8 ms·
TrueCrypt must not die
- Istof 12y agoif the developers of Truecrypt are anonymous and the license doesn't allow something like this, would this allow us to find out who the developers are if they sue?
- missblit 12y agoTo what end? Just because one can steal someones code or force them to reveal their identity doesn't mean it's a good or nice idea. Apologies if I missed anything, I don't follow this truecrypt stuff too closely.
- fyrabanks 12y agoIf they sued, yes, they would have to reveal themselves. One of the developers got dox'd recently, which may have something to do with shutting the project down. (https://translate.google.com/translate?sl=ru&tl=en&js=y&prev=_t&hl=ru&ie=UTF-8&u=http%3A%2F%2Fnews.softodrom.ru%2Fap%2Fb19702.shtml&edit-text= https://translate.google.com/translate?sl=ru&tl=en&js=y&prev...)
- tptacek 12y agoIt would be nice if the people who pick up and run with the "reboot" of Truecrypt's project management had a background in cryptography. Do these people?
- rsync 12y agoDid you not see the .ch domain name ? You can rest assured.
- tptacek 12y agoAlso what is it with the people who suddenly seem to believe Switzerland is a cypherpunk haven? It _really_ isn't.
- pbsd 12y agoIt's clearly a ploy to get everyone backdoored. Just look at Crypto AG.
- tptacek 12y agoHm. Is that Websters definition of "clearly", meaning "easy to perceive, understand, or interpret", or HN's definition, as in "it's clear someone or some agency got to the developers and they just pulled the ejection seat for their own legal protection"?
- deleted 12y ago[deleted]
- mkuhn 12y agoThe domain is registered to Joseph Doekbrijder [1] who does seem to be working in the area. You might be much more knowledgeable about were to look for his crypto background than I am. [1] http://www.linkedin.com/pub/joseph-doekbrijder/2b/384/43a http://www.linkedin.com/pub/joseph-doekbrijder/2b/384/43a
- Sir_Cmpwn 12y agoThis is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore. Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.
- Alupis 12y agoThere is a $30,000 audit currently underway. There will be no security problems un-turned when they are through. That's assuming there are any to begin with (Personally, I think not). I see no issue picking up the codebase and running with it.
- Sir_Cmpwn 12y agoOf all the subsets of the software development world, crypto is the one to be taken most seriously. TrueCrypt was always developed in the shadows, and the recent controversy takes the nails they've set and hammers them firmly into the coffin. Audits aren't perfect.
- Alupis 12y agoIt's code. There are no secrets. Problems come up when nobody reads the code. Right now, there's an awful lot of people reading this code (Given the strange warning's posted on the TC site).
- SoftwareMaven 12y agoThat's a fine attitude for normal code, but crypto is a whole different ball game. Linux security was significantly reduced at one point because somebody changed int i to int i=0, something most developers would thing is a positive. Side channel attacks are extremely easy to create and extremely hard to find. And, unfortunately, the "many eyes" thing doesn't work here because it requires experienced, knowledgable eyes, and there aren't enough of those, and they are usually busy getting paid, researching how to break software or building their own stuff.
- thought_alarm 12y agoWhy don't you send TrueCrypt.org a few dollars then?
- wyager 12y agoThe developers have already decided to call it quits. More money probably won't help.
- Paul12345534 12y agoI would love to see it live on with no new unneeded features, no changes made unless they are to fix bugs. Keep a stable long-term product and get as many people as possible looking over that code for flaws.
- voltagex_ 12y agoThe signatures and binaries are not served over HTTPS. It would be prudent to compare them to other sources.
- voltagex_ 12y agoJust for reference, SHA1s posted from an independent source yesterday: https://news.ycombinator.com/item?id=7816109 https://news.ycombinator.com/item?id=7816109
- dendory 12y agoActually it would be good if the webmaster behind this reboot got SSL set up. Especially if this is going to be the new most authoritative download source.
- zurn 12y agoSSL is better than no SSL, but for better assurance they should offline sign the downloads.
- throwaway7767 12y agoThat would be prudent regardless. If you trust HTTPS, why verify the PGP signatures? And if you don't, verifying the PGP signatures does not get you anything if you have no reason to trust the key.
- deleted 12y ago[deleted]
- callahad 12y agoI don't believe the TrueCrypt license allows this kind of redistribution, does it? Then again, with anonymous developers and unknown jurisdiction, it may be moot.
- Lagged2Death 12y agoIt says derived programs shouldn't be called "TrueCrypt" and shouldn't be ascribed to the original publishers, which honestly seem like pretty mild requirements. https://github.com/warewolf/truecrypt/blob/33c0b8457051796faae1249950cb896dca027e49/Release/Setup%20Files/License.txt https://github.com/warewolf/truecrypt/blob/33c0b8457051796fa...
- xcrunner529 12y agoThe big issue was the clause that didn't protect those who forked from copyright infringement or being sued and the devs said that was intentional. Although, i doubt they'd really want to come out and make themselves public to pursue that.
- cornholio 12y agoSo they are right off on the wrong foot, with that domain name. I belive any TrueCrypt fork should require contributions to be dual licensed under TrueCrypt's original license and BSD. In time, the project can shed original files and re-implement them under BSD or any other GPL compatible license.
- Angostura 12y agoSo far there isn't any derived code. The truecrypt.ch domain seems a reasonable place for people to regroup. If/when a new release comes out, the community can think about a new name and register a new domain.
