Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

21–30 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#21
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

I don't believe BitLocker can be considered secure. Cross-post (mine) from the previous thread:

> Not "backdoors" but it seems Microsoft stores the BitLocker decryption key, based on this leaked slide (just found on twitter): https://twitter.com/TheBlogPirate/status/471759810644283392/... > edit: Confirmed Microsoft stores your recovery key on their servers if you're not connected to a domain: http://windows.microsoft.com/en-AU/windows-8/bitlocker-recov...

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#22
Well this is good for me. I currently use a TrueCyrypt encrypted exFAT volume for backups. My motivation is now to move this to an open source system (probably dm-crypt). This and RDP is the only reason I'm hanging onto windows and that's purely out of apathy. The suggestion of using BitLocker is a bit insulting (this might just be comedy value from TC though). Every other bit of software I use is portable or in a Linux VM already.

So my weekend project is now to move all my stuff to Debian.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#23
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

I do believe that open-source solutions are better when concerned about privacy and security. But why would a user of a mostly closed-source OS bother about the open-source nature of one component of that OS?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#24
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

Surely it would also take very little effort to implement an alternative to truecrypt? What's the big deal

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#25
"BitlLocker, the proprietary disk encryption program that ships with every Windows version since Vista."

This is misleading - Windows 7 product line has Bitlocker only for Ultimate and Enterprise. Even Windows 7 Professional users cannot use Bitlocker without upgrading to Ultimate. Very unfortunate.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#27
post #21
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

I don't believe BitLocker can be considered secure. Cross-post (mine) from the previous thread: > Not "backdoors" but it seems Microsoft stores the BitLocker decryption key, based on this leaked slide (just found on twitter): https://twitter.com/TheBlogPirate/status/471759810644283392/... > edit: Confirmed Microsoft stores your recovery key on their servers if you're not connected to a domain: http://windows.microsof…

> Not "backdoors" but it seems Microsoft stores the BitLocker decryption key, based on this leaked slide (just found on twitter): https://twitter.com/TheBlogPirate/status/471759810644283392/....

That looks dubious to me - if you were creating a slide, would you use 90-degree-rotated text?

> edit: Confirmed Microsoft stores your recovery key on their servers if you're not connected to a domain: http://windows.microsoft.com/en-AU/windows-8/bitlocker-recov....

"There are several locations in which your BitLocker recovery key might have been saved" - emphasis mine - doesn't this mean they'll store the key if you log into "Your Microsoft account"? I have to admit I don't use Windows 8 so I don't know if this is mandatory or not? What about Windows 7?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#28
post #2

"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software." "'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'" "I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”

I think that's why they are quitting. They didn't want the audit to find something. But it's just a speculation like any other.

I doubt that's the reason - Greene says that the audit is going ahead. The other fact that makes this unlikely is that Green's team has the source, so his team can poke around all it likes anyway. Ergo quitting is no guarantee that something won't be found.
Post reply on HN