Live data from Hacker News

"Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

cryptome.org

1–10 of 62 posts

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#4

Worth mentioning that truecrypt volumes can be hidden inside playable video files. Yes, it's security through obscurity, but hey, it makes me feel a little safer. http://keyj.emphy.de/real-steganography-with-truecrypt/

Mentioning a steganographic technique implies that you use it, negating the point.

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#5
Page 16 has some wonderful lines:

  • “Fruit of the poisonous tree” can be circumvented
    • The use of backdoors cannot be detected or proven
    • Vendors are legally and commercially prevented from
      acknowledging their backdoors. Defense will not be
      able to prove their existence
    • The files can be described as “forensically obtained”

Re: "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

#10
post #6

Truecrypt is open source. Can anyone find the backdoor?

"Reflections on trusting trust" [1] may be necessary here. When you install Truecrypt, do you download a packaged binary app? Or do you compile it from source? Do you trust your compiler?

Until you know what the backdoor actually _is_, please don't stop just because you audited the source code.

[1] a good summary is at http://en.wikipedia.org/wiki/Backdoor_%28computing%29#Reflec...

Post reply on HN