9 ms·
German BSI withholds Truecrypt security report
- 60654 7y agoNote, the title is no longer accurate. There's an update at the end of the article, along with a download link: > Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22
- hvidgaard 7y agoEither they had to do that, or they had to be ready for the barrage of incoming requests for the documents.
- usrusr 7y agoWhich gives the "withhold" part of the story a strong push towards Hanlon's Razor, once the topic escalated to higher ranks the copyright ceased to be a hindrance. Or more precisely, towards an organizational variety of Hanlon's Razor, where stupidity takes the form of the organizational failure mode of underlings not being authorized to do what would have been the right thing. Curiously, a less colloquial formulation of Hanlon's Razor would replace stupidity with incompetence and this, when translated to German contains a hint of a precisely matching double entendre: in German, "Kompetenz" is used for two separate things. For being able to (like in English) and being authorized to. It's not a full double entendre because the negated form "Inkompetenz" is exclusive to the mental ability, just like the English counterpart, but what's a good aphorism without subtle extra layers?
- Certhas 7y agoScheinbare Bösartigkeit kann oft durch mangelnde Kompetenz erklärt werden. ;)
- deleted 7y ago[deleted]
- perlgeek 7y agoThe documents seem to be available here: https://fragdenstaat.de/anfrage/untersuchungen-zum-verschlusselungsprogramm-truecrypt/ https://fragdenstaat.de/anfrage/untersuchungen-zum-verschlus... They all have "geschwärzt" (blackened) in the file name, but it looks like only some author's name (and maybe working group name) have been removed -- I've scrolled through a few of these files, and didn't find anything else that might have been removed.
- close04 7y agoI'm not sure if the implication of the following is that sections of the report were withheld or that it was incomplete to begin with. > However the report hints that more such flaws exist. Another chapter in the documents mentions, that several such off-by-one-errors were found, but due to a lack of a complete code analysis only examples can be shown. However even those examples are missing in the document - the following chapter only consists of a headline and has no content.
- johannes1234321 7y agoMy understanding is that the auditors didn't have time to analyze all these errors, thus omitted them from the report already, but only pointing out the potential risk.
- tastroder 7y agoThis AP7 (work package 7) document seemed the most relevant, although most of it reads like generic test results and conceptual stuff. Not sure why they would try to hold that back. A non-malicious view would be that they simply are a part of German bureaucracy and subsequently slow. Non-Google translation of the summary (AP7, page 70) for those interested: "5 Summary This work package first describes the basic building blocks that are utilized to secure the start [boot?] process, as well as ones that might be necessary and helpful to realize hard dism encryption via full-disk-encryption . Beyond that existing attacks are described and investigated if the solutions presented here mitigate against them or not. In chapter 4 several possible solutions are presented, both online (meaning with network connectivity) as well as offline. The most promising solutions use the new Trusted-Computing functionality based on a Trusted Platform Module (TPM) and a Boot of Trust (CRTM/SRTM/DRTM). The most desirable solutions are the Secure Boot procedure from chapters 4.4 and 4.5. These do however require either the development of new hardware or need to be based on special hardware extensions, e.g. Intel's TXT technology. A large-scale deployment in an existing, heterogenous area is therefore improbable. At the moment solutions that combine Trusted Boot with the attestation functionality seem to be the most sensible. This solution can be combined with: - Sealing: Storing a secret on the platform configuration. - NVRAM: Storing a secret in an area of the Trusted Storage, inside the TPM, that is only readable/writable given a valid configuration. - Attestation: Proof of platform integrity towards an external party. As "external parties", multiple counterparts could be realized: - Online, e.g. a central server. - Offline: e.g. a smart card or a smart phone application that takes on the verification for the server. All three variants (sealing, NVRAM, attestation) are reliant on the correctness of the PCRs." The rest is potential use cases and an impact matrix of the attacks described in the document.
- Grumbledour 7y agoIt is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them. I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the developers and many state entities that use the software and its successor. The BSI is sadly often toothless when it comes to actually enforcing security standards on federal entities but to see them not even trying to educate on such matters, when they clearly know better, squanders a lot of trust one may have in them.
- chmod775 7y ago> since this information would be relevant to the developers and many state entities that use the software and its successor. The BSI actually did communicate the findings of the report to the TrueCrypt developers in 2010, which the developers ignored: > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. (From page 2 of the article)
- Grumbledour 7y agoYes, but they neglected to tell the veracrypt developers once truecrypt stopped being developed. Though they also do know many municipalities using both applications. They should have told the veracrypt developers and advised the municipalities to switch to the newer version. And the whole argument about the information being outdated by then when both are clearly in use seems negligent of their duties.
- chmod775 7y ago> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...] > The BSI knew all that. [...] > The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published. This is looking pretty terrible for Truecrypt. It means they ignored a vulnerability report and kept the vulnerabilities around for five years.
- blattimwind 7y agoTruecrypt has been abandoned for ~seven years or so.
- Globz 7y agoYou should no longer use TrueCrypt, if you want an alternative I suggest https://www.veracrypt.fr https://www.veracrypt.fr
- whoopdedo 7y agoBut did the VeraCrypt developers know about it?
- pulse7 7y agoAccording to the article they didn't know about it.
- jmakov 7y ago"... in the simplest case a user can mount a Truecrypt volume that contains a file with suid root permission that will open a shell. Golem.de was able to replicate this scenario in a current version of Veracrypt."
