TrueCrypt shuts down due to alleged 'security issues'


Recommended Posts

I don't know about a fork. Not until a definitive reason comes out for what happened or an audit produces backdoors or flaws that are then fixed. That should be the first priority. 

that's pretty much what the website says as well. which i agree is a good way to handle it

[snip]That guy is a fool and a tool.[/snip]

Quite honestly you're making yourself out to look like one. Gibsons article is the most plausible explanation I've read from all the wild conspiracy theories out there and I won't be surprised if he is right. The audit will continue and it hasn't discovered any major flaws yet. Truecrypt will be forked and reborne once again. For now, keep calm and carry on using 7.1a

Well you'd need an electron microscope and you can't really just scribble them down.  

 

of course the key on the chip is useless without your key as well. so...

 

as for a backdoor, no. NSA would't want a backdoor on the very same equipment they use themselves.  kind of a backfire scenario. and as you so smartly pointed out, by reading what the chip does, other people (foreign elint for example) could find this backdoor. 

Actually they would, which is why all the DoD 'secure smartcard' solutions all also have backdoors, it wasn't designed as a backdoor to get the data from the card, it was designed for firmware upgrading (JTAG etc) but can be used to get the data off the cards or rewrite them, etc.

I would hate it if the reason they stopped was because they didn't receive enough donations to continue running!! Then they have every right to pull the plug. The last few years they were heavily "asking" for donations. Its just a shame its come to this.

Lmfao. That guy is a fool and a tool. I wouldnt trust him for anything and his Spinrite is snake oil.

 

i think the old 7.1 is save but not 7.2. claiming 7.2 to be secure is as ridiculous as truecrypts claim by now to switch to bitlocker.

A long winded post about why using a TPM as a key-factor along with BitLocker is a good thing.  Not responding to anyone specifically since a lot of little things have been said through the thread.

 

Why use BitLocker over TrueCrypt:

  1. Microsoft only supports Windows booting from BitLocker encrypted volumes.
  2. Windows BitLocker supports TPM?s and smart cards.
  • Apple only supports Mac OS booting from FileVault encrypted volumes.
  • Apple FileVault does not support TPM?s (it can however support smart cards), and more unfortunately, Apple hardware does not contain a TPM or equivalent.
  • TrueCrypt does not support TPM (though supposedly it could support smart cards)

 

What good is a TPM:

  1. It can measure your device configuration. A TPM can be aware of what state your computer should be in to be considered "trustworthy". If a device becomes untrustworthy, the TPM will no longer release its key until it's rearmed.
  2. If the physical device supports intrusion detection, your firmware records that an intrusion occurred, when it occurred, and announces this. A TPM can consider a device "untrustworthy" after an intrusion.
  3. You can configure a TPM to consider a device "untrustworthy" when measurements change. Firmware settings have several levels of what can be measured for changes. Otherwise Secure Boot, and OS Boot Loader options are measured. If anything measured fails to match its last known secure configuration, then the TPM fails to release its key. (Enabling or disabling Hyper-V counts as a measurement change)
  4. A TPM can be configured to work with secondary key factors. Using a TPM + Network Unlock, TPM + PIN, TPM + USB, or TPM + USB + PIN is significantly more secure than using a TPM on its own.
  5. When a TPM is used with a secondary factor, it doesn?t matter as much if a third party steals that key. They still don?t have access to boot or data without all factors.

 

Is a TPM, as the only key-factor, "secure"?:

  1. Not really, though it may be considered "secure enough" by some. I personally only think of the TPM as a component that measures everything about a device and then stamps it as "approved" for use. Like a smart card (and in fact a TPM can be used as a smart card), it?s a great key-factor, but on its own it?s not foolproof. You are always best off using a second key-factor in conjunction with a TPM, preferably a factor that cannot be easily obtained along with the device. If the device is portable, or a home computer, TPM + PIN or TPM + USB is great. TPM + PIN + USB is awesome. If device is an enterprise device with Windows 8 or Server 2012 or above, TPM + BitLocker Network Unlock is awesome, especially used with Hyper-V. Now physical servers can have two key-factors required without requiring encryption be suspended before rebooting (or always leaving the USB key attached to the server), and while leaving the server automatically bootable from a cold/crashed state because we?re all not crazy enough (? most of the time) to require a PIN on a production server.
  2. If a third party could gain internal access to a computer without triggering an intrusion, then the TPM is probably not "secure enough" for most usage scenarios.
  3. If a TPM considers a device untrustworthy, it is extremely difficult to attack it and extract the keys. It requires time, energy, knowledge, and skill.
  4. If a TPM considers a device trustworthy, and a man in the middle can insert itself between the TPM and motherboard without altering this state, the device?s security is completely penetrated. The only thing that protects data at this point is if more than one key factor was required.

