7 ms·
Report coauthor here. No significant issues were found in either phase of the TrueCrypt audit. If you're using it today (or have used it in the past), I don't
by sdevlin 12y ago
Report coauthor here.
No significant issues were found in either phase of the TrueCrypt audit. If you're using it today (or have used it in the past), I don't think you have anything to worry about.
But it is an unmaintained piece of software, and for that reason I would migrate away from it. If I were setting up a new laptop today, I wouldn't consider installing it. If I had an existing laptop using it, I would think about transitioning when I had some spare time.
Not a hair-on-fire problem, though.
- Lawtonfogle 12y agoAll else being equal it would make sense to move. But all else isn't equal and having an audit and knowing the programmer knew their stuff enough to pass the audit (especially since this is in the crypto field) seems to be a huge benefit that other projects can't match right now.
- tptacek 12y agoBitLocker and Filevault were almost certainly reviewed more carefully than Truecrypt was (I didn't participate in either audit, but can confirm that both of those companies allocate significant resources to third-party audits).
- thesimon 12y agoYeah, better trust US companies who are subject to NSA, which has been proven to require no backdoors in software /s
- sdevlin 12y agoIf those companies wanted to subvert your TrueCrypt installation, they would have an easy time of it.
- mafribe 12y agoCould you sketch how, so we can think about countermeasures?
- tedunangst 12y agoMITM the http connection you used to download truecrypt?
- Buge 12y agoI assume MITM your https connection by manipulating CAs. Or use one of their 0days to breaking into your machine and get your data while it is decrypted in memory or just steal your password.
- Lawtonfogle 12y agoI would assume both Windows and Mac are compromised to the level of C&C by the NSA. In a threat model that includes them I would not use either. But I would still think Windows + TrueCrypt is better than Windows + BitLocker.
- tptacek 12y agoDo you mean "NSA has stockpiled vulnerabilities they've discovered in Win8 that would enable them to quickly enroll a networked Win8 box into a C&C"? If so: sure, I agree. Do you mean "NSA has implanted backdoors into Win8 that would enable them to directly enroll a Win8 box into a C&C"? If so: virtually nobody who does professional vulnerability research, myself included, agrees. The distinction matters here, because if all you're saying is the former thing, that impacts Truecrypt just as much as Bitlocker, because it's equally true of every operating system, including Linux, FreeBSD and OpenBSD.
- Lawtonfogle 12y agoDoes it have an implanted back door? I don't know. Can it give one to Microsoft and say push it out as an update for these individuals and if you say anything you'll end up in prison? That is the problem with secret courts.
- fluidcruft 12y agoOf course. I mean once your threat model includes secret shadowy intelligencia overlords that can bend corporations to their will, there's just no way they could tamper an audit.
- malka 12y agoThey could even force the CPU makers to include backdoors directly in the silicon ;)
- dijit 12y agotruecrypt had a software AES implementation you could enable.. if seriously paranoid. performance impacting though.
- Lawtonfogle 12y agoThat one layer of security may be compromised with no possible recourse does not mean that one should abandon considerations of compromisation of other layers that do have recourse.
- tracker1 12y agoSee: Trusted Platform Module (TPM) Between China and the USA, there's almost certainly hardware backdoors in place for some systems. IIRC there has been evidence of router tampering for ISP hardware shipping across borders.
- Lawtonfogle 12y agoCertainly reviewed more and certainly infected by the NSA more. Until the taint of the NSA has been removed those are outright no gos.
- tptacek 12y agoI feel like a lot of people probably think the way you do: that software for which source code isn't available is trivially backdoored by NSA. In fact, huge chunks of the billion-dollar software security industry are premised on the idea that this isn't true at all: that you can, for instance, recover the control flow graph from a binary compiled program, and then from that recover an intelligible IR, and then examine that for security flaws. Where, exactly, do you suggest that NSA could have tainted Bitlocker in a manner that wouldn't also implicate Truecrypt?
- pm24601 12y agoIt goes like this: NSA: "Hi, can you please let us see your source code." (The conversation below happens in your head): <thought-bubble> "Do I want to spend the next 15 years and all my money and life trying to stay out of jail?" "Do I want the IRS to know about trips to the Cayman Islands?" "Do I want my wife to know about my mistress?" </thought-bubble> Me/You: "Sure no problem!" I know its nice to think about that we would the moral high ground. Try doing it alone with just a nice government official.
