Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

131–140 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#131

Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...

How about AxCrypt for file encryption? http://www.axantum.com/axcrypt/ (I phrase this as a question because it'd be great if we could have some HN skepticism on this thing. Personally, I think everything basically checks out: open source, free, there's a name, phone number, address, picture etc.)

I worked on a small software package for a financial firm that used AxCrypt for encryption. It wasn't bad from a program integration perspective. I can't personally verify the cryptographic security of it. Like codeulike said, it's a per-file based encryption. No virtual disk services.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#133

Earlier quoted context omitted.

Because this happened to 7.2. Chances are, this is a warrant canary, and people will take the last known good 7.1 (i.e. the one that is being audited) and build their forks from there.

1. 7.2 just disabled things. It didn't introduce a vulnerability. 2. Warrant canary makes no sense. There is nothing for a warrant to grab. 3. Forking is legally troublesome. Just because you can see the source doesn't mean you can distribute the source.

>1. 7.2 just disabled things. It didn't introduce a vulnerability.

I had a look at the diff; I have neither the time nor crypto-specific skill to do an audit, but there are plenty of code changes that aren't warnings in there.

>2. Warrant canary makes no sense. There is nothing for a warrant to grab.

No, but they could have theoretically been asked to introduce a backdoor from a Lavabit-style order.

>3. Forking is legally troublesome. Just because you can see the source doesn't mean you can distribute the source.

Do you think that will stop people? Even if there is some legal issue, the Streisand Effect always overcomes it. So what if a TrueCrypt fork can't use Github because of that issue? Is the world suddenly lacking good hosting providers, perhaps in Switzerland or similar? Has everyone forgotten how to set up a public git repo themselves? Somehow, I think not. So what if many devs will probably have to contribute anonymously? With a product such as TrueCrypt, they probably should anyway.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#134

Earlier quoted context omitted.

How about AxCrypt for file encryption? http://www.axantum.com/axcrypt/ (I phrase this as a question because it'd be great if we could have some HN skepticism on this thing. Personally, I think everything basically checks out: open source, free, there's a name, phone number, address, picture etc.)

Looks like its just a 'right-click ... encrypt this file' sort of thing. Doesn't appear to do whole disk encryption or encrypted virtual drives.

Yep, that's why I mentioned file encryption specifically. :)

My use case is wanting to have an extra layer of paranoia before I upload anything important to the cloud.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#135
post #130

Earlier quoted context omitted.

No, there a big differences with Lavabit. Lavabit was a service, TrueCrypt is a product. Lavabit had access to all their customers' data, and told investigators that they had it. It's completely straightforward law that, given a subpoena, Lavabit must turn over evidence to the government. TrueCrypt is a product. They do not have access to customer data. There is no requirement for TrueCrypt to "help out the governmen…

You're correct to point out the useful distinction that TrueCrypt is a product. But what makes you think U.S. law treats them any differently, assuming TrueCrypt's creators and maintainers can be identified? Here's my article from 8 years ago talking about how the FBI was demanding that makers of certain products include backdoors for FedGov surveillance: http://news.cnet.com/FBI-plans-new-Net-tapping-push/2100-102..…

Your use of "demand" is misleading. Your own words at the time say "drafted sweeping legislation." Did that legislation pass?

Anyone can "draft legislation." I can draft legislation right now. That doesn't make it U.S. law. Getting it passed is the hard part.

Phone companies are required to enable wiretaps. But that happened through the public legislative process, and the legislation even lets the phone company bill the government for costs to comply. (Your linked article explicitly points out CALEA.)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#136

This seems highly suspicious, especially the recommendation of BitLocker, a product we have little to no evidence does what it says and after PRISM, have no reason to trust[2]; not to mention it being limited to a (very small subset of) Windows platforms vs. TrueCrypt's cross-platform functionality. If this was legit[1], it'd probably be directing people to one of the other TrueCrypt-like programs. [1]The new version…

There's alot of FUD in your statement there. BitLocker in it's "click click next" incarnation stores keys in the cloud, but it is fairly trivial to install in a manner that uses the TPM or external media for key storage. For example, NIST publishes guidelines for FIPS compliant BitLocker configuration that gives some guidlines re: the different operating modes: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140…

Bitlocker is also closed source. Truecrypt is (was?) open source.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#137
post #77

Earlier quoted context omitted.

I don't see this as particularly unprofessional or petulant. The owner/manager of the project didn't want to keep maintaining it and is redirecting users to an alternative that will work for almost all use cases. As of last month, there were reported flaws in TrueCrypt and there's nothing that forces a maintainer of a free project to keep going. I'm left almost a little annoyed that the conversation isn't "RIP TrueCr…

You can't just post an announcement like that in the current climate of suspicion and expect everyone to just ignore the possible implications.

Alright, I'll play. How long of an explanation are the users of a free service entitled to receive before the maintainer can happily go his/her way without follow-ups? Development of Truecrypt stopped, and as it's open-source, someone else could keep hacking away on it.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#138

Earlier quoted context omitted.

1. 7.2 just disabled things. It didn't introduce a vulnerability. 2. Warrant canary makes no sense. There is nothing for a warrant to grab. 3. Forking is legally troublesome. Just because you can see the source doesn't mean you can distribute the source.

>1. 7.2 just disabled things. It didn't introduce a vulnerability. I had a look at the diff; I have neither the time nor crypto-specific skill to do an audit, but there are plenty of code changes that aren't warnings in there. >2. Warrant canary makes no sense. There is nothing for a warrant to grab. No, but they could have theoretically been asked to introduce a backdoor from a Lavabit-style order. >3. Forking is le…

been asked to introduce a backdoor from a Lavabit-style order

This makes no sense. Lavabit was compelled to turn over evidence it told the government it had, which is straightforward law. There is nothing "Lavabit-style" about "distribute a back door or else." You would need explicit legislation to allow that. If the developer's cat was kidnapped to force him to put in a backdoor, there is nothing "Lavabit-style" about that.

You do hedge with the word "theoretically," but "theoretically" this could be a message from the aliens.

Do you think that will stop people?

It will stop the smart people, and you need smart people to work on it. Otherwise you would only be allowed to distribute it by illicit means, and you could never trust it. It would be as trustworthy as warez sites. Why even bother with that nonsense?

Much saner to just build something new, having learned from TrueCrypt's experiences. For example, something that starts from the command-line and then has a GUI in top, instead of the reverse.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#139
Here's my theory (step-by-step):

1. Truecrypt is a gigantic pain-in-the-side for US intelligence agencies.

2. Intelligence agencies brainstorm about the best way to deal with the situation.

3. Taking over and tampering with the current code is deemed unrealistic. The user base of Truecrypt is very sophisticated and even minor changes to the source code would be scrutinized.

4. "How can be get people to stop using Truecrypt?" "We can discredit the project - get people to voluntarily stop using it because they don't trust it".

Post reply on HN