True Goodbye: ‘Using TrueCrypt Is Not Secure’
121–130 of 249 posts
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#122"BitlLocker, the proprietary disk encryption program that ships with every Windows version since Vista." This is misleading - Windows 7 product line has Bitlocker only for Ultimate and Enterprise. Even Windows 7 Professional users cannot use Bitlocker without upgrading to Ultimate. Very unfortunate.
There has been a suggestion that the sourceforge post is a canary triggered in a "self-destruct" sequence. I am wondering if the suggestion to use bitLocker, which as you point out is not available to everyone, is also a signal. I want to suggest reading into it something that doesn't exist, but why would TrueCrypt people, if they are what we want them to be, suggest using bitLocker of all things. No better alternati…
https://twitter.com/matthew_d_green/status/47199831543788339...
http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev...
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#123This seems highly suspicious, especially the recommendation of BitLocker, a product we have little to no evidence does what it says and after PRISM, have no reason to trust[2]; not to mention it being limited to a (very small subset of) Windows platforms vs. TrueCrypt's cross-platform functionality. If this was legit[1], it'd probably be directing people to one of the other TrueCrypt-like programs. [1]The new version…
BitLocker in it's "click click next" incarnation stores keys in the cloud, but it is fairly trivial to install in a manner that uses the TPM or external media for key storage.
For example, NIST publishes guidelines for FIPS compliant BitLocker configuration that gives some guidlines re: the different operating modes: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140sp/1...
If you have the technical chops / willingness to download TrueCrypt, you should have the ability to spend 10 minutes googling for instructions on a customized configuration of BitLocker.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#124Earlier quoted context omitted.
* bitLocker??? Alone that suggestion smells like rotten fish * The Bitlocker recommendation does seem strange. But when you look around the Windows ecosystem, there isn't much else that could be recommended. What would you recommend Windows people use, other than Bitlocker?
TrueCrypt 7.1a is still safe to use. So is GPG.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#125That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…
I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…
That's the canary.
Not only is bitlocker backdoored, and most TrueCrypt users would know that, but they also say it is available on all windows versions, which is eminently not the case.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#126Earlier quoted context omitted.
TrueCrypt 7.1a is still safe to use. So is GPG.
how do you conclude that any TrueCrypt version is secure in light of this disclosure?
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#127This seems highly suspicious, especially the recommendation of BitLocker, a product we have little to no evidence does what it says and after PRISM, have no reason to trust[2]; not to mention it being limited to a (very small subset of) Windows platforms vs. TrueCrypt's cross-platform functionality. If this was legit[1], it'd probably be directing people to one of the other TrueCrypt-like programs. [1]The new version…
There's alot of FUD in your statement there. BitLocker in it's "click click next" incarnation stores keys in the cloud, but it is fairly trivial to install in a manner that uses the TPM or external media for key storage. For example, NIST publishes guidelines for FIPS compliant BitLocker configuration that gives some guidlines re: the different operating modes: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140…
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#128That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…
I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…
https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...
He needed to get some older version of Visual Studio and a very specific combination of service packs and updates in order to get to matching (nearly) the entire binary.
Could it be that the devs really wanted to keep developing in XP because some part of their dev chain required it, but with support being discontinued they of course couldn't run XP and consider that computer "secure" to develop on?
Obviously, if this theory has some grain of truth to it, it can only be part of the explanation for the TrueCrypt weirdness that's been going on today.
If I had to bet on it, I would say it's most likely they got Lavabitten. But then still, the XP remark seems like a very odd choice if it's intended to function as a canary of sorts.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#129Earlier quoted context omitted.
how do you conclude that any TrueCrypt version is secure in light of this disclosure?
Because this happened to 7.2. Chances are, this is a warrant canary, and people will take the last known good 7.1 (i.e. the one that is being audited) and build their forks from there.
2. Warrant canary makes no sense. There is nothing for a warrant to grab.
3. Forking is legally troublesome. Just because you can see the source doesn't mean you can distribute the source.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#130Earlier quoted context omitted.
Would this be a Lavabit-like situation? The governement asking for a backdoor and the developers are refusing it. Suddenly (while there is an audit), they quit everything, change the assemblies and the website, so users can get to another product... It seems weird that after 10 years of hard-work, they suddenly quit without further explanation.
No, there a big differences with Lavabit. Lavabit was a service, TrueCrypt is a product. Lavabit had access to all their customers' data, and told investigators that they had it. It's completely straightforward law that, given a subpoena, Lavabit must turn over evidence to the government. TrueCrypt is a product. They do not have access to customer data. There is no requirement for TrueCrypt to "help out the governmen…
But what makes you think U.S. law treats them any differently, assuming TrueCrypt's creators and maintainers can be identified?
Here's my article from 8 years ago talking about how the FBI was demanding that makers of certain products include backdoors for FedGov surveillance:
http://news.cnet.com/FBI-plans-new-Net-tapping-push/2100-102... The FBI has drafted sweeping legislation that would...force makers of networking gear to build in backdoors for eavesdropping... FBI Agent Barry Smith distributed the proposal at a private meeting last Friday with industry representatives and indicated it would be introduced by Sen. Mike DeWine, an Ohio Republican, according to two sources familiar with the meeting...