True Goodbye: ‘Using TrueCrypt Is Not Secure’
krebsonsecurity.com
True Goodbye: ‘Using TrueCrypt Is Not Secure’
1–10 of 249 posts
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#2"'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'"
"I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#3"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software." "'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'" "I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#4Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#5Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#6Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#7Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)
Both of these are hypothetical, however. We've seen tons of vulnerabilities from both. IMHO Open Source works a lot better on paper but once projects get very large auditing them is really hard...which definitely cuts down on the amount of eyes looking at them.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#8"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software." "'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'" "I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”
Granted they only evaluated the bootloader under the first contract, but if you were going to slip in a backdoor or if a serious crypto bypass would be possible it would have likely been there.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#9Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)
There are pros and cons to both closed source and open source. Open source is nice because the community can audit the code and see for themselves, but closed-source is nice because a company generally has the resources to maintain and build software correctly. Both of these are hypothetical, however. We've seen tons of vulnerabilities from both. IMHO Open Source works a lot better on paper but once projects get very…
These two things are orthogonal, IMHO.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#10One of the reasons I like iPhone is the idea that the security system and drive encryption is not hopelessly broken. It would be great to have the same level of confidence in BitLocker.