4 ms·
It could be that they've simply lost interest in developing it. It's quite the ongoing responsibility, and they may well be tired of working on it - a decade is
by quasque 12y ago
It could be that they've simply lost interest in developing it. It's quite the ongoing responsibility, and they may well be tired of working on it - a decade is a long time in anyone's life.
If this is true, then perhaps such listlessness was also catalysed by the ongoing audit. Maybe seeing such a mass of crowdfunding income towards a project to pick Truecrypt apart, in contrast to the scant donations to its development, disheartened the authors towards further work?
Abandoning it in this rather dramatic way ensures that Truecrypt's users are warned against using unsupported software where any bugs will remain unfixed. This is especially important when such bugs revealed in the future (and maybe ones already known) have the possibility of being deleterious for security.
- Zancarius 12y agoIf you're developing a free product and you're going to throw in the towel anyway, why not just open up the sources with a liberal license and/or hand the project over to someone else who's willing to carry the torch.
- quasque 12y agoIt may be the same strong sense of ownership and control that precluded the liberalisation of Truecrypt's license during its lifetime in the past decade.
- Zancarius 12y agoYour reply seems to be the most sensible out of the lot. (Side note: I presumed there'd be a couple other ones that suggested it's open source--never mind that prior to the removal of some of the license text it wasn't "free as in beer" open. To be fair, I had forgotten myself that TrueCrypt wasn't exactly open source.) Perhaps ownership does run deep, even if you've never really released a product for money and it's always been free. Still, it's something I don't understand: If I had a tool that I released for free and finally gave up on it, I'd like to think I'd open it up under an exceptionally liberal license or just dump it in the public domain. That'd be especially true if it had a lot of users. That's what makes me think that if this isn't some elaborate scheme it's likely the result of some sort of legal requirement or action (e.g. Lavabit) which would preclude the author(s) from doing anything else with the software. It's a shame they couldn't take a scorched earth-esque approach of dumping everything in the public domain, including notes on why this was happening, everyone else be damned, but I'd imagine their entire career might be in jeopardy at that point (and possibly their freedom).
- tacotime 12y agoThe one thing I have to add. Maybe by taking this route, the author(s) hope to inspire others to see the obvious need for a project like truecryp more dramatically. It's not like old bin/source repos aren't available in 100 different locations across the net; if you need the program you can get it. But this action does send a strong message and it's that there is no adequate existing cross-platform solution to this problem outside of trusting your os or using (not so plausibly deniable) file archives. I'd like to think that the author(s) are trying to highlight the necessity while secretly cheering on the next generation of trucrypt.
- Zancarius 12y agoThat's a good point, and it's certainly true on many fronts. Commercial alternatives are questionable at best (particularly given the NSA revelations), but the F/OSS community (and others) relied perhaps too heavily on popular software like TrueCrypt to fill the void. Now that it's gone and the other alternatives aren't quite as cross-platform as one might like, it does seem to illustrate a dearth of cryptographic software available for the general public. Given that border searches of electronic hardware are becoming more commonplace in the US, I should think that something like this is important. I know when I was driving back and forth to university, the thought crossed my mind when I had my laptop with me as I went through the border patrol checkpoint that there wasn't anything much I could do (outside lawyering up) if they took it upon themselves to grab it and search. Sure, the worst they could have done was read my email (and maybe clear out the junk folder for me while they're at it), but it was the principle of feeling so violated by the act itself that drove me to stuff all my school work into a TrueCrypt volume. (This was years ago, and TC was the best option for XP. Though I later switched the laptop over to Linux.)
- SAI_Peregrinus 12y agoIt's already open-source.
- quasque 12y agoAs far as I know, its license is incompatible with other open source licenses due to an advertising clause (all derivative works have to state "based on Truecrypt" somewhere in the documentation or via use of the software). The old four clause BSD license had a similar issue.
- throwaway8889 12y agoOne of the changes in the newly-uploaded version is indeed a change in the license.
- quasque 12y agoIt does appear that the authors have removed the advertising clause in this latest license version. Also the section on commercial licensing, some mentions of registered trademarks, and all specific references to the truecrypt.org domain, including email addresses. However it's unclear if this change is only for Truecrypt 7.2 or can be applied retrospectively to previous versions. As the authors have deleted sizeable portions of the encryption code in this final version, such ambiguity could be problematic.
- heroh 12y agothe devs themselves are anon no one is going to come after anyone for licensing fees
- c_c_c 12y agoThe license was changed with the new release. Edit: The following clause was deleted in the 7.2 release. - c. Phrase "Based on TrueCrypt, freely available at - http://www.truecrypt.org/" http://www.truecrypt.org/" must be displayed by Your Product - (if technically feasible) and contained in its - documentation. Alternatively, if This Product or its portion - You included in Your Product constitutes only a minor - portion of Your Product, phrase "Portions of this product - are based in part on TrueCrypt, freely available at - http://www.truecrypt.org/" http://www.truecrypt.org/" may be displayed instead. In each - of the cases mentioned above in this paragraph, - "http://www.truecrypt.org/" http://www.truecrypt.org/" must be a hyperlink (if - technically feasible) pointing to http://www.truecrypt.org/ http://www.truecrypt.org/ - and You may freely choose the location within the user - interface (if there is any) of Your Product (e.g., an - "About" window, etc.) and the way in which Your Product will - display the respective phrase.
- Zancarius 12y agoIndeed it was. As was its ability to encrypt, apparently. I don't exactly count those as one in the same.
- Torgo 12y agoCryptsetup 1.6 supports Truecrypt volumes now, using its own reimplementation: https://code.google.com/p/cryptsetup/wiki/Cryptsetup160 https://code.google.com/p/cryptsetup/wiki/Cryptsetup160 So at least Linux users should be covered.
- mrsteveman1 12y agoThe donations thing could be true, but Truecrypt simply wasn't a donation-friendly project. It was developed in almost total secrecy, with binaries and code being tossed over the wall once in a while, provided under a non-OSI license. I built it from source a few times, but Truecrypt was used by a lot of people, far beyond the developer community, people who totally lacked the technical skill needed to compile it. SO it's a safe bet the majority just used those binaries. And those binaries actually changed without warning more than once, independent of the version changing. That alone bred suspicion and fueled the demand for an audit. The behavior of the developers (and their total lack of a public presence, regardless of the reason) may have also discouraged donations. Same with the behavior of the forum moderators, whoever they were.