Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

231–240 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#231

Back and forth speculation is great and all, but does anyone know of a solid alternative to TrueCrypt? Perferably open-source but at the very least not a potential government lap-dog like Microsoft?

tcplay - https://github.com/bwalex/tc-play - is truecrypt compatible but based on dm-crypt, afaik it's only compatible with Linux/BSD although for privacy-conscious individuals, few other operating systems make sense to run.

Wild guess here but you might want to recreate any containers using tcplay and copy files over, rather than continuing to use possibly compromised truecrypt containers.

For full-disk encryption Linux has LUKS/dm-crypt/cryptsetup.

Re: TrueCrypt suggesting migration to BitLocker?

#232

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

* SourceForge account compromised and developers unwisely stored private keys and other information somewhere inside this account, permitting the attacker to compromise lots of other stuff and generally have a blast.

Re: TrueCrypt suggesting migration to BitLocker?

#233

Earlier quoted context omitted.

It's already open-source.

As far as I know, its license is incompatible with other open source licenses due to an advertising clause (all derivative works have to state "based on Truecrypt" somewhere in the documentation or via use of the software). The old four clause BSD license had a similar issue.

One of the changes in the newly-uploaded version is indeed a change in the license.

Re: TrueCrypt suggesting migration to BitLocker?

#234

Earlier quoted context omitted.

It could be that they've simply lost interest in developing it. It's quite the ongoing responsibility, and they may well be tired of working on it - a decade is a long time in anyone's life. If this is true, then perhaps such listlessness was also catalysed by the ongoing audit. Maybe seeing such a mass of crowdfunding income towards a project to pick Truecrypt apart, in contrast to the scant donations to its develop…

If you're developing a free product and you're going to throw in the towel anyway, why not just open up the sources with a liberal license and/or hand the project over to someone else who's willing to carry the torch.

The license was changed with the new release.

Edit: The following clause was deleted in the 7.2 release.

- c. Phrase "Based on TrueCrypt, freely available at - http://www.truecrypt.org/" must be displayed by Your Product - (if technically feasible) and contained in its - documentation. Alternatively, if This Product or its portion - You included in Your Product constitutes only a minor - portion of Your Product, phrase "Portions of this product - are based in part on TrueCrypt, freely available at - http://www.truecrypt.org/" may be displayed instead. In each - of the cases mentioned above in this paragraph, - "http://www.truecrypt.org/" must be a hyperlink (if - technically feasible) pointing to http://www.truecrypt.org/ - and You may freely choose the location within the user - interface (if there is any) of Your Product (e.g., an - "About" window, etc.) and the way in which Your Product will - display the respective phrase.

Re: TrueCrypt suggesting migration to BitLocker?

#235

So what was the point of raising money to audit TrueCrypt if they knew they would shut it down once XP was EOL? In fact why didn't they announce this earlier?

Yes, it would be major douchbaggery not to tell the auditors that TC was about to shutdown.

Re: TrueCrypt suggesting migration to BitLocker?

#236

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

After examining all the facts, I think it's most likely they just didn't want to develop it anymore: * PGP matches * Authenticode matches * SourceForge data was modified * DNS records were modified And to top it off, let's put ourselves in the theoretical attacker's shoes, the binaries when run make no unexpected connection attempts or write to any unexpected places and don't appear to contain any unexpected imports,…

[deleted]

Re: TrueCrypt suggesting migration to BitLocker?

#238

Providing some details from SourceForge: 1. We have had no contact with the TrueCrypt project team (and thus no complaints). 2. We see no indicator of account compromise; current usage is consistent with past usage. 3. Our recent SourceForge forced password change was triggered by infrastructure improvements not a compromise. FMI see http://sourceforge.net/blog/forced-password-change/ Thank you, The SourceForge Team…

2. We see no indicator of account compromise; current usage is consistent with past usage.

I'm calling BS. This site was disabled repeatedly for exceeding bandwidth today. I find it hard to believe traffic is as usual.

Re: TrueCrypt suggesting migration to BitLocker?

#239

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

After examining all the facts, I think it's most likely they just didn't want to develop it anymore: * PGP matches * Authenticode matches * SourceForge data was modified * DNS records were modified And to top it off, let's put ourselves in the theoretical attacker's shoes, the binaries when run make no unexpected connection attempts or write to any unexpected places and don't appear to contain any unexpected imports,…

>>After examining all the facts, I think it's most likely they just didn't want to develop it anymore:

So they decided to end things with such an extremely juvenile behavior devaluating the years they have invested in this project even if not recently?

Unless the responsible one fell into clinical depression it's a pretty strange reason.

Re: TrueCrypt suggesting migration to BitLocker?

#240

Is it possible that this is the result of a "dead man's switch" (DMS) set by the developer(s)? Perhaps a (continually updated) process was set up so that TrueCrypt would shut itself down if the developer were unable to prove he or she was still actively maintaining the software. I can see a couple of scenarios where this would be wise: A) The developer passes away, leaving nobody else to maintain TrueCrypt. Zero-day…

the page specifically mentions that it's ending support in may because ms is dropping xp support, though

Not quite, though. The page says "The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP." We can infer that the two are connected, but it would be equally valid to say "The development of TrueCrypt was ended in 5/2014 after Snowden interviewed with NBC."

The reason I make this distinction is because continuing from a cautious/paranoid perspective, the DMS might not say "WARNING! Dead Man's Switch Activated! If you are reading this, I may have been compromised, and am no longer available to maintain TrueCrypt." It's possible that the landing page simply references a relatively innocuous event in the cyber security world to plausibly discontinue the software. The best evidence I have for this is the fact that TrueCrypt didn't shut down precisely when XP support was dropped. (In fact, according to http://www.microsoft.com/en-us/windows/enterprise/end-of-sup... official support ended in April, not May like the landing page states.)

Post reply on HN