Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

291–300 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#291

Earlier quoted context omitted.

>>After examining all the facts, I think it's most likely they just didn't want to develop it anymore: So they decided to end things with such an extremely juvenile behavior devaluating the years they have invested in this project even if not recently? Unless the responsible one fell into clinical depression it's a pretty strange reason.

They haven't updated it for years. I'd hardly call the behavior "juvenile" nor would i call it "devaluating". They've simply abandoned it and are offering alternatives.

>> They haven't updated it for years.

As I said even if not recently they still invested many years into that project.

Of course it is juvenile to senselessly ruin the code and suddenly advertising a very different commercial product, especially without proper scientific reason.

Not to mention that precisely because they haven't done much work lately I don't see any reason why the developers would disfigure their project like that.

Re: TrueCrypt suggesting migration to BitLocker?

#292

Earlier quoted context omitted.

...or that BitLocker isn't.

I know everyone likes to bash MS around here but is there any actual proof of Bitlocker's insecurity that is more recent than 2008? If you look at wikipedia it seems like the only known real vulnerability requires someone with physical access to boot via USB into another OS within a few minutes of turning the computer off. When is this a real risk for anyone? I am not a security expert but unless you are doing things…

It's not open source so who knows what's lurking in there? It's not like anyone has been able to audit the source of Bitlocker.

Re: TrueCrypt suggesting migration to BitLocker?

#293

Earlier quoted context omitted.

...or that BitLocker isn't.

I know everyone likes to bash MS around here but is there any actual proof of Bitlocker's insecurity that is more recent than 2008? If you look at wikipedia it seems like the only known real vulnerability requires someone with physical access to boot via USB into another OS within a few minutes of turning the computer off. When is this a real risk for anyone? I am not a security expert but unless you are doing things…

It's really not that hard to imagine scenarios where this might happen. Simply leaving your notebook unattended after a shutdown might leave you compromised. Besides, government agencies in other countries might have a slightly different view on what constitutes "shady behaviour" (think regime critics).

Re: TrueCrypt suggesting migration to BitLocker?

#294

Why have they only talk about how to secure a partition in Windows. Would the developers, or persons who took over the project, not care about other operating systems?! Of course, by 'they', I mean the fake development team that the hijacker of the site wanted to portray... no way this is real

There's a link at the bottom for Mac and Linux. For Mac they recommend the built-in encryption as well.

I'm having trouble taking any of that page seriously however -- to be recommending closed-source solutions like Bitlocker as 'more secure'.

Re: TrueCrypt suggesting migration to BitLocker?

#295
- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... )

- The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 )

- Instructs to migrate to dubious alternatives, so it's not a legit security effort.

- License change, precise instructions and decrypt-only version indicate it's not a completely rushed press release. (license change: https://github.com/warewolf/truecrypt/compare/master...7.2#d... )

- On the other hand the Linux instruction is a joke, so it's not completely well thought either. ( http://truecrypt.sourceforge.net/OtherPlatforms.html )

- The security audit was so far ok, so it's not a sudden vulnerability discovered there. ( https://twitter.com/matthew_d_green/status/47174183672207360... )

- No details whatsoever other than a "may contain unfixed security issues", so it might be an automated release (doesn't know what happened) or gagged reaction (can't say what happened).

- Source code includes unrelated changes, so it probably comes from a developer. ( https://news.ycombinator.com/item?id=7812674 )

If I had to wager a crazy bet, I would go with newly developed Dead-Man's-Switch gone wrong.

Edit: someone on Reddit has an interesting view that it may be a halfhearted attempt at complying with an NSA request ( http://www.reddit.com/r/sysadmin/comments/26pxol/truecrypt_i... ).

Re: TrueCrypt suggesting migration to BitLocker?

#296
post #269

If you're looking for actively developed cross platform free software alternative: http://www.getsafe.org/

Can anyone else comment on the viability of this option? It seems pretty nice, from the website, but I'd like to hear more about it's reputation in the security community.

Re: TrueCrypt suggesting migration to BitLocker?

#297

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

>If I had to wager a crazy bet, I would go with newly developed Dead-Man's-Switch gone wrong.

That's an interesting thought, although I don't think there's any way to verify that it's actually gone 'wrong', is there?

Re: TrueCrypt suggesting migration to BitLocker?

#298

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

>If I had to wager a crazy bet, I would go with newly developed Dead-Man's-Switch gone wrong. That's an interesting thought, although I don't think there's any way to verify that it's actually gone 'wrong', is there?

If it was operator error during the development of a Dead-Man's-Switch, the developer will probably come out in public explaining the situation and apologizing.

And if this is a Dead-Man's-Switch gone right, why are they advocating the use of BitLocker and searching for random Linux packages?

Edit: is "coming out in public" the correct term here? I have a feeling it only applies to closet-like scenarios.

Re: TrueCrypt suggesting migration to BitLocker?

#299
post #273

Earlier quoted context omitted.

But, being a 16-bit program, it won't run on 64-bit windows. I'm not even sure it would install properly on anything newer than XP. I haven't tried installing it since the 9x days. There are several things MS has released that don't install on newer systems very well. There are some where the installer depends on an old version of Internet Explorer being installed and which fail miserably on newer versions.

Its a boot loader, It runs while the system is in real mode (16bit), before windows itself has booted.

I meant MSVC 1.52c is 16-bit.

Re: TrueCrypt suggesting migration to BitLocker?

#300
post #221

Earlier quoted context omitted.

If that's the motivation then in 5 years' time, who's to say the new version will work as well (assuming that it also won't be updated)? That doesn't make any sense.

They're saying that one should not continue to use orphaned software (when it's so security critical). So they're stopping the distribution of the encryption part of it, and continuing to distribute the part of the software that decrypts the code. This means that if (in five years) you find an archive that you can't open without TrueCrypt (and you uninstalled it etc) you'll still be easily able to find a signed versi…

> This means that if (in five years) you find an archive that you can't open without TrueCrypt (and you uninstalled it etc) you'll still be easily able to find a signed version that will decrypt it for you.

That still doesn't seem to answer the point. The differences between 7.1* and the questionable 7.2 are exclusively limited to what was ripped out. In 5 years, 7.1 and 7.2 will likely work precisely the same in terms of decryption. If a glibc update or similar breaks 7.1, it'll likely break 7.2.

Perhaps I wasn't clear enough in my first comment, but fundamentally it seems like a silly argument to make to suggest that distributing a new release for some measure of future proofing readability is necessary. Outside "don't use this, it's broken," I can't really see "this will still work in 5 years' time" as a valid reason.

Post reply on HN