Live data from Hacker News

TrueCrypt must not die

truecrypt.ch

41–50 of 103 posts

Re: TrueCrypt must not die

#41
post #35

Earlier quoted context omitted.

For me this tweet is 404, what is its content?

tweet was deleted for some reason. Here's another from the thread: https://twitter.com/stevebarnhart/status/472192457145597952

It looks like it was deleted because they were concerned about accidentally outing the developer. Which seems like a legitimate thing to be concerned about.

Re: TrueCrypt must not die

#42
post #38

Earlier quoted context omitted.

The Arch Linux wiki page has an excellent overview: https://wiki.archlinux.org/index.php/Encryption

Hmm, it doesn't appear that any of the options there work on Linux, OS X, and Windows?

You are correct. These options are not very portable. My point here is not that the alternatives are ready for non-technical users, but that developers should focus on realizing that future instead of maintaining and advocating a fork of dangerous software.

Edit: I was wrong, dm-crypt is supposedly accessible on Windows and maybe accessible on OS X. Non-FDE methods have decent spread. https://wiki.archlinux.org/index.php/Encryption#compatibilit...

Re: TrueCrypt must not die

#44
post #27

This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.

There is a $30,000 audit currently underway. There will be no security problems un-turned when they are through. That's assuming there are any to begin with (Personally, I think not). I see no issue picking up the codebase and running with it.

> That's assuming there are any to begin with (Personally, I think not)

They already found a few flaws. Nothing major though: https://opencryptoaudit.org/reports/iSec_Final_Open_Crypto_A...

Re: TrueCrypt must not die

#45
post #38

Earlier quoted context omitted.

Hmm, it doesn't appear that any of the options there work on Linux, OS X, and Windows?

You are correct. These options are not very portable. My point here is not that the alternatives are ready for non-technical users, but that developers should focus on realizing that future instead of maintaining and advocating a fork of dangerous software. Edit: I was wrong, dm-crypt is supposedly accessible on Windows and maybe accessible on OS X. Non-FDE methods have decent spread. https://wiki.archlinux.org/index…

> instead of maintaining and advocating a fork of dangerous software.

This smells of hyperbole. Why do you consider TC to be _dangerous_ software? Lack of maintenance? Speculative possibilities regarding recent events?

If the rumors are true that the TrueCrypt devs are throwing in the towel, that discounts a couple of dangerous scenarios I can think of leaving only lax maintenance.

Re: TrueCrypt must not die

#46
post #39
post #37

Earlier quoted context omitted.

It's clearly a ploy to get everyone backdoored. Just look at Crypto AG.

Hm. Is that Websters definition of "clearly", meaning "easy to perceive, understand, or interpret", or HN's definition, as in "it's clear someone or some agency got to the developers and they just pulled the ejection seat for their own legal protection"?

I was hoping the italics spoke for themselves, but I'd better clarify it's the latter. It seems to be an Internet-wide phenomenon to jump to the most bombastic possible conclusion given a limited set of facts.

Re: TrueCrypt must not die

#47
post #46
post #39

Earlier quoted context omitted.

Hm. Is that Websters definition of "clearly", meaning "easy to perceive, understand, or interpret", or HN's definition, as in "it's clear someone or some agency got to the developers and they just pulled the ejection seat for their own legal protection"?

I was hoping the italics spoke for themselves, but I'd better clarify it's the latter. It seems to be an Internet-wide phenomenon to jump to the most bombastic possible conclusion given a limited set of facts.

Sorry, I was just trying to use you to riff.

Re: TrueCrypt must not die

#48
post #10

Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: https://twitter.com/stevebarnhart/status/472203503478509568 Edit: That tweet was deleted for some reason, but the rest of the thread is still there: https://twitter.com/stevebarnhart/status/472192457145597952

topsy still has the tweets cached:

http://topsy.com/trackback?url=http%3A%2F%2Ftwitter.com%2Fst...

and for the user:

http://topsy.com/s?q=from%3Astevebarnhart&window=w&type=twee...

Re: TrueCrypt must not die

#50

Earlier quoted context omitted.

I disagree. TrueCrypt (for better or for worse) made encryption available to the masses in an easy to use application. Without it, similar level of encryption requires knowledge of unix command line or expensive commercial products. The events that have unfolded do certainly raise the stakes for the TrueCrypt audit, but at present, I am still better off using TrueCrypt, than nothing at all.

I'm speaking to developers who would work on something like maintaining a TrueCrypt fork. Instead, improve the usability of the alternatives to solve the problems you've raised.

Who says they aren't going to fork and continue development?

It's just a landing page that a couple of guys put up while they try to figure out what direction to take. Since there's an audit going on right now, when it's done they'll probably start fixing the problems and releasing new versions. Have a bit of patience.

Post reply on HN