Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

311–320 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#311
post #234

Earlier quoted context omitted.

If you're developing a free product and you're going to throw in the towel anyway, why not just open up the sources with a liberal license and/or hand the project over to someone else who's willing to carry the torch.

The license was changed with the new release. Edit: The following clause was deleted in the 7.2 release. - c. Phrase "Based on TrueCrypt, freely available at - http://www.truecrypt.org/" must be displayed by Your Product - (if technically feasible) and contained in its - documentation. Alternatively, if This Product or its portion - You included in Your Product constitutes only a minor - portion of Your Product, phra…

Indeed it was.

As was its ability to encrypt, apparently. I don't exactly count those as one in the same.

Re: TrueCrypt suggesting migration to BitLocker?

#312
post #305

Earlier quoted context omitted.

If it was operator error during the development of a Dead-Man's-Switch, the developer will probably come out in public explaining the situation and apologizing. And if this is a Dead-Man's-Switch gone right , why are they advocating the use of BitLocker and searching for random Linux packages? Edit: is "coming out in public" the correct term here? I have a feeling it only applies to closet-like scenarios.

If it was a hastily constructed DMS (such as in the event of imminent threat), the author may not have had time to research and test a comparable Linux alternative. If you knew that something bad could happen, you would work as fast as possible to set it up, rather than risk not being able to have anything working in time. The reason why is quite simple: if a malicious third party were to raid or steal the private ke…

Why have dozens of steps and seventeen screenshots detailing how to migrate a Windows partition and only a joke line for the Linux version? And why Bitlocker? Then there was the license change, new version with different features... This imbalance of effort strikes me as incredibly odd if the author was merely rushed.

Re: TrueCrypt suggesting migration to BitLocker?

#313

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

>- The version there works and does not seem to have a trojan, so probably not a regular hacker. Incorrect, all the guy did was compare diffs of the source. He did not compile the source to make sure the binaries matched.

Are you sure? He does say "binaries when run make no unexpected...".

And matching binaries is not a trivial task because of OS, compiler and SDK versions. The last time someone did this for Truecrypt it made the news: https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...

Re: TrueCrypt suggesting migration to BitLocker?

#315
post #305

Earlier quoted context omitted.

If it was a hastily constructed DMS (such as in the event of imminent threat), the author may not have had time to research and test a comparable Linux alternative. If you knew that something bad could happen, you would work as fast as possible to set it up, rather than risk not being able to have anything working in time. The reason why is quite simple: if a malicious third party were to raid or steal the private ke…

Why have dozens of steps and seventeen screenshots detailing how to migrate a Windows partition and only a joke line for the Linux version? And why Bitlocker? Then there was the license change, new version with different features... This imbalance of effort strikes me as incredibly odd if the author was merely rushed.

Linux users can be trusted to work things out for themselves?

Re: TrueCrypt suggesting migration to BitLocker?

#316

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

If I were to wager a non-crazy, Occam's Razor-compatible bet, I'd say the author had a bad day, saw one too many digs at the quality of their decade-long work, got pissy, and decided to call it quits. I love popcorn-munching news as much as anyone, but this probably isn't it.

Re: TrueCrypt suggesting migration to BitLocker?

#317

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

My order of likelihood is #1. This is a canary. https://en.wikipedia.org/wiki/Warrant_canary

Do agencies like the NSA/FBI/etc have the power to make a company publicly lie against their will?

Re: TrueCrypt suggesting migration to BitLocker?

#318
post #177
post #170

Earlier quoted context omitted.

The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficien…

> The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. I realize we are firmly in conspiracy theory territory here, but perhaps the suggestion that users switch to Bitlocker is intended to be so patently absurd as to be a signal that the developers are under duress?

This is currently my favorite theory, for lack of a better word. It's also potentially pretty disturbing news. I saw another user mention the term warrant canary. I'd call it a warrant canary for the cautious/well informed. Unless there is some serious action on the horizon, no one well informed will ever use a truecrypt release past 7.2 ever again. https://en.wikipedia.org/wiki/Warrant_canary

My very first thought upon hearing this news was that just maybe the trucrypt devs are secretly cheering for others to come and replace the hole they fill in this world. Maybe this is the best possible thing they could do to inspire the next generation of truecrypt. They've laid a good foundation but they know they can't win the war for free information security on their own. So what better good could they do than to inspire the mother of invention; necessity.

Re: TrueCrypt suggesting migration to BitLocker?

#319

Earlier quoted context omitted.

>- The version there works and does not seem to have a trojan, so probably not a regular hacker. Incorrect, all the guy did was compare diffs of the source. He did not compile the source to make sure the binaries matched.

Are you sure? He does say "binaries when run make no unexpected...". And matching binaries is not a trivial task because of OS, compiler and SDK versions. The last time someone did this for Truecrypt it made the news: https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...

Binaries could have code that will activate in future.

Re: TrueCrypt suggesting migration to BitLocker?

#320
If I take this message at face value and decide to switch to BitLocker, can someone answer this.

Dropbox + Truecrypt take full advantage of block sync & block encryption i.e. if a tiny piece of data is modified inside an encrypted container, only the relevant blocks are synced on update. Dropbox does not need to sync the entire container each time. This is a very useful feature. I know Google Drive & OneDrive aren't that smart.

Will bitlocker + Dropbox work the same way?

Post reply on HN