Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

81–90 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#81

Earlier quoted context omitted.

A screenshot that says "We have the recovery key", but zero indication of how they got it? The previous slide could not possibly be something related to dumping RAM, could it? Or perhaps an optional Microsoft-account feature to back up your encryption keys. Something that most normal users would want, just like they want it on Apple devices? Because a lot of common users aren't going to want FDE if it means "oh and l…

No, bitlocker explicitly send the key to MS for non-domain systems - as such, I would guess it potentially still does for those on a domain too, it'd just be kept quieter. http://windows.microsoft.com/en-us/windows-8/bitlocker-recov... Bitlocker is not trustworthy as an overall method of FDE.

That's an optional feature -- it asks you if you want to backup your key to your online account.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#82
post #81

Earlier quoted context omitted.

No, bitlocker explicitly send the key to MS for non-domain systems - as such, I would guess it potentially still does for those on a domain too, it'd just be kept quieter. http://windows.microsoft.com/en-us/windows-8/bitlocker-recov... Bitlocker is not trustworthy as an overall method of FDE.

That's an optional feature -- it asks you if you want to backup your key to your online account.

So you know that if you click 'no', it definitely isn't sent anyway (perhaps with some "MS/NSA use only" bit set to distinguish it from user-accessible ones)?

Thought not.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#83
post #81

Earlier quoted context omitted.

That's an optional feature -- it asks you if you want to backup your key to your online account.

So you know that if you click 'no', it definitely isn't sent anyway (perhaps with some "MS/NSA use only" bit set to distinguish it from user-accessible ones)? Thought not.

You previously said it "definitely sends your recovery key to MS." Sounds like you don't actually mean that.

It's fine and perfectly reasonable not to trust closed-source code, but no reason to spread half-truths about it.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#84

Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...

How about AxCrypt for file encryption?

http://www.axantum.com/axcrypt/

(I phrase this as a question because it'd be great if we could have some HN skepticism on this thing. Personally, I think everything basically checks out: open source, free, there's a name, phone number, address, picture etc.)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#85
post #83

Earlier quoted context omitted.

So you know that if you click 'no', it definitely isn't sent anyway (perhaps with some "MS/NSA use only" bit set to distinguish it from user-accessible ones)? Thought not.

You previously said it "definitely sends your recovery key to MS." Sounds like you don't actually mean that. It's fine and perfectly reasonable not to trust closed-source code, but no reason to spread half-truths about it.

The very ability to send it to MS is worrying; doing it automatically is more so. If they were honest about the key, it'd say "put this on a flash drive/hardcopy in a safe deposit box".

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#86
post #29

http://web.archive.org/web/*/truecrypt.org "Sorry. This URL has been excluded from the Wayback Machine." :-)

That's funny. The normal technique for telling the Wayback Machine not to archive would result in the message "Page cannot be crawled or displayed due to robots.txt.". How do you get "excluded" this way?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#87
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

This is a pretty confusing case, hard to make much of it, LavaBit 2 is of course a possibility. But while we're making these theories, I wanna sound my wild theory: Considering that: (1) TrueCrypt authors go to great to keep their identities hidden, and (2) it turns out TrueCrypt is not free/open software -- TrueCrypt is actually a project by some spooky 3-letter agency.

But anyway, thoughts on alternatives? CiskCryptor (http://en.wikipedia.org/wiki/DiskCryptor) sounds like a nice one, it's FLOSS. Thoughts on it?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#88
post #86
post #29

http://web.archive.org/web/*/truecrypt.org "Sorry. This URL has been excluded from the Wayback Machine." :-)

That's funny. The normal technique for telling the Wayback Machine not to archive would result in the message "Page cannot be crawled or displayed due to robots.txt.". How do you get "excluded" this way?

I don't know about the message, but you can ask for your site to be removed from the Wayback Machine.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#89
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on?

It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate away as XP degrades. It says nothing about whether XP is secure in and of itself.

This whole incident is about as weird as weird gets.

I saw a post that suggested it might be a canary, i.e., an event that must be interpreted as a certain action having taken place...a negative message....an absence of an indication that everything is ok. But that also seems odd since I am not quite sure that if TrueCrypt people were who we all want to believe they were, would suggest using bitLocker. bitLocker??? Alone that suggestion smells like rotten fish just by its association with MS and the US government.

You should put money on the fact that it really was someone associated with certain ever increasingly fascist governments of, likely the USA or Israel, that compromised TrueCrypt in a way that set off an "auto-destruct" sequence. It's probably a reaction to the Snowden compromise, with increased funding and efforts to regain domination that he exposed by becoming even more totalitarian through an "Operation Kristallnacht" sprint against civilian institutions.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#90
post #25

"BitlLocker, the proprietary disk encryption program that ships with every Windows version since Vista." This is misleading - Windows 7 product line has Bitlocker only for Ultimate and Enterprise. Even Windows 7 Professional users cannot use Bitlocker without upgrading to Ultimate. Very unfortunate.

There has been a suggestion that the sourceforge post is a canary triggered in a "self-destruct" sequence. I am wondering if the suggestion to use bitLocker, which as you point out is not available to everyone, is also a signal.

I want to suggest reading into it something that doesn't exist, but why would TrueCrypt people, if they are what we want them to be, suggest using bitLocker of all things. No better alternative and better than nothing??? I don't know how I feel about that.

Post reply on HN