6 ms·
This is the general assumption I've been under. When someone goes from "This is a secure product being actively developed" to "USE THIS PRODUCT FROM MICROSOFT I
by dark12222000 12y ago
This is the general assumption I've been under. When someone goes from "This is a secure product being actively developed" to "USE THIS PRODUCT FROM MICROSOFT INSTEAD OF THIS. THIS PRODUCT IS BAD. BAAAD", then well, yeah. That's sort of the canary.
- tptacek 12y agoNo, it's not.
- 0x0 12y agoThere was some talk about how BitLocker in newer versions of windows removed an "elephant diffuser" component or something, was that ever explained properly?
- tptacek 12y agoThe "diffuser" was an attempt to provide last-ditch data integrity for a system that is fundamentally incapable of providing real data integrity. XTS doesn't provide integrity either. Long story short: that change does not matter much.
- lawnchair_larry 12y agoOh, the diffuser matters a lot actually. Your former colleagues (I think?) proved this by blindly popping calc on a bitlocker-protected Windows 8.1! https://cryptoservices.github.io/fde/2014/12/08/code-execution-in-spite-of-bitlocker.html https://cryptoservices.github.io/fde/2014/12/08/code-executi... With the diffuser, we have ~9 years of conjecture and speculation, with no one overly certain that attacks are possible. Without it, we have calc.exe fairly quickly after someone got the idea to try. You can't say these are roughly the same in practical terms.
- ocdtrekkie 12y agoSo do you know more about the sudden "TrueCrypt is not secure" thing (http://www.theregister.co.uk/2014/05/28/truecrypt_hack/ http://www.theregister.co.uk/2014/05/28/truecrypt_hack/) and can say definitively why the creators did that?
- tptacek 12y agoYou can see elsewhere on this thread where I'm coming from and what I think about the project.
- hackuser 12y agoI appreciate the time you spent on the project (and on this thread!). However, I don't see this issue specifically addressed: The following was posted on TrueCrypt's SourceForge page [1]; I don't see how it's not a 'canary' (well, technically it's not because it's a direct message) and how users can trust TrueCrypt. Until this is resolved, every other discussion of TrueCrypt's future seems moot. WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues. The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform. [1] Discussed here: * https://news.ycombinator.com/item?id=7828107 https://news.ycombinator.com/item?id=7828107 * https://news.ycombinator.com/item?id=7812133 https://news.ycombinator.com/item?id=7812133 * https://news.ycombinator.com/item?id=7814725 https://news.ycombinator.com/item?id=7814725
- ghostly_s 12y agoSeconded. I was quite puzzled by this whole issue when it happened and surprised to see that there hasn't been much clarification since. The developers who posted this message are real people whom others have been in contact with since, correct? (such as https://www.grc.com/misc/truecrypt/truecrypt.htm https://www.grc.com/misc/truecrypt/truecrypt.htm ). There was a very unambiguous claim of _existing_ security vulnerabilities in the EOL announcement. Have the developers explicitly refused to elaborate on this? Is there no reference to these concerns in the dev mailing list or elsewhere? Have they refused to take ownership for the statement?