Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

221–230 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#221
post #141

Earlier quoted context omitted.

Your (1) partly fails because they'd just toss you in jail until you hand over the key. If they think you're a terrorist that jail might be overseas with no access to lawyers. If they think you're a paedophile they'll just leak that info (and this your life is destroyed). Also, "Truecrypt properly used is a gigantic pain" and although I have nothing to support it I reckon many people use it incorrectly. Has anyone do…

Actually I disagree. The NSA is all about spying. If they can't decrypt what you do without going to you and asking you for the keys (or throwing you in jail) then I would say it -is- a major pain for them. Remember we're talking about an agency who routinely targets one person in the hope to find dirt on others.

On the other hand, the NSA is all about spying. If they can't encrypt their data and keep it secret, they can never get the upper hand.

(The most valuable information is info your enemy doesn't know you know. Information your enemy knows you know is not as powerful)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#222
post #164

My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)

I love this game! "WARNING: Using TrueCrypt is not secure as ..." "WARNING: Using True(C)rypt (i)s not secure (a)s ..." (C) (i) (a) Again! "WARNING: Using TrueCrypt is not secure as ..." "WARNING: Using TrueCrypt i(s) n(o)t (s)ecure as ..." (s) (o) (s)

Not that I think it was intentional, but putting something in that is not grammatically correct like the op version and with no spacing is much stronger than picking random letters from the words to prove a point.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#223

Earlier quoted context omitted.

America has rule of law and the NSA had to go rogue to do what it did; once their program was outed it's on all news, everyone is discussing; Americans enjoy real rights. If China or Russia had the same capabilities there would not be any theoretical backlash against this being discovered, since par for the course there is far less freedom. It's not the abstraction that's promised even theoretically. This is the same…

It might be limited in its actions against Americans but that doesn't make me feel any better. Also the program may have been outed but, it looks like some people are keen to keep it running and possibly make it actually legal

(Oh, I was just answering your literal question, very narrowly.)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#224
Reading through the posted diff, a couple of things stood out to me.

1. The release date string went from "February 7, 2012" in 7.1a to "5/2014" in 7.2 . Might be nothing, but it made me wonder if someone other than the orignal author changed it due to the date style change - I'd've expected it to be changed to "February 2014".

I also wonder why no specific day was given - makes me wonder if the release was automated and the author didn't know exactly when it would happen (possibly a dead man's switch triggered it?). Again, could be nothing.

2. Pretty much every reference to truecrypt.org has been removed - even the licence now states "Your Product [...] must not present any Internet address containing the domain name truecrypt" (instead of truecrypt.org), and there is no requirement to link to it anymore. It might just be a change in licencing stance to encourage forks, or, if the release was made under duress (NSL/threats/blackmail etc.), it might be a way to try and signal that truecrypt.org can no longer be trusted.

Edit: Something is bugging me about this line on the site: "The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP." IT might just how the author writes, but my reaction on reading "was ended" was that something external forced it to stop rather than it being a choice.

Also, why mention XP's EOL? The message doesn't say support for TC stopped _because_ of EOL, just after, and I can't think why the end of XP support would effect TC greatly.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#225

Earlier quoted context omitted.

As far as I know, there's only been speculation on what PRISM is. Nothing that suggests it couldn't be a frontend to CALEA or warrant-based systems. Subsequent Snowden releases made it clear that thdatee NSA has many sources of information that are only "legal" because they said so, including intra-datacenter and international fiber taps, zero day exploits, and physically modified equipment (see photos of network gea…

None of that was part of PRISM.

Let's assume that when people say "PRISM" they mean "digital espionage", and when people say "NSA", they also mean CIA, NRO, FBI, DEA, etc.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#226

Earlier quoted context omitted.

No, bitlocker explicitly send the key to MS for non-domain systems - as such, I would guess it potentially still does for those on a domain too, it'd just be kept quieter. http://windows.microsoft.com/en-us/windows-8/bitlocker-recov... Bitlocker is not trustworthy as an overall method of FDE.

Your link says "There are several locations in which your BitLocker recovery key might have been saved." and then mentions "Your Microsoft account online.". Do you know under which conditions this happens?

[deleted]

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#227

Earlier quoted context omitted.

I love this game! "WARNING: Using TrueCrypt is not secure as ..." "WARNING: Using True(C)rypt (i)s not secure (a)s ..." (C) (i) (a) Again! "WARNING: Using TrueCrypt is not secure as ..." "WARNING: Using TrueCrypt i(s) n(o)t (s)ecure as ..." (s) (o) (s)

Not that I think it was intentional, but putting something in that is not grammatically correct like the op version and with no spacing is much stronger than picking random letters from the words to prove a point.

It's grammatically correct, read the whole sentence. It just looks odd when you take half the sentence out of context.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#228
post #88
post #86

Earlier quoted context omitted.

That's funny. The normal technique for telling the Wayback Machine not to archive would result in the message "Page cannot be crawled or displayed due to robots.txt.". How do you get "excluded" this way?

I don't know about the message, but you can ask for your site to be removed from the Wayback Machine.

[deleted]

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#229
post #89
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…

It's not a panic about XP. The presented reasoning is:

- XP is the only widely used version of Windows with no built-in FDE

- XP is finally, truly, EOL

So TrueCrypt no longer needs to exist.

(I'm not arguing that- that is what the message is saying)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#230
post #115

Earlier quoted context omitted.

No, there a big differences with Lavabit. Lavabit was a service, TrueCrypt is a product. Lavabit had access to all their customers' data, and told investigators that they had it. It's completely straightforward law that, given a subpoena, Lavabit must turn over evidence to the government. TrueCrypt is a product. They do not have access to customer data. There is no requirement for TrueCrypt to "help out the governmen…

> * There is no requirement for TrueCrypt to "help out the government" in this case.* That's what the publicly available laws say, but America has secret interpretations of laws now. We know, for example, that every Internet service is, in theory, free to provide tools that would put user data out of reach of anyone with, or without a warrant. And yet, nobody has. Nobody except Silent Circle, who have decided to domi…

> publicly available law

If you have a business in America, you signed the Patriot Act. That's probably the law they are using for coöperation :)

Post reply on HN