3 ms·
Any input on the cryptic message the TrueCrypt developer left on their website, essentially saying we should all assume TrueCrypt to be insecure?
by bhayden 12y ago
Any input on the cryptic message the TrueCrypt developer left on their website, essentially saying we should all assume TrueCrypt to be insecure?
- sdevlin 12y agoI don't have any inside knowledge, but I don't think there's any cloak-and-dagger stuff here. I think he just didn't want to maintain it anymore (for whatever reason), and he wanted to warn people away from using unmaintained software. Again, this is just my perception.
- LLWM 12y agoThe developers themselves have clarified. Software that is not actively maintained should be assumed to be insecure.
- 0x0 12y agolink/source?
- LLWM 12y agoThe Security Now show from the week after the event had a pretty thorough recounting of what happened. I'd recommend starting there.
- darkstar999 12y agoSecurity Now! episode #458 - 10 Jun 2014 Skip to 2 minutes in if you don't want to hear the drawn out intro https://media.grc.com/sn/sn-459.mp3 https://media.grc.com/sn/sn-459.mp3 https://www.grc.com/sn/sn-459.htm https://www.grc.com/sn/sn-459.htm
- LLWM 12y agoThe developers themselves clarified the situation within the week. Unfortunately, that was not as widely reported as the shutdown since it doesn't provide fertile ground for NSA conspiracy theories. The short answer is that software that is not actively maintained should be assumed to be insecure.