Live data from Hacker News

"Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

cryptome.org

11–20 of 62 posts

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#11
A few gems in here besides the TrueCrypt statement, mainly that Apple iCloud and Dropbox are named, and the legal framework is touched upon.

  All cloud stored content are automatically hash-scanned
  and image-analyzed by their service providers and
  infringing content reported to NCMEC (p16)

  Mobile content are automatically scanned when they are
  synced with cloud storage like Apple iCloud or Dropbox.
  Mobile devices that are not cloud-synced can be accessed
  by their respective vendors (p16)
If I am reading this correctly, when you upload something to Apple iCloud or Dropbox, there is a background process which generates a hash of your content, then compares that hash with infringing content? What defense do companies have? What about proof that these claims are true (sources, etc)? Can anyone just leak a document that claims XYZ tech company spies on its users and everyone takes this as fact?

  Vendors are legally and commercially prevented from
  acknowledging their backdoors. Defense will not be
  able to prove their existence (p16)
Great, blanket denial either way! I hope this is a hoax!

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#12

EDIT: Ignore that. I figured a slide show would not skip slides when you use arrow keys for navigation. Can I get a direct quote? I'm not seeing any mention of TC on p15 or any other page.

I'll quote it here anyway, for the benefit of other readers -

What’s A Backdoor? • A method to bypass data encryption or security • Does not require the password or passphrase to be known • Saves time, cost and effort to access encrypted or secured data • Allows data to be accessed, copied and even modified without tipping off the owner • Currently available for major encryption software – Microsoft Bitlocker, FileVault, BestCrypt, TrueCrypt, etc • Currently implemented by major cloud storage provider to comply with NCMEC requirements

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#13
This really doesn't sound legit. I suspect they might be thinking of backdooring the truecrypt client, which, really wouldn't make it much of a feat.

The container format itself is really just a giant mathematical mess -- there really isn't anything to backdoor there.

And then the client doesn't exactly dial-out to anything when you mount an encrypted volume. Therefore I would suggest that this is probably a matter of using alternative means of access to the machine in order to patch the client itself.

That wouldn't exactly be worthy of the attention of the NSA, given that truecrypt is open-source.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#14
post #6

Truecrypt is open source. Can anyone find the backdoor?

A bit of Googling got me:

"Is Truecrypt A CIA honeypot" http://www.privacylover.com/encryption/analysis-is-there-a-b...

Seems like paranoia is looking just in general more plausible today.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#16
post #13

This really doesn't sound legit. I suspect they might be thinking of backdooring the truecrypt client , which, really wouldn't make it much of a feat. The container format itself is really just a giant mathematical mess -- there really isn't anything to backdoor there. And then the client doesn't exactly dial-out to anything when you mount an encrypted volume. Therefore I would suggest that this is probably a matter…

user: xarball created: 2 minutes ago

Any reason you're using a throwaway?

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#17
post #5

Page 16 has some wonderful lines: • “Fruit of the poisonous tree” can be circumvented • The use of backdoors cannot be detected or proven • Vendors are legally and commercially prevented from acknowledging their backdoors. Defense will not be able to prove their existence • The files can be described as “forensically obtained”

FOTPT: http://www.law.cornell.edu/wex/fruit_of_the_poisonous_tree

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#18
post #2

Wouldn't any backdoor used in a criminal prosecution have to be disclosed to the defense?

Nope, this is what Ginsburg would call an instruction manual for how to defeat the 4th amendment.

  The use of backdoors cannot be detected or proven

  Vendors are legally and commercially prevented from acknowledging their backdoors. Defense will not be able to prove their existence

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#19

A few gems in here besides the TrueCrypt statement, mainly that Apple iCloud and Dropbox are named, and the legal framework is touched upon. All cloud stored content are automatically hash-scanned and image-analyzed by their service providers and infringing content reported to NCMEC (p16) Mobile content are automatically scanned when they are synced with cloud storage like Apple iCloud or Dropbox. Mobile devices that…

You missed a big one there.

    Mobile devices that are not cloud-synced can be accessed 
    by their respective vendors 
Essentially; iOS and Android have a remote backdoor available to the US government.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#20

A few gems in here besides the TrueCrypt statement, mainly that Apple iCloud and Dropbox are named, and the legal framework is touched upon. All cloud stored content are automatically hash-scanned and image-analyzed by their service providers and infringing content reported to NCMEC (p16) Mobile content are automatically scanned when they are synced with cloud storage like Apple iCloud or Dropbox. Mobile devices that…

Well, here is the one for last year. How many times do they have to tell us?

http://www.ndsaa.org/Computer_Forensics_for_Prosecutors.pdf

Post reply on HN