Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

161–170 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#161

Are there any decent alternatives to TrueCrypt for Windows that aren't Bitlocker? http://superuser.com/questions/760091/windows-encrypted-virt...

I wrote a blog posting with similar products to TC:

http://nothingjustworks.com/so-long-truecrypt-what-now/

Nothing really turn-key but you can mix and match a couple different products and get the same results.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#162
post #154

Earlier quoted context omitted.

been asked to introduce a backdoor from a Lavabit-style order This makes no sense. Lavabit was compelled to turn over evidence it told the government it had, which is straightforward law. There is nothing "Lavabit-style" about "distribute a back door or else." You would need explicit legislation to allow that. If the developer's cat was kidnapped to force him to put in a backdoor, there is nothing "Lavabit-style" abo…

> "There is nothing "Lavabit-style" about "distribute a back door or else." You would need explicit legislation to allow that." http://en.wikipedia.org/wiki/Bullrun_(decryption_program) No legislastion authorizes that program, among many others. I think what the parent was referring to as "Lavabit-style" was the "compromise your users or face legal action" move. Turning over customer data or introducing a backdoor ar…

Is there something at that Bullrun link that shows the USG uses legal methods (or even illegal methods) to force product makers to insert backdoors into their equipment against the product makers' will?[1]

The NSA inserting backdoors into the product without the cooperation or maybe even knowledge of the vendor -- while troubling for any number of reasons -- is vastly different. Especially when giving advice to developers about how to stay in bounds with the law. If the metagame becomes "the government can legally force you to insert backdoors into your product" any developer faced with this threat might believe it, when he should know it's bunk.

[1] RSA allegedly got paid $10 million to make a change the NSA wanted. RSA customers should demand an answer, but that's not forcing the RSA. People get paid to do things all the time.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#163
post #89

Earlier quoted context omitted.

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…

Another theory is that some component of the development environment to compile TrueCrypt requires XP. Remember the guy that tried to compile the TC source to match the binary? https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie... He needed to get some older version of Visual Studio and a very specific combination of service packs and updates in order to get to matching (nearly) the entire binary. Could it…

> Another theory is that some component of the development environment to compile TrueCrypt requires XP

This seems unlikely: the screenshots in your link clearly show the source could be built on Windows 7. The trouble Xavier mentions is with the updates to VS2008 SP1, not Windows service packs.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#164
My current favorite insane/facetious conspiracy theory on this:

    "WARNING: Using TrueCrypt is not secure as ..."
     WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ...
                    TrueCrypt is (n)ot (s)ecure (a)s ...
                                 (n)ot (s)ecure (a)s

                    TrueCrypt is (n)   (s)      (a)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#165
post #96
post #8

Earlier quoted context omitted.

That is nonsense. The TrueCrypt developers turned over code and assisted in the initial audit. iSEC found no serious issues. Granted they only evaluated the bootloader under the first contract, but if you were going to slip in a backdoor or if a serious crypto bypass would be possible it would have likely been there.

Which TrueCrypt developers? AFAIK we don't know them yet … and why was it necessary to turn over code for an alleged open source project? iSEC has not found serious issues but that was only phase 1 of the audit.

The project was in contact with TrueCrypt developers (someone who could sign messages using the release keys, and provide images of the build machine that is nearly impossible to reproduce).

They reviewed the bootloader which is one of the most complex parts and touched all the crypto and found no serious issues. That suggests that the rest of the mundane code is probably in pretty good shape.

Of course it is not a guarantee that things are perfect, but it suggests that the developers a) knew what they were doing b) had no issues with an external audit.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#166
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

Obligatory Half-Life 3 is confirmed, 9/11 was an inside job, etc. etc.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#167
post #159

Earlier quoted context omitted.

I really don't think we need to be running to TrueCrypt alternatives quite yet. If Phase II of the audit comes back showing TrueCrypt as insecure, then it's time to start worrying about that, but given that everyone was happy to keep using TrueCrypt up until 1 day ago even though it hasn't been updated in over 2 years, I don't think there's any big rush to switch to something else even if ongoing development stops.

"given that everyone was happy to keep using TrueCrypt up until 1 day ago" The same was true for OpenSSL a few weeks ago. One of the most plausible theories is that the TrueCrypt developers found a gaping security hole (ala OpenSSL) and realised that releasing a fix for it would reveal the bug and compromise every TrueCrypt partition in existence, so they chose to kill the project rather than risk the safety of all o…

If that was the case, why not fix the bug and then tell everybody to upgrade to the new fixed version ASAP?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#169
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

Well the very next sentence continues "This page exists only to help migrate existing data encrypted by TrueCrypt" which could easily be read as a prepared response to the person brandishing the NSL who is now annoyed that the authors have suddenly decided that right NOW is an 'entirely natural' time to end the project.
Post reply on HN