12 ms·
Ask HN: TrueCrypt audit status?
After raising over $70,000 from the community in October 2013, progress on the TrueCrypt audit has been fitful at best. The last update on http://istruecryptauditedyet.com was April 14, 2014.
Two key contributors, Matthew Green (https://twitter.com/matthew_d_green) and Kenn White (https://twitter.com/kennwhite) remain active on Twitter.
I am aware of VeraCrypt and CipherShed but these appear orthogonal to the original audit.
Does anyone know what the heck is going on?
- deleted 12y ago[deleted]
- hayksaakian 12y agoPerhaps this is a naive question: What is the connection between truecrypt and windows xp?
- nateguchi 12y agoI think windows vista introduced encryption on NTFS volumes
- sliverstorm 12y agoI think the key was full disk encryption. I _think_ XP supported individual file encryption.
- atmosx 12y agoThe target platform for TrueCrypt was probably windows because of lack of alternatives? This is what transpires from his last email.
- larssorenson 12y agoSome people think it's a warrant canary of sorts, trying to convey a message that the project had been compromised and was subsequently shut down. But that's all speculation without any evidence to back it up so we may never know.
- tptacek 12y agoJust that it's the last mainstream operating system for which there is no credible alternative to Truecrypt. What Truecrypt does has become a basic feature of modern operating systems.
- aw3c2 12y agoNot as an open-source feature though. I am happy with dm-crypt on Linux, but surely the Windows and MacOS built-in encryption methods are not to be trusted by people who might be targeted by the state?
- pakled_engineer 12y agoConsidering all the proprietary firmware on a standard laptop/desktop/router/modem you're pretty much screwed if targeted by a state. States build SCIF rooms with armed guards to protect against other states. We have FDE and PGP to protect against thieves. Was looking forward to a cryptanalyst's ripping apart of the "cascading ciphers" TC shilled to see if it was snake oil or not.
- kngspook 12y agoAs far as FDE goes, yes. But TrueCrypt was rather unique in that it provided (then) trusted cross-platform encrypted containers, not necessarily encrypted disks. I spent several hours last night trying to find a trustworthy, free tool to encrypt some files that would make them accessible across all my OSes (I use Windows, Linux, _and_ OS X). After looking at Ciphershed and Veracrypt, I didn't find confidence in them, so the closest thing I could come up with was one-off style encryption -- eg. GPG. And I just don't see a good workflow wherein every time I want to access a 3 Mb file I have to unencrypt, untarball, access, retarball, reencrypt 100 GB of files. Or write a script that's going to sort through a couple hundred files to ensure they're all encrypted without tarballing. So yeah, now I jump through hoops using one OS's encryption mechanism, and then kinda-sorta sharing the porn to the other OSes in a way that I hope is semi-secure and I try to make sure I clean up after myself. Edit: In the time I wrote this, I see a huge discussion has blown up around TrueCrypt's containers/block encryption. If anyone has a tool that can encrypt a collection of files and make them transparently accessible to other apps in a cross-platform way, I'm all ears.
- nathantotten 12y agoNewer versions of Windows include BitLocker which provides full disk encryption. http://en.wikipedia.org/wiki/BitLocker http://en.wikipedia.org/wiki/BitLocker
- r3bl 12y agoThe first sentence says it all: it is _not_ available in all of the versions after Windows XP. Combining that with the fact that it is not open source and it is not cross-platform, it's basically useless to me. For now on, I'm sticking with TrueCrypt 7.1a version which I downloaded from https://truecrypt.ch/ https://truecrypt.ch/ on all of my machines.
- ghostly_s 12y agoSo, an open-source product which the developers have publicly declared as insecure, and on which a major code-audit has stalled inconclusively, is superior to closed-source _how_, exactly? Not saying you're wrong, per se, just that it seems like all the choices are wrong, here.
- compbio 12y agoLike tptacek said, versions of Windows after Windows XP shipped with their own disk encryption functionality. XP needed TC for that. Next to that: the announcement to discontinue the product was very close to the MS end-of-life announcement for XP. Remotely related is the difficulty researchers had compiling TC from source and matching the official binaries. The original devs used Visual C++ 1.52 (1993) leading some to believe that the build system for TC still ran on Windows XP and was not up-to-date enough anymore.
