Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

71–80 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#71
post #9

So what was the point of raising money to audit TrueCrypt if they knew they would shut it down once XP was EOL? In fact why didn't they announce this earlier?

Maybe the result of the audit is that it's not secure?

But that's not what the audit found, and the guys who ran the audit are just as in the dark about this as we are, according to recent tweets.

Re: TrueCrypt suggesting migration to BitLocker?

#72

There's no way this is legit, but if it is, what other kind of cross-platform solution is available? I need to be able to encrypt/decrypt on all 3 major OSes.

Maybe EncFS [0]? Its Windows port is experimental, alas. I suppose it would be suitable if you were willing to make frequent backups. [0]: https://en.wikipedia.org/wiki/EncFS

There is a relatively recent audit[1] of EncFS with some damning results. I really wouldn't use it.

[1]: https://defuse.ca/audits/encfs.htm

Re: TrueCrypt suggesting migration to BitLocker?

#73

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Phase 2 of the audit hasn't started yet.

Re: TrueCrypt suggesting migration to BitLocker?

#74
post #40
post #38

Well, if red Times New Roman on a Sourceforge page says so...

http://truecrypt.org/ redirects there, too.

Tom has a point, though. The nature of the message (abandoning truecrypt rather than fixing it simply because XP is end-of-lifed?) and the unwillingness to fix it rather than post a dire message about its insecurity and recommend migrating to other solutions that don't have hidden volume functionality -- it suggests it's either very poorly handled, or a fake message.

It might be more likely that a dev got hacked, compromising the signing key, sourceforge project, and truecrypt.org site.

Re: TrueCrypt suggesting migration to BitLocker?

#75
post #40

Earlier quoted context omitted.

http://truecrypt.org/ redirects there, too.

Tom has a point, though. The nature of the message (abandoning truecrypt rather than fixing it simply because XP is end-of-lifed?) and the unwillingness to fix it rather than post a dire message about its insecurity and recommend migrating to other solutions that don't have hidden volume functionality -- it suggests it's either very poorly handled, or a fake message. It might be more likely that a dev got hacked, com…

We don't know much about the TC developers, do we? It's also possible that they're just really cavalier about this stuff, and that this is their response to the TC audit process ("stop bothering us about it and use something that's maintained").

Re: TrueCrypt suggesting migration to BitLocker?

#76
post #54

Earlier quoted context omitted.

I'm with you. This seems like an odd move, given that most likely only a minority of their users used XP for some time. Why haven't they been warning Windows Vista, 7 and 8 users to use Bitlocker for years (not to mention Mac OS X and Linux users)? Perhaps I just missed the warnings, but I am really puzzled. I suppose the developers could have just found a massive vulnerability (perhaps they're doing their own audit…

If you scroll to the bottom, you'll find this link: http://truecrypt.sourceforge.net/OtherPlatforms.html

I saw that. It's just that taking this line at face value, it's not clear why they would port TrueCrypt to Linux and Mac OS X or suggest that people using later versions of Windows should use TrueCrypt:

>The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP.

Re: TrueCrypt suggesting migration to BitLocker?

#77
post #70

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

If the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".

Yes. This would be just about the worst way to announce and make recommendations. Looks like defacement to me.

Re: TrueCrypt suggesting migration to BitLocker?

#79

Earlier quoted context omitted.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

If this is a hack, then the truecrypt.org site (or dns) and sourceforge site are both compromised, suggesting a dev got hacked who would have had access to both, and perhaps the TC signing key as well (not everyone practices good signing key hygiene, like keeping it offline, even for important software projects). Even if it's a legit announcement, I wouldn't run that 7.2 binary. Anyone running truecrypt already has t…

SourceForge recently forced their users to change their passwords [1] because of an attack on their infrastructure [2]. Pure speculation but I'm not sure if that had anything to do with this?

[1] http://sourceforge.net/blog/sourceforge-net-global-password-...

[2] http://sourceforge.net/blog/sourceforge-net-attack/

Re: TrueCrypt suggesting migration to BitLocker?

#80

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Also might be coming from lack of donations. I remember that button becoming more and more prominent lately...
Post reply on HN