Live data from Hacker News

German BSI withholds Truecrypt security report

golem.de

11–20 of 86 posts

Re: German BSI withholds Truecrypt security report

#11
post #5

> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…

Truecrypt has been abandoned for ~seven years or so.

Development was continued by the VeraCrypt project. Hopefully they fixed the vulnerabilities that TrueCrypt didn't.

Re: German BSI withholds Truecrypt security report

#12
post #5

> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…

But did the VeraCrypt developers know about it?

Re: German BSI withholds Truecrypt security report

#14

It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them. I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the d…

When the developers of a product pay for a third-party security assessment, the results are usually confidential - after all, who'd pay to have their product publicly badmouthed?

Perhaps BSI was merely attempting to provide such a service for free.

Re: German BSI withholds Truecrypt security report

#17
post #2

Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22

Either they had to do that, or they had to be ready for the barrage of incoming requests for the documents.

Which gives the "withhold" part of the story a strong push towards Hanlon's Razor, once the topic escalated to higher ranks the copyright ceased to be a hindrance.

Or more precisely, towards an organizational variety of Hanlon's Razor, where stupidity takes the form of the organizational failure mode of underlings not being authorized to do what would have been the right thing.

Curiously, a less colloquial formulation of Hanlon's Razor would replace stupidity with incompetence and this, when translated to German contains a hint of a precisely matching double entendre: in German, "Kompetenz" is used for two separate things. For being able to (like in English) and being authorized to. It's not a full double entendre because the negated form "Inkompetenz" is exclusive to the mental ability, just like the English counterpart, but what's a good aphorism without subtle extra layers?

Re: German BSI withholds Truecrypt security report

#18
post #5

> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerabil…

But did the VeraCrypt developers know about it?

According to the article they didn't know about it.

Re: German BSI withholds Truecrypt security report

#19
post #7

Earlier quoted context omitted.

> since this information would be relevant to the developers and many state entities that use the software and its successor. The BSI actually did communicate the findings of the report to the TrueCrypt developers in 2010, which the developers ignored: > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the result…

Yes, but they neglected to tell the veracrypt developers once truecrypt stopped being developed. Though they also do know many municipalities using both applications. They should have told the veracrypt developers and advised the municipalities to switch to the newer version. And the whole argument about the information being outdated by then when both are clearly in use seems negligent of their duties.

Those municipalities should dump Vera and TrueCrypt containers, under eIDAS they should really be using .asice for interoperability.

Re: German BSI withholds Truecrypt security report

#20
post #2

Note, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22

Either they had to do that, or they had to be ready for the barrage of incoming requests for the documents.

[deleted]
Post reply on HN