- kuschku 7y agoOuch.
- bonzini 7y ago... if you have sudo.
- aasasd 7y agoWhere does sudo come in with suid executables? Especially since afaik sudo depends on suid in the first place.
- jlgaddis 7y agoOne might be granted privileges to mount the filesystem using sudo, but not privileges to run other commands. If the filesystem just mounted has setuid executables, however, the user can then get around their lack of additional sudo privileges by running the setuid executables. Although most people seem to use sudo to allow a user to run anything, that's really not how it was intended to be used.
- aasasd 7y agoThat's somewhat different from the Veracrypt case, afaict. And it doesn't seem like this is what bonzini meant by mentioning sudo.
- bonzini 7y agoYou still need to gain the privilege to mount filesystems in order to exploit the flaw. So it is a privilege escalation in that you can go from "sudo mount" to a root shell, but it is: 1) not exploitable unless you have sudo 2) pointless if you are authorized to "sudo" any command.
- intc 7y agoFWIF: https://truecrypt.ch/ https://truecrypt.ch/
- kjaftaedi 7y agoIf you're going to comment, it's highly preferable that you read the article where all of this is explained.
- unixhero 7y agoWho cares about the TFA. The comments is the content. Especially here! braces for downvotes
- Forbo 7y agoAs per the guidelines: > Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that."
- yorwba 7y agoSomehow I didn't notice the article was paginated. Thanks for pointing that out.
- EsssM7QVMehFPAs 7y agoWhy would they release an audit that effectively provides them with zero-days into encrypted suspect disks. They release now because no one is using TrueCrypt any longer..
- lucb1e 7y agoBecause there weren't any real zero days in the report in the first place. The article mentions that it's mainly minor things like failing to clear memory, which is only helpful in rare circumstances.
- nolok 7y agoThey did not publish publicly but did report their findings to the true crypt foundation so that it could be fixed (but they in return didn't agree that those were flaws worth thinking)
- onetimemanytime 7y agoMuch safer to assume that a decent nation state can decrypt Truecrypt and a lot of other things. You can hide stuff from your wife, friends or banana Republic countries, but I wouldn't bet against NSA with 30 years in jail.
- treljherthj 7y agoTrue, but not by outright cracking the encryption. They will get your password instead, by implanting your keyboard, putting a camera behind you on the wall, or grabbing you just after you've entered your password.
- onetimemanytime 7y agoGood point. Another thing: even if they can decrypt it, they'd save that for Osama types, not ruin it over a small tax case. Otherwise bad guys would stop using it. Maybe decrypt but not use in court...
- iudqnolq 7y agoOne tool is parallel construction. First they find out what you did through an illegal/classified method, then they use the benefit of knowing the answer to construct a way to figure out the same information legally. For example, an agency illegally taps your phone and find out you'll be driving with something illegal in your car along a certain route. The agency then tells some state troopers to notice $your_car driving unsafely at $location and pull you over for a routine traffic stop and search your car. It's unlikely they'd take even that risk on a tax case, though.
- tootahe45 7y agoThat sounds like effort. Intercepting your next Amazon order for anything that plugs into the pc and loading it up with malware would be better.
- unnouinceput 7y agoI use VeraCrypt and none of this are of my concern in my daily use of it. Can anyone tell me if my containers are still safe from prying eyes since I upload them to cloud? I need specific answers from anyone working on VeraCrypt, not general answers of "yeah, they are unsafe" that usually HN does.
- ficklepickle 7y agoBurn everything and flee to the woods. Can't be too careful.
- Zenbit_UX 7y agoSince you're uploading them to the cloud do keep in mind that given 60 years of computer advancement, today's encryption standards will be unlikely to withstand tomorrow's hardware...
- unnouinceput 7y agoYou're generous. I'd give them no more then 10. Which is all I need in the first place. But I am worried about them this or next year, after that if they get decrypted would just be mildly annoying.
- tgsovlerkhgsel 7y agoCounterpoint: DES was broken because of the short key length, something that had been criticized very early on. Asymmetric crypto will likely fall soon; symmetric crypto with conservative key length choices, e.g. AES-256, may stand for a long time (including the age of quantum computers).
- pushedx 7y agoIs there a solid alternative to TrueCrypt with most of the features that’s been implemented with a proof-checking system such as OcaML Mirage?
- cantrevealname 7y agoThe casual user stumbling on this article is going to think that TrueCrypt or VeraCrypt has been broken. There’s a big difference between attacks on a live system when a volume is being used, versus cases in which an encrypted volume is lost, stolen, or copied. It needs to be firmly said that there is still no known way to recover plaintext from an unmounted TrueCrypt or VeraCrypt volume on a powered-off system without knowing the pass phrase. TrueCrypt and VeraCrypt are still totally secure for the standard use-case of protecting your powered-off laptop being stolen, or your backup drives being lost, or an encrypted volume that you’ve copied over to Dropbox being compromised.
- gruez 7y ago>The casual user stumbling on this article is going to think that TrueCrypt or VeraCrypt has been broken. And why should the casual user use TrueCrypt/VeraCrypt when Bitlocker/Filevault works out of the box and is built into the operating system? I feel like that most people using veracrypt do so because it's open source, and they're distrustful of the software vendors. For that threat model, you need to have protections against evil maid attacks, which TrueCrypt/VeraCrypt does not have.