Live data from Hacker News

TrueCrypt must not die

truecrypt.ch

81–90 of 103 posts

Re: TrueCrypt must not die

#81

Honestly, I was hoping this drama would result in the implementation of hidden containers for other crypto solutions (dm-crypt, etc). Hopefully that may still happen.

The FAQ for cryptsetup states: https://code.google.com/p/cryptsetup/wiki/FrequentlyAskedQue...

This means that if you have a large set of random-looking data, they can already lock you up. Hidden containers (encryption hidden within encryption), as possible with Truecrypt, do not help either. They will just assume the hidden container is there and unless you hand over the key, you will stay locked up. Don't have a hidden container? Though luck. Anybody could claim that.

Re: TrueCrypt must not die

#82
Still have no idea what's the "unfixed security issues", and few guys mention about it. I image there the "security issues" will be (if it exist): 1. because key are easy to stolen by coolboot or trojan. 2. because it has backdoor, will save key to a hidden place. 3. because it will leave some information in other place, like 2 but it's implantation problem. 4. because it use a vulnerable algorithm to generate key. 5. because pbkdf2 or aes256 is broken but nobody known it. exclude 2 and 3, change to other software it's not help at all, algorithm almost same.

Re: TrueCrypt must not die

#83
post #10

Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: https://twitter.com/stevebarnhart/status/472203503478509568 Edit: That tweet was deleted for some reason, but the rest of the thread is still there: https://twitter.com/stevebarnhart/status/472192457145597952

Hope they can give a gpg signed mail content.

Re: TrueCrypt must not die

#84
post #67

Earlier quoted context omitted.

> Linux security was significantly reduced at one point because somebody changed int i to int i=0 Could you please elaborate on this one?

Seems to me they relied on the uninitialized memory of a stack variable as a partial source of randomness for key generation. Initializing the variable with 0 removed that part.

Your explanation makes sense. Though I'm still curious as to when this happened and what the impact was.

Re: TrueCrypt must not die

#85
post #54

Earlier quoted context omitted.

I have much doubt about that since BitLocker is certainly not good enough: https://twitter.com/stevebarnhart/status/472195239005147136 And why not just writing that you no longer feel motivated to continue the further development of your software? It is very common after all …

The developer(s?) who made TrueCrypt did it for their own reasons. They didn't necessarily do it because they wanted to "stop teh NSA." A lot of people who wanted to "stop teh NSA" started using TrueCrypt, and so they assumed that their goals lined up with TrueCrypt's. But maybe they didn't. Maybe the developer using TrueCrypt was perfectly happy with "defend against anyone short of the NSA, especially since the NSA…

Exactly, and it's amazing what a sudden lack of motivation (for a FREE project after 10 years) will do to someone compared to how you feel when you first are building and all giddy and have high aspirations. They're probably worn out and tired and so suddenly they don't feel as strict need to adhere to their previous guidelines.

However, I personally find that interesting since I'd think in today's climate it's even more important and they were getting lots of exposure.

Re: TrueCrypt must not die

#86
post #82

Still have no idea what's the "unfixed security issues", and few guys mention about it. I image there the "security issues" will be (if it exist): 1. because key are easy to stolen by coolboot or trojan. 2. because it has backdoor, will save key to a hidden place. 3. because it will leave some information in other place, like 2 but it's implantation problem. 4. because it use a vulnerable algorithm to generate key. 5…

If we believe the person I was in contact with (big IF, I know), there are no current issues, but it is by definition "harmful" to continue use because it is no longer being maintained. In fact, the person requested I tell Steve Gibson to not distribute or include a notice telling people not to use it.

Re: TrueCrypt must not die

#87
post #79
post #76

Anonymous development on a security relevant Project is no longer an option. Why not?

Because trust is an important commodity on a project like this. Higher trust means fewer horrible things slipping past the review process.

Anonymity is out and I'd say that being an "independent" crypto person that has to defend themself will not get you very far once you have come to the attention of the wrong people.

So what options remain for the person that starts the "next Truecrypt"? The only true safe haven I can think of is employment at a public university. In many countries here in Europe the security researchers working at universities can operate under what is called "academic freedom".

I wonder how that will be destroyed.

Re: TrueCrypt must not die

#88
post #79
post #76

Anonymous development on a security relevant Project is no longer an option. Why not?

Because trust is an important commodity on a project like this. Higher trust means fewer horrible things slipping past the review process.

Trust is indeed important, but is connecting a name (or a number of names) to a project the only way to establish trust?

Re: TrueCrypt must not die

#89

Earlier quoted context omitted.

I disagree. TrueCrypt (for better or for worse) made encryption available to the masses in an easy to use application. Without it, similar level of encryption requires knowledge of unix command line or expensive commercial products. The events that have unfolded do certainly raise the stakes for the TrueCrypt audit, but at present, I am still better off using TrueCrypt, than nothing at all.

Having taught hundreds of people how to use True crypt over the years, I would certainly say that it was hardly easy for the average person to use.

It was, however, easy enough to use for anybody capable of administering their own Windows PC, a situation which most of us on this site have been in at some point in our lives.

Re: TrueCrypt must not die

#90
post #68
post #10

Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: https://twitter.com/stevebarnhart/status/472203503478509568 Edit: That tweet was deleted for some reason, but the rest of the thread is still there: https://twitter.com/stevebarnhart/status/472192457145597952

It doesn't mean anything. That's the exact same reply someone under a gag order would give too.

Bob: [practising] As you know, sir, we have several loans with your institutions, all "past due". But what does "past due" even mean, you know?

Gene: It's brilliant! There's no such thing as time!

Post reply on HN