PDA

View Full Version : Mysterious announcement from Truecrypt declares the project insecure and dead


Surf n Turf
05-30-2014, 19:50
I use this encryption software on my machine(s). Not terrible disturbed :rolleyes:

Snt

Mysterious announcement from Truecrypt declares the project insecure and dead

The abrupt announcement that the widely used, anonymously authored disk-encryption tool Truecrypt is insecure and will no longer be maintained shocked the crypto world--after all, this was the tool Edward Snowden himself lectured on at a Cryptoparty in Hawai'i

Truecrypt is a widely used system for disk-encryption, and is particularly noted for its "plausible deniability" feature, through which users can create hidden partitions within their cryptographic disks that only emerge if you enter the correct passphrase; this is meant to be a defense against "rubber hose cryptanalysis," in which someone is physically or legally threatened in order to coerce them into yielding up her keys. In the "plausible deniability" scenario, the victim can give up the keys to a "harmless" partition while keeping the very existence of a second partition for sensitive material a secret. I am a Truecrypt user, as, apparently, is Edward Snowden, who lectured on the software's use at a Cryptoparty he held in Hawai'i before going on the run.

The response to the Truecrypt news is mostly frank bafflement. The software is licensed under an obscure "open source" license that makes it unclear whether third parties can support the now (apparently) orphaned codebase.

WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues. This page exists only to help migrate existing data encrypted by TrueCrypt. The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform.

IS THE NSA INVOLVED

COMMENTS
http://boingboing.net/2014/05/29/mysterious-announcement-from-t.html

This makes no sense whatsoever. I believe what most of the Reddit commentators do. The NSA started twisting arms with secret suponeas to force the addition of a back door. Rather than comply, and they could not reveal the supoenas - that is a serious crime - the developers put out an obviously bogus explanation in order to warn users off the product.

http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_development_has_ended_052814/

scooter
05-30-2014, 23:22
Interesting.

If the feds were the cause of this, why now? Truecrypt has been around for a minute or two.

JamesIkanov
05-31-2014, 01:48
Perhaps because it took them this long to find the individual(s) responsible for writing the software, and go through the actual hoops to subpoena them?