Arthur Posted May 28, 2014 Posted May 28, 2014 (edited) If you visit the TrueCrypt website you will now see the following message. Not sure if it's legit? Sources: truecrypt.org / truecrypt.sourceforge.net The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform. Edited May 28, 2014 by Arthur 2
Martin Posted May 28, 2014 Posted May 28, 2014 Some (speculative) discussion here - https://news.ycombinator.com/item?id=7812133 mb
penfold_99 Posted May 28, 2014 Posted May 28, 2014 Looks like the NSA are finally burning bridges after been outed as the authors of truecrypt by Edward snowden.
localzuk Posted May 28, 2014 Posted May 28, 2014 (edited) I'm very suspicious of it. Looks like the NSA are finally burning bridges after been outed as the authors of truecrypt by Edward snowden. Huh? Source? I've seen loads of articles and interviews he's done which state specifically to use TrueCrypt, as the NSA don't like it... Edited May 28, 2014 by localzuk
Trapper Posted May 28, 2014 Posted May 28, 2014 Code audit found the NSA back door? Or perhaps they've had sufficent court orders, they are just closing shop like a crypto-email outfit last year? I wouldn't trust Bitlocker for anything personal. I use Sophos Safeguard at work - but that's work!
mac_shinobi Posted May 28, 2014 Posted May 28, 2014 Code audit found the NSA back door? Or perhaps they've had sufficent court orders, they are just closing shop like a crypto-email outfit last year? I wouldn't trust Bitlocker for anything personal. I use Sophos Safeguard at work - but that's work! Why do you say that about bitlocker ?
Arthur Posted May 28, 2014 Author Posted May 28, 2014 (edited) The way the Windows executables are digitally signed is slightly different, although the DNS records for truecrypt.org haven't been modified since 2012 so it can't have been hijacked? I suppose their SourceForge account could have been hacked though? I'm very suspicious of it. Why would anyone go to all of this effort? https://github.com/warewolf/truecrypt/compare/master...7.2 https://github.com/timothyarmstrong/truecrypt/compare/master...7.2 (Forked copy) ^ Source code diffs. No trojans have been found (so far) in the new v7.2 EXE. www.virustotal.com/en/file/df46b0216ba6ba7937031296e1591fa5461225d8ec5b6b2fe2d492e2d8d7170b/analysis/ Edited May 28, 2014 by Arthur
Arthur Posted May 29, 2014 Author Posted May 29, 2014 I wouldn't trust Bitlocker for anything personal. Back-door nonsense « System Integrity Team Blog - MSDN Blogs Two weeks ago BBC News published an article speculating about a possible “back door” in BitLocker. The suggestion is that we are working with governments to create a back door so that they can always access BitLocker-encrypted data. Over my dead body. Well, maybe not literally---I'm not ready to be a martyr quite yet---but certainly not in any product I work on. And I’m not alone in that sentiment. The official line from high up is that we do not create back doors. And in the unlikely situation that we are forced to by law we’ll either announce it publicly or withdraw the entire feature. Back doors are simply not acceptable. Besides, they wouldn’t find anybody on this team willing to implement and test the back door.
pete Posted May 29, 2014 Posted May 29, 2014 I'm waiting for more information, while leaning towards "warrant canary" because this is an odd way to announce the end of a project. You usually get a ranty "I hate you guys and I'm closing the project", a "We just don't have any free time to continue working on the code, so we're closing the project" or (best case) "we've open-sourced the code, it'll be here for $foo long, fork if you want". This just seems odd and not nearly petulant enough for a bunch of devs having a tantrum.
Arthur Posted May 29, 2014 Author Posted May 29, 2014 Brian Krebs thinks it is legit. http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure
featured_spectre Posted May 29, 2014 Posted May 29, 2014 We use DiskCrypt here anyways, so not much affected but our old win XP machines which are nearly gone anyways (only 1 left). diskcrypt was the only one we could find that did GPT and UEFI and didn't cost anything.
pcstru Posted May 29, 2014 Posted May 29, 2014 Back-door nonsense « System Integrity Team Blog - MSDN Blogs The trouble is, if the lavabit story is anything to go by, those statements are pretty meaningless. If they were building back doors in, saying so in public would get them in the deep stuff. MS are unlikely to take the same approach as lavabit and just wind up the company.
sonic1485 Posted May 29, 2014 Posted May 29, 2014 @Trapper how is Sophos Safeguard working out for you? We are now looking for alternative solutions to go forward with
ozydave Posted May 29, 2014 Posted May 29, 2014 Sophos endpoint, I have been looking at this. Problem is cost. Looked at 130 client protection came out at 6k
Theblacksheep Posted May 29, 2014 Posted May 29, 2014 dont shoot the messenger... Windows 8.1? Can do whole disk/os encryption without TPM and without a USB stick. 1
mac_shinobi Posted May 29, 2014 Posted May 29, 2014 dont shoot the messenger... Windows 8.1? Can do whole disk/os encryption without TPM and without a USB stick. Isn't that related to in some way shape or form to eDrive and using eDrive on SSD's that support eDrive ( which can be added to some SSD's via a firmware update on the SSD itself ) ??
Theblacksheep Posted May 29, 2014 Posted May 29, 2014 Isn't that related to in some way shape or form to eDrive and using eDrive on SSD's that support eDrive ( which can be added to some SSD's via a firmware update on the SSD itself ) ?? Dunno, but it can be done on normal PCs/laptops too with a reg key/gpo settings BitLocker - Turn On or Off for OS Drive in Windows 8
Jobos Posted May 29, 2014 Posted May 29, 2014 As my schools use win7 pro which doesn't have bitlocker how would I go about installing it? Is it just a licence key change to upgrade the machine to enterprise edition or would it involve a complete new install?
sted Posted May 29, 2014 Posted May 29, 2014 As my schools use win7 pro which doesn't have bitlocker how would I go about installing it? Is it just a licence key change to upgrade the machine to enterprise edition or would it involve a complete new install? ideally a new install but its possible to upgrade pro to enterprise
Ephelyon Posted May 29, 2014 Posted May 29, 2014 We use DiskCryptor here for the simple reason that it's command-line scriptable (and also pretty decent). I can automate the encryption of staff laptops through scripting as part of my workstation auto-build process now; moved away from TrueCrypt a couple of years ago owing to a lack of this feature.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now