Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

81–90 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#81

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Also might be coming from lack of donations. I remember that button becoming more and more prominent lately...

That would not result in a message of "True Crypt Is Not Secure!!!!" in bold red. Seems to be geared towards frightening people.

I concur -- likely an elaborate website deface.

Re: TrueCrypt suggesting migration to BitLocker?

#83
post #75

Earlier quoted context omitted.

Tom has a point, though. The nature of the message (abandoning truecrypt rather than fixing it simply because XP is end-of-lifed?) and the unwillingness to fix it rather than post a dire message about its insecurity and recommend migrating to other solutions that don't have hidden volume functionality -- it suggests it's either very poorly handled, or a fake message. It might be more likely that a dev got hacked, com…

We don't know much about the TC developers, do we? It's also possible that they're just really cavalier about this stuff, and that this is their response to the TC audit process ("stop bothering us about it and use something that's maintained").

Certainly possible, although this from the audit web page doesn't sound like that would be a big problem:

"Wed, Oct 24, 2013: We have made contact with the TrueCrypt development team. They have stated a commitment to a thorough, independent security audit and cryptanalysis of the code."

Re: TrueCrypt suggesting migration to BitLocker?

#84
post #73

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Phase 2 of the audit hasn't started yet.

Seems to point towards compromised SF account.

Re: TrueCrypt suggesting migration to BitLocker?

#85

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

NSA is obviously in on it. Who else would recommend using holy-bug-riddled proprietary-back-doored-on-purpose encryption software? ;-P

Re: TrueCrypt suggesting migration to BitLocker?

#86
post #75

Earlier quoted context omitted.

Tom has a point, though. The nature of the message (abandoning truecrypt rather than fixing it simply because XP is end-of-lifed?) and the unwillingness to fix it rather than post a dire message about its insecurity and recommend migrating to other solutions that don't have hidden volume functionality -- it suggests it's either very poorly handled, or a fake message. It might be more likely that a dev got hacked, com…

We don't know much about the TC developers, do we? It's also possible that they're just really cavalier about this stuff, and that this is their response to the TC audit process ("stop bothering us about it and use something that's maintained").

True. Security announcements have been botched in the past, for all sorts of reasons, not that you have any experience with that, of course. But what does XP being EOL'd have to do with anything? That and the blithe recommendation to use other solutions, even though they don't have hidden volume functionality which is a main selling point of TC, is what changed my mind, from thinking this is probably a legit mishandled disclosure, to thinking it's probably fake.

On the other hand, as pointed out in other subthreads, if the devs are tired of maintaining it, this could be a legit, unappreciated-developer version of a temper tantrum. Nobody seems to know (yet).

Re: TrueCrypt suggesting migration to BitLocker?

#88

Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.

Matthew Green (@matthew_d_green) was involved in the audit. Follow him for what's what.

Re: TrueCrypt suggesting migration to BitLocker?

#89
post #73

Earlier quoted context omitted.

Phase 2 of the audit hasn't started yet.

Seems to point towards compromised SF account.

There's a new binary that recommends moving to BitLocker during install, and the signature matches.

Edit: with a new, compromised key.

Re: TrueCrypt suggesting migration to BitLocker?

#90
post #81

Earlier quoted context omitted.

Also might be coming from lack of donations. I remember that button becoming more and more prominent lately...

That would not result in a message of "True Crypt Is Not Secure!!!!" in bold red. Seems to be geared towards frightening people. I concur -- likely an elaborate website deface.

As irrational it may be, I've seen people writing something like that out of frustrations...

I don't think any legit organization would do that, but what if it's maintained by a small team or even individual -- I don't think I've ever seen a single face of TrueCrypt developers out there...

Post reply on HN