Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

161–170 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#161
post #66

This is creepy as hell. No mention of why it's supposed to be not secure - it's an open source project so it would be easy to point to a specific vulnerability. All of this shortly after passing audit. There are detailed steps towards switching to supposedly secure closed-source solutions by companies known to be working closely with the NSA. Also, since when do open source projects suddenly decide they are not as go…

It doesn't matter why. If "we are now insecure" then the last thing you say is, "so please download these new versions, used only to decrypt your old files and nothing else." No we won't tell you what, if anything, was wrong, so you can make an informed decision.

The motivation would be so that if you had a TrueCrypt archive lying around on a drive that you find in 5 years time, it would be possible to decrypt it - but they don't want to allow encryption because they won't be continuing development, and so fixing future bugs will not be possible.

Re: TrueCrypt suggesting migration to BitLocker?

#162
post #154
post #85

Earlier quoted context omitted.

NSA is obviously in on it. Who else would recommend using holy-bug-riddled proprietary-back-doored-on-purpose encryption software? ;-P

I choose to believe Niels Ferguson when he says "Over my dead body.": http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...

2 things.

1) Obviously I was joking in my comment above.

2) That post is dated well before common knowledge of how "in-bed" Microsoft is with the USA spy agencies (at least management is).

This is a topic for another discussion, but I just want to point out that, of course someone being coerced under gag order to install less-than above-water "features" and/or purposefully weaken the product would say exactly what is in the blog post.

Re: TrueCrypt suggesting migration to BitLocker?

#163

I don't see why so many are jumping onto conspiracy theories. Truecrypt, like the page states, has become redundant with built-in OS offerings. While it could be used for other things, the main reason/drive behind its development was the Full Disk Encryption feature, which has only ever worked on Windows, and has only ever truly been "necessary" for Windows XP users. Windows had bitlocker for FDE since Vista, Mac OS…

There are people in this world that do not trust big corporations with their data. Truecrypt is (was ?) a welcome alternative to Bitlocker and Filevault.

Because developers who refuse to show any responsibility for the code they've written (by staying anonymous and thus not risking their career/credibility in software) are much more trustworthy than "big corporations" right?

It hasn't even been a month since phase 1 of the first truecrypt audit ended. Which means up until now this piece of software was as shady as it could be.

Re: TrueCrypt suggesting migration to BitLocker?

#164

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Maybe while looking at the code themselves they found a very bad bug which would make previously made encrypted partitions easily crackable, and fixing it would obviously make the world aware to this, and they don't want to endanger or ruin the lives of everybody who has had a truecrypt container with sensitive data taken from them (for example to a malicious government), so the only way to go for them is to tell people their product should not be used any more and is bad.

Re: TrueCrypt suggesting migration to BitLocker?

#165
Providing some details from SourceForge:

1. We have had no contact with the TrueCrypt project team (and thus no complaints).

2. We see no indicator of account compromise; current usage is consistent with past usage.

3. Our recent SourceForge forced password change was triggered by infrastructure improvements not a compromise. FMI see http://sourceforge.net/blog/forced-password-change/

Thank you,

The SourceForge Team communityteam@sourceforge.net

Re: TrueCrypt suggesting migration to BitLocker?

#168
post #75

Earlier quoted context omitted.

Tom has a point, though. The nature of the message (abandoning truecrypt rather than fixing it simply because XP is end-of-lifed?) and the unwillingness to fix it rather than post a dire message about its insecurity and recommend migrating to other solutions that don't have hidden volume functionality -- it suggests it's either very poorly handled, or a fake message. It might be more likely that a dev got hacked, com…

We don't know much about the TC developers, do we? It's also possible that they're just really cavalier about this stuff, and that this is their response to the TC audit process ("stop bothering us about it and use something that's maintained").

Or the NSA was maintaining it the whole time, and they've just sent everyone to the next best thing for them, because of the coming audit.

Re: TrueCrypt suggesting migration to BitLocker?

#170

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficient scale to justify this went unnoticed in an open-source project even after a proper audit, the situation is unlikely to look that much better in a closed-source solution (that only the makers and government agencies have access to).

While this might be reading a tad much into it, the language of the announcement, specifically the "...as it may contain unfixed security issues" bit, sounds like what somebody who just came out on the losing end of a heated debate about whether some bug-feature should or should not be considered the former would say. Knowing the vitriol and determination with which software developer arguments are often carried out, this would explain the observed combination of remarkable dedication and haphazard execution.

Post reply on HN