TrueCrypt suggesting migration to BitLocker?
141–150 of 414 posts
Re: TrueCrypt suggesting migration to BitLocker?
#142Earlier quoted context omitted.
Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.
Well, the thing is though, it's not that they were hosting users' data. It's not like they would be forced to provide the contents of users' communication. I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...
Re: TrueCrypt suggesting migration to BitLocker?
#143Earlier quoted context omitted.
The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.
Same key as the previous binaries? I doubt it, given that the keys were replaced mere 3 hours before the new binaries were published: http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...
Re: TrueCrypt suggesting migration to BitLocker?
#144 -TrueCrypt License Version 3.0
+TrueCrypt License Version 3.1
This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is signed with the same signing keys, can I legally use the new license in derivative software?The new license removes the following restrictions regarding attribution:
- c. Phrase "Based on TrueCrypt, freely available at
- http://www.truecrypt.org/" must be displayed by Your Product
- (if technically feasible) and contained in its
- documentation. Alternatively, if This Product or its portion
- You included in Your Product constitutes only a minor
- portion of Your Product, phrase "Portions of this product
- are based in part on TrueCrypt, freely available at
- http://www.truecrypt.org/" may be displayed instead. In each
- of the cases mentioned above in this paragraph,
- "http://www.truecrypt.org/" must be a hyperlink (if
- technically feasible) pointing to http://www.truecrypt.org/
- and You may freely choose the location within the user
- interface (if there is any) of Your Product (e.g., an
- "About" window, etc.) and the way in which Your Product will
- display the respective phrase.Re: TrueCrypt suggesting migration to BitLocker?
#145I don't see why so many are jumping onto conspiracy theories. Truecrypt, like the page states, has become redundant with built-in OS offerings. While it could be used for other things, the main reason/drive behind its development was the Full Disk Encryption feature, which has only ever worked on Windows, and has only ever truly been "necessary" for Windows XP users. Windows had bitlocker for FDE since Vista, Mac OS…
Re: TrueCrypt suggesting migration to BitLocker?
#146(I'm just bringing up some new machines, myself -- I'll have to hunt a bit for local copies from the last time I downloaded (legitimate copies of) the 7.1a version.)
--
P.S. For two recognizable names/sites (to me, at least) near the top of a Google search, FileHippo and CNET are hosting Windows .exe intallers for 7.1a . No signature files, though. And with CNET (download.com), as I seem to recall and last I heard, they practice wrapping the actual product installers inside their own crapware installer.
Re: TrueCrypt suggesting migration to BitLocker?
#147Re: TrueCrypt suggesting migration to BitLocker?
#148Interestingly enough, they also changed the TrueCrypt license. -TrueCrypt License Version 3.0 +TrueCrypt License Version 3.1 This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is…
Re: TrueCrypt suggesting migration to BitLocker?
#149Interestingly enough, they also changed the TrueCrypt license. -TrueCrypt License Version 3.0 +TrueCrypt License Version 3.1 This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is…