Bitcoin Forum
May 24, 2024, 03:43:04 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: TrueCrypt development ended - now insecure?  (Read 1520 times)
Thylacine (OP)
Member
**
Offline Offline

Activity: 115
Merit: 10


View Profile
June 01, 2014, 08:21:30 AM
 #1

Cliffs: The Sourceforge project page for Truecrypt updated with notice that Truecrypt should no longer be used as it is not secure. Latest binaries on site are read-only - no new encrypted volumes can be created (you may still read ones you have created in previous versions). Whole thing is a little mysterious and smells fishy.

Speculation in spades, no real answers;

http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_development_has_ended_052814/
http://boingboing.net/2014/05/29/mysterious-announcement-from-t.html

Does anyone have any updated information?

This news is certainly bad for me as my security solution was to store my wallets inside a TrueCrypt container - of which I also have multiple backup copies in the cloud. Although it may seem like asking for trouble to store anything in the cloud - I figure even if there is a bad actor on DropBox's end, it's going to be (effectively) computationally impossible for them to get into the container contents. After which, they would have to still then break through the native encryption on the wallet, so I was reasonably happy with the solution. But given this news, it might be time I create a new wallet and transfer my coins over.

Anyone have any thoughts or good TrueCrypt alternatives? Maybe I'll try Armoury etc..
Parazyd
Hero Member
*****
Offline Offline

Activity: 812
Merit: 587


Space Lord


View Profile WWW
June 01, 2014, 08:37:35 AM
 #2

What the actual fuck?
SirChiko
Legendary
*
Offline Offline

Activity: 966
Merit: 1000



View Profile
June 01, 2014, 09:12:10 AM
 #3

Maybe you should look here:
"The first phase of the TrueCrypt audit found no serious problems with the Windows build of TrueCrypt."

http://www.pcworld.com/article/2304851/so-long-truecrypt-5-encryption-alternatives-that-can-lock-down-your-data.html

The only online casino on which i won something. I made 17mBTC from 1mBTC in like 15 minutes.  This is not paid AD!

▀Check it out yourself▀
Newar
Legendary
*
Offline Offline

Activity: 1358
Merit: 1001


https://gliph.me/hUF


View Profile
June 01, 2014, 12:04:23 PM
 #4


http://www.dyne.org/software/tomb/



For possibly more secure cloud storage look into wuala. They claim the files are encrypted on your computer before they are sent to their servers. Of course you still got to trust them that they uphold that promise...
www.wuala.com

OTC rating | GPG keyid 1DC91318EE785FDE | Gliph: lightning bicycle tree music | Mycelium, a swift & secure Bitcoin client for Android | LocalBitcoins
dooglus
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
June 02, 2014, 03:12:15 AM
 #5

Maybe you should look here:
"The first phase of the TrueCrypt audit found no serious problems with the Windows build of TrueCrypt."

http://www.pcworld.com/article/2304851/so-long-truecrypt-5-encryption-alternatives-that-can-lock-down-your-data.html

There is a theory that the TrueCrypt developers were approached by a government body and forced to weaken the security of TrueCrypt, and also forced not to tell anyone about it.

And so this would be their way of them telling us about it without actually telling us.

The fact that they recommend we switch to a closed-source Microsoft solution is just laughable.  Their advice for Linux users is "search for some other package".

Something fishy is definitely going on.

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
b!z
Legendary
*
Offline Offline

Activity: 1582
Merit: 1010



View Profile
June 02, 2014, 04:11:21 AM
 #6

Maybe you should look here:
"The first phase of the TrueCrypt audit found no serious problems with the Windows build of TrueCrypt."

http://www.pcworld.com/article/2304851/so-long-truecrypt-5-encryption-alternatives-that-can-lock-down-your-data.html

There is a theory that the TrueCrypt developers were approached by a government body and forced to weaken the security of TrueCrypt, and also forced not to tell anyone about it.

And so this would be their way of them telling us about it without actually telling us.

The fact that they recommend we switch to a closed-source Microsoft solution is just laughable.  Their advice for Linux users is "search for some other package".

Something fishy is definitely going on.

That is actually very possible in my opinon. Do you think they chose to shut down for the same reason LavaBit did?

This article lists a few possibilities: http://www.coinbuzz.com/2014/06/01/truecrypt/
Truecoin
Sr. Member
****
Offline Offline

Activity: 312
Merit: 250


View Profile
June 02, 2014, 04:39:59 AM
 #7

You can still download it here: http://truecrypt.ch/


BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
June 02, 2014, 04:47:25 AM
 #8

Maybe you should look here:
"The first phase of the TrueCrypt audit found no serious problems with the Windows build of TrueCrypt."

http://www.pcworld.com/article/2304851/so-long-truecrypt-5-encryption-alternatives-that-can-lock-down-your-data.html

There is a theory that the TrueCrypt developers were approached by a government body and forced to weaken the security of TrueCrypt, and also forced not to tell anyone about it.

