6 ms·
It is available the version 7.1a, but the TrueCrypt development has stopped (for now). An alternative solution is VeraCrypt (build over Truecrypt 7.1a): https:
by luck87 11y ago
It is available the version 7.1a, but the TrueCrypt development has stopped (for now).
An alternative solution is VeraCrypt (build over Truecrypt 7.1a): https://veracrypt.codeplex.com/ https://veracrypt.codeplex.com/
VeraCrypt says to add extra security features (ex.
TrueCrypt uses PBKDF2-RIPEMD160 with 1000 iterations whereas in VeraCrypt we use 327661): https://veracrypt.codeplex.com/discussions/569777#PostContent_1313325 https://veracrypt.codeplex.com/discussions/569777#PostConten...
Do you think VeraCrypt is an valid alternative? or have they only fix something in TrueCrypt ( like change the CONSTANT value of iterations )
- dtech 11y agoThey're your most realistic option right now. They are actively developing it and added things like newer algorithms (e.g. SHA2). There's CipherSched but that is basically a completely new program/rewrite which is very far from done. However, I don't agree with VeraCrypts choices. They've changed several things that make mounting slow (0,5s -> 10s), which is annoying, especially if you mistype the password. Providing the option for increased security isn't bad, but they refuse to give users overrides to disable those slow security options because they are of the opinion that users can't assess the tradeoff for themselves. Which leads people to just go back to truecrypt because it works way better in their minds.
- m82labs 11y agoThis is an odd conclusion to come to. Are there a lot of users of True/Veracrypt that don't understand this? I guess I just don't see my grandparents using either of these packages, and I can't imagine a lot of "normal" users "trying out" a new encryption program.
- tired_man 11y agoJust because a person is older than you doesn't mean they're either stupid or completely non-technical. Plenty of older people started using computer in the middle of the sixties. So what if we started with card punch machines, tape readers, and mainframes? Just exactly what do you mean by "normal?" How much computer exposure does it take before one loses that quality and becomes, well, "you?" There are lots of grandparents coding away in cubes across the world or tinkering with their prized home-brew desktop rig. Take a reality pill, kiddo. If anything, there are fewer younger people who will tinker with crypto because the vast majority of them think they're invincible, indestructible, and immortal, when they're really just inexperienced and gullible.
- icebraining 11y agoI understand that there's a prejudice against older people regarding technical ability, but the parent poster didn't actually say anything regarding old people in general, just about his/her grandparents specifically.
- tired_man 11y agoGrandparents _are_ the prototypical older generation. Read areound. That's become the common usage ;-)
- icebraining 11y agoSo how are we supposed to refer to our actual grandparents, without people assuming we're making a generalization?
- kijin 11y ago10 seconds is ridiculous, especially if you know what you're doing and use strong passphrases. The passphrase to one of my TrueCrypt volumes is around 30 characters long. It's not completely random, so let's say it only has 2 bits of entropy per character. That's 60 bits total. A brute-force attack would take an average of 2^59 guesses before it succeeds. At 10 seconds per guess, we're looking at approximately 180 billion years to crack my passphrase. Even if you devoted a million computers to the job (as an extremely well-funded adversary might do), it would still take 180,000 years. If you weakened the PBKDF to take 1 second instead, it would take 18,000 years to crack my relatively weak passphrase using a million computers. That's still long enough that I don't care at all. Moreover, if I were really paranoid, I can easily bring it back to the 180,000-year mark (or more) by adding a few more characters to my passphrase, which would only take another second to type. So why wait 10 seconds?
- monort 11y agoYou can bruteforce much faster on GPU. E.g. 20*10^9 ripe160 hashes per second on 8x AMD R9 290X (price is around $3000): https://hashcat.net/oclhashcat/ https://hashcat.net/oclhashcat/ 60 bits are not secure against attacker with medium budget.
