Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

391–400 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#391

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

infosecslave said in a dead comment: [...] you have to consider the fact that Truecrypt project was started before FDE was popular, maybe their goal all this time was to popularize such encryption. With XPs demise that goal would have been achieved as every current Windows version comes with Bitlocker. Your comment is dead but makes a lot of sense, especially in light of the message on the website: The development of…

One of the planned features according to the TrueCrypt website, was "Full support for Windows 8".

http://en.wikipedia.org/wiki/TrueCrypt#Planned_features

Re: TrueCrypt suggesting migration to BitLocker?

#393

This is the best analysis I have seen on the situation so far. It has the facts, cites sources, and gives a few theories as to what may be happening. http://www.etcwiki.org/wiki/What_happened_to_Truecrypt_-_May...

Great theories, good list of facts, but there aren't too many facts to begin with. Any ideas to add?

Re: TrueCrypt suggesting migration to BitLocker?

#394

Earlier quoted context omitted.

>> They haven't updated it for years. As I said even if not recently they still invested many years into that project. Of course it is juvenile to senselessly ruin the code and suddenly advertising a very different commercial product, especially without proper scientific reason. Not to mention that precisely because they haven't done much work lately I don't see any reason why the developers would disfigure their pro…

I think it makes sense, it can wear on a developer fairly heavily to be burdened by the user community of a cryptography product. Just look at this very thread, so many paranoid theories about NSLs and such, where they don't even make remote sense. They most likely just wanted to stop needing to work on the project or respond to comments. They're not "advertising a very different commercial product". They're recommen…

[deleted]

Re: TrueCrypt suggesting migration to BitLocker?

#395

Earlier quoted context omitted.

Could you post the SHA1s of those? I'm failing to use GPG properly.

tc/linux$ sha1sum * c2a8c78a23f97ffb17bf47448c9f2daa3c8f80cd truecrypt-7.1a-linux-console-x64.tar.gz 078cdd4a58f0342cb872d7456c0ba49e310fcad9 truecrypt-7.1a-linux-console-x64.tar.gz.sig a53a7a609a25d9a1e33f720ce5c0265ddd4e8b25 truecrypt-7.1a-linux-console-x86.tar.gz 66060f9444d5df70b4fcdeb655dc60131fce5ad1 truecrypt-7.1a-linux-console-x86.tar.gz.sig 086cf24fad36c2c99a6ac32774833c74091acc4d truecrypt-7.1a-linux-x64.ta…

Can you please make these available for download, the Linux ones at least?

Re: TrueCrypt suggesting migration to BitLocker?

#396

Earlier quoted context omitted.

>> They haven't updated it for years. As I said even if not recently they still invested many years into that project. Of course it is juvenile to senselessly ruin the code and suddenly advertising a very different commercial product, especially without proper scientific reason. Not to mention that precisely because they haven't done much work lately I don't see any reason why the developers would disfigure their pro…

I think it makes sense, it can wear on a developer fairly heavily to be burdened by the user community of a cryptography product. Just look at this very thread, so many paranoid theories about NSLs and such, where they don't even make remote sense. They most likely just wanted to stop needing to work on the project or respond to comments. They're not "advertising a very different commercial product". They're recommen…

"Bitlocker is probably the most viable alternative on Windows."

How would a software with closed source from a company that has been gladly working with the US government in the past be a "viable alternative" to TrueCrypt? Really, please try to read the comments above before you enter the discussion.

Re: TrueCrypt suggesting migration to BitLocker?

#397

Earlier quoted context omitted.

I think it makes sense, it can wear on a developer fairly heavily to be burdened by the user community of a cryptography product. Just look at this very thread, so many paranoid theories about NSLs and such, where they don't even make remote sense. They most likely just wanted to stop needing to work on the project or respond to comments. They're not "advertising a very different commercial product". They're recommen…

"Bitlocker is probably the most viable alternative on Windows." How would a software with closed source from a company that has been gladly working with the US government in the past be a "viable alternative" to TrueCrypt? Really, please try to read the comments above before you enter the discussion.

Easily. It performs the same task, is actively maintained and supports things like EFI. If you know of a better alternative on the windows platform, please do tell, because I'm not aware of one and neither are the TC devs it appears. Just because an alternative is not as perfect as you would like does not invalidate it completely. If you try actually reading, you'll note that I am the poster of many of the comments above. Please avoid making an ass out of yourself in the future. And keep your retarded paranoia out of legitimate discussion.

Re: TrueCrypt suggesting migration to BitLocker?

#398
post #395

Earlier quoted context omitted.

tc/linux$ sha1sum * c2a8c78a23f97ffb17bf47448c9f2daa3c8f80cd truecrypt-7.1a-linux-console-x64.tar.gz 078cdd4a58f0342cb872d7456c0ba49e310fcad9 truecrypt-7.1a-linux-console-x64.tar.gz.sig a53a7a609a25d9a1e33f720ce5c0265ddd4e8b25 truecrypt-7.1a-linux-console-x86.tar.gz 66060f9444d5df70b4fcdeb655dc60131fce5ad1 truecrypt-7.1a-linux-console-x86.tar.gz.sig 086cf24fad36c2c99a6ac32774833c74091acc4d truecrypt-7.1a-linux-x64.ta…

Can you please make these available for download, the Linux ones at least?

All of the files available here: http://truecrypt.ch/ have the same hashes as provided by this person.

Re: TrueCrypt suggesting migration to BitLocker?

#399
post #398
post #395

Earlier quoted context omitted.

Can you please make these available for download, the Linux ones at least?

All of the files available here: http://truecrypt.ch/ have the same hashes as provided by this person.

Don't just trust my SHA1s, verify with the sigs and the TrueCrypt Foundation public key. Ensure the key has the fingerprint shown in the great-great-great grandparent of this comment, independently verified by others in this thread.

  gpg --import TrueCrypt-Foundation-Public-Key.asc
  gpg --fingerprint F0D6B1E0
  gpg --verify truecrypt-7.1a-linux-x64.tar.gz.sig
You should see:

  gpg: Signature made Tue 07 Feb 2012 12:45:26 PM PST using DSA key ID F0D6B1E0
  gpg: Good signature from "TrueCrypt Foundation "
  gpg: WARNING: This key is not certified with a trusted signature!
  gpg:          There is no indication that the signature belongs to the owner.
  Primary key fingerprint: C5F4 BAC4 A7B2 2DB8 B8F8  5538 E3BA 73CA F0D6 B1E0

Re: TrueCrypt suggesting migration to BitLocker?

#400

Earlier quoted context omitted.

One of the changes in the newly-uploaded version is indeed a change in the license.

It does appear that the authors have removed the advertising clause in this latest license version. Also the section on commercial licensing, some mentions of registered trademarks, and all specific references to the truecrypt.org domain, including email addresses. However it's unclear if this change is only for Truecrypt 7.2 or can be applied retrospectively to previous versions. As the authors have deleted sizeable…

the devs themselves are anon

no one is going to come after anyone for licensing fees

Post reply on HN