Slashdot Mirror


The Sudden Policy Change In Truecrypt Explained

X10 (186866) writes "I use Truecrypt, but recently someone pointed me to the SourceForge page of Truecrypt that says it's out of business. I found the message weird, but now there's an explanation: Truecrypt has received a letter from the NSA." Anyone with a firmer source (or who can debunk the claim), please chime in below; considering the fate of LavaBit, it sure sounds plausible. PCWorld lists some alternative software, for Windows users in particular, but do you believe that Microsoft's BitLocker is more secure?

475 comments

  1. people ruin everything by Anonymous Coward · · Score: 0

    If you want a project to survive, don't share it with people. People are scum, pure and simple.

    1. Re: people ruin everything by Anonymous Coward · · Score: 2, Informative

      https://t.co/x1H2T6UtEv

    2. Re: people ruin everything by Noah+Haders · · Score: 5, Interesting

      this is actually a link to an interesting article, not goatse. it's an editorial about how the most recent full version of true crypt (7.1a) is still as secure as it was last week, and there's no reason to stop using it. It also says they (who?) are working on an open license fork that will be released on a future date.

      still doesn't answer the question on if it's like lava bit. true crypt may be just as secure as it was last week, but maybe it's also been owned by NSA from day one.

    3. Re:people ruin everything by MrL0G1C · · Score: 2

      You are so gonna get Dementia

      --
      Waterfox - a Firefox fork with legacy extension support, security updates and better privacy by default.
    4. Re: people ruin everything by Anonymous Coward · · Score: 0

      That doesn't make sense. TrueCrypt has been open source, and I've been looking at it for a long, long time.

      Just Google for Truecrypt Source 7.1a before the NSA whack it off Google. Also, remember to periodically download versions of software such as Tor and other related utilities. Maintain a radio transmitter as well. It may actually help during the day of the apocalypse.

    5. Re:people ruin everything by tmosley · · Score: 5, Insightful

      No, I think people are fine. It's governments and their poorly organized systems that cause things like this. Suggest you read "The Lucifer Effect". It's not just about prison guards. That same mentality has infiltrated the NSA and most other government offices.

    6. Re:people ruin everything by hackus · · Score: 1

      I would rather get dementia than tell lies and live like it is OK with whats going on in this country.

      --
      Got Geometrodynamics? Awe, too hard to figure out? Too bad.
    7. Re:people ruin everything by Anonymous Coward · · Score: 0

      Pfft like I believe that.

    8. Re: people ruin everything by Anonymous Coward · · Score: 5, Informative

      Link because why in the world do people use URL shorteners?

    9. Re: people ruin everything by jopsen · · Score: 5, Insightful

      Your arrogance is your assumption that you have anything to say worth recording, let alone even listening to you. What makes your personal life so relevant?

      So because my private life is utterly uninteresting, you suggest that I shouldn't care about giving up my human rights?

      The right to privacy is a human right...

      One might as well ask, why you should care about fair trails or torture, if you're not a criminal then why should you care? After all why should anybody want to torture a confession out of you?
      This is not about being personally targeted or affected, it's about basic human rights.

    10. Re:people ruin everything by Fjandr · · Score: 3, Informative

      Governments are made up of people. People are always the problem.

    11. Re: people ruin everything by Anonymous Coward · · Score: 0

      So hang in there: the audit is still proceeding. If it comes up OK, the keep using 7.1

    12. Re: people ruin everything by Anonymous Coward · · Score: 1

      Quite naieve... if information is captured for any one purpose, nothing prevents it from being used for more nefarious purposes down the road.

      Tomorrow's world could be a theocracy or meglaburo or kleptocracy or plutarchy... you never know, and the people who sieze power will abuse it. Hey, just look at Putin who came up thru the ranks of the KGB when Borris tried to make him a puppet governor.

      Heck... look at our own history and the government oppression (at various points) of Indians, Blacks, Japanese, suffragettes, pot smokers, birth control advocates, civil right leaders, and people who just wanted a drink.

      If the government was just dragnetting me, that would be one thing; instead, they have laid the infrastructure for an evil regime, and the damage it can do far outweighs any potential good it might bring.

      The soverighty of the people has been trampled by a rouge internal force.

    13. Re: people ruin everything by Anonymous Coward · · Score: 0

      Make sure to also download some distilled water occasionally.

    14. Re:people ruin everything by fustakrakich · · Score: 1

      No, I think people are fine. It's governments and their poorly organized systems that cause things like this.

      That's a fascinating concept. Are governments and their poorly organized systems comprised of something other than people? Aliens from another universe perhaps?

      --
      “He’s not deformed, he’s just drunk!”
    15. Re: people ruin everything by Nehmo · · Score: 2

      ...

      Your arrogance is your assumption that you have anything to say worth recording, let alone even listening to you...they care about financial and military strategic advantage. You are not relevant to either.

      That reasoning fails on two points.

      • The government is frequently not logical. For example, many people naively assumed that although there were anti-pot laws, the state would never expend the resources to attack a little 'ol nobody like themselves. Thus, they concluded they were safe. Some people who had that attitude are now growing grey behind walls.
      • Sometimes the motivation to attack somebody are the financial concerns of particular people in the government working under tangled rules. Because of the way funding laws are arranged, particular people in the government may get money if they prey on a particular nobody. So there really isn't a valid reason to target that someone. They just happen to be in the cross-hairs, and someone is getting paid to pull the trigger.

      You don't have to be truly important or truly threatening for the state to persecute you. Indeed, if we could rely on the state always being correct in whom they attack, we wouldn't need individual rights.

      --
      (||) Nehmo (||)
    16. Re: people ruin everything by Anonymous Coward · · Score: 0

      Your arrogance is your assumption that you have anything to say worth recording, let alone even listening to you. What makes your personal life so relevant?

      The point is, it doesn't matter, and shouldn't matter, to you or anyone else. My business is my business, it's none of your business!

    17. Re: people ruin everything by symbolset · · Score: 4, Interesting

      The former CEO of USWest was sent to prison based on secret NSA data that could not be independently confirmed - or even discussed. That this happened shortly after he refused to cooperate with illegal NSA data collection is completely coincidental.

      --
      Help stamp out iliturcy.
    18. Re: people ruin everything by Anonymous Coward · · Score: 0

      This is not about being personally targeted or affected, it's about basic human rights.

      Au contrare. The real issue is that there's *not* enough personal targeting...of the legislature members, NSA members, etc who seem to think that "basic human rights" don't exist. Look how quickly they'll grant exceptions for their own right to speech, right to own a gun, or right to privacy but are the first to stop the those rights the second anyone gets within 100 feet of them--they don't want to have to shout over people insulting them on their record, they don't want to have to face an armed crowd where it takes but one person to kill them, and they sure as hell want everyone to be vetted thoroughly before they're allowed that close to reduce the risks of the above.

      You know what the real strength of democracy is? The king is dead; long live the king. In the past, this idea of continuity with monarchies was their supposed strength. In reality, each new king was radically different from the last with their own reshaping of everything before them. Well, we're at the same point now in the US. We don't see a democracy of representatives. If we did, then it wouldn't matter if a representative died; another one could readily take their place. Instead, we elect parties and hope their members "conform" enough to some ideology which we find least objectionable. Well, that's only marginally better than the Chinese logic of divine right to rule which was used to end numerous dynasties. Only if they're "bad enough" do we unelect/assassinate them, and then we simply switch parites and hope they'll be less bad.

      If we only had a democracy... If only weren't so quick to speak of our President as king and so mourn his loss (his death, sure, because he's a person, but the Presidency is an office and he should strive to be what the people want/need) and yet become so upset when a Congressman acts like one too. Neither are king. But they're all the nobility of old with all the rancor that puts them beneath us.

      You may have been elected. You may be popular. But you're our servant and from us derives your power. We clearly need to make that more clear at a real level.

    19. Re: people ruin everything by Anonymous Coward · · Score: 0

      Believing snowden is a traitor

      NSA shill detected

      Pls go fuckoff to your overlord, marionette man

    20. Re:people ruin everything by Rob+the+Bold · · Score: 2

      I would rather get dementia than tell lies and live like it is OK with whats going on in this country.

      If 'dementia' means what I think it means, you can actually do both.

      --
      I am not a crackpot.
    21. Re: people ruin everything by bmo · · Score: 4, Informative

      My point wasn't that privacy is not important. My point is that YOU are not important...and I'm right. You're not.

      Which is entirely beside the point.

      You are irrelevant to The Man until you become a "problem" and all this data gathering is for instant dossiers on people who become a "problem." To nail the head that sticks up.

      Privacy is a human right because without it people are unable to effect change - they remain powerless. There is nobody on the planet without a skeleton in the closet, and exposing that skeleton is what this is all really about. It's national-level Borking, to remove any kind of power from people who would oppose a police-state.

      That's why.

      You, sir, are a short-sighted douchebag and, through your apathy, an enemy to everyone on this planet.

      Ta Ta.

      --
      BMO

    22. Re: people ruin everything by WyldPhyr · · Score: 1

      As well as food, and ammunition

    23. Re: people ruin everything by Xolvix · · Score: 5, Insightful

      Not only that, but the trolling poster also made the assumption that you're not important, which is bullshit for the simple reason that we're ALL important to the people who love and care about us. We're important to someone - I'm important to my wife for example, and soon I'll be important to my newborn. Just because I'm not a politician or celebrity and hence known to thousands/millions of people doesn't mean I'm not important. It's all about spheres of influence - some are larger than others, but they still all matter.

      If the trolling poster honestly believes with such passion that you aren't important, it stands to reason they probably don't feel they are important either. If they can't find at least one person in their life who considers them important in some way... then I find that truly sad for the AC.

    24. Re: people ruin everything by Richy_T · · Score: 1, Insightful

      We need guns. Lots of guns.

    25. Re: people ruin everything by fractoid · · Score: 1

      I don't understand why they never just asked Tank for a tank.

      --
      Rampant carbon sequestration destroyed the Dinosaurs' tropical paradise. I'm here to help repair the damage.
    26. Re: people ruin everything by Noah+Haders · · Score: 1

      Just Google for Truecrypt Source 7.1a before the NSA whack it off Google.

      would NSA have to fill out the "right to be forgotten" form?

    27. Re: people ruin everything by Anonymous Coward · · Score: 0

      rouge? are they red?

    28. Re:people ruin everything by tmosley · · Score: 1

      Read the book. Bad organizations will inevitably turn good people bad, unless you are inoculated against the effect with knowledge.

    29. Re: people ruin everything by Anonymous Coward · · Score: 0

      DEEEEP!

      IOW, what a useless turd you are.

    30. Re: people ruin everything by houstonbofh · · Score: 2

      As well as food, and ammunition

      If you have ammunition, you can get food.

    31. Re:people ruin everything by Anonymous Coward · · Score: 0

      Because governments aren't people, but a unique species?

    32. Re: people ruin everything by pslytely+psycho · · Score: 1

      Weed, lots of weed.
      And good beer too.
      Any other intoxicant that floats your boat.

      Hey, what better reason to party than the Apocalypse?

      --
      Donald Trump, on a crusade to make Nixon look respectable
    33. Re: people ruin everything by Number42 · · Score: 1

      Don't forget to download some more RAM too, just in case.

    34. Re: people ruin everything by smylingsam · · Score: 1

      http://downloadmoreram.com/

      You're Welcome!

      P.S. OB sarcasm tag ^_^

    35. Re: people ruin everything by Tom · · Score: 3, Insightful

      It's 2014, not 1914.

      If you want to fight your government - the government that spends more money on the military then everyone else in the top 5 military spending countries combined, you don't need guns. You need stealth fighters, tanks and ICBMs.

      Good luck with your "honest people defending the country against the government" fantasy.

      --
      Assorted stuff I do sometimes: Lemuria.org
    36. Re: people ruin everything by ZeRu · · Score: 1

      this is actually a link to an interesting article, not goatse.

      What a shame, I would actually applaud a webmaster willing to pay for an SSL certificate just to trick more people to see goatse

      --
      If you post as an AC, don't expect me to spend a mod point on you.
    37. Re: people ruin everything by Anonymous Coward · · Score: 0

      When there's a proper internal conflict going on, it isn't a given that the military will happily do whatever the 1% will tell them.

    38. Re: people ruin everything by Anonymous Coward · · Score: 0

      Your arrogance is your assumption that you have anything to say worth recording, let alone even listening to you. What makes your personal life so relevant?

      Personally I'd find it pretty handy if I knew everything about people who really have nothing to hide (in the sense that this argument is usually invoked). That stuff would give me a competitive edge over pretty much everyone else. I could eg. aggregate times when people opposing my policies are most likely to be away and schedule important shit to happen at that very moment. You thought no-one cared that you were visiting your sick grandma at some other state but I just did. By the way, the vote went 51-49 with twelve people missing. Sorry about that.

    39. Re: people ruin everything by MrKaos · · Score: 1

      Mod Parent up - very well said, totally insightful.

      --
      My ism, it's full of beliefs.
    40. Re: people ruin everything by Anonymous Coward · · Score: 0

      This is true, but one man's "proper" cause is another man's lunatic raving. 99.99% of the people who advocate a "proper" revolt have very selfish motivations. It's like what they say about Homeowner's Associations: the only people who run for a spot on the HA are exactly the kind of people you don't want on a HA. Look who the major financial backers are to Tea Party folks; you think they have some kind of strong political philosophy behind their actions?

    41. Re: people ruin everything by Anonymous Coward · · Score: 0

      Well yeah, that was a pretty big "when".

