Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

101–110 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#102
post #96
post #8

Earlier quoted context omitted.

That is nonsense. The TrueCrypt developers turned over code and assisted in the initial audit. iSEC found no serious issues. Granted they only evaluated the bootloader under the first contract, but if you were going to slip in a backdoor or if a serious crypto bypass would be possible it would have likely been there.

Which TrueCrypt developers? AFAIK we don't know them yet … and why was it necessary to turn over code for an alleged open source project? iSEC has not found serious issues but that was only phase 1 of the audit.

It wasn't "Open Source™." The source, however, was available, and you could compile it yourself if you wished.

(It was somewhat unusual to compile on Linux, since it started as a Windows GUI project and was then ported to Linux.)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#103

Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...

How about AxCrypt for file encryption? http://www.axantum.com/axcrypt/ (I phrase this as a question because it'd be great if we could have some HN skepticism on this thing. Personally, I think everything basically checks out: open source, free, there's a name, phone number, address, picture etc.)

Looks like its just a 'right-click ... encrypt this file' sort of thing. Doesn't appear to do whole disk encryption or encrypted virtual drives.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#104
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

Surely it would also take very little effort to implement an alternative to truecrypt? What's the big deal

If you are being sarcastic, you should be aware of Poe's law, which means we can't tell.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#105
post #47

Is this a warrant canary?

A warrant is how the government compels you to turn over evidence you have. TrueCrypt does not have any access to its users' keys or data.

If we really really stretch, TrueCrypt had server logs that would show who downloaded it that they might be compelled to turn over. This would be an overreaction to such a request.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#106

Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...

For non-full disk I just make AES encrypted files using 7zip. Considering just about everyone has 7zip installed its actually less of a pain in the ass that you'd think.

The only downside I see is that 7zip seems to be almost abandonware at this point. The installer linked at the top of their page is almost 4 years old and there's a recent beta but they haven't moved a beta to stable in a very long time.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#107

Truecrypt is dead, long live ChipCrypt: a Truecrypt fork with TRESOR and scrypt built in. TRESOR is a technique that keeps the volume key strictly in the CPU registers and not in RAM. This completely prevents RAM freezing and related attacks. A running computer that is locked cannot be trivially decrypted anymore by dumping it's RAM. Scrypt is an advanced password derivation function that makes even trivial passwords…

"TRESOR is a technique that keeps the volume key strictly in the CPU registers and not in RAM. This completely prevents RAM freezing and related attacks."

Until an interrupt happens, and the handler saves the registers on the stack. (sad trombone)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#108
post #87
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

This is a pretty confusing case, hard to make much of it, LavaBit 2 is of course a possibility. But while we're making these theories, I wanna sound my wild theory: Considering that: (1) TrueCrypt authors go to great to keep their identities hidden, and (2) it turns out TrueCrypt is not free/open software -- TrueCrypt is actually a project by some spooky 3-letter agency. But anyway, thoughts on alternatives? CiskCryp…

I really don't think we need to be running to TrueCrypt alternatives quite yet. If Phase II of the audit comes back showing TrueCrypt as insecure, then it's time to start worrying about that, but given that everyone was happy to keep using TrueCrypt up until 1 day ago even though it hasn't been updated in over 2 years, I don't think there's any big rush to switch to something else even if ongoing development stops.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#109
post #89
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…

Just another theory but consider that the TrueCrypt team was always anonymous and considering that their licence is somewhat prohibitive for a open-source project it's not totally bonkers to assume that some agency or big coorporation developed TrueCrypt in secret and made it public to gain widespread assurance that there are no bugs in the code.

Maybe they migrated away from XP and have assurance that Bitlocker is safe for them or switched to something entirely different and have no interest or funding for development it anymore...

Post reply on HN