- tptacek 12y agoThis is in no way responsive to my comment, which wasn't about whether the USG would coerce Microsoft.
- deleted 12y ago[deleted]
- Karunamon 12y agoPossibly contrived example: An airgapped Windows machine. We've eliminated the possibility of any data exfiltration (all the software vulnerabilities in the world can't transmit on a downed interface), but that does not mean that the encryption itself is not defeated in some way by the existence of a "master key" or some other flaw that allows an attacker to access the data offline. Truecrypt has now been proven to have no such flaws. It's unlikely that Bitlocker will ever be proven in the same way. Anyone that has a legitimate fear of that kind of attack, the bad guys with guns coming in and seizing your stuff, would use Truecrypt over Bitlocker out of an abundance of caution.
- sdevlin 12y agoI would just use the built-in disk encryption solutions your platform offers. This is also what the TrueCrypt developer recommends.
- huhtenberg 12y ago> This is also what the TrueCrypt developer recommends. You can't be seriously deferring to that? The end-of-the-line announcement was so completely out of sync with all previous communications from the TC devs, so un-TrueCrypt like, that everything it said should be taken with a huge grain of salt. _Especially_ any advice pertaining to better managing one's security needs.
- tptacek 12y agoI'm not sure I know of a professional cryptography engineer who believes that what happened with Truecrypt is anything more than what that developer said. Can you cite one?
- huhtenberg 12y agoThey believe that, huh? Interesting wording.
- LordKano 12y agoWhat convinces me that there is more to the story is what they haven't said.
- compbio 12y agoBut maybe what they did today makes that impossible. They set the whole thing on fire, and now maybe nobody is going to trust it because they’ll think there’s some big evil vulnerability in the code. But now this decision makes me feel like they’re kind of unreliable. Also, I’m a little worried that the fact that we were doing an audit of the crypto might have made them decide to call it quits. - Matthew Green TrueCrypt's developers chose not to graciously turn their beloved creation over to a wider Internet development community, but rather, ... to attempt to kill it off by creating a dramatically neutered 7.2 version ... - Steve Gibson I have no idea what's going on with TrueCrypt, Speculations include a massive hack of the TrueCrypt developers, some Lavabit-like forced shutdown, and an internal power struggle within TrueCrypt. I suppose we'll have to wait and see what develops. - Bruce Schneier.
- compbio 12y agoAs far as I can gather the Dutch authorities are not able to retrieve TrueCrypt keys. I can not say the same about BitLocker and FileVault. If the US knows how to get into TrueCrypt volumes then at least they are not sharing that knowledge with foreign allied agencies.
- bhayden 12y agoAny input on the cryptic message the TrueCrypt developer left on their website, essentially saying we should all assume TrueCrypt to be insecure?
- sdevlin 12y agoI don't have any inside knowledge, but I don't think there's any cloak-and-dagger stuff here. I think he just didn't want to maintain it anymore (for whatever reason), and he wanted to warn people away from using unmaintained software. Again, this is just my perception.
- LLWM 12y agoThe developers themselves have clarified. Software that is not actively maintained should be assumed to be insecure.
- 0x0 12y agolink/source?
- LLWM 12y agoThe Security Now show from the week after the event had a pretty thorough recounting of what happened. I'd recommend starting there.
- darkstar999 12y agoSecurity Now! episode #458 - 10 Jun 2014 Skip to 2 minutes in if you don't want to hear the drawn out intro https://media.grc.com/sn/sn-459.mp3 https://media.grc.com/sn/sn-459.mp3 https://www.grc.com/sn/sn-459.htm https://www.grc.com/sn/sn-459.htm
- LLWM 12y agoThe developers themselves clarified the situation within the week. Unfortunately, that was not as widely reported as the shutdown since it doesn't provide fertile ground for NSA conspiracy theories. The short answer is that software that is not actively maintained should be assumed to be insecure.
- antjanus 12y agoout of curiosity then, what would you use? I've been trying to figure out an alternative.
- sdevlin 12y agoI'm primarily a Mac user, and I use FileVault. If I were on Windows, I would use BitLocker. I'm not sure about Linux.
- ion201 12y agoFor Linux, dm-crypt/LUKS for full-disk encryption (this is already the default on many distros) and eCryptfs for less complete or individual file/directory encryption.
- java-man 12y agoThank you for your work!