Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

91–100 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#93

I missed the part where this document lists the vulnerabilities in TrueCrypt.

It says 'may', which is a responsible message if you're abandoning security software. Never know what the future holds; don't want to encourage people to rely on it if bugs will never be fixed.

Re: TrueCrypt suggesting migration to BitLocker?

#94

Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

[deleted]

Re: TrueCrypt suggesting migration to BitLocker?

#96
post #37

Earlier quoted context omitted.

On the other hand, SourceForge lists the project as having been created in 2004: http://sourceforge.net/projects/truecrypt/

The SF account could have been compromised too.

Certainly, it just makes it less suspect that it’s on SourceForge at all. (Unless SourceForge lets you rename projects? Then it could be an old placeholder project that’s been renamed to truecrypt.)

Re: TrueCrypt suggesting migration to BitLocker?

#97
post #70

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

If the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".

https://twitter.com/matthew_d_green/status/47174183672207360...

It doesn't appear related to the audit

Re: TrueCrypt suggesting migration to BitLocker?

#99

Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

Here's the source code diff https://www.alchemistowl.org/arrigo/truecrypt-7.1a-7.2.diff....

Re: TrueCrypt suggesting migration to BitLocker?

#100
post #64

Earlier quoted context omitted.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

A much simpler explanation is someone defaced the site around the same time a new release was coming out. Is there anything in the signed release package to corroborate what the site says?

Yes. See the sibling poster's image link. I also installed 7.2 in a VM and received the same warning. It also looks like I can't encrypt anything, just decrypt.
Post reply on HN