4 ms·
If they discovered an issue in Windows, and it led to gag orders, why would they tell people to move to BitLocker (a Microsoft product)?
by jaawn 11y ago
If they discovered an issue in Windows, and it led to gag orders, why would they tell people to move to BitLocker (a Microsoft product)?
- nickysielicki 11y agoThis is obviously all conjecture, but my argument is that they made their actions as bizarre as possible because it's the only way to get out a distress call. They abruptly push a release that removes all the core functionality. They abruptly say that there will be no future releases. They wanted everyone to plainly see that this isn't them just giving up on the project because they've lost interest. Suggesting people use Bitlocker is completely against everything they stand for. Here are some quotes off the FAQ on OP's rehosted website: > > Will TrueCrypt be open-source and free forever? > Yes, it will. We will never create a commercial version of TrueCrypt, as we believe in open-source and free security software. > > Why is TrueCrypt open-source? What are the advantages? > As the source code for TrueCrypt is publicly available, independent researchers can verify that the source code does not contain any security flaw or secret ‘backdoor’. If the source code were not available, reviewers would need to reverse-engineer the executable files. However, analyzing and understanding such reverse-engineered code is so difficult that it is practically impossible to do (especially when the code is as large as the TrueCrypt code). > Remark: A similar problem also affects cryptographic hardware (for example, a self-encrypting storage device). It is very difficult to reverse-engineer it to verify that it does not contain any security flaw or secret ‘backdoor’. These same people who condemned closed-source crypto in their FAQ are now suggesting using a closed-source encryption suite? It is completely absurd, and that's the point.
- jaawn 11y agoI think a more likely scenario might be that control of the project was seized, and the final release and statements were not from the developers, or they were issued by the developers under duress. It seems more like an agency wanted to shut it down because it worked too well.
- nickysielicki 11y agoI refuse to believe we live in that unfree of a society. I know that we have FISA courts and so forth, but that's still a tier below preventing someone from continuing to publish their computer code. All the 90's cases surrounding cryptography as armaments cemented the notion that it's protected under the first amendment.
- ionised 11y ago> I refuse to believe we live in that unfree of a society. I could never believe otherwise. Not after everything I've learned in my time on this rock.
- jaawn 11y agoI think our society is not this unfree provided you are willing to fight. Several government agencies have the power through fear to do something like this when they deem it necessary, and a very small dev team with no resources or company lawyers to back them up would be an easy target. Sure, fighting such a seizure might yield success, but it is a lot of time and energy and money to devote to a cause. This is the same reason why many people settle lawsuits out of court instead of seeing them through.
- ionised 11y agoI suspect that by recommending encryption software that is highly unreliable like Bitlocker (by virtue of being closed source and developed by Microsoft who we know cannot be trusted) they sent up a huge red flag to their user base. Nobody would expect the TrueCrypt devs to recommend something like this, so it is immediately suspect and all anyone really needs to asusme something isn't right (like a gag order).