9 ms·
Truecrypt report
- java-man 12y agoThe TL;DR is that based on this audit, Truecrypt appears to be a relatively well-designed piece of crypto software. The NCC audit found no evidence of deliberate backdoors, or any severe design flaws that will make the software insecure in most instances. That doesn't mean Truecrypt is perfect. The auditors did find a few glitches and some incautious programming -- leading to a couple of issues that could, in the right circumstances, cause Truecrypt to give less assurance than we'd like it to.
- lucb1e 12y agoYeah, that's right on top of the post but you comment it like you came up with it yourself...
- spdustin 12y agoPlenty of people check comments before the article. The summary was helpful.
- finnh 12y agoYes, the summary was helpful. I think GP is merely saying "please make it clear that you are cutting-and-pasting from the post itself"
- ebbv 12y agoYes and plenty of people make it clear when they're quoting the article.
- java-man 12y agoYou are right. I should have quoted the excerpt. Sorry.
- chadzawistowski 12y agoCan you still edit the post?
- java-man 12y agoNo, I can't. I think the ability to edit disappears after a while.
- danieldk 12y agoJust edit the post, and use italic markup :).
- deleted 12y ago[deleted]
- anfedorov 12y agoIt's the third paragraph, not right on top.
- rsync 12y agoAre you javaman, as in, #cdc javaman ?
- java-man 12y agoNo.
- java-man 12y agoLink to PDF: https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_OCAP_final.pdf https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_O...
- dtech 12y agoVery good to know. Does anyone know the status of the Truecrypt forks? Although it has proven reliable and doesn't need a lot more functionality, it will eventually break without further development.
- java-man 12y agoForks, in no particular order: https://ciphershed.org/ https://ciphershed.org/ https://truecrypt.ch/ https://truecrypt.ch/ https://veracrypt.codeplex.com/ https://veracrypt.codeplex.com/ Also, please refer to this stackexchange thread: http://security.stackexchange.com/questions/58994/are-there-any-reasonable-truecrypt-forks http://security.stackexchange.com/questions/58994/are-there-...
- jordigh 12y agoHas the licensing situation been clarified? The original license was not open source, but it seems unlikely that it would be enforced, as that would involve de-anonymising the copyright holders.
- jstalin 12y agoThere's nothing to clarify. You've summarized it correctly.
- dm2 12y agoI don't think anyone has a problem with forks just changing the name of TrueCrypt (see VeraCrypt) and start from there. There is a lot of discussion on the license on the VeraCrypt forums. It's completely reasonable to ask people to stay away from the TrueCrypt name in my opinion, so that his software's reputation would not be tarnished if amateurs or problem-causing people took over the TrueCrypt name. I wish the TrueCrypt end was handled better, but it's unique situation has some educational value.
- jstalin 12y agoIs there a consensus project that's carrying on development?
- pbsd 12y agoFor what it's worth, regarding the recommendation in page 14 of the report, there is a portable implementation (well, direct port of the SSSE3 code) of AES-CTR in NaCl: https://github.com/jedisct1/libsodium/tree/master/src/libsodium/crypto_stream/aes128ctr/portable https://github.com/jedisct1/libsodium/tree/master/src/libsod.... Don't expect it to be fast or anything, but it exists.
- creshal 12y agoIt's interesting that XTS mode in general is seen as a weakness – this has implications for LUKS et. al. as well, not just TrueCrypt.
- sdevlin 12y agoReport coauthor here. The weaknesses of XTS mode are mostly limitations imposed by full-disk encryption. You should think of XTS as fine for FDE, but you also shouldn't put too many expectations on FDE. FDE is great if you leave your powered-off laptop in the back of a cab. It's not great if federal agents distract you and steal your powered-on-and-logged-in laptop at the library. You should definitely use FDE, but you should also separately encrypt the things that are really important to you.
- JoachimSchipper 12y agoThis is a known issue with (almost) any full-disk encryption - see e.g. our own tptacek's http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/ http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/.
- keithpeter 12y ago"Someday you’ll leave a laptop in the passenger seat of your parked car and lose it when someone cinderblocks the window. When that happens, you’ll be glad for the failsafe of locked-at-wakeup." Or, in my case, leave the laptop in a rather nice leather messenger bag on the seat in the bus. Very reassuring that the average opportunistic thief (or as I like to imagine, the skint teenager) basically has to wipe the hard drive and reinstall an operating system. Now, on Linux, has anyone here been able to get luksSuspend and luksResume working with suspend to RAM on a Debian/Ubuntu system? That would be golden. http://waaaaargh.github.io/gnu&linux/2013/08/06/lukssuspend-with-encrypted-root-on-archlinux/ http://waaaaargh.github.io/gnu&linux/2013/08/06/lukssuspend-... http://askubuntu.com/questions/348196/how-do-i-enable-ubuntu-using-full-disk-encryption-to-call-lukssupend-before-sl http://askubuntu.com/questions/348196/how-do-i-enable-ubuntu...
