Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

141–150 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#141
post #139

Here's my theory (step-by-step): 1. Truecrypt is a gigantic pain-in-the-side for US intelligence agencies. 2. Intelligence agencies brainstorm about the best way to deal with the situation. 3. Taking over and tampering with the current code is deemed unrealistic. The user base of Truecrypt is very sophisticated and even minor changes to the source code would be scrutinized. 4. "How can be get people to stop using Tru…

Your (1) partly fails because they'd just toss you in jail until you hand over the key. If they think you're a terrorist that jail might be overseas with no access to lawyers. If they think you're a paedophile they'll just leak that info (and this your life is destroyed).

Also, "Truecrypt properly used is a gigantic pain" and although I have nothing to support it I reckon many people use it incorrectly. Has anyone done any research?

See "deanonymizing alt.anonymous.messages" for examples of people doing crypto wrong.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#142
post #78

Earlier quoted context omitted.

It's more likely that they were angry that the audit got a lot of funds and they didn't. In OSS often the people who do the original work get nothing and all the money goes to pundits, packagers, and consultants.

If that were true, and they were so sure of the quality of their code then they'd keep going, wait for the all clear and say: "Look, we've been doing this for 10 years, our system is now independently audited, will you please support us..." I suspect that would have brought in a few dollars in the current climate.

the "current climate" is one where security defects lead to highly visible public witch hunts and shaming and then the forking of code (see: OpenSSL). OpenSSL only just today got funding and an additional two developers. Despite pretty much the entire world using and depending on it for years now. Despite the fact that it's open source and anyone anywhere could have taken the time to conduct an audit.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#143

Earlier quoted context omitted.

Why is that worse?

America has rule of law and the NSA had to go rogue to do what it did; once their program was outed it's on all news, everyone is discussing; Americans enjoy real rights. If China or Russia had the same capabilities there would not be any theoretical backlash against this being discovered, since par for the course there is far less freedom. It's not the abstraction that's promised even theoretically. This is the same…

LOL! You fucking retard. I much prefer the russians or China have my stuff to the megalomaniac US going around all over thwe world killing people or suing them to bankruptcy.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#144
If the TrueCrypt devs are done with the project, is there anything legally preventing others from restarting development on it? I know the software had an oddball license that wasn't always well-received.

My point here being, with the source being available, why do we need to assume that TrueCrypt is history, other than perhaps a lack of people willing to work on it (which I assume could change now that there is an immediate need for some)?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#145

Earlier quoted context omitted.

Would this be a Lavabit-like situation? The governement asking for a backdoor and the developers are refusing it. Suddenly (while there is an audit), they quit everything, change the assemblies and the website, so users can get to another product... It seems weird that after 10 years of hard-work, they suddenly quit without further explanation.

Yes and recommending Bitlocker is how they are trying to tip everyone off that this message is compromised.

Reminiscent of Jeremiah Denton, the American prisoner of war in Vietnam, who was forced to appear before the cameras to say how well he was being treated - but used the opportunity to blink out "TORTURE" in morse code, to place those words in context.

https://en.wikipedia.org/wiki/Jeremiah_Denton

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#146
post #87

Earlier quoted context omitted.

This is a pretty confusing case, hard to make much of it, LavaBit 2 is of course a possibility. But while we're making these theories, I wanna sound my wild theory: Considering that: (1) TrueCrypt authors go to great to keep their identities hidden, and (2) it turns out TrueCrypt is not free/open software -- TrueCrypt is actually a project by some spooky 3-letter agency. But anyway, thoughts on alternatives? CiskCryp…

I really don't think we need to be running to TrueCrypt alternatives quite yet. If Phase II of the audit comes back showing TrueCrypt as insecure, then it's time to start worrying about that, but given that everyone was happy to keep using TrueCrypt up until 1 day ago even though it hasn't been updated in over 2 years, I don't think there's any big rush to switch to something else even if ongoing development stops.

