Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

91–100 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#91
post #89
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…

* bitLocker??? Alone that suggestion smells like rotten fish *

The Bitlocker recommendation does seem strange. But when you look around the Windows ecosystem, there isn't much else that could be recommended. What would you recommend Windows people use, other than Bitlocker?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#92
post #30

Maybe the developers were Americans and they decided to bail before they get caught for exporting cryptographic software.

Wasn't that settled in like 1996?

From Wikipedia [0]:

As of 2009, non-military cryptography exports from the U.S. are controlled by the Department of Commerce's Bureau of Industry and Security.[9] Some restrictions still exist, even for mass market products, particularly with regard to export to "rogue states" and terrorist organizations. Militarized encryption equipment, TEMPEST-approved electronics, custom cryptographic software, and even cryptographic consulting services still require an export license[9](pp. 6–7). Furthermore, encryption registration with the BIS is required for the export of "mass market encryption commodities, software and components with encryption exceeding 64 bits" (75 F.R. 36494). In addition, other items require a one-time review by or notification to BIS prior to export to most countries.[9] For instance, the BIS must be notified before open-source cryptographic software is made publicly available on the Internet, though no review is required.[10] Export regulations have been relaxed from pre-1996 standards, but are still complex.[9] Other countries, notably those participating in the Wassenaar Arrangement,[11] have similar restrictions.[12]

[0] http://en.wikipedia.org/wiki/Export_of_cryptography_from_the...

[9] http://www.access.gpo.gov/bis/ear/pdf/ccl5-pt2.pdf

[10] http://www.bis.doc.gov/encryption/pubavailencsourcecodenofif...

[11] http://www.wassenaar.org/participants/index.html

[12] http://www.wassenaar.org/guidelines/docs/Initial%20Elements%...

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#93
post #89
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…

[deleted]

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#94
post #78

Earlier quoted context omitted.

It's more likely that they were angry that the audit got a lot of funds and they didn't. In OSS often the people who do the original work get nothing and all the money goes to pundits, packagers, and consultants.

If that were true, and they were so sure of the quality of their code then they'd keep going, wait for the all clear and say: "Look, we've been doing this for 10 years, our system is now independently audited, will you please support us..." I suspect that would have brought in a few dollars in the current climate.

If the system works fine, and the auditors are paid and they have certified that the system works, where is the need for any more financial support? I agree that the work should be recognized, but there is no need to pay to support work that has already been completed, as anyone who's ever applied for a research grant already knows.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#95

This seems highly suspicious, especially the recommendation of BitLocker, a product we have little to no evidence does what it says and after PRISM, have no reason to trust[2]; not to mention it being limited to a (very small subset of) Windows platforms vs. TrueCrypt's cross-platform functionality. If this was legit[1], it'd probably be directing people to one of the other TrueCrypt-like programs. [1]The new version…

Would this be a Lavabit-like situation? The governement asking for a backdoor and the developers are refusing it. Suddenly (while there is an audit), they quit everything, change the assemblies and the website, so users can get to another product... It seems weird that after 10 years of hard-work, they suddenly quit without further explanation.

No, there a big differences with Lavabit.

Lavabit was a service, TrueCrypt is a product.

Lavabit had access to all their customers' data, and told investigators that they had it. It's completely straightforward law that, given a subpoena, Lavabit must turn over evidence to the government.

TrueCrypt is a product. They do not have access to customer data. There is no requirement for TrueCrypt to "help out the government" in this case.

If you want to hang a conspiracy theory on this news[1], find some hook besides Lavabit.

[1] And I can't fault the conspiracy theorists for trying to find some explanation over this, because the damn thing is so weird and unusual.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#96
post #8
post #2

"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software." "'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'" "I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”

That is nonsense. The TrueCrypt developers turned over code and assisted in the initial audit. iSEC found no serious issues. Granted they only evaluated the bootloader under the first contract, but if you were going to slip in a backdoor or if a serious crypto bypass would be possible it would have likely been there.

Which TrueCrypt developers? AFAIK we don't know them yet … and why was it necessary to turn over code for an alleged open source project?

iSEC has not found serious issues but that was only phase 1 of the audit.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#97

Earlier quoted context omitted.

I think that's why they are quitting. They didn't want the audit to find something. But it's just a speculation like any other.

It's more likely that they were angry that the audit got a lot of funds and they didn't. In OSS often the people who do the original work get nothing and all the money goes to pundits, packagers, and consultants.

Just that there are no known 'people who do the original work' in the case of TrueCrypt.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#98
post #10

Why isn't BitLocker open source? If the new CEO wants to show he's serious about user privacy, I think opening up BitLocker and letting everyone look inside would be a great start. One of the reasons I like iPhone is the idea that the security system and drive encryption is not hopelessly broken. It would be great to have the same level of confidence in BitLocker.

> One of the reasons I like iPhone is the idea that the security system and drive encryption is not hopelessly broken. Where can you get the source of that?

There is no source for that. Data on iOS devices is not even fully encrypted and accessible to law enforcement agencies etc.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#99
post #78

Earlier quoted context omitted.

It's more likely that they were angry that the audit got a lot of funds and they didn't. In OSS often the people who do the original work get nothing and all the money goes to pundits, packagers, and consultants.

If that were true, and they were so sure of the quality of their code then they'd keep going, wait for the all clear and say: "Look, we've been doing this for 10 years, our system is now independently audited, will you please support us..." I suspect that would have brought in a few dollars in the current climate.

That might make sense in a world of perfectly rational unemotional robots.

In the real world, if you worked for years trying to make people safe, and you felt (correctly or not) that you were being disrespected while others were being respected for picking at your nits, you might say "fine, fuck you all, have fun," too.

To be clear, I don't know what's going on. A "rage quit" is the most likely scenario IMHO, but this is all very weird.

EDIT: On reflection, a rage quit fits my priors, which say "there's no such thing as free-as-in-beer[1] software." So you and I should both be a little skeptical when I find it the likely explanation.

[1] It does exists, but it's the exception, and each project where it works has its own particular quirks that make it work. The successful ones typically rely on someone having a particular and unusual mental setup that doesn't mind free loaders. Stallman and de Raadt develop software for their own use, and the rest of us can use it, too.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#100
post #83

Earlier quoted context omitted.

You previously said it "definitely sends your recovery key to MS." Sounds like you don't actually mean that. It's fine and perfectly reasonable not to trust closed-source code, but no reason to spread half-truths about it.

The very ability to send it to MS is worrying; doing it automatically is more so. If they were honest about the key, it'd say "put this on a flash drive/hardcopy in a safe deposit box".

Lift with your knees, not your back. Those goalposts are heavy.
Post reply on HN