypt already has truecrypt, right? I don't know why they'd release a new version at the same time as such a dire and panic-inducing announcement.

Re: TrueCrypt suggesting migration to BitLocker?

#56

Earlier quoted context omitted.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.

Well, the thing is though, it's not that they were hosting users' data. It's not like they would be forced to provide the contents of users' communication.

I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...

Re: TrueCrypt suggesting migration to BitLocker?

#58
post #43

8 hours ago on the IndieGoGo TrueCrypt Audit page [1] > p.s. We hope to have some big announcements this week, so stay tuned. [1] https://www.indiegogo.com/projects/the-truecrypt-audit#activ...

Although Kenn White, who wrote that message, has no idea what's going on [1]

> .@FiloSottile @matthew_d_green no idea. It's doing a 301 perm to a static pg @ SF, now blocked. Possibly compromised. pic.twitter.com/g5tSFUuXzu

[1] https://twitter.com/kennwhite/status/471740840478797824

Re: TrueCrypt suggesting migration to BitLocker?

#59
In order of likelihood:

    * Defaced site, timed to screw up a big announcement
    * Rogue content maintainer
    * Phase II of audit turned up something rather bad
      (edit: NO - see tptacek below)
edit: Variations on "developer forced to do this" (cf simmerian's comment):

    * Developer was big brother all along and they are shutting it down
    * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly)
    * Legally or otherwise compelled to compromise source code,
      dev complies and/or nukes project from orbit
The last alternative would be suggested in part by the strange content of the page, assuming it is legit from the developer: Normally I'd expect at least something like "there's a major vuln that is unfixable and we'll disclose formally in a week/two, migrate now.".
Post reply on HN