Live data from Hacker News

TrueCrypt must not die

truecrypt.ch

31–40 of 103 posts

Re: TrueCrypt must not die

#31
post #27

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

There is a $30,000 audit currently underway. There will be no security problems un-turned when they are through. That's assuming there are any to begin with (Personally, I think not). I see no issue picking up the codebase and running with it.

Of all the subsets of the software development world, crypto is the one to be taken most seriously. TrueCrypt was always developed in the shadows, and the recent controversy takes the nails they've set and hammers them firmly into the coffin.

Audits aren't perfect.

Re: TrueCrypt must not die

#32
post #28

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

Would you mind pointing me in the direction of a good alternative? Thanks.

The Arch Linux wiki page has an excellent overview: https://wiki.archlinux.org/index.php/Encryption

Re: TrueCrypt must not die

#33
post #27

Earlier quoted context omitted.

There is a $30,000 audit currently underway. There will be no security problems un-turned when they are through. That's assuming there are any to begin with (Personally, I think not). I see no issue picking up the codebase and running with it.

Of all the subsets of the software development world, crypto is the one to be taken most seriously. TrueCrypt was always developed in the shadows, and the recent controversy takes the nails they've set and hammers them firmly into the coffin. Audits aren't perfect.

It's code. There are no secrets.

Problems come up when nobody reads the code. Right now, there's an awful lot of people reading this code (Given the strange warning's posted on the TC site).

Re: TrueCrypt must not die

#34

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

I disagree. TrueCrypt (for better or for worse) made encryption available to the masses in an easy to use application. Without it, similar level of encryption requires knowledge of unix command line or expensive commercial products. The events that have unfolded do certainly raise the stakes for the TrueCrypt audit, but at present, I am still better off using TrueCrypt, than nothing at all.

I'm speaking to developers who would work on something like maintaining a TrueCrypt fork. Instead, improve the usability of the alternatives to solve the problems you've raised.

Re: TrueCrypt must not die

#35
post #10

Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: https://twitter.com/stevebarnhart/status/472203503478509568 Edit: That tweet was deleted for some reason, but the rest of the thread is still there: https://twitter.com/stevebarnhart/status/472192457145597952

For me this tweet is 404, what is its content?

tweet was deleted for some reason. Here's another from the thread: https://twitter.com/stevebarnhart/status/472192457145597952

Re: TrueCrypt must not die

#36
post #27

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

There is a $30,000 audit currently underway. There will be no security problems un-turned when they are through. That's assuming there are any to begin with (Personally, I think not). I see no issue picking up the codebase and running with it.

> There will be no security problems un-turned when they are through.

I really really doubt this is a claim the folks doing the audit would make.

Re: TrueCrypt must not die

#37
post #29
post #23

Earlier quoted context omitted.

Did you not see the .ch domain name ? You can rest assured.

Also what is it with the people who suddenly seem to believe Switzerland is a cypherpunk haven? It _really_ isn't.

It's clearly a ploy to get everyone backdoored. Just look at Crypto AG.

Re: TrueCrypt must not die

#38
post #28

Earlier quoted context omitted.

Would you mind pointing me in the direction of a good alternative? Thanks.

The Arch Linux wiki page has an excellent overview: https://wiki.archlinux.org/index.php/Encryption

Hmm, it doesn't appear that any of the options there work on Linux, OS X, and Windows?

Re: TrueCrypt must not die

#39
post #37
post #29

Earlier quoted context omitted.

Also what is it with the people who suddenly seem to believe Switzerland is a cypherpunk haven? It _really_ isn't.

It's clearly a ploy to get everyone backdoored. Just look at Crypto AG.

Hm. Is that Websters definition of "clearly", meaning "easy to perceive, understand, or interpret", or HN's definition, as in "it's clear someone or some agency got to the developers and they just pulled the ejection seat for their own legal protection"?

Re: TrueCrypt must not die

#40
post #7

This looks like a bootstrap site that was thrown together in an hour by two guys with twitter accounts and $10 for a domain name. I really doubt they're going to be doing any dev work.

Would you trust it more if they used Comic Sans instead of bootstrap?
Post reply on HN