In case this is legit: Bitlocker so far so good, but neither Bitlocker nor any other crypto solution offer plausible deniability (aka hidden volumes).
We should strive not to trust closed crypto.
I use Apple's FileVault on my laptop, but for particularly sensitive data (work code, financial info, etc) I always used truecrypt. We have no idea if apple is actually doing what they claim to be doing. The same applies to MS and bitlocker.
If the developer wanted to 1) motivate a fork, 2) maybe abandon the license under the guise of "he dare not reveal himself for the purpose of enforcing it", and 3) still keep the TC-hugging ciphernerd throngs willing to use the forked software by suggesting an alternative so unpalatable, then he might take actions like we've seen here; and the results might be that he could 1) come out of hiding as some "new" project lead, 2) license it differently, and 3) have a huge, loyal user base. This means he might now be able to participate in funding campaigns like the Audit's and make money from licensing it to, for example, commercial enterprises, without generating too much outrage.
Can't help but think of Marco Arment's point about free applications... Sigh. Just wish I could throw a bit of money at them now to stop whatever the heck is going on here (and yeah, I know I probably could have donated before but fact is I didn't).
Call me paranoid but this just looks like really good evidence that Truecrypt was secure.
...or that BitLocker isn't.
I know everyone likes to bash MS around here but is there any actual proof of Bitlocker's insecurity that is more recent than 2008? If you look at wikipedia it seems like the only known real vulnerability requires someone with physical access to boot via USB into another OS within a few minutes of turning the computer off. When is this a real risk for anyone? I am not a security expert but unless you are doing things shady enough to get raided by the FBI, it seems like Bitlocker is pretty secure. The same problem occurs in other encryption programs on Linux and OSX. Also, it may not be open source like what we want, but MS lets its partners and enterprise customers audit the code subject to an NDA.
In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…
After examining all the facts, I think it's most likely they just didn't want to develop it anymore: * PGP matches * Authenticode matches * SourceForge data was modified * DNS records were modified And to top it off, let's put ourselves in the theoretical attacker's shoes, the binaries when run make no unexpected connection attempts or write to any unexpected places and don't appear to contain any unexpected imports,…
Could you post the PGP & Authenticode details? I was unable to verify the 7.1 releases.
Is source still available? Can we check the commit tree for anything suspicious lately? Can someone compile it and check the hash against the 7.2 binary being offered?
It's not that simple. It won't match anyway. Signatures, compiler versions, SDK versions, etc.
Could it be related to this announcement from yesterday: "just yesterday we added the ability to extract cached Truecrypt passphrases from Linux memory dumps." http://volatility-labs.blogspot.de/2014/05/volatility-update...
Extracting TrueCrypt passwords from memory dumps has been trivial for quite a while now.
Agreed. TrueCrypt has always been upfront about the dangers of physical access to your machine (pulling master keys from RAM). This kind of response wouldn't makes sense
The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficien…
As crazy as it sounds, I think you're right and it's just the developer(s) quitting (rage-quitting?) the project. Nothing else makes sense. The Bitlocker thing seems strange until you realize that it probably really IS the best alternative for most users. The users who are paranoid enough to not trust Bitlocker can probably look out for their own security, so it makes sense to give instructions for the rest. None of…
No more than shutting down Lavabit violated whatever NSLs/court orders were directed at it.