    42. Re: people ruin everything by Anonymous Coward · · Score: 0

      > you don't need guns. You need stealth fighters, tanks and ICBMs.
      Or you need to say NO when you detect that you are being instrument of evil.

    43. Re: people ruin everything by Anonymous Coward · · Score: 0

      "First they came for the Socialists, and I did not speak out--
      Because I was not a Socialist.

      Then they came for the Trade Unionists, and I did not speak out--
      Because I was not a Trade Unionist.

      Then they came for the Jews, and I did not speak out--
      Because I was not a Jew.

      Then they came for me--and there was no one left to speak for me."
      Martin NiemÃfller

    44. Re: people ruin everything by Gavagai80 · · Score: 3, Insightful

      In fact, sufficiently large non-violent protests would bring down the government -- if it can work in non-democracies like Egypt and Tunisia, it would certainly work in the USA. Guns would just provide the government with an excuse for terrorism charges.

      --
      This space intentionally left blank
    45. Re: people ruin everything by DigiShaman · · Score: 1

      Right to bear nukes!?? Yeah, that would explain Fermi's paradox.

      --
      Life is not for the lazy.
    46. Re: people ruin everything by Richy_T · · Score: 1

      Actually, it's 2199. You just haven't unplugged yet.

    47. Re:people ruin everything by dark_requiem · · Score: 1

      A government's just a body of people. Usually, notably ungoverned.

    48. Re: people ruin everything by Anonymous Coward · · Score: 0, Insightful

      ICBMs, tanks, and stealth fighters... Totally useful in the US military's complete eradication of the Taliban, right? Asymmetric warfare is incredibly tough. You're on the enemy's home turf. You can't find them, and you're heavily outnumbered.

    49. Re: people ruin everything by Anonymous Coward · · Score: 1

      It is sad how one bends facts so that they support what one is pre-disposed to believe. Nacchio challenged FISA and ended up not getting a big NSA contract (allegedly he was "punished", but even that is stated without any proof). He went to jail for "massive" insider trading (netting him and his cronies $3B!). However, I'm sure the NSA cooked it all up and deposited millions and millions of dollars into his and five other people's accounts without them knowing about it.

      It is even more sad that your outright lies get modded up so high.

    50. Re: people ruin everything by Anonymous Coward · · Score: 0

      Because, after all, the US has WON every engagement since WWII... right?

    51. Re: people ruin everything by Anonymous Coward · · Score: 0

      You don't need tanks, you need people who'll stand up for something.

    52. Re: people ruin everything by Tom · · Score: 2

      That was a foreign power attacking people at home.

      This would be the people rising up against their government.

      Two different scenarios. The US government doesn't have to eradicate americans to win, it just needs to stay put exactly where it is.

      --
      Assorted stuff I do sometimes: Lemuria.org
    53. Re:people ruin everything by plover · · Score: 1

      Governments are not just made of people. They are made of people, laws, and processes. A bad process (or law) encourages people who prosper by it to leave it unchanged This means that people do the wrong thing in order to keep their jobs. A person who is only trying to do what they were hired to do may do something morally wrong because that's what they were told was correct. A really really bad set of processes in a secret organization can lead to secrecy for secrecy's sake, and that leads to what we saw here.

      --
      John
    54. Re: people ruin everything by Anonymous Coward · · Score: 0

      The Afgans, Iriaqis, and Vietnamese would beg to differ.

    55. Re: people ruin everything by Anonymous Coward · · Score: 0

      Not Goatse? Fuck it then.

    56. Re: people ruin everything by Optali · · Score: 1

      Well, they will do whatever the PAYING 1% tells them to do ;)

      --
      -- 29A the number of the Beast
    57. Re: people ruin everything by Anonymous Coward · · Score: 0

      There is a time when the operation of the machine becomes so odious, makes you so sick at heart, that you can't take part. You can't even passively take part! And you've got to put your bodies upon the gears and upon the wheels, upon the levers, upon all the apparatus, and you've got to make it stop! And you've got to indicate to the people who run it, to the people who own it â" that unless you're free, the machine will be prevented from working at all!

    58. Re: people ruin everything by Tom · · Score: 1

      Yeah, I definitely want my country to look more like theirs.

      --
      Assorted stuff I do sometimes: Lemuria.org
    59. Re: people ruin everything by Richy_T · · Score: 1

      Heh, game of thrones quote coming up...

      "In a room sit three great men, a king, a priest, and a rich man with his gold. Between them stands a sellsword, a little man of common birth and no great mind. Each of the great ones bids him slay the other two. 'Do it,' says the king, 'for I am your lawful ruler.' 'Do it,' says the priest, 'for I command you in the names of the gods.' 'Do it,' says the rich man, 'and all this gold shall be yours.' So tell me- who lives and who dies?"

      The US govt is just a bunch of men in suits. It's the loyalty and goodwill of those that serve under them that makes them anything more.

    60. Re: people ruin everything by Aaden42 · · Score: 1

      Where on earth did you get the idea that the 1% actually pays for government operations?

      http://www.cnsnews.com/news/ar...

    61. Re: people ruin everything by Anonymous Coward · · Score: 0

      The soverighty of the people has been trampled by a rouge internal force.

      Despots do tend to like the color red, don't they?

    62. Re: people ruin everything by Anonymous Coward · · Score: 0

      Don't listen to him ! It's goatse.

    63. Re: people ruin everything by CmdrTamale · · Score: 1

      If you have ammunition, you can get food.

      Only if THERE IS FOOD.
      --
      The program isn't debugged until the last user is dead. Can I help you with your debugging? *cracks knuckles*

    64. Re: people ruin everything by Anonymous Coward · · Score: 0

      Did you actually read your linked article? If you made it to paragraph 3, it states the top 1% paid 28.1% of Federal taxes. I don't understand your comment.

    65. Re: people ruin everything by jxander · · Score: 1

      If only there was a modern day precedent for the US military having a hard time dealing with some low tech insurgents.

      --
      This signature is false.
    66. Re: people ruin everything by Anonymous Coward · · Score: 0

      Obviously. However, the question isn't who pays your bills right now, but who pays them tomorrow.

    67. Re:people ruin everything by MrKaos · · Score: 1

      No, I think people are fine. It's governments and their poorly organized systems that cause things like this.

      That's a fascinating concept. Are governments and their poorly organized systems comprised of something other than people? Aliens from another universe perhaps?

      In a word, Processes. People are just the components it's the processes and procedural rules that determine the behavior orf the system - poorly organized or not.

      --
      My ism, it's full of beliefs.
    68. Re:people ruin everything by fustakrakich · · Score: 1

      Okay, then who or what created the laws and processes? I don't understand how you can separate any of that from people.

      --
      “He’s not deformed, he’s just drunk!”
    69. Re:people ruin everything by fustakrakich · · Score: 1

      People are just the components it's the processes...

      Say whaaa? Were the processes created by aliens then? I find this very intriguing.

      --
      “He’s not deformed, he’s just drunk!”
    70. Re:people ruin everything by MrKaos · · Score: 1

      People are just the components it's the processes...

      Say whaaa? Were the processes created by aliens then? I find this very intriguing.

      Stop being a fucking pedantic idiot. You asked:

      Are governments and their poorly organized systems comprised of something other than people?

      I answered processes. They're also comprised of legislation, mandates, buildings and chairs. All of these things were made by people however that is not what you asked. Under such ridiculous pedantry I could answer atoms, quarks and energy which would give you an accurate answer, just not a particularly useful one based on a reasonable supposition of what is meant by 'what a government department is comprised of'.

      --
      My ism, it's full of beliefs.
    71. Re:people ruin everything by fustakrakich · · Score: 1

      ...that is not what you asked.

      It is precisely what I asked. And you people continue to pass the blame for our problems on some nonresistant ethereal entity called a "process". It's a bunch of hogwash. The problem is people, period. They create the government. They create the process. They are the process. And you're just spouting a bunch of gibberish like some preacher yelling that it's "God's will!". Save it for the believers.

      --
      “He’s not deformed, he’s just drunk!”
    72. Re:people ruin everything by MrKaos · · Score: 1
      You said: Are governments and their poorly organized systems comprised of something other than people?

      ...that is not what you asked.

      It is precisely what I asked.

      atoms, quarks and energy

      ...that is not what you asked.

      It is precisely what I asked.

      legislation, mandates, buildings and chairs, cars, carpet, leasing agreements, legal departments, policy review boards. Snakes and snails and puppy dogs tails

      And you people continue to pass the blame for our problems on some nonresistant ethereal entity called a "process". It's a bunch of hogwash.

      It's fairly obvious that you are one of "those people" who haven't held any position that was responsible for anything other than themselves. If you ever work hard enough to understand higher levels of an organization, either in the business or government world, you will understand that the reporting and functional processes are as real as the dumb look on your face when you look in the mirror. That "nonresistant ethereal entity" controls much of your life.

      Now go back to flipping burgers.

      The problem is people, period. They create the government. They create the process.

      True, but also outside the scope of your question as they don't "comprise governments poorly organized systems".

      They are the process.

      Duuuuuuuuuuuuuuuuuuuuuuuuh.

      It doesn't make the process any less of a component, it's just "something other than people".

      And you're just spouting a bunch of gibberish

      When a person is in a government organization they have effectively zero lattitude to change it, they are a functional component that are either a tool that can be used or a problem that has to be solved all the way up the management chain to the executive. And even the executive has to make a government department function according to the articles of law that enacted it. Even the one person left who can change it, government minister or congresscritter, *still* has to act within the legal functional requirements of the Department. This covers the entire scope of your question.

      A government department is a legal entity as much as a corporation is a legal entity as much as a person is a legal entity. If you choose to have a simpletons view of the world, that's fine. It won't change because you don't understand it.

      like some preacher yelling that it's "God's will!". Save it for the believers.

      Are you even vaugely serious. Have you ever read a peice of legislation longer than 10 pages in its entirety? The entire legal system is made up of words that can have you executed in some places. That's real, there is a legal process that dictates people to behave as functional components in an organization and act in a specific role.

      "...a system based on corrupt practice cannot be saved merely by tinkering with it"

      Look, I only answered your question because I though your sig was fairly on the mark. However even government departments form components of the "system" you are describing.

      Your mindset blames the people who need a job not the people that can resolve the functional issues of government. By all respects you should get this and I fucking truley regret trying to gently answer your question in a way that didn't make you look like a complete fucking idiot.

      From the moderation, it suggests that pretty much the rest of slashdot gets this but I'll correct you grammar and answer it in the closed narrow way you need it answered:

      Are government's and their poorly organized systems, comprised of something other than people?

      Yes.

      --
      My ism, it's full of beliefs.
    73. Re:people ruin everything by fustakrakich · · Score: 1

      That certainly was a long winded piece of... baloney... How do you learn to be so helpless?

      --
      “He’s not deformed, he’s just drunk!”
    74. Re:people ruin everything by MrKaos · · Score: 1

      That certainly was a long winded piece of... baloney... How do you learn to be so helpless?

      Mainly from people like yourself who are so hoplessly inferior to the rest of the normal thinking population I would be need 3/4 of my brain removed to have double your wit. Obviously you are unable to explain whatever point you have to make, even when given an opportunity to do so. I can only gather that you are pointless. So back to 4chan, b/tard/.

      Now get the fuck off my lawn.

      --
      My ism, it's full of beliefs.
    75. Re:people ruin everything by fustakrakich · · Score: 1

      :-) I pity you, completely unable to break the circle. A good servant you are, blaming others for your own misfortunes, but still pitiful.

      --
      “He’s not deformed, he’s just drunk!”
    76. Re:people ruin everything by MrKaos · · Score: 1

      :-) I pity you, completely unable to break the circle. A good servant you are, blaming others for your own misfortunes, but still pitiful.

      Pity yourself, it's an excellent summary of what you are doing now :-)

      --
      My ism, it's full of beliefs.
  2. That's not proof! by Threni · · Score: 5, Insightful

    You're taking twitter posts too seriously. That's just speculation based on what appeared on their site the other day, followed by:

    "Alyssa Rowan @AlyssaRowan
    @munin @0xabad1dea @puellavulnerata I can confirm presence of TrueCrypt duress canary as per 2004 conversation"

    Sorry, who the fuck are you?

    1. Re:That's not proof! by mmell · · Score: 1, Interesting
      Wow, they implemented the canary on their website? That by itself is major league cool!

      I am however very sorry to hear that TrueCrypt may be going away. I personally use LUKS (being a Linux user), but this is still bad news for end users in the computing community.

    2. Re:That's not proof! by arglebargle_xiv · · Score: 1

      "Alyssa Rowan @AlyssaRowan @munin @0xabad1dea @puellavulnerata I can confirm presence of TrueCrypt duress canary as per 2004 conversation"

      Sorry, who the fuck are you?

      If it's the real Alyssa Rowan tweeting that then it's a pretty reliable source.

    3. Re:That's not proof! by jbmartin6 · · Score: 1

      Could you clarify? Who is Alyssa Rowan to TrueCrypt? Sorry for my ignorance, I tried Googling a bit and just got links to this article.

      --
      This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
    4. Re:That's not proof! by arglebargle_xiv · · Score: 5, Interesting

      Could you clarify? Who is Alyssa Rowan to TrueCrypt? Sorry for my ignorance, I tried Googling a bit and just got links to this article.

      It's someone who has been active in the crypto/security community for awhile now. Personal details are pretty scarce (i.e. it could be a front for the NSA for all anyone knows), but the persona has been active in crypto. If you want something to Google on try "alyssa rowan cryptography".

