Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

111–120 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#111

Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...

I just want to point out that TrueCrypt is open(ish) source and the license was modified in the latest update in such a way that could be interpreted as allowing forks (and it's unlikely that the TrueCrypt devs would ever actually deanonymize to enforce any license violations anyway). Considering that we've all been happy to keep using TrueCrypt for these last 2 years without even minor updates and the Phase II audit is going on as planned, I think it's a bit premature to be looking into alternatives at this point. I would give it a better than average chance of being forked, and it's already stable, well-tested, cross-platform software that can be used in the meantime. There are mirrors of version 7.1a available to anyone who didn't already have TrueCrypt installed.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#112

Earlier quoted context omitted.

I think that's why they are quitting. They didn't want the audit to find something. But it's just a speculation like any other.

I doubt that's the reason - Greene says that the audit is going ahead. The other fact that makes this unlikely is that Green's team has the source, so his team can poke around all it likes anyway. Ergo quitting is no guarantee that something won't be found.

But quitting and hence most likely ending the project will substantially increase the chance that Green decides spending the rest of the money auditing it is a waste of cash.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#113

Earlier quoted context omitted.

Would this be a Lavabit-like situation? The governement asking for a backdoor and the developers are refusing it. Suddenly (while there is an audit), they quit everything, change the assemblies and the website, so users can get to another product... It seems weird that after 10 years of hard-work, they suddenly quit without further explanation.

Yes and recommending Bitlocker is how they are trying to tip everyone off that this message is compromised.

[deleted]

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#114

This seems highly suspicious, especially the recommendation of BitLocker, a product we have little to no evidence does what it says and after PRISM, have no reason to trust[2]; not to mention it being limited to a (very small subset of) Windows platforms vs. TrueCrypt's cross-platform functionality. If this was legit[1], it'd probably be directing people to one of the other TrueCrypt-like programs. [1]The new version…

A screenshot that says "We have the recovery key", but zero indication of how they got it? The previous slide could not possibly be something related to dumping RAM, could it? Or perhaps an optional Microsoft-account feature to back up your encryption keys. Something that most normal users would want, just like they want it on Apple devices? Because a lot of common users aren't going to want FDE if it means "oh and l…

As far as I know, there's only been speculation on what PRISM is. Nothing that suggests it couldn't be a frontend to CALEA or warrant-based systems.

Subsequent Snowden releases made it clear that thdatee NSA has many sources of information that are only "legal" because they said so, including intra-datacenter and international fiber taps, zero day exploits, and physically modified equipment (see photos of network gear being intercepted and bugged).

In other words, this paragraph might have been reasonable a year ago, but is now grossly out of date

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#115

Earlier quoted context omitted.

Would this be a Lavabit-like situation? The governement asking for a backdoor and the developers are refusing it. Suddenly (while there is an audit), they quit everything, change the assemblies and the website, so users can get to another product... It seems weird that after 10 years of hard-work, they suddenly quit without further explanation.

No, there a big differences with Lavabit. Lavabit was a service, TrueCrypt is a product. Lavabit had access to all their customers' data, and told investigators that they had it. It's completely straightforward law that, given a subpoena, Lavabit must turn over evidence to the government. TrueCrypt is a product. They do not have access to customer data. There is no requirement for TrueCrypt to "help out the governmen…

> * There is no requirement for TrueCrypt to "help out the government" in this case.*

That's what the publicly available laws say, but America has secret interpretations of laws now. We know, for example, that every Internet service is, in theory, free to provide tools that would put user data out of reach of anyone with, or without a warrant. And yet, nobody has.

Nobody except Silent Circle, who have decided to domicile their company in Switzerland, is a new entrant based on the premise of providing truly secure communication. So, what to make of all the CEO-level complaining but no end-to-end encryption tools and no web-of-trust?

If a major Internet portal provided end-to-end secure mail, real-time communications, and secure storage we would know that, yes, there is no legal or extralegal obligation to keep us all naked in the panopticon. But so far all the indicators are in the wrong direction.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#116
post #77

Earlier quoted context omitted.

Makes the most sense yet. The question that was asked in response to that Slashdot post was why anyone would choose to quit the way they did (unprofessional and so on), and this doesn't sway me. If I lost my star dev and couldn't follow the code myself I might (speculation, as ever) well be petulant enough for this mess. There may be any number of factors behind it, ranging from animosity within the team to fear or s…

I don't see this as particularly unprofessional or petulant. The owner/manager of the project didn't want to keep maintaining it and is redirecting users to an alternative that will work for almost all use cases. As of last month, there were reported flaws in TrueCrypt and there's nothing that forces a maintainer of a free project to keep going. I'm left almost a little annoyed that the conversation isn't "RIP TrueCr…

You can't just post an announcement like that in the current climate of suspicion and expect everyone to just ignore the possible implications.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#117
post #89

Earlier quoted context omitted.

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…

* bitLocker??? Alone that suggestion smells like rotten fish * The Bitlocker recommendation does seem strange. But when you look around the Windows ecosystem, there isn't much else that could be recommended. What would you recommend Windows people use, other than Bitlocker?

TrueCrypt 7.1a is still safe to use. So is GPG.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#118

Earlier quoted context omitted.

The very ability to send it to MS is worrying; doing it automatically is more so. If they were honest about the key, it'd say "put this on a flash drive/hardcopy in a safe deposit box".

Lift with your knees, not your back. Those goalposts are heavy.

[deleted]

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#119
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

Surely it would also take very little effort to implement an alternative to truecrypt? What's the big deal

Well implement one. While getting the encryption right is possible. There comes the pesky problems with presenting stuff to windows as a volume that works as well.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#120
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

If TruCrypt got taken over, it should tell us something that they recommended Bitlocker (about Bitlocker).
Post reply on HN