True Goodbye: ‘Using TrueCrypt Is Not Secure’
191–200 of 249 posts
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#192Earlier quoted context omitted.
I really don't think we need to be running to TrueCrypt alternatives quite yet. If Phase II of the audit comes back showing TrueCrypt as insecure, then it's time to start worrying about that, but given that everyone was happy to keep using TrueCrypt up until 1 day ago even though it hasn't been updated in over 2 years, I don't think there's any big rush to switch to something else even if ongoing development stops.
"given that everyone was happy to keep using TrueCrypt up until 1 day ago" The same was true for OpenSSL a few weeks ago. One of the most plausible theories is that the TrueCrypt developers found a gaping security hole (ala OpenSSL) and realised that releasing a fix for it would reveal the bug and compromise every TrueCrypt partition in existence, so they chose to kill the project rather than risk the safety of all o…
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#193Earlier quoted context omitted.
There's alot of FUD in your statement there. BitLocker in it's "click click next" incarnation stores keys in the cloud, but it is fairly trivial to install in a manner that uses the TPM or external media for key storage. For example, NIST publishes guidelines for FIPS compliant BitLocker configuration that gives some guidlines re: the different operating modes: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140…
My point is that as it's closed source, we still don't know whether it sends the key to MS anyway (even if the user asks not to link it to their hotmail account). Given MS' complicity in PRISM, it's not a leap of trust I'm willing to make.
The more plausible potential for Bitlocker being broken is that there is some subtle flaw in their crypto implementation.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#194Earlier quoted context omitted.
This is pretty much why I said "If you want to hang a conspiracy theory on this news[1], find some hook besides Lavabit." Linking an abuse like you describe to Lavabit only harms developers, who if they were to receive such an illegal demand might remember "wait, Lavabit was required to install back doors, right? I guess I have to, as well!"
I'm not even talking about Lavabit. They have done this to others (it was unconstitutional at the time, but was not yet declared as such). They could do it again. Only the most selfless person would be able to bring it to the publics attention. Until the current regime is dismantled, we cannot rule out the possibility that these abuses are ongoing. To label it as a conspiracy theory is just shameless apologetics.
What's "this"? Is it "the USG compels vendors to install back doors into their software products they ship to others, under threat of jail time and/or fine and/or vacation at Gitmo"? To whom was this done?
NSLs are nasty in many ways. That doesn't mean they are nasty in any way you can imagine.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#195I can't think of a reason why they'd remove sources for earlier versions from SF. I mean, in this day and age somebody is going to upload them again to the internet.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#196Earlier quoted context omitted.
If that were true, and they were so sure of the quality of their code then they'd keep going, wait for the all clear and say: "Look, we've been doing this for 10 years, our system is now independently audited, will you please support us..." I suspect that would have brought in a few dollars in the current climate.
They are humans, not all of which are objectivists. In fact Matthew Green himself has mentioned the possibility of insulting the developers: http://blog.cryptographyengineering.com/2013/10/lets-audit-t... Aren't you worried you'll insult the Truecrypt developers? I sure hope not, since we're all after the same thing. Remember, our goal isn't to find some mythical back door in Truecrypt, but rather, to wipe away any d…
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#197I can't think of a reason why they'd remove sources for earlier versions from SF. I mean, in this day and age somebody is going to upload them again to the internet.
Considering the licensing, its likely that the developers wanted to keep development to themselves, and never turn it over to someone else. If the ragequit theory is correct, its fairly reasonable for them to remove the previous versions to make a fork slightly more difficult, especially since it would be an illegitimate fork.
If ragequitting, why bother with making a new release instead of just removing _everything_ and changing the webpage? (Presumably, you already have a copy of the SW if you have encrypted volumes.)
Also, note "you _should_ migrate data". Could this imply that cold storage is not secure?
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#198That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…
The whole message on the site makes no sense and I think that's on purpose. What likely happened is the US gov found the TC authors, then used their weight to try and get them to back door the binaries. Authors didn't want to, but couldn't publicize the letters without going to jail, so they made up the most ridiculous story for why they were giving up on the project, the best possible outcome so that they wouldn't g…
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#199Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#200My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)
Use any integrated support for encryption. Search available installation packages for words encryption and crypt, install any of the packages found and follow its documentation"""
>>> ''.join(a[0] for a in s.split())
'IyhfebToLUaisfeSaipfweaciaotpfafid'
That short string contains "beast of the apocalypse" [1] plus some other letters ('iuififwaifafi')
[1] https://en.wikipedia.org/wiki/The_Beast_(Revelation) - "The second beast is described in Revelation 13:11-18 and is also referred to as the false prophet."