[deleted]

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#147

Truecrypt is dead, long live ChipCrypt: a Truecrypt fork with TRESOR and scrypt built in. TRESOR is a technique that keeps the volume key strictly in the CPU registers and not in RAM. This completely prevents RAM freezing and related attacks. A running computer that is locked cannot be trivially decrypted anymore by dumping it's RAM. Scrypt is an advanced password derivation function that makes even trivial passwords…

"TRESOR is a technique that keeps the volume key strictly in the CPU registers and not in RAM. This completely prevents RAM freezing and related attacks." Until an interrupt happens, and the handler saves the registers on the stack. (sad trombone)

Actually, they use the internal CPU debug registers which aren't automatically saved - in fact they whole purpose is to trigger a context save when the hardware break-point is hit and invoke the debugger.

If breakpoints are disabled, using 8 1 bit flags contained in the registers, you have a whooping 6x32-8=184 bits of storage on x86 and 376 bits of storage on x64.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#148
post #130

Earlier quoted context omitted.

You're correct to point out the useful distinction that TrueCrypt is a product. But what makes you think U.S. law treats them any differently, assuming TrueCrypt's creators and maintainers can be identified? Here's my article from 8 years ago talking about how the FBI was demanding that makers of certain products include backdoors for FedGov surveillance: http://news.cnet.com/FBI-plans-new-Net-tapping-push/2100-102..…

Your use of "demand" is misleading. Your own words at the time say "drafted sweeping legislation." Did that legislation pass? Anyone can "draft legislation." I can draft legislation right now. That doesn't make it U.S. law. Getting it passed is the hard part. Phone companies are required to enable wiretaps. But that happened through the public legislative process, and the legislation even lets the phone company bill…

We are talking about a government that has, in the recent past, sent nastygrams to people telling them that not only did they have to comply with the orders in the letter, but that it would be a crime to consult a lawyer about the letter.

So you, a non-lawyer developer, get one of these letters. You are pretty damn sure it is a bluff (didn't that clause in NSLs get shot down? Pretty sure I heard something about that... Something about Nicholas Merrill?). What if you are wrong though? What if this is a different kind of letter that you and the rest of the general public are currently unfamiliar with? What if the government has found a new way to create such a clause? Is "pretty damn sure" a high enough standard of sureness for you to call their bluff and talk to a lawyer anyway? How much do you value your freedom, and how much do you value your work?

Not being willing to call their bluff and contact a lawyer means that you are not able to question or interpret anything else in that letter as well. The best you can do is ask the government to interpret the letter for you, and tell you exactly what you need to do in order to comply.

The next best option is likely to burn what they want to the ground.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#149

Earlier quoted context omitted.

Yes and recommending Bitlocker is how they are trying to tip everyone off that this message is compromised.

Reminiscent of Jeremiah Denton, the American prisoner of war in Vietnam, who was forced to appear before the cameras to say how well he was being treated - but used the opportunity to blink out "TORTURE" in morse code, to place those words in context. https://en.wikipedia.org/wiki/Jeremiah_Denton

See also, POWs 'flipping the bird' in propaganda photographs: http://www.usspueblo.org/Prisoners/The_Digit_Affair.html

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#150

Earlier quoted context omitted.

There's alot of FUD in your statement there. BitLocker in it's "click click next" incarnation stores keys in the cloud, but it is fairly trivial to install in a manner that uses the TPM or external media for key storage. For example, NIST publishes guidelines for FIPS compliant BitLocker configuration that gives some guidlines re: the different operating modes: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140…

My point is that as it's closed source, we still don't know whether it sends the key to MS anyway (even if the user asks not to link it to their hotmail account). Given MS' complicity in PRISM, it's not a leap of trust I'm willing to make.

Truecrypt has been around for a decade, and only now is someone getting around to doing a real audit. The people behind Truecrypt are completely unknown, and may well be the NSA for all we know. So do you trust them?
Post reply on HN