- acqq 12y agoThe problem with not complaining if the Microsoft CryptoAPI can't be initialized doesn't appear to be really a thing to worry. I'd really like to hear about any known Windows configuration on which the calls can fail, and even if the calls would magically fail, the RNG is uses other entropy sources, including user's own mouse movements, specially requested from the user before the key is to be generated.
- tomrittervg 12y ago> I'd really like to hear about any known Windows configuration on which the calls can fail Mandatory Profiles
- tedunangst 12y agoIs that likely to intersect with TrueCrypt use in a troublesome way? If you're making the profile, don't do that; if somebody you don't like is making the profile, you're already boned.
- tomrittervg 12y ago> Is that likely to intersect with TrueCrypt use in a troublesome way /shrug While it's certain that if you're operating inside a mandatory profile you are at the mercy of whoever created it... but that doesn't mean that people don't try to circumvent restrictions placed on them by their Administrators. It's also not clear to me just how common Mandatory Profiles are actually.
- toothbrush 12y agoExplained for a layperson: should i be using TrueCrypt, or is LUKS okay? Anyone here use TrueCrypt for whatever reason?
- Quiark 12y agoThe benefit of TrueCrypt over LUKS is that it's portable to Windows and Mac.
- nbaksalyar 12y agoAnd it seems that LUKS supports full disk encryption only, while TrueCrypt allows to use encrypted containers (i.e. single files).
- 0x0 12y agoSurely you can use LUKS on a loopback device backed by a single file?
- krylon 12y agoI did so before moving to TrueCrypt. Mounting and dismounting was a bit convoluted compared to TrueCrypt (or encfs), I remember I wrote a Python script to make it a little more convenient. But it did work fine about five years ago, and I do not think the situation has become worse.
- ryan-c 12y agoFrom http://manpages.ubuntu.com/manpages/trusty/man5/crypttab.5.html http://manpages.ubuntu.com/manpages/trusty/man5/crypttab.5.h... The second field, source device, describes either the block special device or file that contains the encrypted data. Instead of giving the source device explicitly, the UUID is supported as well, using UUID=<luks_uuid>. That covers the init scripts, and it looks like recent versions of cryptsetup will "do the right thing" if pointed at a file rather than a block device.
- ElectricFeel 12y agointeresting application, not going to hire these guys to analyze my software tho, i'm looking for interns not college grads
- deleted 12y ago[deleted]
- tedks 12y agoI think the interesting lesson from this is less about crypto, more about free-software projects and how to grow them. The Truecrypt developers supposedly left because it wasn't interesting/fun for them anymore. I believe that. Funding this audit required ~$65k in donations, probably more than the Truecrypt project ever saw. If you were the developer of a project that you knew was solid, and you knew had no backdoors, how would you feel about people essentially maligning you being able to generate more cash than you've ever seen for your side project? That'd make me want to quit too. At the end of the day, which is more preferable -- a TrueCrypt that was never audited professionally, or a TrueCrypt with active developers? How can we ensure security in open-source software without driving the developers away in the future? I think one way would be to match every single audit donation with a donation to the upstream developers. If it's worth spending a dollar to audit software, it's worth spending a dollar to keep that project alive and show the developer you care. It would have taken twice as long to get the audit funded, but maybe then the developer wouldn't have been hounded away. Personally, though, I think this audit was a colossal waste of time and resources. All it told us was something every truecrypt user was assuming already, and it cost us all Truecrypt. What guarantee is there any of the new developers are going to be as trustworthy as the original developers, or as skilled?
- tptacek 12y agoThe Truecrypt Audit Project did not "cost you Truecrypt". The primary reason the project was abandoned was that it's a 3rd party package that implements something every operating system now implements for itself, better than Truecrypt could. There is a mythology among Linux Truecrypt users that the whole project was an effort to create a cross-platform encrypted disk scheme to free users from the tyrannical yoke of I don't know LUKS, but I've seen zero evidence that such a goal was particularly important to actual TC developers.
- sfk 12y agoThis fact must have been known to Matt Green et al.! Why did they waste 65k on an evidently obsolete project? Also, (as far as I know) all public evidence for your assertion is a purported email from one of the devs to Matt Green. He might just have been polite in that mail...
- ikeboy 12y agoI'm imagining this being finished yesterday and them waiting a day to release it.
- tomrittervg 12y agoWe had it finished earlier, but it was undergoing review. Matt and Kenn _did_ want to release it yesterday, I suggested stalling just a day =P
- java-man 12y agoThank you for your work!
- rdtsc 12y agoAny news, insight or updates on why it is unmaintained anymore? That always seems a bit shady and suspicious
- wil421 12y agoThis all happened when the Snowden leaks were coming out. I always assumed that they were served with some type of National Security court orders, papers, threats whatever the Govt sends out. Similar to what happened with lavabit. I doubt the devs did anything, more likely they were asked to do something they felt was shady. They could've seen the storm that was brewing on the horizon.
