3 ms·
I don't use TrueCrypt myself, and haven't followed what's happening with it in any detail, but I'll comment on the general question here: why do you need to kee
by liw 11y ago
I don't use TrueCrypt myself, and haven't followed what's happening with it in any detail, but I'll comment on the general question here: why do you need to keep up to date with vulnerabilities in order to keep secure.
First, nothing is ever totally secure. If a system gets audited today, the best the auditors can say is that to the best of their knowledge, the system has either no flaws, or list the vulnerabilities they know about. There might be vulnerabilities they missed. Some of the unknown ones might be blatant (say, a backdoor), or very subtle. When the unknown ones are found later on, and become public, the only way to not be vulnerable to those is to update.
Second, a system may become vulnerable later by the environment around it changing. This might be, for example, a change in the compiler (you rebuild for a new platform, and the kernel introduces a vulnerability), or in the language interpreter, or some library that the software uses, or the operating system kernel, or something else. It might be that you upgrade the CPU and the hardware random number generater on the new CPU is worse than in the old CPU. It might be that you move your system from physical hardware you control to a virtual machine you rent, thereby violating security assumptions made by the software.
A system, or software, that is never updated stays still, and never gets better, while potential attackers learn more tricks and more ways to attack. Sooner or later they'll find a way to attack any stale systems.
And that is why updating is important for security.