Earlier quoted context omitted.
Looks like its just a 'right-click ... encrypt this file' sort of thing. Doesn't appear to do whole disk encryption or encrypted virtual drives.
Yep, that's why I mentioned file encryption specifically. :) My use case is wanting to have an extra layer of paranoia before I upload anything important to the cloud.
True Goodbye: ‘Using TrueCrypt Is Not Secure’
231–240 of 249 posts
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#232My current favorite insane/facetious conspiracy theory on this: "WARNING: Using TrueCrypt is not secure as ..." WARNING: Using TrueCrypt is (n)ot (s)ecure (a)s ... TrueCrypt is (n)ot (s)ecure (a)s ... (n)ot (s)ecure (a)s TrueCrypt is (n) (s) (a)
Obligatory Half-Life 3 is confirmed, 9/11 was an inside job, etc. etc.
Oh, wait, it's entirely feasible.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#233Earlier quoted context omitted.
The very ability to send it to MS is worrying; doing it automatically is more so. If they were honest about the key, it'd say "put this on a flash drive/hardcopy in a safe deposit box".
You'd make an amazing PM. "Hey, how should we deal with resetting people's passwords and keys when they forget them?" "Tell them to get a safe deposit box" "And when they're traveling or really need a report and the bank's closed? "They shouldn't have lost their keys. Stupid lusers."
"Hey, who are you and how did you get in this meeting?"
"I'm the new intern. From the CIA."
"Oh, okay, yeah, let's do that."
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#234Earlier quoted context omitted.
Surely it would also take very little effort to implement an alternative to truecrypt? What's the big deal
Well implement one. While getting the encryption right is possible. There comes the pesky problems with presenting stuff to windows as a volume that works as well.
http://dokan-dev.net/en/ might work on windows for implementing something you might otherwise do via FUSE. Can't speak for windows as ive not used it for a decade or more.
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#235Earlier quoted context omitted.
I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…
* bitLocker??? Alone that suggestion smells like rotten fish * The Bitlocker recommendation does seem strange. But when you look around the Windows ecosystem, there isn't much else that could be recommended. What would you recommend Windows people use, other than Bitlocker?
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#236Earlier quoted context omitted.
* bitLocker??? Alone that suggestion smells like rotten fish * The Bitlocker recommendation does seem strange. But when you look around the Windows ecosystem, there isn't much else that could be recommended. What would you recommend Windows people use, other than Bitlocker?
I find it interesting that it is only Microsoft Windows users really affected by this. What does that tell you about it as an ecosystem/platform?
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#237Earlier quoted context omitted.
It might be limited in its actions against Americans but that doesn't make me feel any better. Also the program may have been outed but, it looks like some people are keen to keep it running and possibly make it actually legal
(Oh, I was just answering your literal question, very narrowly.)
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#238Earlier quoted context omitted.
Is there something at that Bullrun link that shows the USG uses legal methods (or even illegal methods) to force product makers to insert backdoors into their equipment against the product makers' will?[1] The NSA inserting backdoors into the product without the cooperation or maybe even knowledge of the vendor -- while troubling for any number of reasons -- is vastly different. Especially when giving advice to devel…
Not there, but in the historical record for sure. >Hushmail stated that the Java version is also vulnerable, in that they may be compelled to deliver a compromised java applet to a user. > http://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_p... >Hushmail turned over cleartext copies of private email messages associated with several addresses at the request of law enforcement agencies under a Mutual Legal Assi…
the company that provides Hushmail, states that it will not release any user data without a court order from the Supreme Court of British Columbia,
This is malarkey. Someone in the US could say "I'll fight all the way to the Supreme Court!!!" but you would be a fool to trust your business to their determination. Especially if they say it about a subpoena, which means they haven't even retained a lawyer to ask about this. (If your business plan depends on being able to wage a legal battle, you really shouldn't be scrambling through the yellow pages for a lawyer when you get your first subpoena.)
Back to the topic, I'll have to point out that this still isn't evidence of a company being required to backdoor a product. Hushmail, the same company that thinks it can fight a subpoena for third-party data all the way to the Supreme Court, said "well, we might be compelled to backdoor our product." This is just more repeating of the meme without evidence. It's unfortunate because some developer who remembers Hushmail might take their ill-informed legal opinion as reality.
Of course, Hushmail had access to cleartext copies of the messages. That's the killer. The government has the right to evidence about third parties in your possession. (Canada derives from British law tradition like the US. The government's right to all evidence is a concept that goes back centuries. If you can show that Canada broke from this tradition I would be most interested.)
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#239Earlier quoted context omitted.
> * There is no requirement for TrueCrypt to "help out the government" in this case.* That's what the publicly available laws say, but America has secret interpretations of laws now. We know, for example, that every Internet service is, in theory, free to provide tools that would put user data out of reach of anyone with, or without a warrant. And yet, nobody has. Nobody except Silent Circle, who have decided to domi…
> publicly available law If you have a business in America, you signed the Patriot Act. That's probably the law they are using for coöperation :)
The fact that nobody is doing that is a kind of probe. Do we really live in a free country, or is pervasive monitoring a condition being imposed on us, with no choice of services that would prevent it?
Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’
#240Earlier quoted context omitted.
I find it interesting that it is only Microsoft Windows users really affected by this. What does that tell you about it as an ecosystem/platform?
It tells me all kinds of things that we've all known since the 90s.