Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

181–190 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#181
post #160

This seems highly suspicious, especially the recommendation of BitLocker, a product we have little to no evidence does what it says and after PRISM, have no reason to trust[2]; not to mention it being limited to a (very small subset of) Windows platforms vs. TrueCrypt's cross-platform functionality. If this was legit[1], it'd probably be directing people to one of the other TrueCrypt-like programs. [1]The new version…

> after PRISM People seem to keep forgetting this (I'm sure it's simply unintentional), but PRISM was and still is nothing much more than an automated warrant/NSL compliance system. You're basically saying that Microsoft is complicit in divulging information in response to specific requests made under specific legislative authorities, which was standard hat since even before Smith v. Maryland.

well, I can see where you're coming from, but automation changes the nature.

license plates on cars wasn't a big deal, it was primarily used to identify stolen cars and track drivers breaking the law. Then automation entered the picture and it became feasible to track the movements of everyone, aggregate it in a huge database, and claim "they might be criminals later".

PRISM is more of the same, they could of compelled Microsoft to do this long before, of course, but PRISM is one of those compromise everything initiatives. Meaning that even if the possibility existed before, it definitely exists now.

so it's not unjustified bringing it up.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#182
Well, if we are going to speculate, I'll offer a guess: the crowd funded security audit made the developers lose their enthusiasm.

I believe I read in another thread that TrueCrypt did not get many donations. I'd be a bit depressed if I worked long and hard on a project that people seemed to appreciate, but not enough to crack open their wallets and toss a few bucks my way, and then some third party comes along and quickly raises $70k to audit my code.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#183
post #141
post #139

Here's my theory (step-by-step): 1. Truecrypt is a gigantic pain-in-the-side for US intelligence agencies. 2. Intelligence agencies brainstorm about the best way to deal with the situation. 3. Taking over and tampering with the current code is deemed unrealistic. The user base of Truecrypt is very sophisticated and even minor changes to the source code would be scrutinized. 4. "How can be get people to stop using Tru…

Your (1) partly fails because they'd just toss you in jail until you hand over the key. If they think you're a terrorist that jail might be overseas with no access to lawyers. If they think you're a paedophile they'll just leak that info (and this your life is destroyed). Also, "Truecrypt properly used is a gigantic pain" and although I have nothing to support it I reckon many people use it incorrectly. Has anyone do…

Actually I disagree. The NSA is all about spying. If they can't decrypt what you do without going to you and asking you for the keys (or throwing you in jail) then I would say it -is- a major pain for them. Remember we're talking about an agency who routinely targets one person in the hope to find dirt on others.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#184

Earlier quoted context omitted.

My point is that as it's closed source, we still don't know whether it sends the key to MS anyway (even if the user asks not to link it to their hotmail account). Given MS' complicity in PRISM, it's not a leap of trust I'm willing to make.

Truecrypt has been around for a decade, and only now is someone getting around to doing a real audit. The people behind Truecrypt are completely unknown, and may well be the NSA for all we know. So do you trust them?

I personally trust open source and audited system much more than closed-source system shipped with Windows (apparently).

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#185
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

The whole message on the site makes no sense and I think that's on purpose. What likely happened is the US gov found the TC authors, then used their weight to try and get them to back door the binaries. Authors didn't want to, but couldn't publicize the letters without going to jail, so they made up the most ridiculous story for why they were giving up on the project, the best possible outcome so that they wouldn't go to jail and wouldn't subject users to the required back door.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#186
post #177

Earlier quoted context omitted.

Your use of "demand" is misleading. Your own words at the time say "drafted sweeping legislation." Did that legislation pass? Anyone can "draft legislation." I can draft legislation right now. That doesn't make it U.S. law. Getting it passed is the hard part. Phone companies are required to enable wiretaps. But that happened through the public legislative process, and the legislation even lets the phone company bill…

I'll repeat my question, which you ignored in favor of quibbling with a tangential point: What makes you think U.S. law treats makers of products any differently, assuming TrueCrypt's creators and maintainers can be identified? If you want examples of FBI surveillance untethered to the law, we can provide those. Look at the video of the public forum I hosted with Ladar (of Lavabit) in SF last fall. Look at warrantles…

I'll repeat my question, which you ignored in favor of quibbling with a tangential point: What makes you think U.S. law treats makers of products any differently, assuming TrueCrypt's creators and maintainers can be identified?

Something must be wrong because this is 100% the question I believe I responded to. I will attempt so again now:

* Statute gives the government the right to compel certain service providers to actively assist in wiretapping. Example law: CALEA

* There is no U.S. law that gives the government the right to compel arbitrary third-parties to modify their products to make wiretapping easier.

You give a long list of bad things the USG has done, but none of them involve vendors being compelled to modify products.

(In another domain, banks have to report transactions over 10K, but that's completely the result of statute, the Bank Secrecy Act.)

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#188
post #159

Earlier quoted context omitted.

"given that everyone was happy to keep using TrueCrypt up until 1 day ago" The same was true for OpenSSL a few weeks ago. One of the most plausible theories is that the TrueCrypt developers found a gaping security hole (ala OpenSSL) and realised that releasing a fix for it would reveal the bug and compromise every TrueCrypt partition in existence, so they chose to kill the project rather than risk the safety of all o…

If that was the case, why not fix the bug and then tell everybody to upgrade to the new fixed version ASAP?

by fixing the bug you tell everybody what/where the bug is and if anybody has a copy of someone else encrypted disk (think external backup, amazon etc..) they can decrypt it.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#189
post #159

Earlier quoted context omitted.

"given that everyone was happy to keep using TrueCrypt up until 1 day ago" The same was true for OpenSSL a few weeks ago. One of the most plausible theories is that the TrueCrypt developers found a gaping security hole (ala OpenSSL) and realised that releasing a fix for it would reveal the bug and compromise every TrueCrypt partition in existence, so they chose to kill the project rather than risk the safety of all o…

If that was the case, why not fix the bug and then tell everybody to upgrade to the new fixed version ASAP?

That's effectively the same thing as releasing details of the bug. It would take time to take the patch and figure out the bug from it, but it would be fairly easily done for a determined attacker.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#190
post #78

Earlier quoted context omitted.

If that were true, and they were so sure of the quality of their code then they'd keep going, wait for the all clear and say: "Look, we've been doing this for 10 years, our system is now independently audited, will you please support us..." I suspect that would have brought in a few dollars in the current climate.

That might make sense in a world of perfectly rational unemotional robots. In the real world, if you worked for years trying to make people safe, and you felt (correctly or not) that you were being disrespected while others were being respected for picking at your nits, you might say "fine, fuck you all, have fun," too. To be clear, I don't know what's going on. A "rage quit" is the most likely scenario IMHO, but thi…

Off-topic, but considering the sheer amount of stuff on GitHub, I'm not sure it's about free loaders - whether or not it's useful, the fact that so much code is published demonstrates that many people are okay with it being used by others.
Post reply on HN