6 ms·
I used Truecrypt heavily for years, but since all the kerfuffle happened I've switched to other stuff. I like Truecypt and would like to move back, but I'm not
by pliu 12y ago
I used Truecrypt heavily for years, but since all the kerfuffle happened I've switched to other stuff. I like Truecypt and would like to move back, but I'm not sure when I'll be able to trust a fork. I can't audit the code myself so I have to rely, I guess, just on mind share and the opinions of security people who are smarter than me.
I'm curious about what other users are doing in this situation. What are your criteria for trusting a fork? How will you know when something (not necessarily CipherShed) is mature and safe enough to use?
- Zikes 12y agoWhat alternatives have you used?
- pliu 12y agoFor disk encryption on Windows, I switched to Bitlocker for my personal use. At my workplace we use Symantec Encryption and Sophos Safeguard, my understanding is they are both pretty okay. For file encryption, now I just do everything on my Ubuntu workstation and use GPG + tarballs. This is sort of a pain in the ass though, and it's not as secure as a TC container of course. It's kind of just a stop gap until I can think of something better.
- tux 12y agoYou think BitLocker closed-source from Micrsofot is more secure and trust worthy then open-source fork CipherShed ? I would take open-source project over closed-source any day. Linux Action Show recently talked about "Tomb", it looks like a nice alternative. https://www.dyne.org/software/tomb/ https://www.dyne.org/software/tomb/
- pyre 12y agoIt's possible for a closed-source product to be written by experts, while the open-source competitor is only written by hobbyists. When it comes to crypto, you probably want the experts. Also, someone needs to actually audit the source code for the 'open-source' part to really come into play (other than from the discontinuation of support angle). Even with open source code, it's only really been recently that TrueCrypt itself ever got any sort of in-depth audit.
- whyever 12y agoDo you think the closed-source crypto did get any sort of audit? From what I gather, crypto experts are strongly opposed to closed-source crypto.
- tptacek 12y agoYou gather that from exactly which crypto experts? Yes: Bitlocker was audited. No company in the world spends more on audits, and is more sophisticated in sourcing them, than Microsoft.
- caf 12y agoWhat information have Microsoft released about the Bitlocker audit(s)? I couldn't find any, although my search wasn't particularly thorough. It seems to me that the value of an audit, for third parties, is that the auditor puts their reputation behind it.
- tptacek 12y agoThat happens in a statistically negligible number of audits, and most especially in the best cryptographic audits. Which systems has Cryptography Research audited? Answer: you have no idea.
- caf 12y agoI don't doubt that, but no doubt a great deal of cryptographic audits are produced entirely for internal consumption at the procuring party, and another large chunk of them would be for bespoke software development gigs where the audit is for the benefit of the single customer. Audits (and here I use the word in its expansive sense) that are intended to build confidence in a large or public audience do tend to be made public.
- tptacek 12y agoIf that's true, it should be easy to cite audits of important software conducted by well-known cryptography engineering firms. So, tell me: where's the audit of OpenSSL, or SChannel, or NSS, done by Cryptography Research or Riscure? Where's the PGP audit? The LUKS audit? Can I ask where you came by these opinions of how security audits work? I know where I came by mine.
- Tomte 12y agohttp://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.aspx http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as... Is that absolute proof? No. Is it better than some unknown guy claiming whatever? I think yes. YMMV.
- Nux 12y agoAll crypto software is guilty until proven innocent, but BitLocker is fine, that guy who wrote the blog post is sure about it. Made by Microsoft and closed source, how could I not trust it.
- TD-Linux 12y agoGiving that you're running a closed source OS, you are pretty much out of luck anyway.
- imaginenore 12y agoUsing Bitlocker over open source software makes zero sense. Thanks to Snowden we know for a fact that Microsoft backdoored many of their products and gave access to NSA. I would be shocked if Bitlocker doesn't have a backdoor.
- Zikes 12y agohttp://en.wikipedia.org/wiki/NSAKEY http://en.wikipedia.org/wiki/NSAKEY
- alister 12y agotl;dr: The crypto component of Windows was discovered to have a 1024-bit public key embedded within it whose symbol name is _NSAKEY. The "obvious" assumption was that this permits the NSA to read, sign, or authenticate anything for Windows. Microsoft denies this and says that "we have not shared this key with the NSA or any other party". I remember when this story first broke. I thought it would lead to major embarrassment and repercussions for Microsoft. Boy was I wrong. There was no news coverage; other than a small subset of techies, nobody was concerned; and as far as I know, Microsoft never gave a technical explanation of how it was intended to be used.
- tptacek 12y agoThere was no news coverage because virtually no expert in the field believes it to have been an NSA backdoor. The arguments suggesting it is were debunked by Bruce Schneier more than a decade ago. Among them, the obvious: Microsoft held the other key, the "non-NSAKEY" key, and could do anything that the NSAKEY can do. If NSA can coerce Microsoft into adding a whole new signing key, it could just as easily have coerced Microsoft into signing things with Microsoft's own key. Given that, an "NSAKEY" backdoor is irrational. In promoting the notion that "NSAKEY" is a backdoor, you're lining up against the likes of Bruce Schneier and lining up alongside the likes of WorldNetDaily, which is indeed among the top Google search results for [NSAKEY backdoor].
- tacotime 12y agoI also shudder at the thought of Bitlocker being the de facto standard for the average American's crypto needs. Microsoft is consistently the first to kneel before any and every demand of the NSA at the behest of their board members. Skype is a prime example. They were willfully deceptive about their ability to collect and record calls and metadata on the Skype network. Microsoft started working on integrating the NSA's PRISM into skype 8 months before they even purchased it. Well, that or they bought it with full knowledge of the PRISM integration and active deception and never planned to mention it to the public until the Snowden leaks forced their hand. Of course they say they only ever took action in accordance with their legal obligations and only after careful review, but their actions would appear to speak for themselves IMO. Bitlocker is no different from Skype. It's probably fine if you're trying to protect yourself from the prying eyes of an average citizen but it is also probably entirely useless against someone with enough influence and/or connection to the government's secret ops. http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...
- blueskin_ 12y agoBitlocker is a bad idea. http://randomoracle.wordpress.com/2013/09/16/all-your-keys-are-belong-to-us-windows-8-1-bitlocker-and-key-escrow/ http://randomoracle.wordpress.com/2013/09/16/all-your-keys-a...
- tptacek 12y agoThis is a blog post that points out that you can back up your keys in a Microsoft online account, among several other options. You've managed to condense it to "Bitlocker is a bad idea". Which leaves me to wonder whether you actually read the piece.
- blueskin_ 12y agoSeems the source has been 1984'd, but a while ago there were leaked Microsoft internal slides about how they store everyone's bitlocker key.
- tptacek 12y agoThey store the keys of people who give them their keys. Microsoft's code is the most heavily reverse engineered in the industry. It's 2014, not 1995; you can't summon a "closed source" boogieman to win arguments about what they do and don't do.
- blueskin_ 12y agoI'm going to trust it because it's using Truecrypt code. I still use the last good version of Truecrypt, but will probably give it a year or so to settle down and get reviewed before I move over to Ciphershed (any truecrypt vulnerability notwithstanding, which might force earlier migration).