Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

381–390 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#381

Earlier quoted context omitted.

They haven't updated it for years. I'd hardly call the behavior "juvenile" nor would i call it "devaluating". They've simply abandoned it and are offering alternatives.

>> They haven't updated it for years. As I said even if not recently they still invested many years into that project. Of course it is juvenile to senselessly ruin the code and suddenly advertising a very different commercial product, especially without proper scientific reason. Not to mention that precisely because they haven't done much work lately I don't see any reason why the developers would disfigure their pro…

I think it makes sense, it can wear on a developer fairly heavily to be burdened by the user community of a cryptography product. Just look at this very thread, so many paranoid theories about NSLs and such, where they don't even make remote sense. They most likely just wanted to stop needing to work on the project or respond to comments.

They're not "advertising a very different commercial product". They're recommending you actually use a maintained alternative. Bitlocker is probably the most viable alternative on Windows.

It's also possible that Bitlocker solved the problem well enough for them so they saw no gain in maintain TC any further.

Re: TrueCrypt suggesting migration to BitLocker?

#382

Earlier quoted context omitted.

I have 7.1a binaries, source, sigs and pub key from September 2013. pub 1024D/F0D6B1E0 2004-06-06 Key fingerprint = C5F4 BAC4 A7B2 2DB8 B8F8 5538 E3BA 73CA F0D6 B1E0 uid TrueCrypt Foundation sub 4077g/6B136ECF 2004-06-06 My version from September is identical to the pub key at http://sourceforge.net/projects/truecrypt/files/TrueCrypt/Ot... .

Could you post the SHA1s of those? I'm failing to use GPG properly.

  tc/linux$ sha1sum *
  c2a8c78a23f97ffb17bf47448c9f2daa3c8f80cd  truecrypt-7.1a-linux-console-x64.tar.gz
  078cdd4a58f0342cb872d7456c0ba49e310fcad9  truecrypt-7.1a-linux-console-x64.tar.gz.sig
  a53a7a609a25d9a1e33f720ce5c0265ddd4e8b25  truecrypt-7.1a-linux-console-x86.tar.gz
  66060f9444d5df70b4fcdeb655dc60131fce5ad1  truecrypt-7.1a-linux-console-x86.tar.gz.sig
  086cf24fad36c2c99a6ac32774833c74091acc4d  truecrypt-7.1a-linux-x64.tar.gz
  45f65bf755d9481d8afa0d17de6a034062b7a7bd  truecrypt-7.1a-linux-x64.tar.gz.sig
  0e77b220dbbc6f14101f3f913966f2c818b0f588  truecrypt-7.1a-linux-x86.tar.gz
  9efcd79e963126d6d8ef242857b4fafb06eb8ff0  truecrypt-7.1a-linux-x86.tar.gz.sig
  d43e0dbe05c04e316447d87413c4f74c68f5de24  TrueCrypt 7.1a Source.tar.gz
  caeb2bb1d5605d1fc960e936a06e52611033788c  TrueCrypt 7.1a Source.tar.gz.sig
  c871f833d6c115f4b4861eed859ff512e994b9fc  TrueCrypt-Foundation-Public-Key.asc

  tc/windows$ sha1sum *
  06961d83e39c7248df09c132cb6e9b9f528ce69a  Configuration.xml
  88b323b416290924621901a10da3f4f7482e3f77  License.txt
  4c4891f5eafcf9b96be01e31031992d9e98d39c3  TrueCrypt.exe
  34442e400e6cb2534f33a0b1599defe36eefef2a  TrueCrypt Format.exe
  7689d038c76bd1df695d295c026961e50e4a62ea  TrueCrypt Setup 7.1a.exe
  e1e3efaeac2fbcdbff0c2c62ac33233bd356edfa  TrueCrypt Setup 7.1a.exe.sig
  62fc4f76540740e63c7f0a33e3a1b66411f0a303  truecrypt.sys
  17249d979b3bc52d0a33821cc7f810337ddea2b6  TrueCrypt User Guide.pdf
  17c46ebc6f4977afbcf4aa11eccee524fd95b1c8  truecrypt-x64.sys

Re: TrueCrypt suggesting migration to BitLocker?

#383
post #316

Earlier quoted context omitted.

If I were to wager a non-crazy, Occam's Razor-compatible bet, I'd say the author had a bad day, saw one too many digs at the quality of their decade-long work, got pissy, and decided to call it quits. I love popcorn-munching news as much as anyone, but this probably isn't it.

Then why pour so much work into re-authoring and re-releasing the program for all os's? And why offer such a canned bullshit explanation like the end of the availability of windows xp? All to show the trolls how much they miss truecrypt now that it's gone? I don't think so... anyone can find an old cloned repo/bin. I don't think it's impossible but it doesn't sit right with me that someone who could write/manage a pr…

Well, free project by anonymous developers right?

At some point the reward metric for that shifts away from your interests. It's never going to be picked up by like, major companies for enterprise-y use since Bitlocker has that market sewn up and it's never been really practical to use with Linux (from what I recall of looking into FDE for my notebook a few times in the past).

