Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

211–220 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#211

Earlier quoted context omitted.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.

IF THIS IS THE CASE and that's an IF then it seriously brings into suspect backdoors in larger proprietary software. Because really if they're going after trucrypt then they have to already have gone after the big players.

I'm not going to jump the gun just yet but after snowden it's not out of the question.

Re: TrueCrypt suggesting migration to BitLocker?

#212
post #154
post #85

Earlier quoted context omitted.

NSA is obviously in on it. Who else would recommend using holy-bug-riddled proprietary-back-doored-on-purpose encryption software? ;-P

I choose to believe Niels Ferguson when he says "Over my dead body.": http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...

If I were the NSA, I'd try to get one of my hundreds of world-class cryptographers a job on the BitLocker team.

In fact, BitLocker would be the first thing I'd weaken. Because

1) It's closed source, hard to externally audit.

2) It's one of the most used encryption packages in the world.

3) Microsoft's poor security track record provides excellent cover if the weakness is ever found.

Closed-source security software is a recipe for disaster.

Re: TrueCrypt suggesting migration to BitLocker?

#213

Earlier quoted context omitted.

This is legit and I am willing to bet. https://gist.github.com/anonymous/e5791d5703325b9cf6d1 The entire source has been modified to reflect the Sourceforge page its contents. Encryption process is disabled. The current binaries can only be used to "migrate". You can deface a webpage but the effort it takes to rewrite the entire source code, compromise the GPG, compromise domain, compromise mail servers et cetera is…

I agree that this really looks like it is legit. It looks like, for some reason (we don't believe in the legend version, do we?) they abruptly (the diff contains many normal changes also) stopped the development and are burning all the bridges. They also slightly changed the license so now the forks are free to not mention that they are based on TrueCrypt, they are not allowed to link to truecrypt.org site or mention…

> we don't believe in the legend version, do we?

I dunno. We saw the legend version happening with a lot of people recently. Yep, we still mostly don't belive it, but...

What's the oposite to The Boy that Cried Wolf?

Re: TrueCrypt suggesting migration to BitLocker?

#214

Earlier quoted context omitted.

Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.

Well, the thing is though, it's not that they were hosting users' data. It's not like they would be forced to provide the contents of users' communication. I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...

If they put a backdor on the binaries, but not source, lots of people will be compromissed, and for a really long time nobody may notice.

EDIT: I normaly don't care. But this time I'd be glad if who downmoded this post explained why.

Re: TrueCrypt suggesting migration to BitLocker?

#215
post #191

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

What if this is an attempt to smoke out the TrueCrypt devs? While this move seems odd, the new binaries are properly signed and the domains have been updated accordingly. If this was another project, like Rails, the maintainer could come out and say they were hacked and the last good version was X. Otherwise, the project would likely die off. But since we know so little about the TrueCrypt maintainers, there's little…

Wouldn't they just have to published a signed message stating that the change was not theirs and the key is compromised? Or better yet, revoke the key?

If two groups with opposing messages control the key, it's pretty clear that the key is compromised in some manner.

Re: TrueCrypt suggesting migration to BitLocker?

#216
post #182

I'll leave others more knowledgeable in such things to comment on the legitimacy of this, but one practical thing I'll note: the assertion on the site that Windows Vista/7/8 has support for encrypted disks is only half true. Quoting from Wikipedia [1] "BitLocker is available in the Enterprise and Ultimate editions of Windows Vista and Windows 7. It is also available in the Pro and Enterprise editions of Windows 8." S…

It's worth pointing out that it doesn't leave people with a free migration path, but it is absolutely easy. Windows 7 and 8 both support "anytime upgrade" functionality, where you can pretty trivially upgrade from Home/Home Premium to a higher-level edition of Windows without needing to reinstall anything or move data--just as long as you pay for the more expensive edition.

Re: TrueCrypt suggesting migration to BitLocker?

#217
post #147

The interesting thing about this is how everyone is going on about there being no cross-platform alternative. Really, is Truecrypt the only available option? Because that's a pretty sad state of affairs then; there needs to be only one unnoticed bug and pretty much all full disk encryption is broken. Unless you want to chain your data to Microsoft, that is.

There are plenty of alternatives that don't work on Windows, and a few that only work on Windows.

Thus, there is no cross-platform alternative.

Re: TrueCrypt suggesting migration to BitLocker?

#218
post #177
post #170

Earlier quoted context omitted.

The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficien…

> The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. I realize we are firmly in conspiracy theory territory here, but perhaps the suggestion that users switch to Bitlocker is intended to be so patently absurd as to be a signal that the developers are under duress?

I'd agree, that seems more believable than some of the other theories I've read.

Re: TrueCrypt suggesting migration to BitLocker?

#219
Is it possible that this is the result of a "dead man's switch" (DMS) set by the developer(s)? Perhaps a (continually updated) process was set up so that TrueCrypt would shut itself down if the developer were unable to prove he or she was still actively maintaining the software.

I can see a couple of scenarios where this would be wise:

A) The developer passes away, leaving nobody else to maintain TrueCrypt. Zero-day 1234 is discovered which compromises TrueCrypt. The DMS activates, depreciating the software and advising users to migrate to another alternative (why BitLocker, I have no idea).

B) The developer(s) is(are) coerced into compromising TrueCrypt in some way. As a part of the coercion, the developer(s) is(are) unable to demonstrate proof of life to the DMS, so the system nukes itself.

Re: TrueCrypt suggesting migration to BitLocker?

#220
post #161

Earlier quoted context omitted.

The motivation would be so that if you had a TrueCrypt archive lying around on a drive that you find in 5 years time, it would be possible to decrypt it - but they don't want to allow encryption because they won't be continuing development, and so fixing future bugs will not be possible.

If that's the motivation then in 5 years' time, who's to say the new version will work as well (assuming that it also won't be updated)? That doesn't make any sense.

[deleted]
Post reply on HN