Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

211–220 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#211
post #154

Earlier quoted context omitted.

> "There is nothing "Lavabit-style" about "distribute a back door or else." You would need explicit legislation to allow that." http://en.wikipedia.org/wiki/Bullrun_(decryption_program) No legislastion authorizes that program, among many others. I think what the parent was referring to as "Lavabit-style" was the "compromise your users or face legal action" move. Turning over customer data or introducing a backdoor ar…

Is there something at that Bullrun link that shows the USG uses legal methods (or even illegal methods) to force product makers to insert backdoors into their equipment against the product makers' will?[1] The NSA inserting backdoors into the product without the cooperation or maybe even knowledge of the vendor -- while troubling for any number of reasons -- is vastly different. Especially when giving advice to devel…

Not there, but in the historical record for sure.

>Hushmail stated that the Java version is also vulnerable, in that they may be compelled to deliver a compromised java applet to a user.

>http://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_p...

>Hushmail turned over cleartext copies of private email messages associated with several addresses at the request of law enforcement agencies under a Mutual Legal Assistance Treaty with the United States.; e.g. in the case of U.S. v. Tyler Stumbo.

>if a court order has been issued by the Supreme Court of British Columbia compelling us to reveal the content of your encrypted email, the "attacker" could be Hush Communications, the actual service provider.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#212
post #160

Earlier quoted context omitted.

> after PRISM People seem to keep forgetting this (I'm sure it's simply unintentional), but PRISM was and still is nothing much more than an automated warrant/NSL compliance system. You're basically saying that Microsoft is complicit in divulging information in response to specific requests made under specific legislative authorities, which was standard hat since even before Smith v. Maryland.

well, I can see where you're coming from, but automation changes the nature. license plates on cars wasn't a big deal, it was primarily used to identify stolen cars and track drivers breaking the law. Then automation entered the picture and it became feasible to track the movements of everyone, aggregate it in a huge database, and claim "they might be criminals later". PRISM is more of the same, they could of compell…

But here automation is only automating the hard part (doing the collection correctly and in accordance with company policies).

Remember, with PRISM each and every request has to be approved by the company in question before it proceeds, which is still a manual step. So the license plate reader example doesn't apply directly; Rather it might be like a license plate reader that only works when activated by a remote magistrate, only for the one car permitted by that activation, but can continue scanning that one car's license plate from then on wherever it's seen in the city until the permission expires.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#213
post #207
post #87

Earlier quoted context omitted.

This is a pretty confusing case, hard to make much of it, LavaBit 2 is of course a possibility. But while we're making these theories, I wanna sound my wild theory: Considering that: (1) TrueCrypt authors go to great to keep their identities hidden, and (2) it turns out TrueCrypt is not free/open software -- TrueCrypt is actually a project by some spooky 3-letter agency. But anyway, thoughts on alternatives? CiskCryp…

TrueCrypt authors go to great to keep their identities hidden I donated at least two times to them via PayPal. How anonymous could they be if they got funds via PayPal? Not very, in this day and age. I would image it's trivial for the US government to find their true names based on this fact alone.

Since this thread is all about paranoia, how did you verify that anyone ultimately received the funds?

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#215
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

When you harbor some pet assumption, the entire world conspires to verify your assumption.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#216
post #213
post #207

Earlier quoted context omitted.

TrueCrypt authors go to great to keep their identities hidden I donated at least two times to them via PayPal. How anonymous could they be if they got funds via PayPal? Not very, in this day and age. I would image it's trivial for the US government to find their true names based on this fact alone.

Since this thread is all about paranoia, how did you verify that anyone ultimately received the funds?

Obviously, I could not. truecrypt.org had a donate button which redirected to a paypal page, and I donated. I'm assuming they wouldn't set up a donation method that merely gave the funds to paypal.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#217

Earlier quoted context omitted.

Why is that worse?

America has rule of law and the NSA had to go rogue to do what it did; once their program was outed it's on all news, everyone is discussing; Americans enjoy real rights. If China or Russia had the same capabilities there would not be any theoretical backlash against this being discovered, since par for the course there is far less freedom. It's not the abstraction that's promised even theoretically. This is the same…

It might be limited in its actions against Americans but that doesn't make me feel any better.

Also the program may have been outed but, it looks like some people are keen to keep it running and possibly make it actually legal

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#218
post #83

Earlier quoted context omitted.

You previously said it "definitely sends your recovery key to MS." Sounds like you don't actually mean that. It's fine and perfectly reasonable not to trust closed-source code, but no reason to spread half-truths about it.

The very ability to send it to MS is worrying; doing it automatically is more so. If they were honest about the key, it'd say "put this on a flash drive/hardcopy in a safe deposit box".

You'd make an amazing PM.

"Hey, how should we deal with resetting people's passwords and keys when they forget them?"

"Tell them to get a safe deposit box"

"And when they're traveling or really need a report and the bank's closed?

"They shouldn't have lost their keys. Stupid lusers."

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#219

Earlier quoted context omitted.

Truecrypt has been around for a decade, and only now is someone getting around to doing a real audit. The people behind Truecrypt are completely unknown, and may well be the NSA for all we know. So do you trust them?

I personally trust open source and audited system much more than closed-source system shipped with Windows (apparently).

It isn't audited yet though.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#220
post #215
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

When you harbor some pet assumption, the entire world conspires to verify your assumption.

More random tidbits of folk-wisdom. This neither helps us further along on any idea(for/against/neither). Merely a blank truism.
Post reply on HN