Well, if red Times New Roman on a Sourceforge page says so...
http://truecrypt.org/ redirects there, too.
TrueCrypt suggesting migration to BitLocker?
51–60 of 414 posts
Re: TrueCrypt suggesting migration to BitLocker?
#52Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.
The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.
Re: TrueCrypt suggesting migration to BitLocker?
#53I missed the part where this document lists the vulnerabilities in TrueCrypt.
Re: TrueCrypt suggesting migration to BitLocker?
#54I'm really confused. Which isn't unusual really, but in this case I think it is understandable.
I'm with you. This seems like an odd move, given that most likely only a minority of their users used XP for some time. Why haven't they been warning Windows Vista, 7 and 8 users to use Bitlocker for years (not to mention Mac OS X and Linux users)? Perhaps I just missed the warnings, but I am really puzzled. I suppose the developers could have just found a massive vulnerability (perhaps they're doing their own audit…
Re: TrueCrypt suggesting migration to BitLocker?
#55Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.
The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.
Even if it's a legit announcement, I wouldn't run that 7.2 binary. Anyone running truecrypt already has truecrypt, right? I don't know why they'd release a new version at the same time as such a dire and panic-inducing announcement.
Re: TrueCrypt suggesting migration to BitLocker?
#56Earlier quoted context omitted.
The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.
Maybe something like the Lavabit scenario where they rather close the shop than sell their users out. On the other hand, proposing Bitlocker as an alternative would be rather suspect in that case.
I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...
Re: TrueCrypt suggesting migration to BitLocker?
#57Does anyone have a cached version?
Re: TrueCrypt suggesting migration to BitLocker?
#588 hours ago on the IndieGoGo TrueCrypt Audit page [1] > p.s. We hope to have some big announcements this week, so stay tuned. [1] https://www.indiegogo.com/projects/the-truecrypt-audit#activ...
> .@FiloSottile @matthew_d_green no idea. It's doing a 301 perm to a static pg @ SF, now blocked. Possibly compromised. pic.twitter.com/g5tSFUuXzu
Re: TrueCrypt suggesting migration to BitLocker?
#59 * Defaced site, timed to screw up a big announcement
* Rogue content maintainer
* Phase II of audit turned up something rather bad
(edit: NO - see tptacek below)
edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down
* Security vuln about to be disclosed, dev scrambles to inform (albeit poorly)
* Legally or otherwise compelled to compromise source code,
dev complies and/or nukes project from orbit
The last alternative would be suggested in part by the strange content of the page, assuming it is legit from the developer: Normally I'd expect at least something like "there's a major vuln that is unfixable and we'll disclose formally in a week/two, migrate now.".Re: TrueCrypt suggesting migration to BitLocker?
#60By "Truecrypt-end" user: https://en.wikipedia.org/wiki/Special:Contributions/Truecryp...