Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

361–370 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#361
Repost from 4chan, there's a silly coincidence in the warning.

>WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues That's worded awkwardly. >Not Secure As Emphasis on the NSA in "not secure as" >WARNING: Using TrueCrypt is NSA it may contain unfixed security issues.

Re: TrueCrypt suggesting migration to BitLocker?

#362
post #288

It is the only full disk encryption software currently used that offers plausible deniability. Plausible deniability is the key here. It think the FBI and/or the NSA bullied the developers and forced them to this.

Have a look at DCPP (http://www.securstar.com/products_drivecryptpp.php , 125 US$), they do offer that for years. As a Europe based company (HQ in Germany AFAIK) chances of backdoored/compromised software are a bit lower than with US based companies.

Also: Places where plausible deniability is of use are reducing over time (in GB they can put you to jail until /you/ proove your drive is /not/ encrypted, other countries will follow). PD does not help here bc 'they' know about PD and (see above). If your disk is not empty (zeroed) but wiped with RND you may have already bad luck. I doubt they do cryptanalysis to see if your RND is true RND or an encrypted disk (I used to use a raw disk editor and to overwrite the boot loader with random data, using the boot loader from CD or UDB stick).

Re: TrueCrypt suggesting migration to BitLocker?

#363
post #288

It is the only full disk encryption software currently used that offers plausible deniability. Plausible deniability is the key here. It think the FBI and/or the NSA bullied the developers and forced them to this.

PLEASE DELETE THIS POST!

Dear mod, as you seem to moderate posts (of new user accounts??) I post here despite mailing: Please update http://ycombinator.com/newswelcome.html to reflect that posts are moderated before being published (and in which cases) and the actual meaning of "You're submitting too fast. Please slow down. Thanks." (i.e. which frequency is 'OK' etc.). It made your site easier to handle and so more attractive to users willing to abide the rules.

Thank you.

Re: TrueCrypt suggesting migration to BitLocker?

#364
post #222

A very interesting comment from netsec: http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... This is very strange. I have another theory since I don't believe in coincidences. We don't know the real author of TrueCrypt. I think someone found his identity (cough NSA) and made him an offer like lavabit.com received. This time probably with security classification so he can't talk about that. HOWEVER, if we t…

Interesting, but probably unrelated:

http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... says:

> I asked around and apparently Visual Studio switched from generating "U.S." to "United States" in VS2010. Hence it is probably just the author having upgraded their VS at some point recently.

Re: TrueCrypt suggesting migration to BitLocker?

#365
post #348

Earlier quoted context omitted.

IF THIS IS THE CASE and that's an IF then it seriously brings into suspect backdoors in larger proprietary software. Because really if they're going after trucrypt then they have to already have gone after the big players. I'm not going to jump the gun just yet but after snowden it's not out of the question.

Not "backdoors" but it seems Microsoft stores the BitLocker decryption key, based on this leaked slide (just found on twitter): https://twitter.com/TheBlogPirate/status/471759810644283392/... edit: Confirmed Microsoft stores your recovery key on their servers if you're not connected to a domain: http://windows.microsoft.com/en-AU/windows-8/bitlocker-recov...

Microsoft storing your key is opt-in and optional.

Whether or not they superstitiously store it anyway is a different question.

Re: TrueCrypt suggesting migration to BitLocker?

#366
post #154
post #85

Earlier quoted context omitted.

NSA is obviously in on it. Who else would recommend using holy-bug-riddled proprietary-back-doored-on-purpose encryption software? ;-P

I choose to believe Niels Ferguson when he says "Over my dead body.": http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...

> Over my dead body.

> Well, maybe not literally---I’m not ready to be a martyr quite yet

So, in short he's written 8 years ago that in principle he was totally against backdoors. Times have changed so much that a statement of that tone is almost entirely useless IMHO.

Re: TrueCrypt suggesting migration to BitLocker?

#367

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

I'm taking the risk of sounding sarcastic, which I don't want to, but:

> Signature is valid, so it's not a defacement.

Under normal circumstances, I would assume the same, but given the exceptional situation and chaos ensued, I think it's not entirely silly to think that this could be a case of http://xkcd.com/538/

That could explain the inconsistency of a hypothetical scenario where the key is compromised by a third-party but the owner doesn't come out. If they are under physical threat, I suspect a lot of the "normal" measures like revocation certificates would be hard/impossible to achieve.

Re: TrueCrypt suggesting migration to BitLocker?

#368
post #346

Earlier quoted context omitted.

If this is a hack, then the truecrypt.org site (or dns) and sourceforge site are both compromised, suggesting a dev got hacked who would have had access to both, and perhaps the TC signing key as well (not everyone practices good signing key hygiene, like keeping it offline, even for important software projects). Even if it's a legit announcement, I wouldn't run that 7.2 binary. Anyone running truecrypt already has t…

> Anyone running truecrypt already has truecrypt, right? I frequently reformat my boot volumes—but I've had a .tc file laying around on an external HD since forever, with my websites' X.509 private keys and such inside. I'm probably going to do exactly as this announcement says: download the export-only binary, create a loop-mounted LUKS volume, and migrate everything over.

Recent versions of cryptsetup support decrypting truecrypt volumes, just use cryptsetup for both.
Post reply on HN