Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

171–180 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#171
post #2

"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software." "'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'" "I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”

If the audit made them call it quits, then having them cough up the source and abandon the project for someone else to pick up is the perfect outcome.

We already have the source.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#172

Earlier quoted context omitted.

A screenshot that says "We have the recovery key", but zero indication of how they got it? The previous slide could not possibly be something related to dumping RAM, could it? Or perhaps an optional Microsoft-account feature to back up your encryption keys. Something that most normal users would want, just like they want it on Apple devices? Because a lot of common users aren't going to want FDE if it means "oh and l…

As far as I know, there's only been speculation on what PRISM is. Nothing that suggests it couldn't be a frontend to CALEA or warrant-based systems. Subsequent Snowden releases made it clear that thdatee NSA has many sources of information that are only "legal" because they said so, including intra-datacenter and international fiber taps, zero day exploits, and physically modified equipment (see photos of network gea…

None of that was part of PRISM.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#173
post #141
post #139

Here's my theory (step-by-step): 1. Truecrypt is a gigantic pain-in-the-side for US intelligence agencies. 2. Intelligence agencies brainstorm about the best way to deal with the situation. 3. Taking over and tampering with the current code is deemed unrealistic. The user base of Truecrypt is very sophisticated and even minor changes to the source code would be scrutinized. 4. "How can be get people to stop using Tru…

Your (1) partly fails because they'd just toss you in jail until you hand over the key. If they think you're a terrorist that jail might be overseas with no access to lawyers. If they think you're a paedophile they'll just leak that info (and this your life is destroyed). Also, "Truecrypt properly used is a gigantic pain" and although I have nothing to support it I reckon many people use it incorrectly. Has anyone do…

Or they could simply use rubber-hose cryptanalysis.

http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#174

Earlier quoted context omitted.

>But that also seems odd since I am not quite sure that if TrueCrypt people were who we all want to believe they were, would suggest using bitLocker. bitLocker??? Alone that suggestion smells like rotten fish just by its association with MS and the US government. That's the canary. Not only is bitlocker backdoored, and most TrueCrypt users would know that, but they also say it is available on all windows versions, wh…

Isn't a canary something that is 'removed', not 'added'? As in, the canary warns by being absent.

Not in this case [1], or rather, not always. And if you consider where the term arose (canaries in mines), it's really an issue of state more than it is absence. If the state of the canary changes it's cause for alarm.

In this situation, warrant canaries (or maybe an NSL canary as the case might be) is a subtle indication that everything is no longer in a known-good state and something has been compromised.

Although given some of the comments by danielweber, I'm increasingly less inclined to believe this was a canary. Developers throwing in the towel might be a more plausible situation, no matter how disappointing that may be.

[1] http://en.wikipedia.org/wiki/Warrant_canary

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#175
post #148

Earlier quoted context omitted.

We are talking about a government that has, in the recent past, sent nastygrams to people telling them that not only did they have to comply with the orders in the letter, but that it would be a crime to consult a lawyer about the letter. So you, a non-lawyer developer, get one of these letters. You are pretty damn sure it is a bluff (didn't that clause in NSLs get shot down? Pretty sure I heard something about that.…

This is pretty much why I said "If you want to hang a conspiracy theory on this news[1], find some hook besides Lavabit." Linking an abuse like you describe to Lavabit only harms developers, who if they were to receive such an illegal demand might remember "wait, Lavabit was required to install back doors, right? I guess I have to, as well!"

I'm not even talking about Lavabit. They have done this to others (it was unconstitutional at the time, but was not yet declared as such). They could do it again. Only the most selfless person would be able to bring it to the publics attention.

Until the current regime is dismantled, we cannot rule out the possibility that these abuses are ongoing. To label it as a conspiracy theory is just shameless apologetics.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#176
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

Another interesting thing is that in the diff for 7.1a and 7.2 the author changed U.S. to United States several times. Some people think this is to draw attention to it being related to the US government

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#177
post #130

Earlier quoted context omitted.

You're correct to point out the useful distinction that TrueCrypt is a product. But what makes you think U.S. law treats them any differently, assuming TrueCrypt's creators and maintainers can be identified? Here's my article from 8 years ago talking about how the FBI was demanding that makers of certain products include backdoors for FedGov surveillance: http://news.cnet.com/FBI-plans-new-Net-tapping-push/2100-102..…

Your use of "demand" is misleading. Your own words at the time say "drafted sweeping legislation." Did that legislation pass? Anyone can "draft legislation." I can draft legislation right now. That doesn't make it U.S. law. Getting it passed is the hard part. Phone companies are required to enable wiretaps. But that happened through the public legislative process, and the legislation even lets the phone company bill…

I'll repeat my question, which you ignored in favor of quibbling with a tangential point: What makes you think U.S. law treats makers of products any differently, assuming TrueCrypt's creators and maintainers can be identified?

If you want examples of FBI surveillance untethered to the law, we can provide those. Look at the video of the public forum I hosted with Ladar (of Lavabit) in SF last fall. Look at warrantless cell tracking, which I was the first to disclose circa 2006, and which is now the subject of significant litigation. Look at the warrantless use -- not just by the bureau but other police agencies as well -- of physical GPS tracking devices. How about surreptitious black bag jobs to install key loggers to extract PGP passphrases before this was authorized by the 2001 Patriot Act?

Here's another from last summer, which I was the first to disclose:

http://www.cnet.com/news/fbi-pressures-internet-providers-to... "The U.S. government is quietly pressuring telecommunications providers to install eavesdropping technology deep inside companies' internal networks to facilitate surveillance efforts..."

Huh! Where does the FBI get the legal authority to do that? Shouldn't, you know, Congress set the rules here after openly debating them in a public hearing?

Again, all these points are tangential to the question of FedGov product backdoors. (Note I'm expressing no opinion here about what's going on with TrueCrypt.) This survey I did in 2007 is probably worth repeating: http://news.cnet.com/Will+security+firms+detect+police+spywa...

I'm no longer doing this kind of reporting (and left to found the SF-area startup http://recent.io instead) but I hope someone tries to replicate it today with a broader set of companies.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#178
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

Another interesting thing is that in the diff for 7.1a and 7.2 the author changed U.S. to United States several times. Some people think this is to draw attention to it being related to the US government

But other people point out that Visual Studio changed its default name for America from the former to the latter.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#179
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

There's another possibility that I haven't seen mentioned yet.

It could be that the developer(s) want to get out anyway. The fact that they've been doing it for so long indicates that they've got some strong feelings about privacy.

Perhaps they're staging the whole thing as their way out, to make a political statement, pushing us further to do something about the government's stand on privacy.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#180
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

I love this game!

    "WARNING: Using TrueCrypt is not secure as ..."
    "WARNING: Using True(C)rypt (i)s not secure (a)s ..."

                        (C)     (i)             (a)
Again!

    "WARNING: Using TrueCrypt is not secure as ..."
    "WARNING: Using TrueCrypt i(s) n(o)t (s)ecure as ..."

                               (s)  (o)  (s)
Post reply on HN