Live data from Hacker News

TrueCrypt must not die

truecrypt.ch

21–30 of 103 posts

Re: TrueCrypt must not die

#21
post #12
post #10

Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: https://twitter.com/stevebarnhart/status/472203503478509568 Edit: That tweet was deleted for some reason, but the rest of the thread is still there: https://twitter.com/stevebarnhart/status/472192457145597952

Yeah, this comment appears to be spot on as well: http://krebsonsecurity.com/2014/05/true-goodbye-using-truecr...

The funniest part about that comment is the response that says "I really was leaning toward NSL, till I read this post."

Head-desk-head-desk.

Re: TrueCrypt must not die

#22
post #10

Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: https://twitter.com/stevebarnhart/status/472203503478509568 Edit: That tweet was deleted for some reason, but the rest of the thread is still there: https://twitter.com/stevebarnhart/status/472192457145597952

For me this tweet is 404, what is its content?

He'd tell you, but he's been NSL'd.

Re: TrueCrypt must not die

#23
post #19

It would be nice if the people who pick up and run with the "reboot" of Truecrypt's project management had a background in cryptography. Do these people?

Did you not see the .ch domain name ?

You can rest assured.

Re: TrueCrypt must not die

#24
This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore.

Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

Re: TrueCrypt must not die

#26

Earlier quoted context omitted.

For me this tweet is 404, what is its content?

Sorry, I didn't really want people trying to further bug the supposed dev. Steve Gibson has a good enough roundup. I wish he didn't use my info though :)

You'll be alright.

Re: TrueCrypt must not die

#27

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

There is a $30,000 audit currently underway. There will be no security problems un-turned when they are through. That's assuming there are any to begin with (Personally, I think not).

I see no issue picking up the codebase and running with it.

Re: TrueCrypt must not die

#28

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

Would you mind pointing me in the direction of a good alternative? Thanks.

Re: TrueCrypt must not die

#29
post #23
post #19

It would be nice if the people who pick up and run with the "reboot" of Truecrypt's project management had a background in cryptography. Do these people?

Did you not see the .ch domain name ? You can rest assured.

Also what is it with the people who suddenly seem to believe Switzerland is a cypherpunk haven? It _really_ isn't.

Re: TrueCrypt must not die

#30

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

I disagree. TrueCrypt (for better or for worse) made encryption available to the masses in an easy to use application. Without it, similar level of encryption requires knowledge of unix command line or expensive commercial products. The events that have unfolded do certainly raise the stakes for the TrueCrypt audit, but at present, I am still better off using TrueCrypt, than nothing at all.
Post reply on HN