    5. Re:That's not proof! by rogoshen1 · · Score: 1

      clearly the name is an anagram that you aren't Robert Langdon enough to suss out.

    6. Re:That's not proof! by Anonymous Coward · · Score: 0

      Anal Was Rosy.

    7. Re:That's not proof! by Anonymous Coward · · Score: 0

      Oral Ass Yawn.

    8. Re:That's not proof! by Anonymous Coward · · Score: 2, Informative

      Just an old, jaded reverser who hung around in a few places with a few people. I didn't always use my real name. /akr

    9. Re:That's not proof! by fnj · · Score: 3, Informative

      very sorry to hear that TrueCrypt may be going away

      Ya think? Really? You are hereby awarded the prize for most spectacular understatement of the obvious. Sorry, I do not intend to be mean; it just hit my funny bone; peace, man. It's somewhat akin to stating that the US "may be entering a period of decline" or saying in 2004 the space shuttle program "may be winding down".

      OTOH, seriously, the project may have gone deader than a doornail overnight, but use of 7.1a is still just as viable as it was before the stunning suicide note. It has passed the independent stage 1 security audit with thumbs up, and if you don't already have a copy it's not hard to find out there. Pretty sure in the long run somebody will pick up the pieces and carry on. The HQ for the next project will clearly have to be located some place other than the inheritor of the Nazi Germany/Soviet Russia mantle of most despicable police state.

      LUKS is very good, but until someone works out a way to do hidden containers, it's not even close to a replacement for the most critical feature of TrueCrypt.

    10. Re:That's not proof! by Threni · · Score: 4, Informative

      Already there, dude.

      http://truecrypt.ch/

      Switzerland!

    11. Re:That's not proof! by philip.paradis · · Score: 3, Informative

      LUKS is very good, but until someone works out a way to do hidden containers, it's not even close to a replacement for the most critical feature of TrueCrypt.

      Hidden containers are less useful than you might imagine in practice for a variety of reasons. Some of these points are relevant. I don't have any use for hidden containers, although I do use LUKS on a large number of systems.

      --
      Write failed: Broken pipe
    12. Re:That's not proof! by fnj · · Score: 3, Insightful

      It's a good step, no doubt about it, although given recent caving of Swiss entities to US bullying I do not feel as ebullient as I want to.

    13. Re:That's not proof! by Anonymous Coward · · Score: 0

      It's not a canary. It's an ordinary notice. truecrypt.sourceforge.net doesn't have anything confidential to divulge. The developers might not know for sure if their code has been subverted though (not to be confused with subversion vs. git).

    14. Re:That's not proof! by Anonymous Coward · · Score: 0

      So people have heard of her before but aren't sure if she exists? Oh then it's OK. Solid scientific proof.

    15. Re:That's not proof! by AmiMoJo · · Score: 1

      Considering all the hints that the TC developers put on their web site and in the new license agreement it seems that if she is trying to claim it is innocent she must be an NSA persona. Everything she ever worked on must now be questioned and re-examined, every statement she made re-evaluated on the assumption that it is malicious.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    16. Re:That's not proof! by ColaMan · · Score: 2

      Or we could just, like, not bother.

      --

      You are in a twisty maze of processor lines, all alike.
      There is a lot of hype here.
    17. Re:That's not proof! by blueg3 · · Score: 1

      It's someone who has been active in the crypto/security community for awhile now.

      So are all the other people in that Twitter conversation, most of whom are more than a little bit skeptical of a completely unsubstantiated claim like this. All of the claimed elements of the "canary" are odd changes in the source code that were commented on long before they were "revealed" as parts of the canary. One of them is a change to source that post-dates the claimed 2004 date the canary was established.

    18. Re:That's not proof! by Anonymous Coward · · Score: 1

      With respect, that is the opposite of what I said. I think the changes were made under duress, based on what I've seen (==what you've seen) and a note I saved about duress markers from a chat I had with a dev about a decade ago when the TrueCrypt fork was in its infancy (pre-TrueCrypt Foundation). [I doubt an NSA shill would raise so many concerns about them, let alone ask someone from there to step down from a co-chair position in a cryptographic research forum! :)]

      But I would honestly prefer it if you didn't take my lone statement at face-value: I have no proof to give you. Reach your own conclusions based on the evidence available to you. (Would it actually change your response? Having thought about it some more, I don't think it actually would.)

      We shouldn't take software at face-value either - the identity of the TrueCrypt devs isn't widely known, and not taking it at face value is why TrueCrypt 7.1a's code is being audited, and that's a hugely positive step all round! - and we should also audit code that we _do_ know the developers of, because as recent high-profile bugs have shown (Heartbleed; goto fail; GnuTLS), there has not been nearly enough auditing in general of security-sensitive projects, and we need more. Much more. Really good auditing can catch bugs, whether they are caused by mistake or malice, no matter who they came from. Please, go help with that if you can. e.g. GnuPG or LibreSSL could use more eyes.

      By the way - having noticed the ElGamal encryption subkey on the TC site seems new (was it expired? I didn't think it was) but the 1024-bit DSA key signing it (and TrueCrypt 7.2) matched the old one, hence the same overall PGP keyid - I'm a little worried that in 2014 we still have security-critical software that's probably a target of nation-state adversaries signed using 1024-bit (!!) DSA keys! I think that is insufficient - probably crackable, given the threat model. So I'd wonder whoever @truecrypt.org could decrypt messages sent to the old, authentic 2048-bit ElGamal encryption subkey - but it seems truecrypt.org isn't even accepting email anymore, so we may never know. :-(

      Well, no matter what the cause, the TrueCrypt Foundation is definitively toast, and "7.2" isn't useful. A good fork would be great, if it's by trusted people, openly-auditable, deterministically built (á lâ Tor?), and based on 7.1a with updates. That would be a positive outcome overall. I think (left over from the old, far more cursory audit I did) TrueCrypt 7.1a is probably solid, except by any means that any other otherwise-secure FDE could be crackable: to very briefly summarise known practical attacks: rooted boxes/evil maids/keyloggers; crap passwords; available keyfiles; coldboot attacks; $5 wrenches (with apologies to xkcd). The current audit seems to broadly concur, for the moment.

      I'd like to see BitLocker, dm-crypt, and everything else audited too. It can't hurt. But triage your attention and focus on what matters to you. /akr

    19. Re:That's not proof! by viperidaenz · · Score: 1

      Alyssa Milano's cousin?

    20. Re:That's not proof! by Kiwikwi · · Score: 1

      Hidden containers are less useful than you might imagine in practice for a variety of reasons. Some of these points are relevant.

      None of those points are relevant, except maybe "it's difficult to get right".

      The first third of the thread, people are either not talking about hidden containers or don't know what a hidden container is, and instead go on about various steganographic methods of hiding the use of encryption. (E.g. "LUKS header, by design, is visible header."... that goes for TrueCrypt as well, and has nothing to do with hidden containers.)

      In the middle third of the thread, they're discussing variations of "it's hard!" and "you can't protect the outer container" (though TrueCrypt does just that).

      In the last third of the thread, random people are musing about their little pet-ideas and other off-topic tangents.

      There are good arguments for not adding hidden containers to LUKS, most importantly the fact that nobody's stepping up to implement it, but no real arguments against hidden containers.

    21. Re:That's not proof! by Anonymous Coward · · Score: 0

      it contains the letters N S A in that name, and that's where I stopped having to think about the anagram any more :)

    22. Re:That's not proof! by socceroos · · Score: 1

      You just echoed the sentiment of 99% of the population - "Sorry, mate, I can't be bothered...". It saddens me. =/

    23. Re:That's not proof! by ihtoit · · Score: 1

      I have one.

      If you've attracted the attention of the security services (and if you haven't I'm VERY disappointed in you!), they'll be looking for encryption. If they see a hard drive with only half its capacity in use yet the system reads full, they'll be wondering what's in the hidden container. Assuming you're not about to give them the key to your cat porn collection, they're gonna assume it's something much more insidious.

      Security 101: if it's not meant to be on a network, don't store it on a network. If you want to hide something, don't hide it where you're gonna glance at it - encrypted/hidden partitions are going to do nothing but raise suspicions. There's good situations to have secure partitions, for example in medium to large business networks where onion security is easily implemented, those without proper credentials are not going to be able to access data in readable form. Period. There's no reason for the mail room to have access to financial data, but they might need the mail database. Secure them both, pass out credentials on a need to know basis. If you want to hide data from outside parties, don't put it in an obvious place like a Truecrypt container (hidden or not) on your fucking laptop.

      --
      Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
    24. Re:That's not proof! by ihtoit · · Score: 1

      Alyssa Rowan is a pretty senior figure in the CFRG (Crypto Forum Research Group) which offers advice and technical assistance to IETF and other bodies in matters crypto. They recently had (through December 2013) had a bit of a set-to in attempting to remove a co-chair based on the suspicion that he worked for the NSA. This attempt failed when the (unsurprisingly balanced) decision was made in January not to remove him.

      --
      Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
    25. Re:That's not proof! by Kiwikwi · · Score: 1

      If they see a hard drive with only half its capacity in use yet the system reads full, they'll be wondering what's in the hidden container.

      They won't see a hardrive that reads full, because they will only have the password to the outer container, and the hidden container will hence not be protected... writes to the outer container will simply overwrite the contents of the inner container, making it impossible to tell that it was ever there.

      Whoever the Truecrypt developers are, they're not idiots.

    26. Re:That's not proof! by Anonymous Coward · · Score: 0

      I'd like to point out, that the "caving in" you claim is not quite correct. Swiss Banks (not the state) have been fined for helping tax evasion.

      A good example of the Swiss not submitting to US authorities is the fact that in Switzerland it is still legal to download almost any content you like - movie, music, etc. The US has tried multiple times to stop this, but have always failed! What is illegal in Switzerland is to "spread" (upload) copyrighted material - so to repeat, download no worries, upload and you're in trouble.

    27. Re:That's not proof! by philip.paradis · · Score: 1

      Please accept my apologies for the delayed reply. You appear to be lacking firsthand experience with interactions involving certain law enforcement agencies and persons who are subject to device examination. The first step will be production of a bit for bit copy of the digital media in question, followed by a quick analysis of the disk image. In many cases, said analysis will rapidly identify media regions which are likely to represent "hidden containers", and interesting interactions between the owner of the device and law enforcement personnel will commence shortly thereafter.

      This may disappoint you, but it speaks directly to my original statement regarding the utility of hidden containers. The link included in my prior post was mostly intended to spur further thought, in the hopes that you would consider (at a minimum) the scenario I've just described. Given my apparent failure to spark that trail of reasoning, I elected to provide a more direct example in this post. Cheers.

      --
      Write failed: Broken pipe
    28. Re:That's not proof! by Kiwikwi · · Score: 1

      Please accept my apologies for the delayed reply. You appear to be lacking firsthand experience with interactions involving certain law enforcement agencies and persons who are subject to device examination. The first step will be production of a bit for bit copy of the digital media in question, followed by a quick analysis of the disk image. In many cases, said analysis will rapidly identify media regions which are likely to represent "hidden containers", and interesting interactions between the owner of the device and law enforcement personnel will commence shortly thereafter.

      I may not have first-hand experience with police overreach, but then I have first-hand experience with cryptography, and therefore I know that an analysis of a TrueCrypt-encrypted disk will determine the presence of the outer, encrypted container. The hidden container, on the other hand, is mathematically indistinguishable from encrypted empty space, and there is no way to determine if a hidden container is present unless you 1) have the secret second key (which we assume you don't), 2) can brute-force the key (which you can't), 3) can learn about it from side channel attacks (of which several are known, but for which countermeasures exist) or 4) exploit bugs in the TrueCrypt software (of which none are known).

    29. Re:That's not proof! by philip.paradis · · Score: 1

      You're still entirely missing the point, so please allow me to clear it up for you. In the scenario we're discussing, specifically the utility of hidden containers with respect to plausible deniability, the police already have access to the outer container. Either the key decryption passphrase was directly conveyed to them, or they had the device owner unlock the outer container to facilitate spot inspection of the device and the device owner complied given his belief that he will be protected by hidden containers. At this point, the device is confiscated. If the outer passphrase was not supplied, it matters little at this point, because the volume is unlocked and mounted. The outer container key will be extracted shortly thereafter as a result by any one of numerous means.

      The police now proceed to inspect the digital media in question. In many cases, said analysis will rapidly identify media regions which are likely to represent "hidden containers", and interesting interactions between the owner of the device and law enforcement personnel will commence shortly thereafter.

      What part of this is unclear? Perhaps you should explain the nature of your experience with cryptography, preferably with emphasis on practical applications pertinent to this conversation.

      --
      Write failed: Broken pipe
  3. Without any evidence by Anonymous Coward · · Score: 0, Insightful

    ...isn't the very strange things happening enough proof?

    1. Re:Without any evidence by Anonymous Coward · · Score: 0

      Not really.

  4. BitLocker by Anonymous Coward · · Score: 0

    BitLocker? You mean the closed source "encryption" software, made by Microsoft?

    Sure, be my guess.

    1. Re:BitLocker by Anonymous Coward · · Score: 0

      I am 39. Is that your guess? If not, maybe your guess should be me.

  5. No by Anonymous Coward · · Score: 0

    It is pretty much agreed that the devs just got tired of doing the work and decided they wanted to get on with their lives and do other things. That has been much more "confirmed" than an NSL...

    1. Re:No by fnj · · Score: 1

      It is pretty much agreed that the devs just got tired of doing the work and decided they wanted to get on with their lives and do other things. That has been much more "confirmed" than an NSL...

