Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

111–120 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#112

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Their mail server is on the same IP as truecrypt.org, and it's now rejecting mail.

Re: TrueCrypt suggesting migration to BitLocker?

#114
Sourceforge seems to have recently updated their password hashing algorithm, so that might hint at the cause of a compromise. Here's the body of the email sent to me on the 22nd:

  Greetings,
  
  To make sure we're following current best practices for security, we've
  made some changes to how we're storing user passwords. As a result, the
  next time you go to login to your SourceForge.net account, you will be
  prompted to change your password. Once this is done, your password will be
  stored more securely. We recommend that you do this at your earliest
  convenience by visiting the SourceForge website and logging in.
  
  And, as always, be vigilant about password security. Use a secure password,
  never include your password in an email, and don't click on links for
  unsolicited password resets.
  
  If you have any concerns about this, please contact SourceForge support at
  sfnet_ops@slashdotmedia.com
  
  Best regards,
  SourceForge Team
  
  ----------------------------------------------------------------------
  SourceForge.net has made this mailing to you as a registered user of
  the SourceForge.net site to convey important information regarding
  your SourceForge.net account or your use of SourceForge.net services.
  
  We make a small number of directed mailings to registered users each
  year regarding their account or data, to help preserve the security of
  their account or prevent loss of data or service access.
  
  If you have concerns about this mailing please contact our Support
  team per: http://sourceforge.net/support

Re: TrueCrypt suggesting migration to BitLocker?

#115
post #89

Earlier quoted context omitted.

Seems to point towards compromised SF account.

There's a new binary that recommends moving to BitLocker during install, and the signature matches. Edit: with a new, compromised key.

Is source still available? Can we check the commit tree for anything suspicious lately? Can someone compile it and check the hash against the 7.2 binary being offered?

Re: TrueCrypt suggesting migration to BitLocker?

#116

Earlier quoted context omitted.

Maybe EncFS [0]? Its Windows port is experimental, alas. I suppose it would be suitable if you were willing to make frequent backups. [0]: https://en.wikipedia.org/wiki/EncFS

There is a relatively recent audit[1] of EncFS with some damning results. I really wouldn't use it. [1]: https://defuse.ca/audits/encfs.htm

> damning results

They didn't seem that severe to me, they seemed pretty minor actually. Especially if your attack vector is solely a read attack rather than a read-write attack.

Which one got you worried?

Re: TrueCrypt suggesting migration to BitLocker?

#117
post #66

This is creepy as hell. No mention of why it's supposed to be not secure - it's an open source project so it would be easy to point to a specific vulnerability. All of this shortly after passing audit. There are detailed steps towards switching to supposedly secure closed-source solutions by companies known to be working closely with the NSA. Also, since when do open source projects suddenly decide they are not as go…

It doesn't matter why. If "we are now insecure" then the last thing you say is, "so please download these new versions, used only to decrypt your old files and nothing else." No we won't tell you what, if anything, was wrong, so you can make an informed decision.

Re: TrueCrypt suggesting migration to BitLocker?

#118
post #81

Earlier quoted context omitted.

Also might be coming from lack of donations. I remember that button becoming more and more prominent lately...

That would not result in a message of "True Crypt Is Not Secure!!!!" in bold red. Seems to be geared towards frightening people. I concur -- likely an elaborate website deface.

That's not what the message says, though.

> WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues

That is a perfectly reasonable thing to say if you are abandoning security software. Any issues discovered will not be fixed, so you should stop relying on this software for security.

Post reply on HN