- kordless 12y ago> I doubt the devs did anything The best course of action was to do nothing, given they couldn't talk about it if they were served. Walking away was the only option. This is pure speculation. Logical, but still speculation.
- tedunangst 12y agoAlternatively, since accusations of being NSA sympathizer were getting tossed around pretty freely, maybe they didn't want to find themselves on the wrong end of a witch hunt.
- LLWM 12y agoTo the contrary. It was nearly a miracle that it was maintained as long as it was, considering how underappreciated the developers were.
- yalogin 12y agoCan someone tell me why so much attention is paid to Truecrypt? Is it that popular? I thought openssl or mozilla's crypto engine are the most used.
- jonathantm 12y agoTLDR: Its a relatively easy way to create encrypted digital virtual drives. --------------------------------------------- Details: Truecrypt creates a .txt file - via a GUI - which is complete gibberish... until you unlock it. It is then a mounted drive. At time of creation of the Truecrypt volume you: * set the drive size - it can be very small (ex: 1mb) to very large (many GB iirc) * set the access credentials. This can be a password, or it can be a password and key-file - that is a file you must pass in addition to the password. The file can be any kind of file. A jpg, an MS Word doc file, a OS iso, a .pem or .ppk... it doesn't matter. I think the hash generated by the file is essentially a second passphrase. Change the contents of the file and you change the hash... it doesn't work. Pick your favorite picture among the tens of thousands you have backed up several places online... and it's much less obvious than the one or two .ppk files you have tucked away in you lastpass account. * you can have a "hidden volume." Say for example somebody drugs you and hits you over the head with a wrench to get your Truecrypt volume access credentials. You give them the credentials, they unlock and mount the drive... and inside is your grandma's banana bread recipe... not your bitcoin wallet details. You gave them the passphrase to a "dummy volume." If you follow the instructions correctly regarding this you can have the actually valuable information hidden within the Truecrypt volume. There's no indication that any particular volume has a hidden volume in it or not. So there's a kind "plausible deniability" about what's there.
- Adlai 12y agoAny electric anthill operator worth his salt knows that banana bread recipes aren't real secrets. A convincing dummy volume has a high-traffic mostly-empty bitcoin wallet, with enough coins remaining that the agents can claim it was recovered empty, and everybody goes home happy.
- java-man 12y agoDiscussion on Arstechnica: http://arstechnica.com/security/2015/04/truecrypt-security-audit-is-good-news-so-why-all-the-glum-faces/?comments=1 http://arstechnica.com/security/2015/04/truecrypt-security-a...
- chdir 12y agoThis is good to know. Thank you for the great work. I've been looking for alternatives, but I think I'll stick with TC for now. 1. Download it for your OS : https://www.grc.com/misc/truecrypt/truecrypt.htm https://www.grc.com/misc/truecrypt/truecrypt.htm 2. Verify the hash : https://defuse.ca/truecrypt-7.1a-hashes.htm https://defuse.ca/truecrypt-7.1a-hashes.htm
- rsync 12y agoSo there is now a complete truecrypt audit. What is the checksum of the source tree that I can use to verify that I have exactly the copy they audited ? I looked at the full report PDF and saw no mention of downloads, binaries, source trees or checksums.
- alexwlchan 12y agoThere's a paragraph in the Phase I Audit Report (published a year ago) which includes a checksum: > The iSEC team reviewed the TrueCrypt 7.1a source code, which is publicly available as a zip archive (“truecrypt 7.1a source.zip”) at http://www.truecrypt.org/downloads2 http://www.truecrypt.org/downloads2. The SHA1 hash of the reviewed zip archive is 4baa4660bf9369d6eeaeb63426768b74f77afdf2. The Phase II report (today;s release) claims to be auditing 7.1a, so I assume it's exactly the same version and ZIP file. Last June, they published "a verified TrueCrypt v. 7.1 source and binary mirror", including file hashes, on GitHub: https://github.com/AuditProject/truecrypt-verified-mirror https://github.com/AuditProject/truecrypt-verified-mirror I just cloned that repo and inspected the source ZIP; the SHA1 sum matches what they quote in the report.
- sandworm 12y agoFrankly, I have to dismiss this report. As Truecrypt is cross-platform and this report evaluates Truecrypt only under windows, this is at best 33% of a report. A fault in the linux/mac implementations could result failings in the windows version. For example, if the mac version has issues with RNGs, volumes created on mac could be week even when mounted and used on windows machines years later. "Linux" only appears once in the report, and then only in a footnote.
- getdavidhiggins 12y agoInteresting reading, for those trying to reproduce the official binaries: "How I compiled TrueCrypt 7.1a for Win32 and matched the official binaries" ― https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binaries-analysis/ https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binarie...