Re: TrueCrypt suggesting migration to BitLocker?

#384
post #316

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

If I were to wager a non-crazy, Occam's Razor-compatible bet, I'd say the author had a bad day, saw one too many digs at the quality of their decade-long work, got pissy, and decided to call it quits. I love popcorn-munching news as much as anyone, but this probably isn't it.

That's been my thinking as well since this came out yesterday. And it kind of makes sense why they modified the license to no longer require attribution, the only thing left in 7.2 is decryption related code, this would allow 3rd parties to distribute derivative works around decrypting legacy volumes (and possibly migrating to other encryption methods). But would stop anyone from creating a fork of earlier versions that still contained the encryption routines.

Re: TrueCrypt suggesting migration to BitLocker?

#385

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Another possibility - the author was required by a court order to provide a backdoor for unfettered access to truecrypt disk, and to not disclose the existence of the order. The solution was to modify the code so that everyone has unfettered access (i.e. disable encryption entirely) and make the recommendation that everyone switch to something else.

Question: has any such court order, ever, in the history of the United States, actually been given? Can it be given? Because that would be news to me.

Because while specific orders can't be disclosed if they'd give away information to the actual target, the general nature of such orders is well known - information can be demanded if held. You can't be compelled to engage in subterfuge though, and since such an order would be illegal, you could freely disclose it and let the civilian courts strike it down.

As one might note from the Lavabit fiasco, things only got weird because Lavabit decided to screw around being non-compliant, while also always having the technical capacity to decrypt everyone's email (and thus opening up the legal doorway to just seize the keys and all the data, rather then the tiny chunk that was wanted).

Re: TrueCrypt suggesting migration to BitLocker?

#386

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

Maybe while looking at the code themselves they found a very bad bug which would make previously made encrypted partitions easily crackable, and fixing it would obviously make the world aware to this, and they don't want to endanger or ruin the lives of everybody who has had a truecrypt container with sensitive data taken from them (for example to a malicious government), so the only way to go for them is to tell peo…

That's rather radical move in the face of the audit currenlty being conducted. If the bug is so dramatic, it will be revealed by the audit with high probability rendering this move practically useless.

Re: TrueCrypt suggesting migration to BitLocker?

#388
post #377
post #204

Earlier quoted context omitted.

As crazy as it sounds, I think you're right and it's just the developer(s) quitting (rage-quitting?) the project. Nothing else makes sense. The Bitlocker thing seems strange until you realize that it probably really IS the best alternative for most users. The users who are paranoid enough to not trust Bitlocker can probably look out for their own security, so it makes sense to give instructions for the rest. None of…

> The Bitlocker thing seems strange until you realize that it probably really IS the best alternative for most users. The users who are paranoid enough to not trust Bitlocker can probably look out for their own security, so it makes sense to give instructions for the rest. It seems odd to me that security specialists would recommend a flawed tool to 'the masses'. It just doesn't fit with what I usually read from peop…

It's pragmatic. BitLocker may or may not be flawed[1], but I don't see a lot of better options for disk encryption on Windows being presented.

[1] - Whether it's flawed or not depends on your needs. Not everyone cares about defending their data against an attacker with the resources of a nation-state - many just want their laptop's hard drives to be effectively inaccessible if the device is stolen or lost.

Re: TrueCrypt suggesting migration to BitLocker?

#390

Earlier quoted context omitted.

Your reply seems to be the most sensible out of the lot. (Side note: I presumed there'd be a couple other ones that suggested it's open source--never mind that prior to the removal of some of the license text it wasn't "free as in beer" open. To be fair, I had forgotten myself that TrueCrypt wasn't exactly open source.) Perhaps ownership does run deep, even if you've never really released a product for money and it's…

The one thing I have to add. Maybe by taking this route, the author(s) hope to inspire others to see the obvious need for a project like truecryp more dramatically. It's not like old bin/source repos aren't available in 100 different locations across the net; if you need the program you can get it. But this action does send a strong message and it's that there is no adequate existing cross-platform solution to this p…

That's a good point, and it's certainly true on many fronts. Commercial alternatives are questionable at best (particularly given the NSA revelations), but the F/OSS community (and others) relied perhaps too heavily on popular software like TrueCrypt to fill the void. Now that it's gone and the other alternatives aren't quite as cross-platform as one might like, it does seem to illustrate a dearth of cryptographic software available for the general public.

Given that border searches of electronic hardware are becoming more commonplace in the US, I should think that something like this is important. I know when I was driving back and forth to university, the thought crossed my mind when I had my laptop with me as I went through the border patrol checkpoint that there wasn't anything much I could do (outside lawyering up) if they took it upon themselves to grab it and search. Sure, the worst they could have done was read my email (and maybe clear out the junk folder for me while they're at it), but it was the principle of feeling so violated by the act itself that drove me to stuff all my school work into a TrueCrypt volume.

(This was years ago, and TC was the best option for XP. Though I later switched the laptop over to Linux.)

Post reply on HN