9 ms·
Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA co
by buddylw 12y ago
Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all:
https://twitter.com/stevebarnhart/status/472203503478509568 https://twitter.com/stevebarnhart/status/472203503478509568
Edit: That tweet was deleted for some reason, but the rest of the thread is still there:
https://twitter.com/stevebarnhart/status/472192457145597952 https://twitter.com/stevebarnhart/status/472192457145597952
- isxek 12y agoYeah, this comment appears to be spot on as well: http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure/comment-page-1/#comment-255908 http://krebsonsecurity.com/2014/05/true-goodbye-using-truecr...
- tptacek 12y agoThe funniest part about that comment is the response that says "I really was leaning toward NSL, till I read this post." Head-desk-head-desk.
- mschuster91 12y agoFor me this tweet is 404, what is its content?
- xcrunner529 12y agoSorry, I didn't really want people trying to further bug the supposed dev. Steve Gibson has a good enough roundup. I wish he didn't use my info though :)
- el_duderino 12y agoYou'll be alright.
- tptacek 12y agoHe'd tell you, but he's been NSL'd.
- buddylw 12y agotweet was deleted for some reason. Here's another from the thread: https://twitter.com/stevebarnhart/status/472192457145597952 https://twitter.com/stevebarnhart/status/472192457145597952
- tptacek 12y agoIt looks like it was deleted because they were concerned about accidentally outing the developer. Which seems like a legitimate thing to be concerned about.
- tptacek 12y agoI'm shocked, shocked: https://news.ycombinator.com/item?id=7812476 https://news.ycombinator.com/item?id=7812476
- nikcub 12y agotopsy still has the tweets cached: http://topsy.com/trackback?url=http%3A%2F%2Ftwitter.com%2Fstevebarnhart%2Fstatus%2F472192457145597952 http://topsy.com/trackback?url=http%3A%2F%2Ftwitter.com%2Fst... and for the user: http://topsy.com/s?q=from%3Astevebarnhart&window=w&type=tweet&sort=date&offset=10 http://topsy.com/s?q=from%3Astevebarnhart&window=w&type=twee...
- thejdude 12y agoNo it doesn't. At least from here it looks like they took the posts down as well.
- chmars 12y agoI have much doubt about that since BitLocker is certainly not good enough: https://twitter.com/stevebarnhart/status/472195239005147136 https://twitter.com/stevebarnhart/status/472195239005147136 And why not just writing that you no longer feel motivated to continue the further development of your software? It is very common after all …
- danielweber 12y agoThe developer(s?) who made TrueCrypt did it for their own reasons. They didn't necessarily do it because they wanted to "stop teh NSA." A lot of people who wanted to "stop teh NSA" started using TrueCrypt, and so they assumed that their goals lined up with TrueCrypt's. But maybe they didn't. Maybe the developer using TrueCrypt was perfectly happy with "defend against anyone short of the NSA, especially since the NSA would need to expose their ability to break into this in order to do anything bad to me." There are millions of people who legitimately share that threat model. We can parse out each comment in the source code like lawyers fighting about a comma before SCOTUS or biblical scholars debating on the definition of a word in Hebrew. We will never know. But there is a really big possibility that the developer(s) consider BitLocker acceptable, even if it's closed-source by Microsoft. EDIT replaced an instance of "BitLocker" with "TrueCrypt" in second paragraph, whooops!
- xcrunner529 12y agoExactly, and it's amazing what a sudden lack of motivation (for a FREE project after 10 years) will do to someone compared to how you feel when you first are building and all giddy and have high aspirations. They're probably worn out and tired and so suddenly they don't feel as strict need to adhere to their previous guidelines. However, I personally find that interesting since I'd think in today's climate it's even more important and they were getting lots of exposure.
- Andrew_Quentin 12y agoAt what point did you answer that simple question of - well why didn't they just say they are not motivated to continue the project any longer, but instead say Truecrypt is not secure.
- eps 12y agoIt doesn't mean anything. That's the exact same reply someone under a gag order would give too.
- tptacek 12y agoBob: [practising] As you know, sir, we have several loans with your institutions, all "past due". But what does "past due" even mean, you know? Gene: It's brilliant! There's no such thing as time!
- throwaway129837 12y ago@stevebarnhart: ask him if he would continue for $70000...
- 100rsa 12y agoHope they can give a gpg signed mail content.