Live data from Hacker News

True Goodbye: ‘Using TrueCrypt Is Not Secure’

krebsonsecurity.com

201–210 of 249 posts

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#202
post #182

Well, if we are going to speculate, I'll offer a guess: the crowd funded security audit made the developers lose their enthusiasm. I believe I read in another thread that TrueCrypt did not get many donations. I'd be a bit depressed if I worked long and hard on a project that people seemed to appreciate, but not enough to crack open their wallets and toss a few bucks my way, and then some third party comes along and q…

That also seems very possible.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#203
post #197
post #195

Earlier quoted context omitted.

Considering the licensing, its likely that the developers wanted to keep development to themselves, and never turn it over to someone else. If the ragequit theory is correct, its fairly reasonable for them to remove the previous versions to make a fork slightly more difficult, especially since it would be an illegitimate fork.

It doesn't add up. You can't (easily) enforce licensing while remaining anonymous, so why bother with removing the earlier versions? If ragequitting, why bother with making a new release instead of just removing _everything_ and changing the webpage? (Presumably, you already have a copy of the SW if you have encrypted volumes.) Also, note "you _should_ migrate data". Could this imply that cold storage is not secure?

The kind of person I can see maintaining Truecrypt for a decade I can also see making this decision. They're upset and are completely done with the project. They take down all the old versions, knowing that the licensing means they're largely useless for purposes of forking (unless you want to violate the licensing, which causes questions to the validity of the fork). Despite their frustration with the project, they still deeply care about crypto and keeping their users secure, so they publish some brief recommendations on alternatives, and release a read-only version of their software to support it.

There are any number of possible vulnerabilities that could exist. Its definitely a plausible possibility. I could fairly easily believe that they were contacted by a researcher who was about to publish a major AES flaw, or one of the other algorithms in use.

There's a number of relatively plausible theories. I wouldn't be surprised if we don't find out for 20 years what the actual reason for this was, when the developer is on their deathbed.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#204
post #156

Earlier quoted context omitted.

For non-full disk I just make AES encrypted files using 7zip. Considering just about everyone has 7zip installed its actually less of a pain in the ass that you'd think. The only downside I see is that 7zip seems to be almost abandonware at this point. The installer linked at the top of their page is almost 4 years old and there's a recent beta but they haven't moved a beta to stable in a very long time.

Is there a good way to mount an encrypted 7z archive as a filesystem, for interactive usage? That was the advantage of TrueCrypt, IMO. Not for FDE (I'm not a huge fan of FDE anyway), but because it created an interactive partition rather than forcing you to decrypt an entire archive to storage, work on it, and then re-encrypt the whole thing and cleanse the storage device you decrypted to. It seems like putting somet…

It looks like WinArchiver can mount 7z and other archive formats. There's not much documentation about it. It does not say if it supports mounting encrypted archives. It does not say if it supports write-access either. The 7z format is normally solid, so unless you're accessing files at the beginning of the archive, it could be pretty slow anyway.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#205
post #89

Earlier quoted context omitted.

I just don't quite understand the panic about microsoft not supporting XP anymore. It's not like that was a surprise announcement or even that the deadline was just met. It was April 8th....and TrueCrypt just now shut down in panic? ...Because XP support stopped??? WTF is going on? It's not even like support means anything, other than that they will no longer improve or fix it, i.e., there's still time to migrate awa…

Another theory is that some component of the development environment to compile TrueCrypt requires XP. Remember the guy that tried to compile the TC source to match the binary? https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie... He needed to get some older version of Visual Studio and a very specific combination of service packs and updates in order to get to matching (nearly) the entire binary. Could it…

I don't think that the EOL of XP has much do with it because they could simple air gap their Windows XP installation to continue development in a secure fashion.

Unless, of course, something more shadowy is going on.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#206
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

The whole message on the site makes no sense and I think that's on purpose. What likely happened is the US gov found the TC authors, then used their weight to try and get them to back door the binaries. Authors didn't want to, but couldn't publicize the letters without going to jail, so they made up the most ridiculous story for why they were giving up on the project, the best possible outcome so that they wouldn't g…

This my first thought when I read it and how it ended so abruptly. Conspiracy theories not withstanding, it's clear someone or some agency got to the developers and they just pulled the ejection seat for their own legal protection.

Can't say I blame them. I've had the feds show up where I lived once and I nearly shit a brick when I realized what was going on. You never want the weight the government beating down your back.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#207
post #87
post #74

That's LavaBit 2. I've been a long time TC user and if there's the trait it has it's the quality and a high degree of polish. And now looking at the diff and the screenshot of that in-app "Not secure" message, the polish is just not there. It feels like it was something that was slapped together in a rush or by someone who's not an original developer. The SF page alone is a big red flag. If you compare its nearly hys…

This is a pretty confusing case, hard to make much of it, LavaBit 2 is of course a possibility. But while we're making these theories, I wanna sound my wild theory: Considering that: (1) TrueCrypt authors go to great to keep their identities hidden, and (2) it turns out TrueCrypt is not free/open software -- TrueCrypt is actually a project by some spooky 3-letter agency. But anyway, thoughts on alternatives? CiskCryp…

TrueCrypt authors go to great to keep their identities hidden

I donated at least two times to them via PayPal. How anonymous could they be if they got funds via PayPal? Not very, in this day and age. I would image it's trivial for the US government to find their true names based on this fact alone.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#208
post #182

Well, if we are going to speculate, I'll offer a guess: the crowd funded security audit made the developers lose their enthusiasm. I believe I read in another thread that TrueCrypt did not get many donations. I'd be a bit depressed if I worked long and hard on a project that people seemed to appreciate, but not enough to crack open their wallets and toss a few bucks my way, and then some third party comes along and q…

Yep. And reading the pdf for phase 1 of the audit, worth about $40k, the findings didn't seem very impressive. Specifically the readability portion where they give a critique of naming conventions in the code. I could see the developers figuring for that money they could've done a lot more good with it.

Re: True Goodbye: ‘Using TrueCrypt Is Not Secure’

#209
post #182

Well, if we are going to speculate, I'll offer a guess: the crowd funded security audit made the developers lose their enthusiasm. I believe I read in another thread that TrueCrypt did not get many donations. I'd be a bit depressed if I worked long and hard on a project that people seemed to appreciate, but not enough to crack open their wallets and toss a few bucks my way, and then some third party comes along and q…

I believe I read in another thread that TrueCrypt did not get many donations

Given the anonymity of the developer(s), how would anyone know this?

However, the downside of being anonymous is that it makes it hard to ask for donations (in places other than your website).

If, and it's a big if, the reason for them throwing in the towel like this, was compensation, I think it would have been handled a lot of other ways.

My money is on an NSL and this was their way of telling us about it.

Post reply on HN