Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

171–180 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#171

Earlier quoted context omitted.

There are people in this world that do not trust big corporations with their data. Truecrypt is (was ?) a welcome alternative to Bitlocker and Filevault.

Because developers who refuse to show any responsibility for the code they've written (by staying anonymous and thus not risking their career/credibility in software) are much more trustworthy than "big corporations" right? It hasn't even been a month since phase 1 of the first truecrypt audit ended. Which means up until now this piece of software was as shady as it could be.

People who create security software are always targeted by governments, and a lesser extent hackers. Truecrypt devs who remain anonymous can produce software in a much safer environment. Just like Satoshi. Code can speak for itself.

Re: TrueCrypt suggesting migration to BitLocker?

#172
post #171

Earlier quoted context omitted.

Because developers who refuse to show any responsibility for the code they've written (by staying anonymous and thus not risking their career/credibility in software) are much more trustworthy than "big corporations" right? It hasn't even been a month since phase 1 of the first truecrypt audit ended. Which means up until now this piece of software was as shady as it could be.

People who create security software are always targeted by governments, and a lesser extent hackers. Truecrypt devs who remain anonymous can produce software in a much safer environment. Just like Satoshi. Code can speak for itself.

> Code can speak for itself.

The constant open source mantra of "code speaks for itself" strikes again.. except that none of the competent eyeballs have looked at truecrypt up until very recently (phase 1 audit ended in April 2014 which is ten years after the first truecrypt release). A lot of good did it do with OpenSSL too.

But surely, code written by anonymous, untrustworthy developers that hasn't been looked at much for ten years is worth more than code written by a corporation that has a public image to uphold.

As for "being targeted by government" that's called conspiracy theories. Unless you live in a place like Russia or Saudi Arabia you don't have anything to fear just because you wrote encryption software.

Re: TrueCrypt suggesting migration to BitLocker?

#173

I don't see why so many are jumping onto conspiracy theories. Truecrypt, like the page states, has become redundant with built-in OS offerings. While it could be used for other things, the main reason/drive behind its development was the Full Disk Encryption feature, which has only ever worked on Windows, and has only ever truly been "necessary" for Windows XP users. Windows had bitlocker for FDE since Vista, Mac OS…

None of those options you listed are cross platform. I have many TrueCrypt volumes that I use on Windows, Linux, and Mac. Being able to mount them on all of of the OSes is very important.

Re: TrueCrypt suggesting migration to BitLocker?

#174

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

This is legit and I am willing to bet. https://gist.github.com/anonymous/e5791d5703325b9cf6d1 The entire source has been modified to reflect the Sourceforge page its contents. Encryption process is disabled. The current binaries can only be used to "migrate". You can deface a webpage but the effort it takes to rewrite the entire source code, compromise the GPG, compromise domain, compromise mail servers et cetera is…

I agree that this really looks like it is legit. It looks like, for some reason (we don't believe in the legend version, do we?) they abruptly (the diff contains many normal changes also) stopped the development and are burning all the bridges. They also slightly changed the license so now the forks are free to not mention that they are based on TrueCrypt, they are not allowed to link to truecrypt.org site or mention the TrueCrypt name in their product's domain name. They also removed all the links to their site from the source code (even the donation page).

Re: TrueCrypt suggesting migration to BitLocker?

#175
post #171

Earlier quoted context omitted.

People who create security software are always targeted by governments, and a lesser extent hackers. Truecrypt devs who remain anonymous can produce software in a much safer environment. Just like Satoshi. Code can speak for itself.

> Code can speak for itself. The constant open source mantra of "code speaks for itself" strikes again.. except that none of the competent eyeballs have looked at truecrypt up until very recently (phase 1 audit ended in April 2014 which is ten years after the first truecrypt release). A lot of good did it do with OpenSSL too. But surely, code written by anonymous, untrustworthy developers that hasn't been looked at m…

[deleted]

Re: TrueCrypt suggesting migration to BitLocker?

#176

> WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues I see many readers here and on Twitter who interpret that as "TrueCrypt has security issues". That's not what it says. It says that it might be insecure. That does not make too much sense right now, but considering this webpage would be meant to stay up, unchanged, for years, that makes a lot more sense: security problems may be found,…

For security software, deprecation is effectively a security issue since there are no plans for fixing future bugs.

Re: TrueCrypt suggesting migration to BitLocker?

#177
post #170

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficien…

> The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker.

I realize we are firmly in conspiracy theory territory here, but perhaps the suggestion that users switch to Bitlocker is intended to be so patently absurd as to be a signal that the developers are under duress?

Re: TrueCrypt suggesting migration to BitLocker?

#178
post #170

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficien…

Agreed on the language/vitriol interpretation. I was thinking the same when I listed rogue content maintainer.

Re: TrueCrypt suggesting migration to BitLocker?

#180
post #161

Earlier quoted context omitted.

It doesn't matter why. If "we are now insecure" then the last thing you say is, "so please download these new versions, used only to decrypt your old files and nothing else." No we won't tell you what, if anything, was wrong, so you can make an informed decision.

The motivation would be so that if you had a TrueCrypt archive lying around on a drive that you find in 5 years time, it would be possible to decrypt it - but they don't want to allow encryption because they won't be continuing development, and so fixing future bugs will not be possible.

If that's the motivation then in 5 years' time, who's to say the new version will work as well (assuming that it also won't be updated)? That doesn't make any sense.
Post reply on HN