Call me paranoid but this just looks like really good evidence that Truecrypt was secure.
TrueCrypt suggesting migration to BitLocker?
131–140 of 414 posts
Re: TrueCrypt suggesting migration to BitLocker?
#132Earlier quoted context omitted.
Seems to point towards compromised SF account.
There's a new binary that recommends moving to BitLocker during install, and the signature matches. Edit: with a new, compromised key.
http://sourceforge.net/projects/truecrypt/files/TrueCrypt/
http://sourceforge.net/projects/truecrypt/?source=navbar
http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...
Odd, 6 hours ago someone updated the TruCrypt-key.asc files, then 3 hours later posted all the new binaries.
Also odd is whoever posted the new binaries completely yanked all the previous ones, leaving only the new and questionable binary available for download.
hmm...
Re: TrueCrypt suggesting migration to BitLocker?
#133I just came across this on Twitter: https://github.com/warewolf/truecrypt/compare/master...7.2 This is supposedly the commit for the 7.2 release. Just looks like a bunch of code replaced with the app aborting as insecure. I'm not sure how legit this is, the repository was just created a few minutes ago. Apparently there is a new binary release that goes along with this, though. [I've created a fork here just in case…
Re: TrueCrypt suggesting migration to BitLocker?
#134In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…
If the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".
Re: TrueCrypt suggesting migration to BitLocker?
#135Earlier quoted context omitted.
Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.
Well, the thing is though, it's not that they were hosting users' data. It's not like they would be forced to provide the contents of users' communication. I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...
Re: TrueCrypt suggesting migration to BitLocker?
#136In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…
If the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".
Re: TrueCrypt suggesting migration to BitLocker?
#137> WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues I see many readers here and on Twitter who interpret that as "TrueCrypt has security issues". That's not what it says. It says that it might be insecure. That does not make too much sense right now, but considering this webpage would be meant to stay up, unchanged, for years, that makes a lot more sense: security problems may be found,…
Looks like they've taken out the ambiguity.
Re: TrueCrypt suggesting migration to BitLocker?
#138Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.
The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.
http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...
Re: TrueCrypt suggesting migration to BitLocker?
#1391. Truecrypt.org redirects to TrueCrypt's sourceforge account.
2. The sourceforge page is defaced.
3. There is a signed(?) binary which can only be used to migrate.
Sounds remarkably bad ( and remarkably much effort for the lu1z.) So is there a defined version for the audit? ( Such that there is a known good version to roll back to?)
Re: TrueCrypt suggesting migration to BitLocker?
#140Perhaps it's time for a fork.