Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

131–140 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#132
post #89

Earlier quoted context omitted.

Seems to point towards compromised SF account.

There's a new binary that recommends moving to BitLocker during install, and the signature matches. Edit: with a new, compromised key.

Project on SF is still available if you have a direct link:

http://sourceforge.net/projects/truecrypt/files/TrueCrypt/

http://sourceforge.net/projects/truecrypt/?source=navbar

http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...

Odd, 6 hours ago someone updated the TruCrypt-key.asc files, then 3 hours later posted all the new binaries.

Also odd is whoever posted the new binaries completely yanked all the previous ones, leaving only the new and questionable binary available for download.

hmm...

Re: TrueCrypt suggesting migration to BitLocker?

#133

I just came across this on Twitter: https://github.com/warewolf/truecrypt/compare/master...7.2 This is supposedly the commit for the 7.2 release. Just looks like a bunch of code replaced with the app aborting as insecure. I'm not sure how legit this is, the repository was just created a few minutes ago. Apparently there is a new binary release that goes along with this, though. [I've created a fork here just in case…

Notice the added functions like IsNonSysPartitionOnSysDrive and ResolveAmbiguousSelection, and all the unrelated minor changes like the comment line in Common/Volumes.h. Looks a lot like they based it on current pre-release development code.

Re: TrueCrypt suggesting migration to BitLocker?

#134
post #70

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

If the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".

Nitpick: Truecrypt is proprietary (it's source is viewable, but you aren't licensed to distribute modifications of it).

Re: TrueCrypt suggesting migration to BitLocker?

#135

Earlier quoted context omitted.

Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.

Well, the thing is though, it's not that they were hosting users' data. It's not like they would be forced to provide the contents of users' communication. I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...

considering heartbleed... yes

Re: TrueCrypt suggesting migration to BitLocker?

#136
post #70

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

If the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".

Unless some kind of backdoor was about to be discovered...and they'd rather close it down before it gets discovered.

Re: TrueCrypt suggesting migration to BitLocker?

#137

> WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues I see many readers here and on Twitter who interpret that as "TrueCrypt has security issues". That's not what it says. It says that it might be insecure. That does not make too much sense right now, but considering this webpage would be meant to stay up, unchanged, for years, that makes a lot more sense: security problems may be found,…

At the bottom of this page it says "WARNING: Using TrueCrypt is not secure"

Looks like they've taken out the ambiguity.

Re: TrueCrypt suggesting migration to BitLocker?

#138

Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

Same key as the previous binaries? I doubt it, given that the keys were replaced mere 3 hours before the new binaries were published:

http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...

Re: TrueCrypt suggesting migration to BitLocker?

#139
Just trying to make sense of the news, ( did I miss something, or is this the current state of the rumor mill?)

1. Truecrypt.org redirects to TrueCrypt's sourceforge account.

2. The sourceforge page is defaced.

3. There is a signed(?) binary which can only be used to migrate.

Sounds remarkably bad ( and remarkably much effort for the lu1z.) So is there a defined version for the audit? ( Such that there is a known good version to roll back to?)

Re: TrueCrypt suggesting migration to BitLocker?

#140

Perhaps it's time for a fork.

The TrueCrypt license is not OSI approved, so probably noone wants to touch it for the same reason noone wanted to touch OpenSSL for all those years ... unless you really really have to and have no alternatives.
Post reply on HN