TrueCrypt shuts down due to alleged 'security issues'


Recommended Posts

Link?

 

Are you sure they can unencrypt it without your key? last I heard was they were cold-booting them and getting the key from memory.

 

I remember reading something a few years ago also about bitlocker being unsafe due to secret keys or something like that

speculation is wild on Reddit right now: http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_development_has_ended_052814/

 

nobody knows what's happening.

 

also a little odd that version 7.2 which they just put out is smaller by a good bit than 7.1a

 

It's read only.

 

Since TrueCrypt had an official code review, I guess they decided fixing the issues was not feasible.

 

I'm still using 7.1a on Windows 8.1, and I am not having any issues, so for the time being will continue to do so. But at the same time, I will do some research into BitLocker as well.

The code review only got through preliminary stages that found no significant issues. Stage two hasn't even completed yet.

 

ROT-13 or 1024-bit NSAKey

psh... ROT-26 is where it's at.

 

I thought development had stopped ages ago?

They used to be really slow at new releases too.

I remember reading something a few years ago also about bitlocker being unsafe due to secret keys or something like that

Really? All I've seen around it are the old NSAKey rumors/reports (before Bitlocker), some reports that if you can copy the RAM contents fast enough you can get the secret key out (which is a vulnerability that all encryption programs have, AFAIK), and a lot of reports saying that Microsoft consistently turned down law enforcement requests for backdoors in Bitlocker.

 

It's actually kind of weird that I haven't heard any legitimate rumors (rumors coming from someone who claims to be affiliated with the company/NSA) about a Bitlocker backdoor O.o

So aside from using this for whole disk encryption, what about when just creating containers, still considered unsecure? You cannot create container files with bitlocker.

 

I think one way i read to get around that was to create a VHD file, mount it and then bitlocker it, that was you would have the file container and it would be encrypted. I haven't tried it so can't say if it works.

Just curious, in the grand scheme of things, what are you guys all hiding in your encrypted folders/disks that you are so worried about someone seeing? Short of personal info, medical info, financial/bill info. (Which can all be had through the internet or the vendor being hacked directly). If someone wants to get something, they can and will, even if it takes social engineering to do it. Which no level of encryption will protect.

Just curious, in the grand scheme of things, what are you guys all hiding in your encrypted folders/disks that you are so worried about someone seeing? Short of personal info, medical info, financial/bill info. (Which can all be had through the internet or the vendor being hacked directly). If someone wants to get something, they can and will, even if it takes social engineering to do it. Which no level of encryption will protect.

So people should just give up their attempts to protect their info, because it is pointless to try?

 

 

Thats what you make it sound like.

 

I use TC as a password manager.

Just curious, in the grand scheme of things, what are you guys all hiding in your encrypted folders/disks that you are so worried about someone seeing?

Porn obviously. Can't have the wife finding it.

That aside, only systems I actually bother with it on is mobile devices that actually hold stuff that may be important. Not worried about it on the desktops, if "they" actually got physical access to it I've probably got bigger problems.

Just curious, in the grand scheme of things, what are you guys all hiding in your encrypted folders/disks that you are so worried about someone seeing? Short of personal info, medical info, financial/bill info. (Which can all be had through the internet or the vendor being hacked directly). If someone wants to get something, they can and will, even if it takes social engineering to do it. Which no level of encryption will protect.

 

Why make it easy for the little bleeder that has just stolen my laptop to get at any of my data?

Just curious, in the grand scheme of things, what are you guys all hiding in your encrypted folders/disks that you are so worried about someone seeing? Short of personal info, medical info, financial/bill info. (Which can all be had through the internet or the vendor being hacked directly). If someone wants to get something, they can and will, even if it takes social engineering to do it. Which no level of encryption will protect.

Security is not about making it impossible for attackers, it's about making it as hard as possible. Hard enough that it's unlikely an attacker will find it worthwhile to pursue the attack.

anything with TPM is not secure if physical access is acquired, and potentially remotely too. the key can be easily extracted(by those who know how to do it,like biggun).

Isn't the method for doing this something very few people can actually do successfully? I don't think your average anyone can accomplish this with 100% success rate. 

I remember reading something a few years ago also about bitlocker being unsafe due to secret keys or something like that

 

This guy hints at it I think. There's definitely a presentation about it where he says that Microsoft have a Top Secret way to work with Law Enforcement. 

This guy hints at it I think. There's definitely a presentation about it where he says that Microsoft have a Top Secret way to work with Law Enforcement. 

I understand but I don't think the majority of people are worried about keeping anything from top level law enforcement.. more like hackers and criminals. If you have top law enforcement on you.. encryption is not going to save you.  I am talking about some reasonable security on your personal files. 

I understand but I don't think the majority of people are worried about keeping anything from top level law enforcement.. more like hackers and criminals. If you have top law enforcement on you.. encryption is not going to save you.  I am talking about some reasonable security on your personal files. 

 

Shame I used TrueCrypt to encrypt a file and burn it to a CD and gave it to a mate to look after, I told him to look after it incase I ever needed it again  :shiftyninja:

Isn't the method for doing this something very few people can actually do successfully? I don't think your average anyone can accomplish this with 100% success rate. 

heres the thing though. all it takes is one person to extract the code, then holes could be found in software. it doesn't always have to be a physical break to extract the key. as for breaking the chip physically,if you possess the knowledge,and have only $5000 worth of tools,you can do it.

I was just looking on the truecrypt page and I noticed something.  If this was done by the real developers or a hacker they did a great job on the screen grabs that are posted.  They were very careful not to reveal any un-needed info and not include any info in the picture.  I do find it interesting though that the pics are png files instead of jpg.

Security is not about making it impossible for attackers, it's about making it as hard as possible. Hard enough that it's unlikely an attacker will find it worthwhile to pursue the attack.

This.  You don't need to have the best security. You only need to be more secure than your neighbor.

I was just looking on the truecrypt page and I noticed something.  If this was done by the real developers or a hacker they did a great job on the screen grabs that are posted.  They were very careful not to reveal any un-needed info and not include any info in the picture.  I do find it interesting though that the pics are png files instead of jpg.

why's that interesting? We do most high quality images now in PNG format

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Look who's back!
    • I wonder how driving laws around the world will change. No way to really tell if people are using phone. Same with smart watches i guess even now and those silly built in tablets for controlling the car instead of buttons.
    • They found a better aligned evil overlord for WhatsApp...
    • Google Chrome 149.0.7827.197 (offline installer) by Razvan Serea The web browser is arguably the most important piece of software on your computer. You spend much of your time online inside a browser: when you search, chat, email, shop, bank, read the news, and watch videos online, you often do all this using a browser. Google Chrome is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. Use one box for everything--type in the address bar and get suggestions for both search and Web pages. Thumbnails of your top sites let you access your favorite pages instantly with lightning speed from any new tab. Desktop shortcuts allow you to launch your favorite Web apps straight from your desktop. Chrome has many useful features built in, including automatic full-page translation and access to thousands of apps, extensions, and themes from the Chrome Web Store. Google Chrome is one of the best solutions for Internet browsing giving you high level of security, speed and great features. Important to know! The offline installer links do not include the automatic update feature. Download web installer: Google Chrome Web 32-bit | Google Chrome 64-bit | Freeware Download: Google Chrome Offline Installer 64-bit | Direct Link | 131.0 MB Download: Google Chrome Offline Installer 32-bit | Direct Link | 119.0 MB Download page: Google Chrome Portable Download: Chrome ARM64 | Direct Link View: Chrome Website | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      462
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      112
    4. 4
      Michael Scrip
      85
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!