Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

1–10 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#2
"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software."

"'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'"

"I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#3
post #2

"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software." "'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'" "I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”

I think that's why they are quitting. They didn't want the audit to find something. But it's just a speculation like any other.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#5
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

That would be my opinion, but then I'd probably bet everything I own on BitLocker containing a backdoor of some sort.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#7
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

There are pros and cons to both closed source and open source. Open source is nice because the community can audit the code and see for themselves, but closed-source is nice because a company generally has the resources to maintain and build software correctly.

Both of these are hypothetical, however. We've seen tons of vulnerabilities from both. IMHO Open Source works a lot better on paper but once projects get very large auditing them is really hard...which definitely cuts down on the amount of eyes looking at them.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#8
post #2

"[Matthew] Green last year helped spearhead dual crowdfunding efforts to raise money for a full-scale, professional security audit of the software." "'I think the TrueCrypt team did this,' Green said in a phone interview. 'They decided to quit and this is their signature way of doing it.'" "I’m a little worried that the fact we were doing an audit of the crypto might have made them decide to call it quits.”

That is nonsense. The TrueCrypt developers turned over code and assisted in the initial audit. iSEC found no serious issues.

Granted they only evaluated the bootloader under the first contract, but if you were going to slip in a backdoor or if a serious crypto bypass would be possible it would have likely been there.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#9
post #7
post #4

Out of curiosity, wouldn't the open-source TrueCrypt be better than the closed BitLocker? (assuming, of course, that TrueCrypt was not already compromised)

There are pros and cons to both closed source and open source. Open source is nice because the community can audit the code and see for themselves, but closed-source is nice because a company generally has the resources to maintain and build software correctly. Both of these are hypothetical, however. We've seen tons of vulnerabilities from both. IMHO Open Source works a lot better on paper but once projects get very…

>>closed-source is nice because a company generally has the resources to maintain and build software correctly.

These two things are orthogonal, IMHO.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#10
Why isn't BitLocker open source? If the new CEO wants to show he's serious about user privacy, I think opening up BitLocker and letting everyone look inside would be a great start.

One of the reasons I like iPhone is the idea that the security system and drive encryption is not hopelessly broken. It would be great to have the same level of confidence in BitLocker.

Post reply on HN