      Bullshit, idiot. If that were the case, they just would have publically turned over development to whoever would like to take it over. They certainly wouldn't have set off bombs to destroy the source code repo and all trace of it in the archive wayback machine.

    2. Re:No by Anonymous Coward · · Score: 0

      It is pretty much agreed that the devs just got tired of doing the work [and other nonsense]

      Agreed by whom? Did the NSA take a poll on the topic?

      That has been much more "confirmed" than an NSL..

      Yes, and zero is much larger than zero ... wait, does that mean that the NSL is also much more confirmed than your "agreement"?

      So much fun watching the damage control train wreck in action - as it's only damage control that would so forcibly submit such amusing assertions backed by thin air.

  6. Speculation by borcharc · · Score: 5, Insightful

    There is no concrete information that the NSA or a national security letter was involved. When did we start linking to random blogs for speculation presented as fact? May as well just posted a link to reddit thread about this.

    1. Re: Speculation by Anonymous+Psychopath · · Score: 1

      That's probably where they got this anyway.

      --

      Eagles may soar, but weasels don't get sucked into jet engines.

    2. Re:Speculation by Anonymous Coward · · Score: 2, Insightful

      Ever since actual news stopped mattering and what everyone cares about is clicks (read as money).

    3. Re:Speculation by Anonymous Coward · · Score: 5, Insightful

      We do not need concrete information.
      When a major encryption project like this closes shop, without any explanation, duress should be assumed.
      The current climate requires it.

    4. Re: Speculation by Anonymous Coward · · Score: 1

      Exactly. When people get all antsy about this stuff I have to wonder what the fuck they are encrypting to begin with that they feel isn't available already to any agency that wants it. Financial records? The NSA can access those at any time through any number of sources. Secret plans? About what? If you have secret plans that the government should be interested in, then I want them to find out about it - because unless you are planning terrorist activity, there is no reason to fear so much. It's mostly just folks who are paranoid and/or filled will delusions that they have any "secret" information to hide anyway. There is nothing an individual has on their computers that requires such measures, and if you don't want something public, you don't send it out over the Internet period, encrypted or not.

    5. Re:Speculation by jopsen · · Score: 2, Insightful

      There is no concrete information that the NSA or a national security letter was involved.

      Before Snowden we used to say the same thing about NSA messing with encryption standard bodies, or NSA conductive widespread warrant-less surveillance of everybody.

      We used to think people wasn't subjected to secret trails in the US. That's no longer the case, we now know by fact that the US doesn't honor basic human rights, not for it's citizens or anybody else.

      Do we really need more proof. This isn't the worst thing the NSA have attempted yet.

    6. Re:Speculation by aaaaaaargh! · · Score: 5, Funny

      That's exactly what I thought first. But then it came to my mind that Bitlocker is much more secure than Truecrypt, because it has been developed and carefully audited by a corporation with a proven track record in cyber security. That fact makes it practically 100% certain that the developers of Truecrypt just thought "nah, fuck it, we now have Bitlocker, which uses military-grade encryption against all kinds of criminals and cyber-threads, and there are minor to medium potential problems with our code, so we just throw the towel and give up all the work on Truecrypt."

      That's obvious, right?

    7. Re:Speculation by Anonymous Coward · · Score: 0

      There is no concrete information that the NSA or a national security letter was involved. When did we start linking to random blogs for speculation presented as fact? May as well just posted a link to reddit thread about this.

      Did you forget what site you're on?

    8. Re: Speculation by Anonymous Coward · · Score: 3, Insightful

      It's not necessarily the NSA you always want to protect things from. What if your laptop gets stolen, would you want the thieves to be able to look through the contents?

    9. Re: Speculation by Anonymous Coward · · Score: 0

      We've seen plenty of recent evidence that the government cannot be trusted with this sort of access to private information. Whether it's an individual like Snowden with access to it or a FISA judge who believes he doesn't have adequate visibility to provide the kind of oversight that our existing laws require. Here are a few solid examples to ease your inane sense of wonder:

      -political activism
      -investigative journalism
      -whistleblow collection and planning
      -cryptography research
      -microbiology research

    10. Re:Speculation by marcello_dl · · Score: 0, Flamebait

      Is it a fact that they said "use bitlocker instead, it's safe"?
      If it is, your BS detector should be blaring at full volume.

      What you call speculation is only the most obvious explanation. It might not be the correct one, and the bloggers you refer to could all be al qaeda operatives on russian mafia hardware, but it still is the most obvious explanation, with a string of documented precedents. So you should come up with some other interpretation, or your doubt is not very productive, IMHO.

      --
      ---- MISSING MISCELLANEOUS DATA SEGMENT --- [sigdash] trolololol
    11. Re:Speculation by Anonymous Coward · · Score: 0

      There is no concrete information that the NSA or a national security letter was involved.

      Even if it was concrete information; a NSL "ordering" to implant a backdoor is implausible, as it's obviously an unlawful order, and the right response is for the developers to publish and simply avail themselves of their 1st amendment rights, including whistleblower protections.

    12. Re:Speculation by AmiMoJo · · Score: 0

      To be fair it might not be the NSA, it could be GCHQ or any number of other government agencies. Some people seem to think that the Truecrypt authors are from eastern Europe. Maybe some eastern European government knocked on their door.

      The only thing that is really certain is that this appears to be a case of duress.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    13. Re: Speculation by Anonymous Coward · · Score: 1

      I'm comfortable that some random prick pinching my machine from a pub won't be able to access (or even identify) my old TrueCrypt files, thanks. Come to that, since the reason to swipe my machine would be to either use it or sell it, I'm comfortable they wouldn't even bother. Same goes if I had my stuff in FileVault or BitLocker, or anything.

    14. Re:Speculation by AmiMoJo · · Score: 0

      Replying to myself, lame...

      Having speculated all that, the fact that U.S. was changed to United States is a pretty big hint. I just hope whoever did it isn't rotting in Guantanamo now, because I doubt that the NSA took kindly to that.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    15. Re:Speculation by Anonymous Coward · · Score: 0

      What are you doing with your computer that BitLocker doesn't count as safe?

      Let's drop the hyperbole -- the NSA don't actually give a shit about your stash of porn, some accounts and a little collection of passwords, and neither does the government. They can get all of that in other ways if they have to, but they actually don't give a shit about you, either. The idea that any of us are protecting things from the governments of this world is laughable. At best we're deluding ourselves of our importance, and at worst we're deluding ourselves that any information we lock away isn't available elsewhere for the expenditure of a lot less effort than cracking a file on someone's computer.

      This caveat does not include journalists who are lucky enough to get a sudden massive scoop but there are very, very few of those even in relation to the number of journalists in the world, let alone everyone else -- and I doubt you're one of them.

      So let us conclude that nothing you have on your computer is of importance to your government, or that if any of it somehow was, they could get it elsewhere. So why else are we encrypting things on our machines -- as I am myself with TrueCrypt 7.1a? Simple: other people. And I have no doubt that those people would struggle to get into a TrueCrypt file, or even identify it, if they got onto my machine, be there backdoors or not. Almost anyone using this computer will have stolen it to sell it on or, in an extreme, use it themselves. Sure, they'd be happy to rip out credit card information and sell it off but none of it is in the clear, and I think the chances of someone stealing my machine *and* caring to look for credit card numbers *and* having the ability to identify my TrueCrypt files *and* to be able to hack them are so near to zero that I don't care.

      Thing is, exactly the same would be true if I were using FileVault (or, on my Windows machine, BitLocker. The kicker there is that since my Windows machine runs Vista I can't use BitLocker. Thanks, Microsoft, you fucking pricks.) Governments could still get onto my drives, practically no-one else would bother unless the security hole was so gaping that it was widely known how to access it, but not widely known enough that neither I nor Apple/Microsoft had patched against it.

    16. Re:Speculation by Anonymous Coward · · Score: 1

      It must be sad living in a world of such heightened paranoia.

    17. Re: Speculation by Anonymous Coward · · Score: 0

      Exactly. When people get all antsy about this stuff I have to wonder what the fuck they are encrypting to begin with that they feel isn't available already to any agency that wants it.

      Let's just say that many Bothans died to bring us this information.

    18. Re:Speculation by Anonymous Coward · · Score: 0

      It makes sense if you look at this announcement as something meant to still be there in 5 or 10 years. Consider what it would be like to visit that page as someone looking for disk encryption soft in 2020 - even if there won't be any crytical bugs found in 7.1a by then, it will likely be useless on a current OS and its encryption might be made too weak by tech advances.

      When I saw it first, I thought it might be some kind of deadman switch knocking in.

    19. Re:Speculation by Anonymous Coward · · Score: 0

      Your argument doesn't hold water, as the original TC notice basically said to just go and use BitLocker. So they've obviously figured that if TC has been compromised, then it is no better than any other 'equivalent' software that is also extremely likely to have been compromised.

      If you want serious protection against a corrupt and oppressive regime, then you really don't want to rely on a false sense of security that an NSA back-doored TC has potentially become.

      If you're just protecting your shit from the guy next door, then it doesn't really matter which of these products you use.

    20. Re: Speculation by Anonymous Coward · · Score: 0

      So you admit you use TrueCrypt and can't understand why someone would want to use TrueCrypt?

    21. Re:Speculation by Aighearach · · Score: 4, Interesting

      Not really, when the project used an incompatible license all along and while marginally "open source," they were clearly taking a hostile stance towards other FLOSS projects, as nobody could integrate their work with anything else.

      In that context their explanation makes perfect sense; they didn't do it for love of FLOSS, they did it because there was no other portable options that included support for all windows versions. Without XP, that ceases being true.

      As a supporter of Free Software that reasoning might sound lame to me, but it is very consistent. And if their whole point was to provide an option for windows users, then recommending bitlocker is actually consistent. Having different values doesn't imply he's lying about his.

      As far as canaries go, you have to have the live bird before going into the mine, and then have the dead bird. In this case there was no live bird in advance, and there is dead bird afterwards. Not only have we not been warned by a canary, nobody actually even claims to have seen one, dead or alive.

      The name of the person who registered a non-profit and for-profit for TrueCrypt in the US was David Morgan. That person has already verified the posted information from an email address @truecrypt, so this other person not known to be associated with TrueCrypt should be ignored.

    22. Re:Speculation by sysrammer · · Score: 4, Insightful

      It must be sad living in a world of such heightened paranoia.

      ...sez the AC.

      --
      His ignorance covered the whole earth like a blanket, and there was hardly a hole in it anywhere. - Mark Twain
    23. Re:Speculation by lsllll · · Score: 5, Funny

      Amen brother! I switched to Bitlocker a while ago and never even looked back at LUKS or TrueCrypt. The problem I had, though, was that I run only Linux on my machine. No worries. I installed VirtualBox, created a VM and installed Windows on it. That way I could make /home/lsllll as a private share available in the VM and have Bitlocker go at it. That is the ONLY reason why I run Windows. God praise the Bitlocker developers. They saved me from the NSA.

      --
      Is that a roll of dimes in your pocket or are you happy to see me?
    24. Re: Speculation by Anonymous Coward · · Score: 0

      With the NSLs directed at Lavabit, how can a reasonable person not believe that the government would pressure all parties behind the tools that allowed Snowden to have outed their programs and escape also escape the same fate?

    25. Re:Speculation by fustakrakich · · Score: 1

      When did we start linking to random blogs for speculation presented as fact?

      Are we supposed to believe regular mass media is any better, or even different? Since we are allowing abusive authority to prevail with no oversight, we have to assume the worse about it. Reddit is every bit as credible as the Times and the Post, which are essentially government institutions.

      --
      “He’s not deformed, he’s just drunk!”
    26. Re: Speculation by Anonymous Coward · · Score: 0

      No, not at all -- I use TrueCrypt and don't understand why someone would panic about using BitLocker or FileVault. (I wouldn't *like* it because I like having mountable virtual drives rather than encrypting the whole drive, but that's a totally different matter.)

    27. Re:Speculation by dcollins117 · · Score: 4, Insightful

      What are you doing with your computer that BitLocker doesn't count as safe?

      That's none of your concern. That being said, you're kinda missing the point of privacy. The use of encryption in no way implies that you are doing anything wrong. Just the opposite - you've taken steps to insure your data is not accessed by an unauthorized person. So in fact, you're doing something right.

    28. Re:Speculation by Anonymous Coward · · Score: 1

      It is not a matter of being FLOSS friendly, but to recommend a black box made by someone with the track record of Microsoft. It is not a canary, it's what people resort to when they have to send a message that something is wrong. If somebody comes up and says it's a canary, well, his call. IIRC indirect disclosure using a canary technique is equivalent to disclosure, if you get the NSA at the door. If you discredit him and because of that you assume that everything is ok, you make a leap of faith. Your call.

    29. Re:Speculation by Anonymous Coward · · Score: 0

      When Americans decide there is oil in a country that should rightly be theirs.

    30. Re:Speculation by Anonymous Coward · · Score: 0

      I didn't mean to solely imply you might be doing anything wrong, or illegal - but the encryption you get routinely on computers is going to be strong enough to block practically anyone trying to get onto your machines with the arguable exception of government authorities. (And perhaps second-hand computer stores and unethical repair shops, and if your machine is going to someone who actually may be expert and you're not shifting encrypted or sensitive material off it then you're not being paranoid *enough*.)

