Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

261–270 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#261

In case this is legit: Bitlocker so far so good, but neither Bitlocker nor any other crypto solution offer plausible deniability (aka hidden volumes).

We should strive not to trust closed crypto.

I use Apple's FileVault on my laptop, but for particularly sensitive data (work code, financial info, etc) I always used truecrypt. We have no idea if apple is actually doing what they claim to be doing. The same applies to MS and bitlocker.

Re: TrueCrypt suggesting migration to BitLocker?

#262
If the developer wanted to 1) motivate a fork, 2) maybe abandon the license under the guise of "he dare not reveal himself for the purpose of enforcing it", and 3) still keep the TC-hugging ciphernerd throngs willing to use the forked software by suggesting an alternative so unpalatable, then he might take actions like we've seen here; and the results might be that he could 1) come out of hiding as some "new" project lead, 2) license it differently, and 3) have a huge, loyal user base. This means he might now be able to participate in funding campaigns like the Audit's and make money from licensing it to, for example, commercial enterprises, without generating too much outrage.

Re: TrueCrypt suggesting migration to BitLocker?

#264

Call me paranoid but this just looks like really good evidence that Truecrypt was secure.

...or that BitLocker isn't.

I know everyone likes to bash MS around here but is there any actual proof of Bitlocker's insecurity that is more recent than 2008? If you look at wikipedia it seems like the only known real vulnerability requires someone with physical access to boot via USB into another OS within a few minutes of turning the computer off. When is this a real risk for anyone? I am not a security expert but unless you are doing things shady enough to get raided by the FBI, it seems like Bitlocker is pretty secure. The same problem occurs in other encryption programs on Linux and OSX. Also, it may not be open source like what we want, but MS lets its partners and enterprise customers audit the code subject to an NDA.

http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption#Secu...

Re: TrueCrypt suggesting migration to BitLocker?

#265

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

After examining all the facts, I think it's most likely they just didn't want to develop it anymore: * PGP matches * Authenticode matches * SourceForge data was modified * DNS records were modified And to top it off, let's put ourselves in the theoretical attacker's shoes, the binaries when run make no unexpected connection attempts or write to any unexpected places and don't appear to contain any unexpected imports,…

Could you post the PGP & Authenticode details? I was unable to verify the 7.1 releases.

Re: TrueCrypt suggesting migration to BitLocker?

#266
post #230
post #115

Earlier quoted context omitted.

Is source still available? Can we check the commit tree for anything suspicious lately? Can someone compile it and check the hash against the 7.2 binary being offered?

It's not that simple. It won't match anyway. Signatures, compiler versions, SDK versions, etc.

This guy managed to compile a previous version and have it match the released binaries https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...

Re: TrueCrypt suggesting migration to BitLocker?

#267
post #130
post #120

Could it be related to this announcement from yesterday: "just yesterday we added the ability to extract cached Truecrypt passphrases from Linux memory dumps." http://volatility-labs.blogspot.de/2014/05/volatility-update...

Extracting TrueCrypt passwords from memory dumps has been trivial for quite a while now.

Agreed. TrueCrypt has always been upfront about the dangers of physical access to your machine (pulling master keys from RAM). This kind of response wouldn't makes sense

Re: TrueCrypt suggesting migration to BitLocker?

#268
post #204
post #170

Earlier quoted context omitted.

The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficien…

As crazy as it sounds, I think you're right and it's just the developer(s) quitting (rage-quitting?) the project. Nothing else makes sense. The Bitlocker thing seems strange until you realize that it probably really IS the best alternative for most users. The users who are paranoid enough to not trust Bitlocker can probably look out for their own security, so it makes sense to give instructions for the rest. None of…

No more than shutting down Lavabit violated whatever NSLs/court orders were directed at it.
Post reply on HN