- ocdtrekkie 12y agoThe way it was closed was suspicious enough for me to wonder if they were driven to close by the government because it was one of the methods they couldn't crack efficiently.
- dark12222000 12y agoThis is the general assumption I've been under. When someone goes from "This is a secure product being actively developed" to "USE THIS PRODUCT FROM MICROSOFT INSTEAD OF THIS. THIS PRODUCT IS BAD. BAAAD", then well, yeah. That's sort of the canary.
- tptacek 12y agoNo, it's not.
- 0x0 12y agoThere was some talk about how BitLocker in newer versions of windows removed an "elephant diffuser" component or something, was that ever explained properly?
- tptacek 12y agoThe "diffuser" was an attempt to provide last-ditch data integrity for a system that is fundamentally incapable of providing real data integrity. XTS doesn't provide integrity either. Long story short: that change does not matter much.
- lawnchair_larry 12y agoOh, the diffuser matters a lot actually. Your former colleagues (I think?) proved this by blindly popping calc on a bitlocker-protected Windows 8.1! https://cryptoservices.github.io/fde/2014/12/08/code-execution-in-spite-of-bitlocker.html https://cryptoservices.github.io/fde/2014/12/08/code-executi... With the diffuser, we have ~9 years of conjecture and speculation, with no one overly certain that attacks are possible. Without it, we have calc.exe fairly quickly after someone got the idea to try. You can't say these are roughly the same in practical terms.
- ossreality 12y agoIs this a serious post?
- lnanek2 12y agoDidn't TrueCrypt throw in the towel?
- stith 12y agoAs far as I know the audit project was abandoned when the TrueCrypt developer did his dramatic exit. Cannot remember a source for that though.
- tptacek 12y agoNo, the project was not "abandoned" like that. What source told you that?
- daxelrod 12y agoThe wording on the top of http://truecrypt.sourceforge.net/ http://truecrypt.sourceforge.net/ leads me to believe that TrueCrypt is no longer being developed, and bugs (including vulnerabilities) are not being fixed. If that's the case, what's the purpose of of the audit? Thank you, tptacek, for the huge amount of time you're spending answering questions in these threads.
- stith 12y agoApparently none! Apparently that idea made it into my head somehow, I must've just jumped to conclusions and assumed I read it somewhere. Oops!
- Onymous 12y ago"diminoten" is Michael Kadeem Burks jr. Michael is a kingpin that sells DRUGS, FAKE ID'S and many other illegal items. http://www.complaintsboard.com/complaints/michael-k-burks-jr-sells-drugs-and-fake-ids-dallas-tx-michael-k-burks-jr-sells-drugs-and-fake-ids-dallas-tx-c727856.html http://www.complaintsboard.com/complaints/michael-k-burks-jr...
- wyager 12y agoSo we all know Truecrypt is dead. What should we use instead? I don't know of any other software that provides cross-platform, encrypted, and mountable disk images. We have Bitlocker, Filevault, and Luks, but none of these work (easily, at least) on different platforms.
- tptacek 12y agoThe idea that you'd want cross-platform full disk encryption suggests you may be investing too much faith in the powers of full disk encryption. FDE does basically one thing for you: it reassures you if your laptop is stolen from the back seat of your car or left in a cab. Cross platform encryption is very important, and you should look for good solutions (most of us who rely on encryption for real operational reasons just hold our noses are use PGP). But full disk encryption has very limited utility. The idea of a USB drive you can plug into any computer that is locked by default is attractive, but you can get better security out of a USB drive that holds nothing but files encrypted at the application layer. More: http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/ http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/
- michaelt 12y agoA few times in the past I've taken a hard drive out of a failed computer and retrieved data from it on another computer. Sometimes this was cross-platform, reading Windows data on a Linux machine. I haven't had to do this often, but the times I have had to do it, it's been a lifesaver. Any advice, apart from keeping better backups so I don't have to do any cross-platform data recovery?
