11 ms·
In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rat
by Adaptive 12y ago
In order of likelihood:
* Defaced site, timed to screw up a big announcement
* Rogue content maintainer
* Phase II of audit turned up something rather bad
(edit: NO - see tptacek below)
edit: Variations on "developer forced to do this" (cf simmerian's comment):
* Developer was big brother all along and they are shutting it down
* Security vuln about to be disclosed, dev scrambles to inform (albeit poorly)
* Legally or otherwise compelled to compromise source code,
dev complies and/or nukes project from orbit
The last alternative would be suggested in part by the strange content of the page, assuming it is legit from the developer: Normally I'd expect at least something like "there's a major vuln that is unfixable and we'll disclose formally in a week/two, migrate now.".
- Netcob 12y agoIf the audit turned up something bad, the obvious step to take would be to publish it in all detail, fix the flaw, and then tell users to upgrade as soon as possible. Not go "OK SHOW'S OVER, USE PROPRIETY SOFTWARE FROM NOW ON".
- Adaptive 12y agoYes. This would be just about the worst way to announce and make recommendations. Looks like defacement to me.
- opendais 12y agohttps://twitter.com/matthew_d_green/status/471741836722073600 https://twitter.com/matthew_d_green/status/47174183672207360... It doesn't appear related to the audit
- Flimm 12y agoNitpick: Truecrypt is proprietary (it's source is viewable, but you aren't licensed to distribute modifications of it).
- riffic 12y agoOpen(ish) source but non-free.
- higherpurpose 12y agoUnless some kind of backdoor was about to be discovered...and they'd rather close it down before it gets discovered.
- tptacek 12y agoPhase 2 of the audit hasn't started yet.
- Adaptive 12y agoSeems to point towards compromised SF account.
- zorked 12y agoThere's a new binary that recommends moving to BitLocker during install, and the signature matches. Edit: with a new, compromised key.
- Alupis 12y agoIs source still available? Can we check the commit tree for anything suspicious lately? Can someone compile it and check the hash against the 7.2 binary being offered?
- Canada 12y agoIt's not that simple. It won't match anyway. Signatures, compiler versions, SDK versions, etc.
- guan 12y agoThis guy managed to compile a previous version and have it match the released binaries https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binaries-analysis/ https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...
- tripzilch 12y agoNot quite. First, it was a ton of work to do so. Second, in the end he in fact only managed to match most of the released binary. Then, for most of the unmatched parts he came up with some solid arguments why they would be different (timestamps, pathnames and such). However, in the end there were still a couple of chunks of unmatched data that he couldn't explain why it has the value it does. Finally he argues that these chunks probably can't contain any hidden backdoors. This last bit I have a bit of a problem with because it's just speculation, all the rest of the research is very solid and without guesswork, and the conclusion of the article IMO incorrectly states he "has matched the binaries". I'm chalking this up to, after all that work, having come so far, kind of wanting to say you did it, and providing a few (IMO) hand-wavy arguments why those last impossible chunks of bits probably don't matter, instead of having to admit defeat after being able to account for 99.9% of all bytes. I can understand that, I've been wanting to type "but it's probably not backdoored" three times already typing this post, and catching myself because really I have nothing to go on to make or back that statement.
- unsignedint 12y agoAlso might be coming from lack of donations. I remember that button becoming more and more prominent lately...
- Alupis 12y agoThat would not result in a message of "True Crypt Is Not Secure!!!!" in bold red. Seems to be geared towards frightening people. I concur -- likely an elaborate website deface.
- unsignedint 12y agoAs irrational it may be, I've seen people writing something like that out of frustrations... I don't think any legit organization would do that, but what if it's maintained by a small team or even individual -- I don't think I've ever seen a single face of TrueCrypt developers out there...
- Alupis 12y agoGood point. If true, I'd much rather have them post a countdown clock and say "If we don't reach X funding goal in donations by date Y, then we will be forced to close the project". Funds would come in then... a lot of people depend on truecrypt.
