Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

141–150 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#141
I don't see why so many are jumping onto conspiracy theories. Truecrypt, like the page states, has become redundant with built-in OS offerings. While it could be used for other things, the main reason/drive behind its development was the Full Disk Encryption feature, which has only ever worked on Windows, and has only ever truly been "necessary" for Windows XP users. Windows had bitlocker for FDE since Vista, Mac OS X had FDE built-in with Filevault 2 since Lion, and linux since installers started shipping with dm-crypt built-in. Like it or not, with Windows XP being obsoleted there isn't much drive left to develop something like Truecrypt. Just use the built-in OS features.

Re: TrueCrypt suggesting migration to BitLocker?

#142

Earlier quoted context omitted.

Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.

Well, the thing is though, it's not that they were hosting users' data. It's not like they would be forced to provide the contents of users' communication. I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...

Yeah it could be a gag order from a secret court. maybe they folded because they were forced to compromise the code...

Re: TrueCrypt suggesting migration to BitLocker?

#143

Earlier quoted context omitted.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

Same key as the previous binaries? I doubt it, given that the keys were replaced mere 3 hours before the new binaries were published: http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...

Anyone have key fingerprints for pub keys used for the 7.1a vs 7.2 signing? Preferably pub key from a while ago I guess.

Re: TrueCrypt suggesting migration to BitLocker?

#144
Interestingly enough, they also changed the TrueCrypt license.

    -TrueCrypt License Version 3.0
    +TrueCrypt License Version 3.1
This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is signed with the same signing keys, can I legally use the new license in derivative software?

The new license removes the following restrictions regarding attribution:

    -    c. Phrase "Based on TrueCrypt, freely available at
    -    http://www.truecrypt.org/" must be displayed by Your Product
    -    (if technically feasible) and contained in its
    -    documentation. Alternatively, if This Product or its portion
    -    You included in Your Product constitutes only a minor
    -    portion of Your Product, phrase "Portions of this product
    -    are based in part on TrueCrypt, freely available at
    -    http://www.truecrypt.org/" may be displayed instead. In each
    -    of the cases mentioned above in this paragraph,
    -    "http://www.truecrypt.org/" must be a hyperlink (if
    -    technically feasible) pointing to http://www.truecrypt.org/
    -    and You may freely choose the location within the user
    -    interface (if there is any) of Your Product (e.g., an
    -    "About" window, etc.) and the way in which Your Product will
    -    display the respective phrase.

Re: TrueCrypt suggesting migration to BitLocker?

#145

I don't see why so many are jumping onto conspiracy theories. Truecrypt, like the page states, has become redundant with built-in OS offerings. While it could be used for other things, the main reason/drive behind its development was the Full Disk Encryption feature, which has only ever worked on Windows, and has only ever truly been "necessary" for Windows XP users. Windows had bitlocker for FDE since Vista, Mac OS…

There are people in this world that do not trust big corporations with their data. Truecrypt is (was ?) a welcome alternative to Bitlocker and Filevault.

Re: TrueCrypt suggesting migration to BitLocker?

#146
So... the best course is likely a bit of patience. However, is there any way to establish some trustworthy mirrors of 7.1a for those who need it while this is still in the course of blowing over?

(I'm just bringing up some new machines, myself -- I'll have to hunt a bit for local copies from the last time I downloaded (legitimate copies of) the 7.1a version.)

--

P.S. For two recognizable names/sites (to me, at least) near the top of a Google search, FileHippo and CNET are hosting Windows .exe intallers for 7.1a . No signature files, though. And with CNET (download.com), as I seem to recall and last I heard, they practice wrapping the actual product installers inside their own crapware installer.

Re: TrueCrypt suggesting migration to BitLocker?

#147
The interesting thing about this is how everyone is going on about there being no cross-platform alternative. Really, is Truecrypt the only available option? Because that's a pretty sad state of affairs then; there needs to be only one unnoticed bug and pretty much all full disk encryption is broken. Unless you want to chain your data to Microsoft, that is.

Re: TrueCrypt suggesting migration to BitLocker?

#148
post #144

Interestingly enough, they also changed the TrueCrypt license. -TrueCrypt License Version 3.0 +TrueCrypt License Version 3.1 This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is…

Only if the derivative software is based on this 7.2 release, which, given its authenticity is in question, is in violation of the prior license version.

Re: TrueCrypt suggesting migration to BitLocker?

#149
post #144

Interestingly enough, they also changed the TrueCrypt license. -TrueCrypt License Version 3.0 +TrueCrypt License Version 3.1 This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is…

Interesting, especially since the author(s) are anonymous and not working off public repositories, it will be very hard, if not impossible, for them to prove that they did not release this software.
Post reply on HN