      Basically I highly doubt anything on your machine is important enough to worry about the few types of people who'd be able to get in, meaning you're protecting against the random dude, most of whom don't even know what encryption really is, and most of the rest of whom will still struggle to first identify and then unlock the encrypted data. It was a rhetorical question rather than a concrete one, meant to suggest that practically nothing is really of that level of importance. Not that we shouldn't want to lock valuable information away; of course we should, and we should ensure that that doesn't go near someone who might want to, say, pinch credit card and bank details, which in turn means being careful about who gets to take your computer or hard drive into a back room and fiddle with it. But practically any of that would be available to a government agency already, through other, far easier means, if you or your information were actually of importance to them, which on that level of detail, it really isn't.

      I don't think that's missing the point so much as suggesting we're making a bit too strong a thing of this.

    31. Re:Speculation by dcollins117 · · Score: 1

      Upon reflection, I think I probably misinterpreted your initial point, and then went off a a weird tangent. I'd retract my post if I could.

    32. Re:Speculation by YukariHirai · · Score: 1

      Which is all well and good... except for the facts that A) the NSA doesn't seem to be constrained by what is legal or not, and B) whistleblower protections aren't doing people who blow the whistle on this sort of level a whole lot of good.

    33. Re:Speculation by The+Snowman · · Score: 1

      Which is all well and good... except for the facts that A) the NSA doesn't seem to be constrained by what is legal or not, and B) whistleblower protections aren't doing people who blow the whistle on this sort of level a whole lot of good.

      Don't forget that the GP's 1st amendment comment assumes TrueCrypt was developed by U.S. citizens. Being that the domain was registered in Antarctica and the developers are rumored to be European, that could be another blow: the NSA then has full authority under U.S. law to do whatever they want to the project.

      --
      24 beers in a case, 24 hours in a day. Coincidence? I think not!
    34. Re:Speculation by shutdown+-p+now · · Score: 1

      As far as canaries go, you have to have the live bird before going into the mine, and then have the dead bird. In this case there was no live bird in advance, and there is dead bird afterwards.

      The canary in this case is the specific changes that were made to the code (specifically, the subtle wording of some of the comments) - or so it is claimed.

    35. Re: Speculation by jelIomizer · · Score: 3, Insightful

      Secret plans? About what? If you have secret plans that the government should be interested in, then I want them to find out about it - because unless you are planning terrorist activity, there is no reason to fear so much.

      Wow. Did you seriously just use "Nothing to hide, nothing to fear"... seriously? Are you retarded, or do I have to point out that hundreds of millions of people were abused and/or murdered by governments--including the US government--throughout history? If you knew, then why do you seem so confident that people who wants to keep their plans secret must be doing something immoral? History just isn't on your side, fool.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    36. Re:Speculation by jelIomizer · · Score: 1

      The more people that use encryption, the more people that can provide cover for those who do things the government doesn't like (Which isn't necessarily immoral!) and prevent those people from being abused. If very few use encryption, those who do use encryption may be singled out and harassed.

      So, how about caring about someone other than yourself? Perhaps you should also start caring about the constitution, fundamental liberties, and the ability to know what the software on your computer is doing?

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    37. Re:Speculation by jelIomizer · · Score: 1

      And to suggest that the government can just get all this information elsewhere is just absurd.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    38. Re:Speculation by Anonymous Coward · · Score: 0

      Whatever the case, the bizarre abrupt ending suggests some sort of government involvement.

    39. Re: Speculation by Euler · · Score: 4, Insightful

      Ah, yes... "If you aren't doing anything wrong, then what do you have to worry about"
      Except there are plenty of cases of persecution if you happen to be:
        - Gay,
        - A former member of the communist party,
        - Union organizer,
        - Whistle blower,
        - Protester, objector, not in line with corporate America,
        - Catholic, Jewish, Japanese, or anything else not favorable at the time...
      None of these people are terrorists, but clearly lost their liberties, reputation, or assets when they were "outed"

    40. Re:Speculation by Euler · · Score: 1

      There isn't any way they can give us confidence that they are playing nice either. This is what happens when you violate the trust of the US people and the rest of the world. People used to believe that the US Constitution was the fire-block that was stopping this same nonsense that you would expect from China or other authoritarian governments with no protection of human rights. Now its official, there is no difference.

      US corporations have lost major credibility in the world technology market: "We promise this time we won't put secret back doors in our products that we won't tell you about because our government forced us to and we couldn't tell you. We promise this won't happen anymore."

    41. Re:Speculation by Anonymous Coward · · Score: 0

      This all reminds me of Flappy Bird.

    42. Re:Speculation by Anonymous Coward · · Score: 0

      I didn't mean to solely imply you might be doing anything wrong, or illegal - but the encryption you get routinely on computers is going to be strong enough to block practically anyone trying to get onto your machines with the arguable exception of government authorities. (And perhaps second-hand computer stores and unethical repair shops, and if your machine is going to someone who actually may be expert and you're not shifting encrypted or sensitive material off it then you're not being paranoid *enough*.)

      Basically I highly doubt anything on your machine is important enough to worry about the few types of people who'd be able to get in, meaning you're protecting against the random dude, most of whom don't even know what encryption really is, and most of the rest of whom will still struggle to first identify and then unlock the encrypted data. It was a rhetorical question rather than a concrete one, meant to suggest that practically nothing is really of that level of importance. Not that we shouldn't want to lock valuable information away; of course we should, and we should ensure that that doesn't go near someone who might want to, say, pinch credit card and bank details, which in turn means being careful about who gets to take your computer or hard drive into a back room and fiddle with it. But practically any of that would be available to a government agency already, through other, far easier means, if you or your information were actually of importance to them, which on that level of detail, it really isn't.

      I don't think that's missing the point so much as suggesting we're making a bit too strong a thing of this.

      Really? Nobody is doing anything important enough for the feds to squash them like a bug? Why do you assume it'll always be federal level state security issues they act on?

      The IRS didn't selectively attack various non-profit groups in an interesting and specific manner recently?

      Maybe today, right now, they don't care. But the time will come where they CAN go through and decide "well, this porn actress is MY girlfriend all of THESE guys with her in their collections are now getting flagged."

      Do you realize that some of the "anonymous tips", indeed, a RASH of them recently could be the fact that the feds now know the public will find out they have known about several hundred child porn trading folks (some of them, also making it) all along? That they now HAVE to clean house like this with the small fry because the public now _KNOWS_ that they can see this stuff or will figure it out soon. (Pick your crime, it could be anything, including stuff that ISN'T a crime now.) So now they have to start pushing this intel down to the local idiots.

      All that would have to happen is a little bit more information come out in the right place and all of a sudden the flood gates of this information open and it all comes pouring down to the local doughnut eaters to rev up their MRAPs to come throw flashbangs on your cat as they break down your door, because once, you said "well when I comes time to have an insurgency, I am all in!" as a joke.

      You are a clueless, myopic retard. There is no way to undo what they have done. The system will never go away, it'll be sitting there, and someone's job will be to run it and use it. So they will. I can't fucking WAIT for the "other side" to get control of these organizations and go to town. If you think the jug-eared-motherfucker in office now is bad, wait till someone who's TRYING to do a bit of evil lands in office and has control over these tools. Our great experimental nation is already done. It's just not begun to visibly rot yet.

      Yeah, TrueCrypt is going to be useful for securing stuff that is legal, only slightly risque, and hiding it from the GF. But if you think this event is nothing, you are stupid.

    43. Re:Speculation by Anonymous Coward · · Score: 1

      > Did you forget what site you're on?

      According to our collected metadata, you're new here.

    44. Re:Speculation by epyT-R · · Score: 1

      There are plenty of the faux intellectual type liberals here, more than enough to offset the smaller but very vocal libertarian contingent. There are few if any neocons here.

    45. Re: Speculation by epyT-R · · Score: 1

      Unless the bitlocker master keys leak (or are bruteforced in the future)..

    46. Re:Speculation by tlhIngan · · Score: 1

      We do not need concrete information.
      When a major encryption project like this closes shop, without any explanation, duress should be assumed.
      The current climate requires it.

      The problem is, it doesn't make sense.

      First of all, Lavabit is a bad example because they used one encryption key for everything - hence the FBI's request for all user's email because it's impossible to isolate just one mailbox. That was a Lavabit fault (one would reasonably assumed there was no master key involved).

      TrueCrypt though doesn't have a "master key" - there is no one key that when disclosed will unlock every TrueCrypt volume out there. (At least, that's what the preliminary audit reports say).

      And given the nature of TrueCrypt, it would be a challenge to implement such a backdoor - the audit verified that it's possible to recreate the binaries from the source.

      And there's no real update in over 2 years. A NSL that forces them to implement something that sends the master key to the NSA would be known - it's not like people won't diff the source code or build and compare to see if there were holes.

      And the audit itself didn't reveal anything big or major.

      A more likely reason cropped up when someone claiming to be a TrueCrypt developer stepped up and claimed boredom as the reason. Basically the developers were burned out and didn't want to do it anymore. Perhaps some of the minor flaws in the audit would be too boring to fix, for example.

      So why the announcement? Because unsupported it IS less secure - eventually more holes and vulnerabilities will turn up and it might be fatal. Better to get everyone off it rather than believing their data is secure against unknown future attacks.

      And other people are trying to resurrect/fork it, trying to get all the legal ducks in a row to meet the requirements of the license.

    47. Re: Speculation by Anonymous Coward · · Score: 0

      Then simply do your best at being nothing your government doesn't like you to be and conform to what the authorities want. Where is the problem? Europeans have always done it and everybody knows Europe is superior to anyone else in the world.

    48. Re:Speculation by epyT-R · · Score: 1

      well if second hand computer shops and unethical civilians can crack bitlocker, then it isn't very useful at all as it implies there are master keys in the wild.

    49. Re: Speculation by gsslay · · Score: 1

      If you have secret plans that the government should be interested in, then I want them to find out about it - because unless you are planning terrorist activity, there is no reason to fear so much.

      I really hope you're not giving us the "if you have nothing to hide then you have nothing to fear" line? Because that one has always been bullshit.

      You are totally clueless to what "the government should be interested in", and have even less of an idea on "the government is be interested in".

    50. Re: Speculation by Anonymous Coward · · Score: 0

      There's nothing wrong with persecuting gays. Such perverse behaviour should be discouraged.

    51. Re:Speculation by gsslay · · Score: 1

      The point is that some people's machines may have sensitive information on it. Just because you personally can't think of any doesn't mean there are none. Maybe commercial secrets. Maybe juicey blackmail material. Maybe they live in an oppressive regime and are writing a book the government doesn't care for. Or maybe they've just got a sexual orientation that the religious police don't find acceptable, and any evidence of that would be fatal. Withdrawal of things like Truecrypt hurt these people too. It's not all about self-interest.

      Do you trust all governments, and all future governments, to never use their backdoor into that for any other purpose, other than the all the good, wholesome things they say they need it for? You know, the holy trinity of "war against terrorism", "national security" and "protecting the children". You really think that "protecting economic interests" never, ever, features? Really?

    52. Re:Speculation by Anonymous Coward · · Score: 0

      Better paranoia than ignorance...

    53. Re:Speculation by Anonymous Coward · · Score: 0

      Let me bring you up to date on the current state of the world:

      http://lmgtfy.com/?q=edward+snowden

    54. Re:Speculation by TheCarp · · Score: 1

      I was thinking that myself as I typed a response to a previous comment but, I canceled it because I realized something.....few other scenarios make sense.

      If their signing keys were compromised, they could issue revocations, they could announce it. They would be foolish not to. If they just wanted to end the project, why such an off the wall announcement? Why release a decrypt only version?

      These actions together make no sense unless they have some reason that they cannot talk about. There are not a lot of reasons that I can think of that they would be unable to disclose some information, like their real reason for stopping or what real vulnerabilities may or may not be out there.

      It is really hard to find much else that fits here. Maybe not an NSL but some sort of goverment action with a gag order attached. What else could they not talk about unless it involved their own misdeeds? However, if they had backdoored trucrypt in some way (and no passing a security audit doesn't mean they didn't do it)....why release a decrypt-only now? Why not just, end the project and call it a good run? It doesn't add up, criminals don't clean up the messes they leave behind, not when it doesn't actually cover their tracks in any way.

      No this stinks and there are not too many reasons I can think of for it to smell like that. Not proof but, I think suspicion is warranted. I have seen a lot of projects end a lot of different ways, from pissy developer infighting to lack of funds to life issues taking over. This doesn't look like any of them. This isn't how long running projects usually end.

      And that is the whole point of the Canary, by its most sudden and peculiar death, you know its time for people to begin walking calmly to the exits of the mine shaft.

      --
      "I opened my eyes, and everything went dark again"
    55. Re:Speculation by Anonymous Coward · · Score: 0

      When did we start linking to random blogs for speculation presented as fact?

      This is slashdot. We always link to random blogs and stuff it with large quantities of speculation.

    56. Re:Speculation by Anonymous Coward · · Score: 0

      But then it came to my mind that Bitlocker is much more secure than Truecrypt, because it has been developed and carefully audited by a corporation with a proven track record in cyber security

      Microsoft has a proven track record in cyber security? How good are the drugs you take.. damn.

    57. Re:Speculation by neghvar1 · · Score: 1

      Of course there is no concrete evidence. If there was, those involved with Truecrypt would have been arrested and charged with violating 18 U.S.C. 2709(c) of the USA Patriot Act.

    58. Re: Speculation by spacepimp · · Score: 1

      So we have an anonymous coward who is whining about other people feeling they have something to hide. You realize what a fool you look like by posting this comment as AC?

    59. Re:Speculation by Unordained · · Score: 1

      And other people are trying to resurrect/fork it, trying to get all the legal ducks in a row to meet the requirements of the license.

