Bye Bye True Crypt!?!?!?!

For complex topics that regular users would not be interested in. For power users and database administrators.
Post Reply
User avatar
Justin Shafer
Posts: 596
Joined: Sat Jul 28, 2007 7:34 pm
Location: Fort Worth, TX.

Bye Bye True Crypt!?!?!?!

Post by Justin Shafer » Wed May 28, 2014 4:53 pm

http://www.pcworld.com/article/2241300/ ... ocker.html

Image

TrueCrypt now encouraging users to use Microsoft's Bitlocker

TrueCrypt, the popular open-source encryption program, on Wednesday unexpectedly recommended that users drop its product and shift to Microsoft's Bitlocker.

TrueCrypt's Web page redirected itself to a SourceForge repository, which carried the following warning:

"WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues," a note at the top of the page read. "This page exists only to help migrate existing data encrypted by TrueCrypt."
truecrypt site Mark Hachman

The site continued: "The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP," it read. "Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform."

The page then goes on to describe how users should migrate their data from TrueCrypt to an encrypted BitLocker drive. (Note: BitLocker is ony available on Windows 8.1 Pro and Windows 8.1 Enterprise, making this a solution of limited use, reader Wesley Novack points out.)

The move was especially puzzling, given that TrueCrypt, a popular security choice for PCWorld users for several years, had recently passed the first round of a security audit. iSec, the firm that did the audit, found 11 flaws, but none that were immediately exploitable. Otherwise, iSec said it “found no evidence of backdoors or intentional flaws”.

Matthew Green, who teaches cryptoanalysis at Johns Hopkins and who worked on the audit, tweeted that he thought the change was a legitimate exit on the part of the developer, and not a hack. He said that he had attempted to contact the developers, and not heard back from them yet. But The Register is reporting that the most recent version of TrueCrypt appears compromised.

In the meantime, it's probably best that users who were going to download TrueCrypt simply hold off, until more information is revealed.

This story was updated at 4:15 PM with additional details.

User avatar
Justin Shafer
Posts: 596
Joined: Sat Jul 28, 2007 7:34 pm
Location: Fort Worth, TX.

Re: Bye Bye True Crypt!?!?!?!

Post by Justin Shafer » Wed May 28, 2014 5:03 pm

Wrote a blog post about it. :D
http://www.theregister.co.uk/2014/05/2 ... rypt_hack/

Holy Crap!!!!

KevinRossen
Posts: 293
Joined: Mon Apr 22, 2013 8:49 am
Location: Dallas, TX
Contact:

Re: Bye Bye True Crypt!?!?!?!

Post by KevinRossen » Thu May 29, 2014 10:59 am

I'm usually not a conspiracy theory guy, but something seems fishy about this. It's out of character for the open source community to say something is not secure without elaborating on exactly what is insecure.
Kevin Rossen
Office Manager, Rossen Dental
Founder, DivergentDental.com
Image

User avatar
Justin Shafer
Posts: 596
Joined: Sat Jul 28, 2007 7:34 pm
Location: Fort Worth, TX.

Re: Bye Bye True Crypt!?!?!?!

Post by Justin Shafer » Thu May 29, 2014 11:59 am

I think it has to do with phase 2 of the audit they were doing, and some internal developer strife.

Backdoors into the encryption?

User avatar
Justin Shafer
Posts: 596
Joined: Sat Jul 28, 2007 7:34 pm
Location: Fort Worth, TX.

Re: Bye Bye True Crypt!?!?!?!

Post by Justin Shafer » Thu May 29, 2014 12:12 pm

http://www.zdnet.com/truecrypt-quits-in ... 000029994/

There had been real accusations that TrueCrypt could be compromised. As this conversation between Green, and reporter Glenn Greenwald shows, they think Greenwald's partner's hard disk, protected with TrueCrypt, was somehow penetrated by the authorities. Green tells Greenwald "...trusting an uncertified Windows binary from a mysterious anonymous organization isn't good practice."

User avatar
Justin Shafer
Posts: 596
Joined: Sat Jul 28, 2007 7:34 pm
Location: Fort Worth, TX.

Re: Bye Bye True Crypt!?!?!?!

Post by Justin Shafer » Thu May 29, 2014 12:14 pm

So like.. trust BitLocker..... OMG..

:lol:

KevinRossen
Posts: 293
Joined: Mon Apr 22, 2013 8:49 am
Location: Dallas, TX
Contact:

Re: Bye Bye True Crypt!?!?!?!

Post by KevinRossen » Thu May 29, 2014 12:47 pm

Well, until I see that there is indeed a vulnerability in TCs encryption, I don't think it's an issue I'm going to worry about. There is a known back door into BitLocler's encryption designed for law enforcement, but it won't take long for that to get out into other's hands if it hasn't already.
Kevin Rossen
Office Manager, Rossen Dental
Founder, DivergentDental.com
Image

User avatar
Justin Shafer
Posts: 596
Joined: Sat Jul 28, 2007 7:34 pm
Location: Fort Worth, TX.

Re: Bye Bye True Crypt!?!?!?!

Post by Justin Shafer » Thu May 29, 2014 1:14 pm

KevinRossen wrote:Well, until I see that there is indeed a vulnerability in TCs encryption, I don't think it's an issue I'm going to worry about. There is a known back door into BitLocler's encryption designed for law enforcement, but it won't take long for that to get out into other's hands if it hasn't already.
Very interesting story...

IT kind of makes sense... Some developers inside must have figured out a backdoor and threatened the entire project, and their anger spread... and.. yeah...

Image

Post Reply