And so this would be their way of them telling us about it without actually telling us.

The fact that they recommend we switch to a closed-source Microsoft solution is just laughable.  Their advice for Linux users is "search for some other package".

Something fishy is definitely going on.
This, it's called the canary. aka lavabit.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
dooglus
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
June 02, 2014, 04:51:50 AM
 #9

Do you think they chose to shut down for the same reason LavaBit did?

That would be my guess.

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
Parazyd
Hero Member
*****
Offline Offline

Activity: 812
Merit: 587


Space Lord


View Profile WWW
June 02, 2014, 04:54:56 AM
 #10

7.1 is still on all of my boxes. Has anyone audited the source?
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
June 02, 2014, 06:31:53 AM
 #11

7.1 is still on all of my boxes. Has anyone audited the source?
it was being audited and the results are to be released soon from my understanding.
Nothing major was found. I might have read it wrong too. always check these things for yourself.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
dooglus
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
June 02, 2014, 07:17:59 AM
 #12

7.1 is still on all of my boxes. Has anyone audited the source?

http://istruecryptauditedyet.com/

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
Thylacine (OP)
Member
**
Offline Offline

Activity: 115
Merit: 10


View Profile
June 02, 2014, 08:33:30 AM
 #13

I was a couple of days late after the TrueCrypt announcement posting this to bitcointalk to begin with, and somewhat surprised no one had posted it before. I guess everyone uses paper wallets/cold storage or whatever, and not that many keep their own encrypted volumes anymore.

I'll be keeping an eye on the audit of 7.1 results, as I kind of liked TrueCrypt. But Tomb seems pretty good too looking at it now...
Parazyd
Hero Member
*****
Offline Offline

Activity: 812
Merit: 587


Space Lord


View Profile WWW
June 02, 2014, 08:50:14 AM
 #14

Yeah Tomb seems nice. The entire dyne thing is pretty awesome.
dooglus
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
June 02, 2014, 09:39:59 AM
 #15

See https://www.grc.com/misc/truecrypt/truecrypt.htm too.

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
Parazyd
Hero Member
*****
Offline Offline

Activity: 812
Merit: 587


Space Lord


View Profile WWW
June 02, 2014, 11:06:40 AM
 #16

I think I'll continue using v7.1. I don't see why I shouldn't.
Este Nuno
Legendary
*
Offline Offline

Activity: 826
Merit: 1000


amarha


View Profile
June 02, 2014, 02:10:01 PM
 #17

The whole 'go use bitlocker' thing is blowing my mind. How could they possibly say that?

I'm on 7.1a but I'm not too happy right now. Honestly I don't have anything really worth protecting since I don't keep btc on it, but still.

I'm not a paranoid person but after seeing that message my imagination starts going off.

Has there been any other unofficial messages from the TC people? The lack of explanation really makes me even more suspicious...like they can't legally talk about or something.
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
June 02, 2014, 05:48:29 PM
 #18

The whole 'go use bitlocker' thing is blowing my mind. How could they possibly say that?

I'm on 7.1a but I'm not too happy right now. Honestly I don't have anything really worth protecting since I don't keep btc on it, but still.

I'm not a paranoid person but after seeing that message my imagination starts going off.

Has there been any other unofficial messages from the TC people? The lack of explanation really makes me even more suspicious...like they can't legally talk about or something.
If they have been served a NSL they can't talk about it at all. Not even hint really.


The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
Este Nuno
Legendary
*
Offline Offline

Activity: 826
Merit: 1000


amarha


View Profile
June 02, 2014, 06:03:56 PM
 #19

The whole 'go use bitlocker' thing is blowing my mind. How could they possibly say that?

I'm on 7.1a but I'm not too happy right now. Honestly I don't have anything really worth protecting since I don't keep btc on it, but still.

I'm not a paranoid person but after seeing that message my imagination starts going off.

Has there been any other unofficial messages from the TC people? The lack of explanation really makes me even more suspicious...like they can't legally talk about or something.
If they have been served a NSL they can't talk about it at all. Not even hint really.



Would the government consider what they said a hint though? Legally speaking?
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
June 02, 2014, 06:08:21 PM
 #20

The whole 'go use bitlocker' thing is blowing my mind. How could they possibly say that?

I'm on 7.1a but I'm not too happy right now. Honestly I don't have anything really worth protecting since I don't keep btc on it, but still.

I'm not a paranoid person but after seeing that message my imagination starts going off.

Has there been any other unofficial messages from the TC people? The lack of explanation really makes me even more suspicious...like they can't legally talk about or something.
If they have been served a NSL they can't talk about it at all. Not even hint really.



Would the government consider what they said a hint though? Legally speaking?
Sure but they have to be able to prove it as well which probably isn't worth that effort alone.
We can't even prove what we "think" it might be. It might be what it is at face value..
The lack of any further information though could be a good indicator they are not at liberty to discuss anything.
I'm taking it as they have been compromised. I'm keeping my old copy and I read it's been forked already.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!