True Goodbye: ‘Using TrueCrypt Is Not Secure’
101–110 of 249 posts
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#102Earlier quoted context omitted.
That is nonsense. The TrueCrypt developers turned over code and assisted in the initial audit. iSEC found no serious issues. Granted they only evaluated the bootloader under the first contract, but if you were going to slip in a backdoor or if a serious crypto bypass would be possible it would have likely been there.
Which TrueCrypt developers? AFAIK we don't know them yet … and why was it necessary to turn over code for an alleged open source project? iSEC has not found serious issues but that was only phase 1 of the audit.
(It was somewhat unusual to compile on Linux, since it started as a Windows GUI project and was then ported to Linux.)
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#103Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...
How about AxCrypt for file encryption? http://www.axantum.com/axcrypt/ (I phrase this as a question because it'd be great if we could have some HN skepticism on this thing. Personally, I think everything basically checks out: open source, free, there's a name, phone number, address, picture etc.)
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#104Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)
Surely it would also take very little effort to implement an alternative to truecrypt? What's the big deal
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#105Is this a warrant canary?
If we really really stretch, TrueCrypt had server logs that would show who downloaded it that they might be compelled to turn over. This would be an overreaction to such a request.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#106Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...
The only downside I see is that 7zip seems to be almost abandonware at this point. The installer linked at the top of their page is almost 4 years old and there's a recent beta but they haven't moved a beta to stable in a very long time.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#107Truecrypt is dead, long live ChipCrypt: a Truecrypt fork with TRESOR and scrypt built in. TRESOR is a technique that keeps the volume key strictly in the CPU registers and not in RAM. This completely prevents RAM freezing and related attacks. A running computer that is locked cannot be trivially decrypted anymore by dumping it's RAM. Scrypt is an advanced password derivation function that makes even trivial passwords…
Until an interrupt happens, and the handler saves the registers on the stack. (sad trombone)
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#108That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…
This is a pretty confusing case, hard to make much of it, LavaBit 2 is of course a possibility. But while we're making these theories, I wanna sound my wild theory: Considering that: (1) TrueCrypt authors go to great to keep their identities hidden, and (2) it turns out TrueCrypt is not free/open software -- TrueCrypt is actually a project by some spooky 3-letter agency. But anyway, thoughts on alternatives? CiskCryp…
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#109That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…
I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…
Maybe they migrated away from XP and have assurance that Bitlocker is safe for them or switched to something entirely different and have no interest or funding for development it anymore...