- jordigh 12y agoThe Truecrypt licenses also say that it cannot be sold, which makes it non-free and non open source. The OSI even said, "it is not at all appropriate for [TrueCrypt] to describe itself as 'open source.'" http://www.infoworld.com/d/open-source-software/truecrypt-or-false-would-be-open-source-project-must-clean-its-act-230862 http://www.infoworld.com/d/open-source-software/truecrypt-or...
- nhayden 12y agoThis looks like a bootstrap site that was thrown together in an hour by two guys with twitter accounts and $10 for a domain name. I really doubt they're going to be doing any dev work.
- aliakbarkhan 12y agoWhy does the amount of effort on the site matter? I don't understand how that tells you anything about the project or its likely outcome.
- thefreeman 12y agowell the fact that they are asking for a copy of the original site isn't a good start. The original dev's made it clear they don't want people to continue with the TrueCrypt name. If they were really interested in continuing the project for the sake of security they would have chosen a different name.
- TuxLyn 12y agoOriginal site archived here > http://archive.today/www.truecrypt.org http://archive.today/www.truecrypt.org
- gaadd33 12y agoWould you trust it more if they used Comic Sans instead of bootstrap?
- buddylw 12y agoAlso, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: https://twitter.com/stevebarnhart/status/472203503478509568 https://twitter.com/stevebarnhart/status/472203503478509568 Edit: That tweet was deleted for some reason, but the rest of the thread is still there: https://twitter.com/stevebarnhart/status/472192457145597952 https://twitter.com/stevebarnhart/status/472192457145597952
- isxek 12y agoYeah, this comment appears to be spot on as well: http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure/comment-page-1/#comment-255908 http://krebsonsecurity.com/2014/05/true-goodbye-using-truecr...
- tptacek 12y agoThe funniest part about that comment is the response that says "I really was leaning toward NSL, till I read this post." Head-desk-head-desk.
- mschuster91 12y agoFor me this tweet is 404, what is its content?
- xcrunner529 12y agoSorry, I didn't really want people trying to further bug the supposed dev. Steve Gibson has a good enough roundup. I wish he didn't use my info though :)
- el_duderino 12y agoYou'll be alright.
- tptacek 12y agoHe'd tell you, but he's been NSL'd.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- throwaway7767 12y agoHonestly, I was hoping this drama would result in the implementation of hidden containers for other crypto solutions (dm-crypt, etc). Hopefully that may still happen.
- romseb 12y agoThe FAQ for cryptsetup states: https://code.google.com/p/cryptsetup/wiki/FrequentlyAskedQuestions#5._Security_Aspects https://code.google.com/p/cryptsetup/wiki/FrequentlyAskedQue... This means that if you have a large set of random-looking data, they can already lock you up. Hidden containers (encryption hidden within encryption), as possible with Truecrypt, do not help either. They will just assume the hidden container is there and unless you hand over the key, you will stay locked up. Don't have a hidden container? Though luck. Anybody could claim that.
- draugadrotten 12y agoHidden containers perhaps won't be enough to protect you from being locked up, but that is not always their purpose. One purpose of hidden containers is to make the presence of information hidden from the attacker. They may lock you up, but they will never really know if you had encrypted information or not. That means you win something.
- throwaway7767 12y agoI think that's a very narrow view. It assumes there are only two possibilities, either you live in a "free country" where you can refuse to hand over the key, or you live in a totalitarian state where the police will decide to beat you if they suspect you have crypto software, and will keep doing so no matter what you say. There is a lot of middle ground there. For example in the UK, I believe you are legally required to provide the decryption password. But I don't think the police there would be likely to beat you if they think you may have a hidden container. They could argue that they believe you do, and you would respond with "prove it!", and I doubt it would go any further (unless they had some evidence that you specifically were using hidden containers). There is value in hidden containers in some circumstances. It's disappointing to see the cryptsetup maintainers take this position.
- read 12y agoAnonymous development on a security relevant Project is no longer an option. Why not?
- jaibot 12y agoBecause trust is an important commodity on a project like this. Higher trust means fewer horrible things slipping past the review process.
- sentenza 12y agoAnonymity is out and I'd say that being an "independent" crypto person that has to defend themself will not get you very far once you have come to the attention of the wrong people. So what options remain for the person that starts the "next Truecrypt"? The only true safe haven I can think of is employment at a public university. In many countries here in Europe the security researchers working at universities can operate under what is called "academic freedom". I wonder how that will be destroyed.
- npongratz 12y agoTrust is indeed important, but is connecting a name (or a number of names) to a project the only way to establish trust?
- 100rsa 12y agoStill have no idea what's the "unfixed security issues", and few guys mention about it. I image there the "security issues" will be (if it exist): 1. because key are easy to stolen by coolboot or trojan. 2. because it has backdoor, will save key to a hidden place. 3. because it will leave some information in other place, like 2 but it's implantation problem. 4. because it use a vulnerable algorithm to generate key. 5. because pbkdf2 or aes256 is broken but nobody known it. exclude 2 and 3, change to other software it's not help at all, algorithm almost same.
- xcrunner529 12y agoIf we believe the person I was in contact with (big IF, I know), there are no current issues, but it is by definition "harmful" to continue use because it is no longer being maintained. In fact, the person requested I tell Steve Gibson to not distribute or include a notice telling people not to use it.
- bitJericho 12y agoMy opinion, the fact that some security researcher was going to be getting more money than the actual developer ever made off the project must have been infuriating. I think that's good enough reason to burn the project to the ground.
- Andrew_Quentin 12y agoor not start it at all
- bitJericho 12y agoThe license issues surrounding TC are reason enough to not restart the project.
- christianbryant 12y agoSearch off the phrase "TrueCrypt Developers Association. All rights reserved." and you will find many other projects that include embedded TrueCrypt code. Food for thought...