      I've been curious how the original anonymous developers would be able to enforce the terms of their previous license ... even if they had some means of proving in court that they really were who they claimed to be, and had the right to sue, they would lose their anonymity in the process, which is of some value to them.

      The anonymity of the developers is a double-edged sword, in this kind of product. It temporarily makes it harder for intelligence agencies (or organized crime) to put pressure on them, but long-term, is it worthwhile? Either their identities will be found out and used against them, or their continued anonymity will be used against the project by at least casting down on the trustworthiness of the project. Ownership of crypto keys (software signing keys) is a pretty good stand-in for identity, except that our laws don't have the same respect for them as for other cases of identity-theft -- they're "just data", to be handed over, and possibly abused.

      (Doubting the usefulness of anonymity in no way endorses the likes of Microsoft, and their line that having an established identity entrains reputation, and the desire to protect said reputation in turn guarantees trustable software. At least with TC we have source, and a hopefully independent audit, and that's perhaps the most important piece in the end.)

    60. Re:Speculation by Anonymous Coward · · Score: 0

      Oh yeah, he's that asshole who sold out the foreign intel secrets of my country! That fucker can enjoy his Russian holiday until Putin gets done pulling his strings. He sold out his country and people like you are lining up to suck his dick. I gotta wonder what our country is in for in the future when people like you graduate high school or college and end up going out and have to live in the real world.

    61. Re:Speculation by Anonymous Coward · · Score: 0

      2009? 2010? Whenever bloggers decided they were journalists because of filming hippie vandalizing stuff and not wanting to go to jail or reveal their sources. Or we just got lazy.

    62. Re:Speculation by Anonymous Coward · · Score: 0

      There is no concrete information that the NSA or a national security letter was involved. When did we start linking to random blogs for speculation presented as fact? May as well just posted a link to reddit thread about this.

      You have been around long enough to have a 5-digit UID and yet you say there is "no concrete information". What form, exactly, must information take for you to consider it "concrete"? Should it be carved in stone? Should it be released by a major corporation? A think-tank? The government? You need to clarify for your comment to make any sense. Blogs are one way the Internet communicates. Shame on you for being (or acting) ignorant about that.

    63. Re:Speculation by plover · · Score: 1

      So why the announcement? Because unsupported it IS less secure - eventually more holes and vulnerabilities will turn up and it might be fatal. Better to get everyone off it rather than believing their data is secure against unknown future attacks.

      The problem is they didn't say it that way, instead they claimed it had unfixed security issues. Which is weird, because the audit has demonstrated the opposite.

      However, I think we should all read what they wrote a bit more literally: "Warning: Using TrueCrypt is not secure." The key word we're all overlooking in all this paranoia is "using". TrueCrypt itself may be just fine as is, but according to Snowden's documents, virtually every single computing platform is susceptible to some form of software or hardware hacking that allow the NSA access. Keyloggers built into keyboards, motherboards, USB cables, hubs; the ability to wirelessly transmit logs up to 8 miles away; BIOS that allows remote control; routers with subverted access commands - it doesn't matter how secure the software is if the attackers already own the platform itself.

      --
      John
    64. Re: Speculation by Anonymous Coward · · Score: 0

      First they came for the gays, and I didn't speak up, because I wasn't gay.
      Then they came for the furries, and I didn't speak up, because I wasn't a furry.
      Then they came for those who cut up wieners in their sauerkraut...

    65. Re:Speculation by Aighearach · · Score: 1

      Claimed by who? Claimed by people outside the project. The main claim is from twitter from a person who hasn't talked to them since 2004, and is going by memory, and hasn't even clarified if they gave specific changes that would happen; though clearly not if it wasn't written down and that much time passed.

    66. Re:Speculation by MrNaz · · Score: 1

      It must be comforting, living in a world of such naivete. At least, it will be until you wake up and realize where you are.

      --
      I hate printers.
    67. Re:Speculation by ihtoit · · Score: 1

      The difference between blogs and mass media:

      The Chilcott Report, if it were posted on a blog, would be posted in its entirety. As it is, it is but a claim right now that it exists; we know a fuckload of public money was diverted and spent on the inquiry, and absent proof to the contrary, claims in MSM that the report implicates former Prime Minister Anthony Blair in war crimes, is itself grounds to issue a warrant for his arrest - at which point full public disclosure is an inevitability as it becomes evidence in a criminal trial. My question on that, is just who exactly originated that claim and have they actually read the Chilcott Report?

      Blogs: are generally prepared to furnish evidence to claims made.
      MSM: reports what Government tells them to, evidenced or not.

      --
      Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
    68. Re: Speculation by Anonymous Coward · · Score: 0

      I interpreted it as "you probably have nothing of value to hide that that NSA couldn't get by other means anyway, so don't worry about it". However if the Truecrypt project has been subverted by the NSA, they must have a reason for doing so, which implies some people use it with information the NSA can't get by other means.

    69. Re:Speculation by lovejw2 · · Score: 1

      So it's Schrodinger's Canary?

  7. Re:Nonsence by Anonymous Coward · · Score: 0, Insightful

    Who the fuck are you, anon? If reputation is important to you, where's your fucking reputation?

  8. Re:Nonsence by Anonymous Coward · · Score: 1

    He is not making extraordinary claims, so reputation is irrelevant.

  9. tc-play is a reimplementation of Truecrypt by Anonymous Coward · · Score: 5, Informative

    Fyi Truecrypt, with its dubious code provenance, has been suspect for a long time anyway, regardless of these developments. S there already is a re-implementation of Truecrypt from the ground up for Linux and BSD by non-anonymous(?) developers: https://github.com/bwalex/tc-play

    Also, cryptsetup-LUKS (recent versions only) can mount truecrypt containers under Linux.

    1. Re:tc-play is a reimplementation of Truecrypt by ysth · · Score: 4, Informative

      You are behind the times.

      The binary build was duplicated from the source.
      The source has been audited.

    2. Re:tc-play is a reimplementation of Truecrypt by davydagger · · Score: 4, Insightful

      There is actually a code audit underway, and so far they've found nothing.

      the concept of anonymitty means nothing, because we live in an age where reputation can be bought.

      all that matters is if the source code can be inspected, and if the source code matches the binaries.

      who actually makes it does not matter as long as its audited properly.

      stop with the FUD.

    3. Re:tc-play is a reimplementation of Truecrypt by Anonymous Coward · · Score: 0

      The source code is being audited. AFAIK they haven't yet completed the audit.

    4. Re:tc-play is a reimplementation of Truecrypt by Anonymous Coward · · Score: 0

      While a step in the right direction that is simply not good enough. The code aught to be released under a free software license. Not some half-baked unclear academic license that has been called into question by multiple people over the years and results in incompatible licensing with major free software projects (Debian, Tails, Trisquel, Parabola GNU/Linux-libre, etc). The only security you can be confident in is an open development model where everybody in the community can review each and every tidbit of code that is submitted as it happens. By distributing the code there is less possibility for a secret entity like the NSA injecting bugs or code going unvetted in the first place. Then the binaries should also be verifiable (see Tor's effort on this. search for Deterministic Builds).

    5. Re:tc-play is a reimplementation of Truecrypt by ysth · · Score: 3, Informative

      The audit of the source is complete. The next phase of the audit is cryptanalysis.

    6. Re:tc-play is a reimplementation of Truecrypt by ysth · · Score: 1

      I agree with your first part, but then you go off on a tangent ("By distributing the code...") that seems inapplicable??

    7. Re:tc-play is a reimplementation of Truecrypt by Atomic+Fro · · Score: 1

      Open source or not, you can't trust anything even with code audits:
      Dennis Ritchie's back door

      --

      ==================
      Hippie Logger Jock
      ==================
    8. Re:tc-play is a reimplementation of Truecrypt by HuguesT · · Score: 1

      Yes you can, if you can reproduce the binary from an audited compiler, which is exactly what has been done in the case of TrueCrypt. BTW this is Ken Thompson's backdoor, not DRR.

    9. Re:tc-play is a reimplementation of Truecrypt by fnj · · Score: 1

      Yeah, right. And as a matter of fact I have no evidence that I am not the only sentient being actually alive on earth. In fact, is the earth even real? Everything I can possibly ever know or guess comes to me from my five senses, and there is no proof and cannot possibly ever be any proof that my five senses are connected to anything real.

      In fact, how do I really know even *I* am sentient? Because I have self-awareness? What is that, anyway? What is self? Man, this must be a really far out acid trip.

      You have to draw the line of doubt and second-guessing SOMEWHERE.

    10. Re:tc-play is a reimplementation of Truecrypt by philip.paradis · · Score: 1

      Why not just link to the original work instead of some blog entry? Reflections on Trusting Trust

      --
      Write failed: Broken pipe
    11. Re:tc-play is a reimplementation of Truecrypt by kbg · · Score: 1

      The binary on Windows is compiled from a Microsoft complier which most likely has NSA code which creates a backdoor in the TrueCrypt binary.

    12. Re:tc-play is a reimplementation of Truecrypt by Anonymous Coward · · Score: 0

      The audit of the source is complete. The next phase of the audit is cryptanalysis.

      No it is not. Read the report. The audit covered a very small part of the binary for the project. Much more needed to be done.

    13. Re:tc-play is a reimplementation of Truecrypt by sconeu · · Score: 1

      I would suspect that VC 1.52 predates NSA backdoor-isms.

      The source is being audited.
      The binaries have been proven to be generated from the source.

      The only backdoor I can see is a Thompson style compiler attack.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    14. Re:tc-play is a reimplementation of Truecrypt by Anonymous Coward · · Score: 0

      stop pretending you exist! it aggravates my doctors.

    15. Re:tc-play is a reimplementation of Truecrypt by T.E.D. · · Score: 1

      Don't forget to audit the compilers too. And the compiler's compilers...

    16. Re:tc-play is a reimplementation of Truecrypt by Reziac · · Score: 1

      I was just reading the bit on GRC.com, that exchange with 'David' and a couple things struck me:

      'David' sounds like mainland Chinese in his use of English.

      The NSA is not the only such agency in the world.

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    17. Re:tc-play is a reimplementation of Truecrypt by Anonymous Coward · · Score: 0

      . . . which most likely has NSA code which creates a backdoor . . .

      And by "most likely", you mean "I don't know shit, but this fits into my little carefully constructed world view so it must be true."

    18. Re:tc-play is a reimplementation of Truecrypt by ihtoit · · Score: 1

      here's a line:
      -----
      We are all figments of a deranged imagination.

      --
      Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
  10. Who to believe? by Anonymous Coward · · Score: 1

    There is also "confirmation" that the developers are simply tired of the project and don't want anyone else to work on it:
    https://www.grc.com/misc/truecrypt/truecrypt.htm
    Who do we believe?

    1. Re:Who to believe? by Aighearach · · Score: 1

      I say we believe david@truecrypt

      https://twitter.com/stevebarnh...

    2. Re:Who to believe? by Jane+Q.+Public · · Score: 1

      There is also "confirmation" that the developers are simply tired of the project and don't want anyone else to work on it:
      https://www.grc.com/misc/truec...

      Gibson is generally a reliable source. He was very much right back in the day when he built the "Shields Up!" site and everybody else called him paranoid.

      And his explanation also makes sense: they did change the license, and they did take the time and trouble to build 7.2 before the "sudden" announcement on their page.

      Why would they want to kill the project? Who knows? People sometimes do perverse things.

      But if that were actually their intent, they won't succeed. The group doing the audit said that if it passes, they plan to offer a fork build and continue the project.

    3. Re:Who to believe? by Shawndeisi · · Score: 1

      You have to look at everything as one big picture:

      1) You can't legally talk about being the subject of an NSL, or you probably do time in a PMITA prison.
      2) The developers would really like to fight the NSL, but would really not like to do time in a PMITA prison
      3) An NSL presumably cannot coerce you to keep doing what you're doing, only to not tell people that you were subject to one.

      Therefore, it would seem prudent to tip everyone off in a covert way (e.g. replacing instances of "U.S." with "United States", reuploading your same signing keys, saying "not secure as", etc.) but have an overt reason to stop use of the product. It's a very fine line they're walking, and they risked a lot by doing what they did if they were subject to an NSL. In their shoes, I would also say that I lost interest after walking as close to the line as possible. They're gagged and already have at least some chance of having their lives ruined for the actions that they did take. It's not like they can say "Yep, I was NSL'd"

    4. Re:Who to believe? by fnj · · Score: 1

      Has anyone in this group checked their postal mail lately? Any registered letters in there with NSLs inside? Where does it stop?

    5. Re:Who to believe? by Aighearach · · Score: 1

      No, look up the law for National Security Letters. There are only civil penalties. And indeed, it is from the wrong branch of government to have anything else attached. They can sue you for an unlimited amount of money, they cannot imprison you. That threat is connected to traditional process that involves the Courts.

  11. Re:Nonsence by Anonymous Coward · · Score: 0

    That neuron must be feeling lonely by now, doesn't it?

  12. What else? by NotInHere · · Score: 1

    It has to be an NSL. What should be the other explanation? The truecrypt accounts hacked? I don't think so.
    However, it is too early for a story "The Sudden Policy Change In Truecrypt Explained". There is no proof of this speculation yet.

    1. Re:What else? by rahvin112 · · Score: 5, Informative

      The simplest explanation is that the developers simply got tired of the project and decided to abandon it. It's been years since any update and it's certainly plausible that those developers remaining simply decided it wasn't worth it to keep the project alive when no one was maintaining it. .

