3 ms·
A lot of discussions of TrueCrypt replacements I've read today miss a major point, which is that users of the Windows version are now left with no reliable, up-
by y-satellite 12y ago
A lot of discussions of TrueCrypt replacements I've read today miss a major point, which is that users of the Windows version are now left with no reliable, up-to-date software with an equivalent feature set and security guarantees. I know we tend to be *nix-heavy here, but some of us used TrueCrypt because it was the best solution for Windows, not because it was cross-platform.
- x1798DE 12y agoWe can always use TrueCrypt, which everyone was fine with and most people were recommending 2 days ago, even though it hadn't been updated it 2 years.
- jmnicolas 12y agoYes but 2 days ago Truecrypt looked like it was backed by some serious devs (albeit anonymous).
- x1798DE 12y agoWho hadn't updated their code in 2 years. It's stable software that's likely more secure than most things you'd switch to, whether or not it has active development. I'm not saying you don't want to keep an eye out for a new alternative, but you may want to wait for the dust to settle, since in response to this, it seems likely that we'll see a TC fork.
- y-satellite 12y agoWe can, as long as you believe these new warnings shouldn't be taken at face value. It adds a layer of doubt to the situation that wasn't there before.
- dublinben 12y agoTrueCrypt version 7.1a didn't suddenly stop working yesterday. It is still just as secure and easy to use as it ever was. Relying on TC into the future might not be wise, but there's no reason for users to immediately dump it.
- CWuestefeld 12y agoThis isn't necessarily true. If we take the TC message at face value, it seems like we should all move away from it ASAP.
- x1798DE 12y agoIf you take the TC message at face value, you should "just search for encrypt and use whatever pops up" on Linux, and use these settings for encryption on OS X: http://truecrypt.sourceforge.net/OSXNewImage.png http://truecrypt.sourceforge.net/OSXNewImage.png Needless to say, I think you can take their cryptic recommendations with a huge grain of salt.
- higherpurpose 12y agoDon't forget to set encryption to "none" on Mac OS: https://twitter.com/matthew_d_green/status/471998315437883392 https://twitter.com/matthew_d_green/status/47199831543788339...
- LaSombra 12y agoOne of the greatest TrueCrypt features, to me, was that it was multiplatform, much like GPG. Now I have no idea what to do...
- Spooky23 12y agoIf you need full disk encryption, how is appropriately configured BitLocker any less reliable, or offering fewer "security guarantees" than TrueCrypt? The knee jerk reaction here is "omg, prism, Microsoft!". But the reality is that you have no idea who the TrueCrypt people are and their level of trustworthiness --- for all you know they work for NSA or FSB! If you are a windows user, use the manual and use BitLocker for FDE and EFS for folder and files.
- y-satellite 12y agoThe most obvious difference is that the TrueCrypt code has had at least the first stage of a formal security audit done, which uncovered no evidence of backdoors. With BitLocker being closed source and no public audits being done, you don't have the same guarantees. BitLocker may be perfectly secure, but I feel I'm justified in saying that its status is much more uncertain.
- acqq 12y agoThe most aspects of TC were never publicly audited. People were using it on blind faith only: betting that if somebody had cared to audit he'd publish his findings too. You can have the same assumption for BitLocker.
- kaoD 12y agoYou can't audit BitLocker, its source is not available. That's a huge difference.
- acqq 12y agoMicrosoft has special licensing models where the sources for OS are available. Somebody looks at that, at least comparable to that how somebody was expected to detect the bug in OpenSSL, or to review TrueCrypt and nobody did until recently, because, well let somebody else care. So as far as I understand, it is possible to audit Microsoft's crypto code too. I can imagine the audit of crypto code wouldn't find anything. The real problem is: http://regmedia.co.uk/2014/05/16/0955_peter_gutmann.pdf http://regmedia.co.uk/2014/05/16/0955_peter_gutmann.pdf "Crypto won't save you either" "Crypto Summary: Number of attacks that broke the crypto: 0 Number of attacks that bypassed the crypto: All the rest - No matter how strong the crypto was, or how large the keys were, the attackers walked around it"
- cjg 12y agoUnfortunately it doesn't support Windows 8 because of the UEFI problem.