- kogepathic 12y agoPass the disk through to a VMWare/KVM/Xen container (if you can find another machine of the same processor architecture) and then boot the OS in the VM. Usually it will piss Windows right off to be booted on completely different hardware, but usually it works enough to grab any files you may want from within the FDE. It's utterly useless if the FDE was using any TPM hardware though, in that case then I'm afraid you're stuck using the original hardware.
- tptacek 12y agoIt's in a weird logistical state. I'll take a healthy chunk of the blame. The TC audit project commissioned iSEC to do a formal code audit. That audit was completed professionally and efficiently. No smoking gun problems were found (several nits were, but nothing that would make it any easier to decide whether to trust the package). That iSEC audit was the headline achievement for the project, so the fact that it was finished should reassure people worrying about whether the project did anything. After the code audit, the project was supposed to move on to review the cryptography in TC. Which is where I come in. Because the project was considering commissioning services from professional appsec firms, I recused myself from the project (at the time, I worked for a very large appsec firm). My feeling is that a better use of the TC project resources would be to set up some kind of crowdsourced audit slash bug bounty. When the code audit was completed, and after I had left Matasano, I volunteered to coordinate a crowdsourced crypto audit. Unfortunately, I was also in the midst of starting a new company and recruiting cofounders and then the holidays hit and long story short things went off the rails. There are two big paths forward for the TC project that I am aware of: 1. They can rekindle the crowdsourced crypto audit (I'd be happy to remain involved, or to talk to any other subject matter expert that wanted to do that job --- n.b., I was going to do the work gratis). If any kind of formal review of TC's cryptography is to be done, this is the way to do it; the project can't afford what it costs to retain professional cryptography engineers to review the code (real crypto security consulting costs a multiple of what appsec consulting does). 2. They can devote all the remaining funds to a public bug bounty for Truecrypt. There may be options 3 or 4 that I'm not aware of. I have a decent relationship with Kenn and Matthew, but I have not been trying to keep myself in the loop on the project. There you go: more than you wanted to know about the TC audit project! None of it has much of anything to do with that weird announcement from last year.
- tptacek 12y agoAlso: speaking in no "official" capacity whatsoever, I'd advise you to stay away from the forks of Truecrypt. Unless something new has come to light since last I looked, the licensing situation on the TC code is weird: http://lists.freedesktop.org/archives/distributions/2008-October/000276.html http://lists.freedesktop.org/archives/distributions/2008-Oct... ... which means there is a pretty strong disincentive for people with serious crypto and systems expertise to invest their time and energy building on it. You don't want to trust crypto platforms with built-in adverse selection problems.
- Tangokat 12y agoThe EFF seems to recommend using DiskCryptor for Windows [1]. What are HN's opinions on this? Also what does HN think about still using TrueCrypt? Any reason not to? [1]https://ssd.eff.org/en/module/how-encrypt-your-windows-device https://ssd.eff.org/en/module/how-encrypt-your-windows-devic...
- luxpir 12y agoBeen mulling this over myself. Doubt anyone with a reputation would like to stake theirs to another 'solution' that may well turn out to be flawed. Plus the FDE approach seems broken in that machines have to be powered down etc. I take the view that for my own threat model (i.e. someone nabbing my machine) DC, even TC would be perfectly adequate for that first layer of protection. Advice given by tptacek on using PGP individually for sensitive information (if I have understood correctly) could then be coupled to that FDE where required. For my own purposes this would protect what needs protecting in terms of at-rest data. A vast improvement over the no-encryption situation. SSDs with hardware encryption seem to be the new frontline defense for mainstream users such as myself. Same issues as with any FDE, I suppose, but coupled with filesystem PGP encryption ought to again offer adequate protection from opportunistic thieves.
- godgod 12y agoTrueCrypt and related drive encryption technologies are useless if the NSA has installed their custom firmware onto your hard drive.
- Onymous 12y ago"diminoten" is Michael Kadeem Burks jr. Michael is a kingpin that sells DRUGS, FAKE ID'S and many other illegal items. http://www.complaintsboard.com/complaints/michael-k-burks-jr-sells-drugs-and-fake-ids-dallas-tx-michael-k-burks-jr-sells-drugs-and-fake-ids-dallas-tx-c727856.html http://www.complaintsboard.com/complaints/michael-k-burks-jr...