- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…
If I were to wager a non-crazy, Occam's Razor-compatible bet, I'd say the author had a bad day, saw one too many digs at the quality of their decade-long work, got pissy, and decided to call it quits. I love popcorn-munching news as much as anyone, but this probably isn't it.
TrueCrypt suggesting migration to BitLocker?
321–330 of 414 posts
Re: TrueCrypt suggesting migration to BitLocker?
#322If I take this message at face value and decide to switch to BitLocker, can someone answer this. Dropbox + Truecrypt take full advantage of block sync & block encryption i.e. if a tiny piece of data is modified inside an encrypted container, only the relevant blocks are synced on update. Dropbox does not need to sync the entire container each time. This is a very useful feature. I know Google Drive & OneDrive aren't…
Re: TrueCrypt suggesting migration to BitLocker?
#323Earlier quoted context omitted.
Are you sure? He does say "binaries when run make no unexpected...". And matching binaries is not a trivial task because of OS, compiler and SDK versions. The last time someone did this for Truecrypt it made the news: https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...
Binaries could have code that will activate in future.
Re: TrueCrypt suggesting migration to BitLocker?
#324There is no electronic privacy, there never has been.
It's perfectly plausible that we're reaching a saturation point and society will start shying away from over-sharing online. A return to offline cash purchasing and face-to-face conversations would be a positive change in my eyes.
Re: TrueCrypt suggesting migration to BitLocker?
#325If you're looking for actively developed cross platform free software alternative: http://www.getsafe.org/
Can anyone else comment on the viability of this option? It seems pretty nice, from the website, but I'd like to hear more about it's reputation in the security community.
It is not full disk encryption, so not a direct alternative for a product like TrueCrypt. I believe it uses a RAM disk for the files so you're limited in size, too - something like that.
Personally I'm not a big fan of using WebDAV to expose the encrypted file system - it seems like a large liability. But I'm not a real security expert at all, just saying it sounds complicated to get right (caching could keep a unencrypted copy) and exposes an even larger attack surface.
Re: TrueCrypt suggesting migration to BitLocker?
#326Earlier quoted context omitted.
Why have dozens of steps and seventeen screenshots detailing how to migrate a Windows partition and only a joke line for the Linux version? And why Bitlocker? Then there was the license change, new version with different features... This imbalance of effort strikes me as incredibly odd if the author was merely rushed.
Linux users can be trusted to work things out for themselves?
Re: TrueCrypt suggesting migration to BitLocker?
#327I honestly think that the government is behind this fiasco, nobody just ups and leaves a massive project used by millions without leaving a valid note.
Re: TrueCrypt suggesting migration to BitLocker?
#328Earlier quoted context omitted.
...or that BitLocker isn't.
I know everyone likes to bash MS around here but is there any actual proof of Bitlocker's insecurity that is more recent than 2008? If you look at wikipedia it seems like the only known real vulnerability requires someone with physical access to boot via USB into another OS within a few minutes of turning the computer off. When is this a real risk for anyone? I am not a security expert but unless you are doing things…
Re: TrueCrypt suggesting migration to BitLocker?
#329Earlier quoted context omitted.
It may be the same strong sense of ownership and control that precluded the liberalisation of Truecrypt's license during its lifetime in the past decade.
Your reply seems to be the most sensible out of the lot. (Side note: I presumed there'd be a couple other ones that suggested it's open source--never mind that prior to the removal of some of the license text it wasn't "free as in beer" open. To be fair, I had forgotten myself that TrueCrypt wasn't exactly open source.) Perhaps ownership does run deep, even if you've never really released a product for money and it's…
Re: TrueCrypt suggesting migration to BitLocker?
#330- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…
infosecslave said in a dead comment: [...] you have to consider the fact that Truecrypt project was started before FDE was popular, maybe their goal all this time was to popularize such encryption. With XPs demise that goal would have been achieved as every current Windows version comes with Bitlocker. Your comment is dead but makes a lot of sense, especially in light of the message on the website: The development of…
It's only available in Ultimate and Enterprise Vista/Win7 and Pro/Enterprise versions of Win8. Lots of machines ship(ped) with only Win7 Home Premium or vanilla Win8.