- owlmanatt 12y agoThat's not what the message says, though. > WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues That is a perfectly reasonable thing to say if you are abandoning security software. Any issues discovered will not be fixed, so you should stop relying on this software for security.
- philtar 12y agoScroll all the way to the bottom
- Alupis 12y agoNSA is obviously in on it. Who else would recommend using holy-bug-riddled proprietary-back-doored-on-purpose encryption software? ;-P
- Tomte 12y agoI choose to believe Niels Ferguson when he says "Over my dead body.": http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.aspx http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...
- mschuster91 12y agoA NSL is powerful enough to render all this moot. Therein lies the great danger of NSLs.
- Alupis 12y ago2 things. 1) Obviously I was joking in my comment above. 2) That post is dated well before common knowledge of how "in-bed" Microsoft is with the USA spy agencies (at least management is). This is a topic for another discussion, but I just want to point out that, of course someone being coerced under gag order to install less-than above-water "features" and/or purposefully weaken the product would say exactly what is in the blog post.
- alextgordon 12y agoIf I were the NSA, I'd try to get one of my hundreds of world-class cryptographers a job on the BitLocker team. In fact, BitLocker would be the first thing I'd weaken. Because 1) It's closed source, hard to externally audit. 2) It's one of the most used encryption packages in the world. 3) Microsoft's poor security track record provides excellent cover if the weakness is ever found. Closed-source security software is a recipe for disaster.
- r0muald 12y ago> Over my dead body. > Well, maybe not literally---I’m not ready to be a martyr quite yet So, in short he's written 8 years ago that in principle he was totally against backdoors. Times have changed so much that a statement of that tone is almost entirely useless IMHO.
- pearjuice 12y agoThis is legit and I am willing to bet. https://gist.github.com/anonymous/e5791d5703325b9cf6d1 https://gist.github.com/anonymous/e5791d5703325b9cf6d1 The entire source has been modified to reflect the Sourceforge page its contents. Encryption process is disabled. The current binaries can only be used to "migrate". You can deface a webpage but the effort it takes to rewrite the entire source code, compromise the GPG, compromise domain, compromise mail servers et cetera is not minimal. It is happening. Whether they are being forced to do so is a whole different story.
- conductor 12y agoI agree that this really looks like it is legit. It looks like, for some reason (we don't believe in the legend version, do we?) they abruptly (the diff contains many normal changes also) stopped the development and are burning all the bridges. They also slightly changed the license so now the forks are free to not mention that they are based on TrueCrypt, they are not allowed to link to truecrypt.org site or mention the TrueCrypt name in their product's domain name. They also removed all the links to their site from the source code (even the donation page).
- marcosdumay 12y ago> we don't believe in the legend version, do we? I dunno. We saw the legend version happening with a lot of people recently. Yep, we still mostly don't belive it, but... What's the oposite to The Boy that Cried Wolf?
- simmerian 12y ago* That's a lot of wasted effort for a defacement with seemingly no motive except some (uncredited) lulz. * Possible, but once again I see no motive that would produce this brand of outburst. * And it's unfixable? That would be a world first. I think it's much more plausible this is some powerful entity forcing a hand. We know by now there's plenty of motive and candidates to fit that shoe.
- Adaptive 12y agoIt is a lot of effort, and you make good points. I'll add a note to my original post.
- deleted 12y ago[deleted]
- Torgo 12y agoTheir mail server is on the same IP as truecrypt.org, and it's now rejecting mail.
- gregatragenet2 12y agoAnother possibility - the author was required by a court order to provide a backdoor for unfettered access to truecrypt disk, and to not disclose the existence of the order. The solution was to modify the code so that everyone has unfettered access (i.e. disable encryption entirely) and make the recommendation that everyone switch to something else.
