Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

61–70 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#61
post #13

The advice for Linux is "Search available installation packages for words encryption and crypt, install any of the packages found and follow its documentation." So... just any of them, then? Sure, ok.

https://wiki.archlinux.org/index.php/Disk_encryption#Compari... This might help.

I think the point was just that the advice given was so vague, that it seems suspicious that this is actually an official communication.

Re: TrueCrypt suggesting migration to BitLocker?

#64

Well - this comes as a pretty big surprise. Is this real? Is there a known vulnerability that catalyzed this? Money from Microsoft? Threats? I'm not buying into conspiracy theories, but it does seem pretty out of place.

The binaries are properly GPG-signed with the same key as the previous binaries, check for yourself. [They] either compromised their private key too or the actual developer(s) did this. Be it voluntarily or by force of secret three-character agencies / a massive pay check.

A much simpler explanation is someone defaced the site around the same time a new release was coming out. Is there anything in the signed release package to corroborate what the site says?

Re: TrueCrypt suggesting migration to BitLocker?

#65
post #58
post #43

8 hours ago on the IndieGoGo TrueCrypt Audit page [1] > p.s. We hope to have some big announcements this week, so stay tuned. [1] https://www.indiegogo.com/projects/the-truecrypt-audit#activ...

Although Kenn White, who wrote that message, has no idea what's going on [1] > .@FiloSottile @matthew_d_green no idea. It's doing a 301 perm to a static pg @ SF, now blocked. Possibly compromised. pic.twitter.com/g5tSFUuXzu [1] https://twitter.com/kennwhite/status/471740840478797824

He's responded specifically about the message:

  .@Costly no idea. The announcement was about a
  new Open Crypto Audit Project initiative, not TC.
https://twitter.com/kennwhite/status/471741290552782849

Re: TrueCrypt suggesting migration to BitLocker?

#66
This is creepy as hell.

No mention of why it's supposed to be not secure - it's an open source project so it would be easy to point to a specific vulnerability. All of this shortly after passing audit. There are detailed steps towards switching to supposedly secure closed-source solutions by companies known to be working closely with the NSA.

Also, since when do open source projects suddenly decide they are not as good enough as a closed-source alternative and then stop the project? Are we in danger of seeing a similar message on the homepage of LibreOffice and OpenOffice, declaring that you should switch to Microsoft Office?

I can't even begin to imagine a valid scenario in which something like this would be put up by the developers, with no pressure other than some fatal security flaw about which they just really don't want to talk.

Re: TrueCrypt suggesting migration to BitLocker?

#67
post #37
post #15

Earlier quoted context omitted.

truecrypt.org does a redirect to this sourceforge page, so perhaps it is the DNS that got hijacked, and not truecrypt website itself. I don't remember TC ever being hosted on SF, so I think this is a bad redirect...

On the other hand, SourceForge lists the project as having been created in 2004: http://sourceforge.net/projects/truecrypt/

The SF account could have been compromised too.

Re: TrueCrypt suggesting migration to BitLocker?

#70

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

If the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".
Post reply on HN