There's a "TrueCrypt Foundation" key on the keyservers from 2004, the ID is E3BA73CAF0D6B1E0.
The time stamp on key servers can not be trusted. Anyone can spoof keys in anyone elses name, with any timestamp they want. The only way to verify is if you have the previous key stored somewhere, or can find a trustpath to it.
As far as I know, its license is incompatible with other open source licenses due to an advertising clause (all derivative works have to state "based on Truecrypt" somewhere in the documentation or via use of the software). The old four clause BSD license had a similar issue.
One of the changes in the newly-uploaded version is indeed a change in the license.
It does appear that the authors have removed the advertising clause in this latest license version. Also the section on commercial licensing, some mentions of registered trademarks, and all specific references to the truecrypt.org domain, including email addresses.
However it's unclear if this change is only for Truecrypt 7.2 or can be applied retrospectively to previous versions. As the authors have deleted sizeable portions of the encryption code in this final version, such ambiguity could be problematic.
Suppose that the author received a secret order from a secret court that required the author keep secret the secrecy of the secret order from the secret court. Furthermore, the author was secretly required to turn over his secret signing key to a secret third party.
If you were the author, what would you do? Consider your options.
One is that you could issue an update with a warning that the program is no longer secure. Even though the program really is, at this moment, secure. The only source code changes are to insert the warnings. But what the warnings are warning you about, but cannot just come out and say, is that the program will not be secure in the future because a third party now has the keys to sign authentic new insecure versions.
This wouldn't be unlike Lavabit shutting down. The author is choosing to fall on his sword for the good of everyone.
Providing some details from SourceForge: 1. We have had no contact with the TrueCrypt project team (and thus no complaints). 2. We see no indicator of account compromise; current usage is consistent with past usage. 3. Our recent SourceForge forced password change was triggered by infrastructure improvements not a compromise. FMI see http://sourceforge.net/blog/forced-password-change/ Thank you, The SourceForge Team…
2. We see no indicator of account compromise; current usage is consistent with past usage. I'm calling BS. This site was disabled repeatedly for exceeding bandwidth today. I find it hard to believe traffic is as usual.
um... we're all looking at the site due to the change. We all used bandwidth.
i just wanted to say thanks to the truecrypt devs for a decade of largely unthanked and criticised work that, as far as i can tell, has been impressively reliable.
[kinda disappointed that, despite arriving so late to this thread, no-one seems to have said this.]
If this is true it's time to fork I guess. Though I remember TC having a weird license. Anyone knows to what extent TC would be forkable?
Amusingly, they modified the license to remove the advertising clause that was causing trouble. The author seems really awesome the way they are handling this, wish they weren't stopping. It may be out of their hands, however: NSA, law suit, whatever.
One thing I have noticed is that the version they have on this site is 7.2, and if I remember this correctly, it was 7.1a that was on the truecrypt.org (checked a few days ago...) So they've put up a new version and telling us it's for migration only?
Amusingly it also has unrelated changes that look like the developer was working on 7.2 for a proper release before this.
Same key as the previous binaries? I doubt it, given that the keys were replaced mere 3 hours before the new binaries were published: http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...
Anyone have key fingerprints for pub keys used for the 7.1a vs 7.2 signing? Preferably pub key from a while ago I guess.
Yes, I can confirm that F0D6B1E0 was on the Truecrypt web site about a year or two ago, since it's been on my keyring for at least that long. I've installed Truecrypt multiple times over the past few years, and have always used this key to verify (or its signing subkey, I suppose).
Wouldn't they just have to published a signed message stating that the change was not theirs and the key is compromised? Or better yet, revoke the key? If two groups with opposing messages control the key, it's pretty clear that the key is compromised in some manner.
No, because the suggested "hackers" have published a signed message.
Doesn't matter. Publish another message signed with the same key saying "this key is compromised."
What if this is an attempt to smoke out the TrueCrypt devs? While this move seems odd, the new binaries are properly signed and the domains have been updated accordingly. If this was another project, like Rails, the maintainer could come out and say they were hacked and the last good version was X. Otherwise, the project would likely die off. But since we know so little about the TrueCrypt maintainers, there's little…
Wouldn't they just have to published a signed message stating that the change was not theirs and the key is compromised? Or better yet, revoke the key? If two groups with opposing messages control the key, it's pretty clear that the key is compromised in some manner.
If 7.2 is part of the hoax, then they would be signing with a compromised key. This would be evidence, but would not be conclusive.