 

Other Comments:

BitLocker for bootable devices can be done via USB without a TPM, but there are costs.  Your boot key is never really ?secure?, and you cannot have multiple key-factors on a bootable partition unless a TPM is present, but if a third party steals a device without stealing the key they at least didn?t gain access to the data. You lack measured boot without a TPM. On older devices that do not support UEFI Secure Boot, this is a more serious attack vector, as your boot loader never exists on an encrypted partition and can be tampered with without the device user becoming aware of it.

 

Anyway, all said, Windows is most secure when used with a TPM + (Other Key Factor) with full Measured Boot options enabled, UEFI Firmware that is password protected, UEFI Secure Boot is enabled plus Trusted Boot measuring all code used in the OS boot process. If you use all of those, plus Windows SmartScreen and AppLocker, your Windows device is one seriously tough nut to crack open.

i think the old 7.1 is save but not 7.2. claiming 7.2 to be secure is as ridiculous as truecrypts claim by now to switch to bitlocker.

 

7.2 is not capable of encryption anyway. It is a stripped version they only put up to decrypt your existing files.

A long winded post about why using a TPM as a key-factor along with BitLocker is a good thing.  Not responding to anyone specifically since a lot of little things have been said through the thread.

[. . .]

ITFiend, your post is a beautiful summary of Bitlocker and TPM benefits and features. It also doesn't include any nonsense (read: uninformed speculation) about the hardware, which is rare . . .

