Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

101–110 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#102

In case this is legit: Bitlocker so far so good, but neither Bitlocker nor any other crypto solution offer plausible deniability (aka hidden volumes).

I've heard multiple rumors that the NSA has a backdoor in Bitlocker. I don't trust any of this.

Re: TrueCrypt suggesting migration to BitLocker?

#103
I tried sending a message to their contact email PGP-encrypted to their public key, asking them for a PGP-signed confirmation. And it came back:

550 5.1.1 : Recipient address rejected: User unknown in local

If they got hacked, it's not just their sourceforge account.

Re: TrueCrypt suggesting migration to BitLocker?

#104

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

This is legit and I am willing to bet.

https://gist.github.com/anonymous/e5791d5703325b9cf6d1

The entire source has been modified to reflect the Sourceforge page its contents. Encryption process is disabled. The current binaries can only be used to "migrate". You can deface a webpage but the effort it takes to rewrite the entire source code, compromise the GPG, compromise domain, compromise mail servers et cetera is not minimal.

It is happening. Whether they are being forced to do so is a whole different story.

Re: TrueCrypt suggesting migration to BitLocker?

#107

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

* That's a lot of wasted effort for a defacement with seemingly no motive except some (uncredited) lulz.

* Possible, but once again I see no motive that would produce this brand of outburst.

* And it's unfixable? That would be a world first.

I think it's much more plausible this is some powerful entity forcing a hand. We know by now there's plenty of motive and candidates to fit that shoe.

Re: TrueCrypt suggesting migration to BitLocker?

#109
post #81

Earlier quoted context omitted.

That would not result in a message of "True Crypt Is Not Secure!!!!" in bold red. Seems to be geared towards frightening people. I concur -- likely an elaborate website deface.

As irrational it may be, I've seen people writing something like that out of frustrations... I don't think any legit organization would do that, but what if it's maintained by a small team or even individual -- I don't think I've ever seen a single face of TrueCrypt developers out there...

Good point.

If true, I'd much rather have them post a countdown clock and say "If we don't reach X funding goal in donations by date Y, then we will be forced to close the project". Funds would come in then... a lot of people depend on truecrypt.

Re: TrueCrypt suggesting migration to BitLocker?

#110
post #99

Earlier quoted context omitted.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

Here's the source code diff https://www.alchemistowl.org/arrigo/truecrypt-7.1a-7.2.diff....

Time to call in the underhanded C contest (http://underhanded.xcott.com/) participants on a special bugfinding challenge :)
Post reply on HN