- XorNot 12y agoQuestion: has any such court order, ever, in the history of the United States, actually been given? Can it be given? Because that would be news to me. Because while specific orders can't be disclosed if they'd give away information to the actual target, the general nature of such orders is well known - information can be demanded if held. You can't be compelled to engage in subterfuge though, and since such an order would be illegal, you could freely disclose it and let the civilian courts strike it down. As one might note from the Lavabit fiasco, things only got weird because Lavabit decided to screw around being non-compliant, while also always having the technical capacity to decrypt everyone's email (and thus opening up the legal doorway to just seize the keys and all the data, rather then the tiny chunk that was wanted).
- enimodas 12y agoMaybe while looking at the code themselves they found a very bad bug which would make previously made encrypted partitions easily crackable, and fixing it would obviously make the world aware to this, and they don't want to endanger or ruin the lives of everybody who has had a truecrypt container with sensitive data taken from them (for example to a malicious government), so the only way to go for them is to tell people their product should not be used any more and is bad.
- demosito 12y agoThat's rather radical move in the face of the audit currenlty being conducted. If the bug is so dramatic, it will be revealed by the audit with high probability rendering this move practically useless.
- 4bpp 12y agoThe element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. Surely, a Truecrypt developer who got served a gagging order to build in a backdoor would realise that a big and compliant target such as Microsoft would have been subject to the same measure long ago, and likewise that if a pre-existing vulnerability on a sufficient scale to justify this went unnoticed in an open-source project even after a proper audit, the situation is unlikely to look that much better in a closed-source solution (that only the makers and government agencies have access to). While this might be reading a tad much into it, the language of the announcement, specifically the "...as it may contain unfixed security issues" bit, sounds like what somebody who just came out on the losing end of a heated debate about whether some bug-feature should or should not be considered the former would say. Knowing the vitriol and determination with which software developer arguments are often carried out, this would explain the observed combination of remarkable dedication and haphazard execution.
- UVB-76 12y ago> The element that does not square with any theories that suggest benevolent intent behind the change is the recommendation that users switch to Bitlocker. I realize we are firmly in conspiracy theory territory here, but perhaps the suggestion that users switch to Bitlocker is intended to be so patently absurd as to be a signal that the developers are under duress?
- jebblue 12y agoI'd agree, that seems more believable than some of the other theories I've read.
- dsuth 12y agoThat's my take on it as well, even though it fails the Occam's razor test. This all sounds like a very understated way of saying "we can no longer develop truecrypt with impunity, and the only other options are closed source, and highly likely to be compromised out of the gate".
- tacotime 12y ago
- quasque 12y agoIt could be that they've simply lost interest in developing it. It's quite the ongoing responsibility, and they may well be tired of working on it - a decade is a long time in anyone's life. If this is true, then perhaps such listlessness was also catalysed by the ongoing audit. Maybe seeing such a mass of crowdfunding income towards a project to pick Truecrypt apart, in contrast to the scant donations to its development, disheartened the authors towards further work? Abandoning it in this rather dramatic way ensures that Truecrypt's users are warned against using unsupported software where any bugs will remain unfixed. This is especially important when such bugs revealed in the future (and maybe ones already known) have the possibility of being deleterious for security.
- Zancarius 12y agoIf you're developing a free product and you're going to throw in the towel anyway, why not just open up the sources with a liberal license and/or hand the project over to someone else who's willing to carry the torch.
- quasque 12y agoIt may be the same strong sense of ownership and control that precluded the liberalisation of Truecrypt's license during its lifetime in the past decade.
- Zancarius 12y agoYour reply seems to be the most sensible out of the lot. (Side note: I presumed there'd be a couple other ones that suggested it's open source--never mind that prior to the removal of some of the license text it wasn't "free as in beer" open. To be fair, I had forgotten myself that TrueCrypt wasn't exactly open source.) Perhaps ownership does run deep, even if you've never really released a product for money and it's always been free. Still, it's something I don't understand: If I had a tool that I released for free and finally gave up on it, I'd like to think I'd open it up under an exceptionally liberal license or just dump it in the public domain. That'd be especially true if it had a lot of users. That's what makes me think that if this isn't some elaborate scheme it's likely the result of some sort of legal requirement or action (e.g. Lavabit) which would preclude the author(s) from doing anything else with the software. It's a shame they couldn't take a scorched earth-esque approach of dumping everything in the public domain, including notes on why this was happening, everyone else be damned, but I'd imagine their entire career might be in jeopardy at that point (and possibly their freedom).