    2. Re:What else? by Anonymous Coward · · Score: 0

      On the other hand, would a NSL letter do? A lot of Americans are pissed and awake due to Snowden. Seeing TrueCrypt being taken down by a NSL just means that TrueCrypt goes from the average 4-chan guy stashing his bronie picture collection, to the average person seeing that "hmm, TC is so good the gub'mint shut it down", and starts using a previous version.

      Of course, it means that TrueCrypt code ends up moving offshore. If the bad guys know that it is good enough to be shut down, then someone in Elbonia will copy the source code and work on it, well out of reach of the US government. Even China would gain propaganda abilities by making this (and not having it available to their citizens.)

      Don't forget the more pedestrian cause. SecurStar took the E4M devs (the guys who made the base code for TC), demanded they cease work on E4M, and has alleged on other forums of IP violations. It could be that SecurStar managed to get their way and get the TC project shut down. All it would take is a DMCA takedown notice. I have not have had good experiences with SecurStar in the past. For example, their (IMHO) Draconian license manager. (in my experience, reinstalling a system without de-registering the key usually means a support call, or just re-buying the product.)

    3. Re:What else? by Anonymous Coward · · Score: 0

      Then why not say that? Why pull old sources? I'm afraid "they just got tired of it" doesn't match the facts we have. The reason we're given is that it's insecure, but no posts about how or why or how to mitigate are given. The bits about using bitlocker as an alternative when it only runs on windows are even less in line with TC's use case. There are a few scenarios that match the facts and receiving some sort of coercion from NSA or whoever matches up far better with the weirdness happening here than "just got tired of it."

    4. Re:What else? by rahvin112 · · Score: 1

      They are anonymous, what do you expect them to conduct interviews? Doesn't fit the facts my ass, it's the most logical assumption.

    5. Re:What else? by Anonymous Coward · · Score: 0

      That is not the simplest explanation for burning the project down. If they simply said, "we're not maintaining it" then your's could be the simplest. To do as they did indicates more.

    6. Re:What else? by dcollins117 · · Score: 3, Insightful

      The simplest explanation is that the developers simply got tired of the project and decided to abandon it. It's been years since any update and it's certainly plausible that those developers remaining simply decided it wasn't worth it to keep the project alive when no one was maintaining it.

      Fine. The simplest way to do that is to put a clear and unambiguous message on their webpage staing that development is frozen at version 7.1a, and the project will no longer be maintained. Instead they gave no explanations, but very bizzare set of statements that raise more questions than they answer.

      This has the flavor of a practical joke or an unstable mind. Certainly not someone you would trust to protect your data.

      It's a shame. I really liked the application.

    7. Re:What else? by thegarbz · · Score: 1

      Occam's Razor works both ways. You're correct. The project is closed, Occam's Razor would say that the developers didn't want any part of it.

      It would also say that the normal way to go about it is writing a post on their home page detailing how they are pulling out because they are bored and to wish everyone a good day and thank the community blah blah blah. Instead they have quit in an amazing dramatic way leaving a community confused with no information and recommending to abandon the use of Open Source software in favor of commercial alternatives. They gutted their webpage, no guides, no information, not even any kind of branding indicating what TrueCrypt was.

      For such an exit the simplest explanation is that it was left under extreme duress or they were hacked, though the latter would have been resolved by now.

    8. Re:What else? by radarskiy · · Score: 1

      The counter-example is Flappy Birds.

    9. Re:What else? by Euler · · Score: 1

      The whole misdirection to Bitlocker is probably a sarcastic joke pointing to a company far more likely to adhere to NSL's.. Bitlocker isn't even provided on Home editions of Windows, so it really isn't such an obvious alternative. Their directions literally go through steps to change the Windows product key. I would assume to do this legally you pay Microsoft, is that correct? So you are telling me that TrueCrypt as a free alternative for home users isn't still worth developing by someone?

    10. Re:What else? by epyT-R · · Score: 1

      Then why change the site? The old site was reasonably well written and organized. It would've been easier to post an update to that. Instead we get this bizarre layout with broken english and a half-assed release. It's far more likely that the half assed release was just the payloader to distribute the canary changes..

    11. Re:What else? by thegarbz · · Score: 0

      Is it really? The announcement that Flappy Birds was being pulled saw a huge increase in downloads. That just seemed like clever marketing.
      In any case the programmer came out and clearly explained his actions and what he was about to do and gave deadlines.

      That's not a counter example. The TrueCrypt response is akin to dropping a project due to a very sudden onset of brain damage. Did the Flappy Birds creator tell everyone to go out and download Candy Crush? Did the professional programmer ask you on an incredibly shitty webpage that looks like it was hobbled together by a 2 year old to jump into the welcoming arms of the very people his ideological choices (open source in closed source world, heavy encryption with lots of options in a world of export restrictions) oppose?

      The only people who think this is any kind of sane way to shut down a project scare me with their inability to reason.

    12. Re:What else? by Anonymous Coward · · Score: 0

      Right. Tens of thousands of dollars of support, an endorsement from Snowden and a global furor...Meh, boring.

      Are you kidding? This is making HISTORY, dude!

      Also, no matter how unmotivated they may have become, they didn't magically forget obvious facts like bitlocker being unsafe, most windows not having it, etc.

      Err, it's safe from your parents. Maybe safe from hackers who probably aren't going to physically access your HD anyway. If you don't want the NSA to have access to your stuff, I doubt bitlocker will help.

    13. Re:What else? by Anonymous Coward · · Score: 0

      Yeah! Whenever I get bored with something I spend dozens of hours rewriting it to remove all the functionality then write up a whole website on how it's shit.

      This is how all anonymous cowards behave, therefore it is the logical assumption.

    14. Re:What else? by david_thornley · · Score: 1

      On the other hand, anybody concerned with security has to account for the possibility that the project was shut down by the US government. It would be unsafe not to.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  13. It is all pretty obvious by hsmith · · Score: 2, Interesting

    U.S. changed to "United States" - "use bitlocker," "use any crypto package in Linux," when setting up an OS X disk image no encryption...

    The message is clear what happened.

    1. Re:It is all pretty obvious by Jane+Q.+Public · · Score: 1

      U.S. changed to "United States" - "use bitlocker," "use any crypto package in Linux," when setting up an OS X disk image no encryption...

      The "no encryption on OS X" is clearly FUD. The picture did not show encryption, but the instructions clearly tell you to select an encryption scheme.

      There are real questions about this... no need to go off into la-la land.

    2. Re:It is all pretty obvious by Anonymous Coward · · Score: 1

      The U.S. -> United States is an automatic VS change that occurred with an update. Take off your tinfoil hat for a moment.

    3. Re:It is all pretty obvious by loosescrews · · Score: 1

      Do you have a source for that? I Googled it and I didn't find anything.

    4. Re:It is all pretty obvious by epyT-R · · Score: 1

      What does the first change prove?

  14. Re:Nonsence by Anonymous Coward · · Score: 0

    Nope, it's loaded with neurotransmitters, oh yeah.

  15. Re:The FBI is mostly entirely comprised of Mormons by Anonymous Coward · · Score: 0

    Because that is a lie.

  16. Bottom Line by msobkow · · Score: 1, Insightful

    The bottom line is that TrueCrypt was too good for "the man" to tolerate.

    You will be spied upon.

    You will be surveilled.

    You will be monitored.

    Refusing to let the government rape your data is going to be called "terrorism", and leave you locked up.

    Sickening, isn't it? George Orwell was only wrong about the year...

    --
    I do not fail; I succeed at finding out what does not work.
    1. Re:Bottom Line by Anonymous Coward · · Score: 0

      Either that or it was developed by the Chinese government as a spy tool, and "the man" was just shutting them down.

    2. Re:Bottom Line by Anonymous Coward · · Score: 0

      The article was bad enough, but this comment is insightful? It's just some 8th grader spouting random cliches he doesn't really understand.

    3. Re:Bottom Line by Anonymous Coward · · Score: 0

      Agree.

      I was actually shocked, after reading the entire comment, to see that there wasn't any l33t spelling or poor grammar in it anywhere. I would expect someone like that to be "hax0ring teh gibson" every chance he got and be incapable of a coherent post.

      Of course, he could have just copied/pasted it from somewhere...

    4. Re:Bottom Line by Anonymous Coward · · Score: 0

      Welcome to Slashdot :(

    5. Re:Bottom Line by msobkow · · Score: 1

      A fifty year old eigth grader?

      Bwahahahhahahaha!

      And you didn't even come up with a cliche, so you're one to talk! :P :P :P

      --
      I do not fail; I succeed at finding out what does not work.
    6. Re:Bottom Line by Anonymous Coward · · Score: 0

      George Orwell being off by 30 years isn't too bad, in the grand scheme of things (Internet of Things).

    7. Re:Bottom Line by Anonymous Coward · · Score: 0

      Age has very little to do with mental capacity, something which you're proving quite well with your senile babbling.

    8. Re:Bottom Line by Anonymous Coward · · Score: 0

      It's very sad that you don't realize that being 50 and acting like a paranoid 8th grader is a major failing on your part.

      You should hang your head in shame rather than laughing at the sensible ac like the clueless lout you are.

    9. Re:Bottom Line by msobkow · · Score: 0

      What's sad is that you don't see the disaster that has come for the societies of the world with the behaviour of the American goveernment and it's agencies.

      What's sad is that you think I'm "paranoid" when the evidence has already been laid out before you.

      What's sad is that you have to resort to name calling, insults, and slams rather than making any pointed arguments without them.

      Personally I think you're a chat bot whose script goes something like this:

      $RandomInsult$
      $HolierThanThoughSmugRetort$
      $InsightlufCommentary$

      Unfortunately that typo in the last expansion rule leaves you being a pretty useless chat bot. :P

      --
      I do not fail; I succeed at finding out what does not work.
  17. TC developer used hidden message!!! by Anonymous Coward · · Score: 4, Interesting

    "WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues"

    1. Re:TC developer used hidden message!!! by ysth · · Score: 2

      Yes, it seems pretty clear to me that this is a warrant canary.

      It may still be that they triggered it (or let it self-trigger via inaction) out of lack of desire to continue the project.

      In any case, the presumed goal of the canary - making sure that no one trusts any future TrueCrypt version released via the normal channel - has certainly been successful.

    2. Re:TC developer used hidden message!!! by Threni · · Score: 1

      But the website says not to trust the previous (7.1a - the proper one) version, and to use 7.2 to decrypt only (stupid, because you can do that with 7.1a). The project will be forked and released by some other people. Do you trust them? Why? Or distrust them? Why? What's your criteria either way? Surely you trust the source code, and the audits thereof.

    3. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      If you were to augment their code from 7.1a I bet that would be the best bet overall.

    4. Re:TC developer used hidden message!!! by Jane+Q.+Public · · Score: 5, Insightful

      WARNING: Using TrueCrypt is notsecure as it may contain unfixed security issues

      But this raises many questions.

      (1) If Truecrypt were secure in the first place, a National Security Letter would have been of no use: the developers would be no more help de-crypting something than anyone else. So in the usual context, a NSL has no point whatever.

      (2) A demand for other records, say about the developers, would also not invalidate the CODE of Truecrypt in any way.

      So that only leaves a couple of possibilities as legitimate reason for a canary: (3) Possible coercion by the government to somehow weaken their crypto.

      (4) Discovery of some prior "backdoor" that had somehow been inserted in the past.

      (5) Maybe some of the developers wanted to remain strictly anonymous and so any overtures made by the government at all created panic.

      Since the people doing the security audit have announced that it will continue, if it turned out to be (4) it will be discovered soon. Which it seems to me leaves only (3) and (5) as any kind of government "threats" that make any sense.

      Any other ideas?

    5. Re:TC developer used hidden message!!! by Shawndeisi · · Score: 5, Insightful

      I would guess that they were NSL'd for their signing keys; that would make it less secure in the future so the correct option is to burn the brand now. Reports said that both signing keys signed the new (crippled/canaried) executable, and that the keys had been re-uploaded with the same content on sourceforge. Their legit URL points to their sourceforge site. Instances of "U.S." in their source code were replaced with "United States".

      It looks to me like they went through a lot of trouble to burn the brand down before any damage could be done with the NSA's new-found signing keys. It's a very, very bad sign that this happened to TrueCrypt. Good on them for being brave enough to inform us, despite the real risks they faced in doing so. If this project is forked, we can only hope the new maintainers are brave enough to do the same when the NSA goes after them. It also raises the question: how much other infrastructure has been compromised while the maintainers have stood silently by?

    6. Re:TC developer used hidden message!!! by Jane+Q.+Public · · Score: 2

      I would guess that they were NSL'd for their signing keys; that would make it less secure in the future so the correct option is to burn the brand now.

      I know that it sometimes doesn't mean much given today's Federal government, but an NSL would not cover this eventuality. A NSL only gives the government authority to grab information without a warrant that would otherwise be grabbable with a warrant.

      Their signing keys do not qualify. There is no law in this country authorizing the seizure of this kind of information. It is a "trade secret", nothing else. The ONLY thing the government could want signing keys for is nefarious purposes.

    7. Re:TC developer used hidden message!!! by Ann+Coulter · · Score: 0

      Here is a diff between 7.1a and 7.2. The most interesting thing is that there are 2073 line additions and 10163 line deletions.

    8. Re:TC developer used hidden message!!! by Shawndeisi · · Score: 2

      I'm sure some contorted logic could qualify; subject X is using software Y, and we need to fool subject X into downloading our software Z... I agree with your initial sentiment though: "sometimes doesn't mean much given today's Federal government".

