8 ms·
Ask HN: What ever happened with the TrueCrypt shutdown?
I haven't heard anything since the first few forum posts. Did we ever figure out definitively if it was a hack, information operation, canary, dead man's switch or what?
- dewey 12y agoFollowing http://truecrypt.ch/ http://truecrypt.ch/ and https://twitter.com/TrueCryptNext https://twitter.com/TrueCryptNext is a good resource to get new information on this case at the moment. I haven't come across any new and definite information since the hack/shutdown.
- dfc 12y agoHow are you recommending two places to get new information if you admittedly have not come across any new information since the shutdown? Dino's Pizzeria is my favorite place to get pizza. I have never had a pizza from Dino's Pizzeria.
- korzun 12y agoSo a random developer with 4 years of experience teamed up with a Drupal developer to take leadership of this project? This is pretty sad/funny.
- hbeaver 12y agoI would encourage you to listen to Steve Gibson's Security Now podcast on Twit. But the gist is TrueCrypt has not been hacked. Take a listen to the "TrueCrypt WTF?" episode. http://twit.tv/show/security-now http://twit.tv/show/security-now
- MiWDesktopHack 12y agoSteve Gibson has also made the TrueCryptⓇ Final Release Repository at https://www.grc.com/misc/truecrypt/truecrypt.htm https://www.grc.com/misc/truecrypt/truecrypt.htm I had to use this mirror recently as there are already bad copies floating about; it is a trusted hosting for the last ungimped version for windows and linux. check the hashes n' sigs!
- tobias3 12y agoConjecture: TrueCrypt was developed by mainly by one person. This person did write TrueCrypt to encrypt his WinXP Laptop/PC, but does not need it anymore now, because he can now use Bitlocker. TrueCrypt is a consumer facing Open Source project. Those rarely have a large developer community and seldom get patches. Most successful ones are backed by corporate interests (Firefox, Eclipse, VirtualBox, ...). Having no need of TrueCrypt himself, no other developer in the community to whom he could entrust the project and faced with drudgery the like he probably also has at his job (except he gets payed there), he probably did not want to continue developing and improving TrueCrypt (e.g. EFI support). At this point. Since it is a critical security product there is no other option then to warn of all users. If there is a fork, it has to earn its reputation first. I view truecrypt.ch as a bad development, since a) TrueCrypt is trademarked by the developer and b) the TrueCrypt license explicitly says that you cannot fork the project without renaming it to something other than TrueCrypt. See https://www.grc.com/misc/truecrypt/truecrypt.htm https://www.grc.com/misc/truecrypt/truecrypt.htm "And then the TrueCrypt developers were heard from . . ."
- nhayden 12y agoMy issue with the fork is the two guys who threw together the site to get "FIRST!!" dibs don't actually seem like developers capable or willing to continue the fork themselves. They just want credit for the work they want others to do for them.
- JohnTHaller 12y agoIt is worth being clear that TrueCrypt is not an 'Open Source project'. The source is available, but it is under a proprietary license designed to discourage forks and reuse and allowing the original authors to sue you. The one-off TrueCrypt license means that TrueCrypt code can not be utilized under any OSI-recognized open source licenses as it is incompatible with them. The FSF, Ubuntu, etc all agree that TrueCrypt can't be considered open source. The source is available, but it's difficult for you to use it other than to analyze it.
- Netcob 12y agoI'm not an expert, but I thought there was a distinction between what's meant by "Open Source" and "Free Software". The way I understand it: Open Source: You can analyze the source code and build it yourself - which is great if you don't trust anyone to give you binaries from what you analyzed. Usually at least free as in "free beer". Free Software: Open source software which gives you lots of permissions via its license, while making sure you get to keep these permissions. Usually free as in "free speech" (in addition to "free beer"). TrueCrypt not being free as in speech is a bummer, but being able to inspect the code and build it yourself is a critical advantage, especially when it comes to cryptography. I have a hard time imagining BitLocker not having any backdoors built in. At the very least it'll have some kind of weak random number generator or whatever, making sure that with the right algorithm you get to crack it within a few minutes or so.
- nodata 12y agoIt was discredited. Mission accomplished!
- aaw 12y agoThe best of all the conspiracy theories was http://pastebin.com/9catw4X7 http://pastebin.com/9catw4X7.
- pessimizer 12y agoWow. I'm going to spread that one around:)
- abdullahkhalids 12y agoThere is this person claiming "I can confirm presence of TrueCrypt duress canary as per 2004 conversation." There were a bunch of other tweets with further details, but those seem to have been deleted. https://twitter.com/AlyssaRowan/status/472303977997279232 https://twitter.com/AlyssaRowan/status/472303977997279232 Note: I am not claiming this is necessarily true.
- tptacek 12y agoI don't know anyone who works in cryptography who thinks those twerps were credible. Do you? I'd be interested in a name.
- abdullahkhalids 12y agoA developer for tor (@puellavulnerata) retweeted this. That is the only claim to it's credibility that I know of