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Anthropic introduces Claude Tag, a new AI teammate for Slack by Fiza Ali Anthropic has announced Claude Tag, a new feature that lets teams work with Claude directly inside Slack. The idea is simple: once Claude is added to a Slack workspace and given access to selected channels, users can tag @Claude in conversations and assign tasks. Claude can then work through those requests using connected tools and data sources before posting its results back into a Slack thread. What makes Claude Tag different from a typical chatbot is that it's designed to operate as a shared assistant for an entire team rather than a single user. Everyone in a channel interacts with the same Claude instance. This allows the team members to see ongoing work and continue tasks started by others. Furthermore, Anthropic says the AI can build context over time by following conversations in channels where it has permission to operate. This means users don't have to repeatedly provide the same background information for every request. The system is also designed for asynchronous work. Instead of waiting for responses in a chat window, users can assign a task to Claude and return later once the work is complete. Anthropic says Claude can break larger requests into multiple steps and use connected tools to complete them. Moreover, the system can also schedule follow-up tasks and continue working on projects over extended periods. Another feature allows Claude to keep the users updated and follow up on unresolved tasks when its optional "ambient" mode is enabled. The company says the tool is already being used internally for software development, data analysis, support workflows, and debugging. According to Anthropic, around 65% of its product team's code is now generated through its internal version of Claude Tag. For organisations concerned about security, administrators can control which channels, tools, and data sources Claude can access. Separate Claude instances can also be configured for different departments, helping keep information isolated between teams. Administrators can also monitor activity logs, review completed tasks, and set spending limits at both the organisation and channel level. Claude Tag is now available in beta for Claude Enterprise and Claude Team customers and runs on Claude Opus 4.8 that was announced this May. The feature will also replace Anthropic's existing Claude in Slack application, with current users able to migrate within a 30-day migration window. Lastly, eligible customers will receive introductory credits to help teams evaluate the new experience.
    • Beats Studio Pro wireless over-ear ANC headphones drop to their lowest price yet by Fiza Ali Amazon is currently offering the Beats Studio Pro headphones at their all-time low price. The Studio Pro use 40mm active drivers which are designed to improve clarity and reduce distortion compared to previous models, with up to an 80% improvement over the Beats Studio3 Wireless. A built-in digital processor adjusts frequency response to keep the sound balanced rather than overly boosted in any one area. They also include Active Noise Cancelling that adapts to your surroundings to reduce background noise along with a Transparency mode that lets outside sound in when you need awareness of what’s going on around you. Furthermore, the headphones support personalised Spatial Audio with dynamic head tracking as well as Dolby Atmos playback on supported content. Moreover, built-in voice-targeting microphones improve call quality. You can also switch between three sound profiles including Beats Signature for balanced music playback, Entertainment for films and gaming, and Conversation for clearer voice in calls and podcasts. Physically, they are designed to be worn for long periods without feeling heavy or awkward. The ear cushions use UltraPlush engineered leather while metal sliders allow you to adjust the fit. On the connectivity side, the Studio Pro use Class 1 Bluetooth for a stable, long-range wireless connection. There is also a 3.5mm input if you want to plug in directly, including use with in-flight entertainment systems. Controls are located on the headphones and include a "b" button for music and call control, a volume rocker, and a multifunction button used for switching listening modes, EQ settings, power, and pairing. In addition, the headphones offer integration with both Apple and Android devices. On Apple devices, they support one-touch pairing with iCloud-linked devices, hands-free Siri access, Find My tracking based on last connected location, and automatic software updates. On Android devices, they support Google Fast Pair, Audio Switch between compatible devices, and Google Find My Device tracking, with additional features available through the Beats app. When it comes to the battery performance, it is rated at up to 40 hours of listening time with ANC turned off, and up to 24 hours with ANC or Transparency mode enabled. A 10-minute Fast Fuel charge should provide up to 4 hours of playback. Finally, the headphones use a rechargeable lithium-ion battery and charge via USB-C. Beats Studio Pro Wireless Over-Ear ANC Headphones: $149.95 (Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • "lets you pause updates by choosing an end date, for up to 35 days" Wasn't it "indefinitely"?
    • Those extra reboots are related to the UEFI Secure Boot certificate update thing.
    • Hands on with the ProtoArc EM25: Affordable ergonomic mouse that focuses on the right things by Taras Buria ProtoArc is known for making all sorts of office products with a big focus on ergonomics and comfort. Its latest product, the EM25, promises a comfortable-to-use, affordable, and customizable mouse. We took one for a spin; here are our impressions. The ProtoArc EM25 is a $49.99 mouse, but right now, during Prime Day 2026, you can get it for just $37.99. Right off the bat, you can see that the EM25 is inspired by Logitech's MX Master lineup and the legendary MX Master 3/3S. Its shape and proportions are very similar, so for a person with large hands (right-handed person, mind you), the EM25 is very comfortable to use. The mouse fills the palm, and the thumb rests on a small extension, giving your wrist a small tilt to reduce strain. The mouse is made of black plastic without any coating, eliminating long-term wear concerns. However, I can see the main buttons and other areas you touch the most getting polished over time. Despite its size and bulk, the mouse is not too heavy. It weighs about 100 grams, which is significantly less than the MX Master 3S and its successor. It is no lightweight gaming mouse by any means, but it is not excessively heavy like the MX Master 4. The EM25 has a built-in storage for its USB dongle. It is a cleverly made magnetic flap that you open by simply pressing on it. Next to the flap, you will find the on/off switch, the 1,000 Hz sensor, and a DPI button (up to 8,000 DPI). I find the DPI button location a bit odd, and I would prefer it somewhere below the main scroll wheel. Still, given that I never change DPI on my mice, I will let it pass. What is more important is that, unlike MX Master 3/3S/4, the device switch button is located below the left-click button, which allows you to switch devices without lifting and flipping the mouse. For a multi-device setup, this is a perfect solution: the button does not require too much effort to use, it does not get in your way, but it is also easily reachable with your thumb. The main scroll wheel has two modes: ratcheted and free-flow. You can only change between them with a bright orange button (I like this little touch of color), which is sprung and requires some effort to press. The wheel is dead-silent in free-flow mode, but ratched is quite loud and stiff, perhaps even too much to my liking. I can hardly call it deal-breaking, but it will certainly take some time to get used to. The side scroll wheel, it is notched, silent, and pleasant to use. Next to it, you can find a piece of glossed plastic with connection indicators: Dongle, Bluetooth 1, Bluetooth 2, and the low battery indicator. By the way, the built-in battery is rechargeable via a USB Type-C cable, which is included. It is sleeved and has an orange velcro strap to keep it tidy. After using the EM25 for a few weeks, I can say that its main buttons are my absolute favorite. They have very pronounced clicks, which feel great with just the right amount of force required to register a press. I would say they feel like something in between regular mouse clicks and silent ones. You can hear and feel the springy switch, but it is not sharp or loud to the point of annoying you. As for back/forward and device switch buttons, they are very clicky and quite noisy. Unfortunately, there are no extra buttons that you can map to specific things like in the MX Master lineup. Besides great primary clicks, another thing I like about the EM25 is its 1,000 Hz sensor. In the world, where Logitech still uses 125 Hz sensors in $100+ mice, seeing a much faster sensor in a mouse that costs three times less is very refreshing. Also, all the settings and customization you make are stored on-device, and you do not need to install any software. Just open the web-based app and change all that you need. Speaking of customization, you can remap what buttons do, adjust the DPI, and the sensor speed. Sadly, gestures are not supported, but you can still map pretty much anything to each button, including shortcuts, media buttons, and more. I also recommend using software like XMouseControl, as it will let you remap the side scroll wheel. At the end of the day, the ProtoArc EM25 is a great mouse. Clearly inspired by the MX Master lineup, it takes the best of it and complements it with a much more wallet-friendly price tag, significantly better sensor, on-device memory, a built-in storage for the dongle, and more (it fixes everything that I complained about the MX Master 4 recently). And for only $37.99 during Prime Day, the EM25 is an easy recommendation. Buy ProtoArc EM25 mouse - $37.99 | 24% off with Prime As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      460
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      110
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!