- tghw 12y agoWhat if this is an attempt to smoke out the TrueCrypt devs? While this move seems odd, the new binaries are properly signed and the domains have been updated accordingly. If this was another project, like Rails, the maintainer could come out and say they were hacked and the last good version was X. Otherwise, the project would likely die off. But since we know so little about the TrueCrypt maintainers, there's little way for us to hear that this isn't legitimate. In order to keep the project from dying (if this is a hoax), they would have to prove that they are the maintainers, because any plausible deniability would undermine their claim that the change was not legitimate.
- deleted 12y ago[deleted]
- ColinDabritz 12y agoWouldn't they just have to published a signed message stating that the change was not theirs and the key is compromised? Or better yet, revoke the key? If two groups with opposing messages control the key, it's pretty clear that the key is compromised in some manner.
- monokrome 12y agoNo, because the suggested "hackers" have published a signed message.
- hamburglar 12y agoDoesn't matter. Publish another message signed with the same key saying "this key is compromised."
- jcrawfordor 12y ago> If two groups with opposing messages control the key, it's pretty clear that the key is compromised in some manner.
- tghw 12y agoIf 7.2 is part of the hoax, then they would be signing with a compromised key. This would be evidence, but would not be conclusive.
- ultramancool 12y agoAfter examining all the facts, I think it's most likely they just didn't want to develop it anymore: * PGP matches * Authenticode matches * SourceForge data was modified * DNS records were modified And to top it off, let's put ourselves in the theoretical attacker's shoes, the binaries when run make no unexpected connection attempts or write to any unexpected places and don't appear to contain any unexpected imports, so if this was a hack, it's a very stealthy and very boring one. The most they achieved would be uninteresting to most attackers. It would only really be an effective attack against people who had TrueCrypt volumes but not a current copy of TrueCrypt as there's no compelling reason for anyone to upgrade to 7.2 and certainly they'd be skeptical after this. Any attacker with the intelligence and patience for such an attack would surely realize how poor an execution this would be. A better attack would be "here, it's TrueCrypt 8, it has loads of EFI support and mad security, everyone should install it, it's the best!". There's simply no reason to shut it down like this, unless the attack is just an elaborate practical joke. It's quite possible this came from 1 big developer hack, but considering how the release was done, with full source and everything for every supported platform... if it was a hack, it's a very, very good one. They've also decided to modify the license terms, perhaps bringing it into compatibility with more common FOSS licenses. I think it's far more likely at this point that the devs, who had not updated their software in years, finally decided to call the project over and have marked it insecure because the codebase is now unmaintained and should be assumed insecure.
- mandalar12 12y agoI guess the new license only applies to the release it is distributed with and this latest version removed encryption features so I doubt it will make the truecrypt project more compatible with FOSS licenses.
- ultramancool 12y agoTrue, but they likely intended it for all releases and I highly doubt the dev(s) are going to burn their anonymity to go after you even if they didn't. Though I suppose that's not the best legal rationale, now is it?
- deleted 12y ago
- api 12y ago* SourceForge account compromised and developers unwisely stored private keys and other information somewhere inside this account, permitting the attacker to compromise lots of other stuff and generally have a blast.
- asdkl234890 12y agoMy order of likelihood is #1. This is a canary. https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- DrStalker 12y agoDo agencies like the NSA/FBI/etc have the power to make a company publicly lie against their will?
- joshAg 12y agoif you count lies of omission, yes. you can be required as part of an ongoing investigation or court case to not talk about it. The legal term is "gag order".
- danielweber 12y agoIf you are ordered not to communicate something, you are ordered not to communicate it. Doing a "I'm not not telling you something, ha ha" might work on the playground, but not in real life.
- DrStalker 12y agoI meant can the NSA force you to keep publishing "we have not worked with the NSA" when you have worked with them.