This seems highly suspicious, especially the recommendation of BitLocker, a product we have little to no evidence does what it says and after PRISM, have no reason to trust[2]; not to mention it being limited to a (very small subset of) Windows platforms vs. TrueCrypt's cross-platform functionality. If this was legit[1], it'd probably be directing people to one of the other TrueCrypt-like programs. [1]The new version…
Would this be a Lavabit-like situation? The governement asking for a backdoor and the developers are refusing it. Suddenly (while there is an audit), they quit everything, change the assemblies and the website, so users can get to another product... It seems weird that after 10 years of hard-work, they suddenly quit without further explanation.
True Goodbye: ‘Using TrueCrypt Is Not Secure’
71–80 of 249 posts
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#72Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)
Surely it would also take very little effort to implement an alternative to truecrypt? What's the big deal
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#73Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#74I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hysterical tone and ridiculous BitLocker advice to the tone and content of the actual app, they don't add up at all.
This leaves us with a handful of discrepancies between the last good state of the project and what's out there now. So it's either someone else's hackjob or it is original and the discrepancies are intentional. Then, factor in the .exe sig match, and it pretty much leaves only the latter option - the original devs made an absurdly non-TC-like release. The question is "why?"
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#75Earlier quoted context omitted.
Would this be a Lavabit-like situation? The governement asking for a backdoor and the developers are refusing it. Suddenly (while there is an audit), they quit everything, change the assemblies and the website, so users can get to another product... It seems weird that after 10 years of hard-work, they suddenly quit without further explanation.
If so, I would at least like to think they would have likely pointed people towards something which gives at least comparable security, rather than a backdoored product.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#76Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...
DiskCryptor (GPLv3) - https://diskcryptor.net/wiki/Main_Page The author seems to be an anonymous Russian-speaking person. Another option is FreeOTFE - http://sourceforge.net/projects/freeotfe.mirror/ It is compatible with Linux's LUKS and dm-crypt, and it doesn't support system partition encryption.
http://www.reddit.com/r/crypto/comments/1ciopg/freeotfe_acco...
The Way Back Machine has an old copy of her FreeOTFE website (freeotfe.org): https://web.archive.org/web/20130531062457/http://freeotfe.o...
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#77Somebody who has been following TrueCrypt closely seem to think the project lost momentum and they just decided to call it quit.Their comment is on slashdot and the link is: http://it.slashdot.org/comments.pl?sid=5212985&cid=47115785
Makes the most sense yet. The question that was asked in response to that Slashdot post was why anyone would choose to quit the way they did (unprofessional and so on), and this doesn't sway me. If I lost my star dev and couldn't follow the code myself I might (speculation, as ever) well be petulant enough for this mess. There may be any number of factors behind it, ranging from animosity within the team to fear or s…
The owner/manager of the project didn't want to keep maintaining it and is redirecting users to an alternative that will work for almost all use cases. As of last month, there were reported flaws in TrueCrypt and there's nothing that forces a maintainer of a free project to keep going.
I'm left almost a little annoyed that the conversation isn't "RIP TrueCrypt project, thank you goes out to the maintainers for helping people feel more secure for years."
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#78Earlier quoted context omitted.
I think that's why they are quitting. They didn't want the audit to find something. But it's just a speculation like any other.
It's more likely that they were angry that the audit got a lot of funds and they didn't. In OSS often the people who do the original work get nothing and all the money goes to pundits, packagers, and consultants.
I suspect that would have brought in a few dollars in the current climate.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#79Is this a warrant canary?
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#80Earlier quoted context omitted.
Makes the most sense yet. The question that was asked in response to that Slashdot post was why anyone would choose to quit the way they did (unprofessional and so on), and this doesn't sway me. If I lost my star dev and couldn't follow the code myself I might (speculation, as ever) well be petulant enough for this mess. There may be any number of factors behind it, ranging from animosity within the team to fear or s…
I don't see this as particularly unprofessional or petulant. The owner/manager of the project didn't want to keep maintaining it and is redirecting users to an alternative that will work for almost all use cases. As of last month, there were reported flaws in TrueCrypt and there's nothing that forces a maintainer of a free project to keep going. I'm left almost a little annoyed that the conversation isn't "RIP TrueCr…