Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

411–414 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#411

- Signature is valid, so it's not a defacement. ( http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_dev... ) - The version there works and does not seem to have a trojan, so probably not a regular hacker. ( https://news.ycombinator.com/item?id=7813373 ) - Instructs to migrate to dubious alternatives, so it's not a legit security effort. - License change, precise instructions and decrypt-only version indicate i…

I can imagine how TrueCrypt with all the features like the plausible deniability was a major pain in terms of 'national security'.

And it is apparent the project was shut down by the original developer in a way that at best satisfies a gag order but doesn't actually hold up to scrutiny, so I see only two possible explanations for what happened:

1. An NSL with a gag order;

2. A nice lump sum of money in exchange for silence.

Or of course a combination of the two which is the most likely.

I don't blame the dev - he obviously spent years developing software which provided nothing in return.

I can only say one thing - if you want to hide stuff from the big brother, don't use BitLocker! ;-)

Re: TrueCrypt suggesting migration to BitLocker?

#412

Earlier quoted context omitted.

"Bitlocker is probably the most viable alternative on Windows." How would a software with closed source from a company that has been gladly working with the US government in the past be a "viable alternative" to TrueCrypt? Really, please try to read the comments above before you enter the discussion.

Easily. It performs the same task, is actively maintained and supports things like EFI. If you know of a better alternative on the windows platform, please do tell, because I'm not aware of one and neither are the TC devs it appears. Just because an alternative is not as perfect as you would like does not invalidate it completely. If you try actually reading, you'll note that I am the poster of many of the comments a…

One of TrueCrypt's best features was hidden volumes. As far as I know, BitLocker doesn't haven anything like that. I can definitely see that someone would have an interest in getting that shut down.

BitLocker lacks another one of TrueCrypt's most important features: open-source code, readable, verifiable, and compilable by any interested user. BitLocker is almost definitely already backdoored, so encouraging people to switch to that makes all of that data accessible by the powers that be.

I think it's silly to pretend like no authorities would have an interest in promoting the use of closed-source encryption techs. Apple and Microsoft were both willful participants in the PRISM program. TrueCrypt was the only open-source FDE software that had widespread adoption on non-Linux systems. After this, no major corporation or group is going to use TrueCrypt to encrypt anything anymore and will rely entirely on the backdoored encryption solutions provided by the NSA's known and confirmed compatriots.

Re: TrueCrypt suggesting migration to BitLocker?

#413

Earlier quoted context omitted.

Do agencies like the NSA/FBI/etc have the power to make a company publicly lie against their will?

If you are ordered not to communicate something, you are ordered not to communicate it. Doing a "I'm not not telling you something, ha ha" might work on the playground, but not in real life.

I meant can the NSA force you to keep publishing "we have not worked with the NSA" when you have worked with them.
Post reply on HN