- luck87 11y agoSome years before oclHashCat support, I buil a gpu cracker for truecrypt volume TrueCrack (https://code.google.com/p/truecrack/ https://code.google.com/p/truecrack/) . To be honest oclHashCat has better performance. Now the board of the oclHashCat tests ( AMD R9 290X ) costs about 300 euro (not $3000).
- monort 11y agoThey used 8 cards for that test.
- kijin 11y agoThen we can use GPUs to speed up VeraCrypt's PBKDF, too. The point is that there's no need for a PBKDF that takes 10 seconds on modern hardware. Sure, that 60-bit passphrase is weak. But it takes a trivial amount of effort to increase the entropy of a passphrase. Let's say I increased it to 80 bits. In terms of brute-force resistance, that's equivalent to increasing the PBKDF's iteration count 1 million times.
- mhogomchungu 11y ago> They're your most realistic option right now. zuluCrypt[1] is another option if you are on linux. Its GPL licensed and exists in a lot of distribution's repositories(Will appear in debian and ubuntu repositories shortly) It supports TrueCrypt volumes,VeraCrypt volumes and LUKS volumes. [1] http://mhogomchungu.github.io/zuluCrypt/ http://mhogomchungu.github.io/zuluCrypt/
- vog 11y agoUnder Linux, what is the advantage of TrueCrypt/zuluCrypt over plain old LUKS? (which is automatically set up on any modern Linux Distro installation)
- Sir_Cmpwn 11y agoThere is no advantage. Choosing TrueCraft is a choice to use software with more questionable origins.
- bitL 11y agoPlausible deniability? With LUKS everyone can see your volume is encrypted; to avoid that you'd have to use plain dm-crypt/cryptsetup, randomize your drives (time consuming) and manage keys yourself (too much work).
- fluidcruft 11y agoAnyone can be pretty sure that your drive is encrypted rather than full of entropy, anyway.
- bitL 11y agoImagine somebody decided to use $5 wrench method on you right after you randomized your RAID ;-)
- mhogomchungu 11y agoLUKS is an on-disk format where as TrueCrypt is both an on-disk format and an application.zuluCrypt is only an application that supports multiple on-disk formats so your question is not easy to answer since it mixes up different things. LUKS advantages over TrueCrypt is that it can support up to 8 different passwords and each password security can be fine tuned by a changeable pbkdf2 iteration count that is set per password. TrueCrypt on-disk format advantages over LUKS is that it can support two volumes(outer one and hidden one) and its header is completely hidden since its encrypted.LUKS volume header is unencrypted and hence visible. With a LUKS based encrypted volume,its possible to mimic a hidden header on a device through the usage of a "detached header" but this is a property of tools that manage LUKS volumes and not of a LUKS volume on disk-format.It is also possible to mimic a hidden volume through a plain dm-crypt volume at a non zero offset but this is also a property of a tool that manages LUKS volume and not of a LUKS volume format. When it comes to binary applications,zuluCrypt is better than TrueCrypt because it supports TrueCrypt on-disk format together with other formats and it also supports multiple hidden volumes through the use of plain dm-crypt volumes. zuluCrypt also supports LUKS volumes with a detached header and this is more or less like TrueCrypt volume that requires a password and a keyfile(the detached header will act as a keyfile in this case). zuluCrypt also supports plain dm-crypt volumes at a none zero offset and this means it can have more than one "hidden volumes" although it does not offer protection of these hidden volumes.
- ikeboy 11y agoWhy would someone want to use Veracrypt but not have the increased security? Why not just use Truecrypt?
- ilurk 11y ago> Disclaimer: this site is not affiliated with, nor is it the official site of TrueCrypt AFAIK there are several forks out there. But who is behind them? Can they be trusted? BTW, for those looking for the code, this is the only reliable host for the Truecrypt source code: https://github.com/AuditProject/truecrypt-verified-mirror https://github.com/AuditProject/truecrypt-verified-mirror
- tokenizerrr 11y agoWe don't even know who was behind TrueCrypt itself. How could that be trusted? Because it was open source and people could and have reviewed the code.