    9. Re:TC developer used hidden message!!! by fnj · · Score: 2

      Mod up. This is exactly the explanation. There can be no doubt whatsoever. No proof, but no doubt. You can interpret the whole message of the suicide note to be the following, in the form of a veiled suggestion of course:

      "We were NSL'ed and would face the vengeance of the grandaddy of all police states if we said that here, or if we told you in plain language to just keep using 7.1a as acquired cleanly before this thuggery, or henceforward compiled from source which you can convince yourself is a clean copy of 7.1a."

      The proof that 7.1a remains effective is that the NSL was launched.

    10. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      So let's say this is what happened. What would stop them from revoking the old keys and generating new ones?

    11. Re:TC developer used hidden message!!! by timothy · · Score: 1

      Your own line, or a running gag?

      That would be the basis of a funny T-shirt design to sell at security conventions, or for speakers to weave casually into their talks about crypto ;)

      Maybe under a nice image of Washington crossing the Delaware, or a Jefferson Wheel ...

      --
      jrnl: http://tinyurl.com/c2l8yr / foes: http://tinyurl.com/ckjno5
    12. Re:TC developer used hidden message!!! by westlake · · Score: 2

      The most interesting thing is that there are 2073 line additions and 10163 line deletions

      7.2. is a one-way - decryption only - file recovery tool.

    13. Re:TC developer used hidden message!!! by AHuxley · · Score: 2

      The gov gets the server, the staff to step away with a NSL and the ability to become the 'staff'.
      At first you just get the build ability. Then a safe, expected build with the surrounding jargon and skill set is tried.
      If the community did not notice the change to the staff or build or site then a project can be turned.
      The new tame staff are slowly rolled out to the wider community with a full 'crypto' history on the web to be found.
      If the community did not notice then a project can be altered to ensure the user gets full crypto but so do a few govs around the world and their friends have keys.
      Its just building on the classic hardware and software methods the US and UK gov used in the 1940-80's - the NSL is a tool to get in, then the work starts on the project.
      The NSL is just the first outer step. It shows the gov who will turn, who will turn but get a message 'out'. All the NSL might be about is a server, logs and all related access to every part of the project.
      Then the offers start: Work with the gov, walk away but approve all changes/staff, walk away or .....
      The NSL got the results of providing a way in, no outside changes if done right and over time the 'new' staff can shape the project in many different ways.
      From just a honey trap to find/chat up/turn the helpers and experts who are hard to find but would be attracted to some types of projects.
      To give a past, faces on ongoing staff that can be used for decades but need a turned project to build that lifestyle s they start out.
      Later a project may get a classic trap/back door with extra keys for gov decryption or not - the staff go on building great code but provide decade of introductions to a wider community allowing 100% gov run front crypto efforts.
      Why risk a back door in an existing project when in a few years you have a 100% gov crypto front with the blessing and 100% support of an older trusted project? Over time the older project gets more limited. People are attracted to the 'new' 100% gov crypto front project.
      It can all start with a chat over a log under a NSL with results around people or the existing code or the next gen of code or a side project.
      The interesting aspect is the wider public is now talking about the topics.

      --
      Domestic spying is now "Benign Information Gathering"
    14. Re:TC developer used hidden message!!! by AHuxley · · Score: 1

      The "signing keys for is nefarious purposes" usually come with a set of people. The NSL lets the gov sit down and make offers before that middle class, trust fund or wealthy extended family security cleared legal team finds their way to the interview.

      --
      Domestic spying is now "Benign Information Gathering"
    15. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      That is only part of the answer. U T I N S A I M C U S I or Under The Influence, National Security Agency Invasively Monitoring Cagey User's System Information. Either that or Urinary Tract Infection Necessitate Systematic Alleviation, It May Cause Unwanted Secondary Infection.

    16. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      The grandaddy of all police states? Things are bad and getting worse, but there's no need to actually lie about it.

    17. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      Everything is speculation until/if the devs come forward. For all we know the devs worked for the NSA and killed the project because of all the bad press recently. (least they be discovered)

    18. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      JNEAVAT: Hfvat GehrPelcg vf abg frpher nf vg znl pbagnva hasvkrq frphevgl vffhrf

    19. Re:TC developer used hidden message!!! by LordKronos · · Score: 1

      So let's say this is what happened. What would stop them from revoking the old keys and generating new ones?

      So the NSA compelled you to hand over your old keys. Now you've generated new one. Gee, if only the NSA had some way to compel you to hand over those new signing keys, too.

      I seriously can't believe you didn't think that one through

    20. Re:TC developer used hidden message!!! by Jason+Levine · · Score: 4, Interesting

      Let's assume that the government would be breaking the law by NSLing the signing keys. (As opposed to the law being so mucked up that such an action is entirely legal.)

      1) What lawyer is going to be able to fight this battle against the US Government and win? Let me narrow that list down a bit. What lawyer that the TrueCrypt developers would hire would be able to fight this battle against the US Government and win?

      2) Would the TrueCrypt developers even be allowed to see a trial or would they be arrested on "unrelated" charges and sent to prison? Or worse. (There is plenty that a power hungry governmental agency can do to someone that says "no" to them that makes "being arrested on unrelated charges" preferable.)

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    21. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      I'd rather just wear a shirt that said "Fuck NSA" outright. Why would I want to hide my contempt for them?

    22. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      Nope, you're wrong.

      The NSA can hypothetically tell them hand over your signing keys, just like they told lavabit to do whatever they told lavabit to do. More important, it doesn't matter if the NSA isn't explicitly authorized to take signing keys. You have to fight the NSA in secret NSA court, where they can screw with your ability to make your case. All of this is moot if you cannot afford the legal representation required to even attempt to fight an NSL.

      The American developer involved in running truecrypt project had his balls in an NSA vice. That's why truecrypt shutdown the way it did. Because they can disappear into a US prison for merely revealing that they were NSLed.

    23. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      That was my own line. +1 to put that on a T-Shirt or a Slide. ;)

    24. Re:TC developer used hidden message!!! by ultranova · · Score: 1

      If Truecrypt were secure in the first place, a National Security Letter would have been of no use: the developers would be no more help de-crypting something than anyone else. So in the usual context, a NSL has no point whatever.

      TrueCrypt version n is secure. Version n + 1 stores your key in a location known to the NSA.

      --

      Forget magic. Any technology distinguishable from divine power is insufficiently advanced.

    25. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      It's a sad thing that "NSL" can now be used as a verb. It's an even sadder thing that it took me a couple of minutes after reading your post to even realize that.

    26. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      Why they didn't export developement in other countries? It was made with other softwares (I recall Pretty Good Privacy).

      And, you are assuming that developers are from U.S.A. As far as we can tell, they could be polar bears from north pole. :)

    27. Re:TC developer used hidden message!!! by michelcolman · · Score: 1

      I would assume that, if the NSA had a back door in TrueCrypt, it would be in their best interest for people to keep using it. So in that case, they definitely would not want to have it taken down.

      On the other hand, maybe someone discovered the back door, wanted to remove it, was told by the NSA not to, and then decided the project should be scrapped.

      The most likely explanation, though, was that the NSA did not have a back door and therefore sent a letter to have it taken down.

    28. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      My bet is on 3.

      "Using TrueCrypt is NSA" can be interpreted as 3 or 4 but given the difficulty of corrupting source-available software and the recent rise in prominence of truecrypt it is unlikely 7.1 is corrupt. But in a few weeks, if the truecrypt website is up, and also in the 7.2 executable, there could be carefully malicious software from the NSA. I'm guessing their NSL said "Thou shalt release new versions of truecrypt with this sneakypatch straightaway" or something to that effect.

      Unfortunately 5 doesn't hold water since if they weren't under any coercion then they could speak openly.

    29. Re:TC developer used hidden message!!! by ray-auch · · Score: 3, Insightful

      Frankly, useless crypto kits backdoored entire time are.

      FTFY
       

    30. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 1

      I dunno. Maybe the same reason you're posting AC?

    31. Re:TC developer used hidden message!!! by Wootery · · Score: 1

      As if Yoda wasn't cryptic enough already.

    32. Re:TC developer used hidden message!!! by tlhIngan · · Score: 1

      I would guess that they were NSL'd for their signing keys; that would make it less secure in the future so the correct option is to burn the brand now. Reports said that both signing keys signed the new (crippled/canaried) executable, and that the keys had been re-uploaded with the same content on sourceforge. Their legit URL points to their sourceforge site. Instances of "U.S." in their source code were replaced with "United States".

      It looks to me like they went through a lot of trouble to burn the brand down before any damage could be done with the NSA's new-found signing keys. It's a very, very bad sign that this happened to TrueCrypt. Good on them for being brave enough to inform us, despite the real risks they faced in doing so. If this project is forked, we can only hope the new maintainers are brave enough to do the same when the NSA goes after them. It also raises the question: how much other infrastructure has been compromised while the maintainers have stood silently by?

      The problem is, corrupted binaries would be found out really easily.

      First of all, we know you can produce the exact same binaries of TrueCrypt from the source code. The audit proved that.

      With that, if you have a set of binaries, signed or not, you should be able to reproduce that binary with the source code. If you can't, it means the binary you have was not built from the source code you have

      I.e., that binary is not trustworthy - do not use it.

      But if you can repro the binary from source, it means the source and binary match, which means if there is something inside the binary, it would be in the source. Which means all you need to do is diff the source code from the previous version.

      Thus making the whole signing key thing completely pointless and a red herring as you can bet TrueCrypt binaries and source will be cross verified by many people to begin with.

      The only way to get around this is if the compilers are compromised in the classic attack.

      Binaries reproducible via source code is important, it's why the TrueCrypt audit did it as the first thing. Once you have that, it can be re-verified easily and continually, proving the binaries and source correlate. From there, you can diff the sources to verify backdoors.

      And all a user has to do is wait a few days after release when all the people much smarter do their analysis.

    33. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      Good point - but here is my rebuttal:

      (1) Keep doing this over and over. Will they stop after the 20th NSL? Find out and see.

      (2) Do not generate a new key until it is release time. Sign this new release and distribute it, then publicly announce that all future releases will have a brand new key. Each release will have a checksum and PGP signature, but that PGP signature is valid FOR THAT RELEASE ONLY. Any future release signed with the same key should be discarded. Don't explain why (you're under the gag provisions of the NSL after all) but simply make the statement that any future releases will be signed /w a new key that you publish at that time.

      (3) Assign build and release manager duties to somebody outside of the jurisdiction of the United States. They will not be under legal obligation to accept and obey and NSL.

    34. Re:TC developer used hidden message!!! by RockDoctor · · Score: 1

      A NSL only gives the government authority to grab information without a warrant that would otherwise be grabbable with a warrant.

      I see the relevance of that, if NSLs are in the least bit relevant.

      Do you know (e.g., any previous public statement by Truecrypt developer(s) ) that NSLs are in the slightest bit relevant? It's a very common error of logic on Slashdot for most commentators to make the incorrect assumption that everyone in the world is an American Citizen living in America. And who is therefore subject to pressure from an NSL. Which sounds very silly to me, being a non-American, not resident in American and not likely to travel via or to America in the foreseeable future.

      There is a faint rumour that the Truecrypt developer(s) are at least partly based in Eastern Europe. Where the subtlety of the previous security regimes is ... "legendary" is a good word. The arrival of an NSL is more likely to be accompanied by a sympathetic hand written note (or tape recorder with self-igniting tape) saying "The fucking Yankees know who you are. Kill it. Now. Or we'll let them have you, and then your friends."

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
    35. Re:TC developer used hidden message!!! by Anonymous Coward · · Score: 0

      "WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues"

      Half-life 3 confirmed

    36. Re:TC developer used hidden message!!! by LordKronos · · Score: 1

      Wow, again. I can't believe you didn't think this through. Generate a new key to sign each release? You've just totally missed the point of what a signing key is supposed to be for. You might as well just use an MD5 checksum, because that's all the per-release key is good for. What you've proposed is the equivalent of saying "I'm worried someone might forge my signature, so instead I'm going to sign my name differently every time, and then nobody can ever forge it". By changing it every time, nobody can authenticate that a signature was really YOUR signature. When the NSA comes along and says "oh hey, we're the Truecrypt guys, honest, and here's our latest release with our brand new signature", you have no way to know it's really the NSA.

  18. still speculation by tero · · Score: 4, Informative

    According to this page - someone e-mailed a dev contact and claims they called it quits due to lack of interest

    https://www.grc.com/misc/truec...

    (Scroll to the bottom, the green box).

    The only real "confirmation" we have is the info on the TrueCrypt page. It's over (no matter what the reason is), best to move on.

    1. Re:still speculation by MouseTheLuckyDog · · Score: 2, Funny

      Rightr because everything that Steve Gibson does is completely accurate. Right?

    2. Re:still speculation by nurb432 · · Score: 1

      I tend to agree, we will never really know why . Even if someone comes up and clearly says 'hey i was with the team and we did it due to xyz', since the team was anonymous how can you be sure hes with the team, and even he was, if hes telling the truth?

      No matter what the reason, or even if there is a legit reason the game is over and it really doesn't matter why, other than curiosity. The code ( or group ) can no longer be trusted, and who knows how far back this breach goes.

      Time to move on to something else and not look back. And do it *today*..

      --
      ---- Booth was a patriot ----
    3. Re:still speculation by tero · · Score: 1

      It's just his page, read the actual quote I referenced, it's nothing to do with Steve Gibson - he is just quoting two people on twitter.

      Bottom line - we have no evidence of warrant canary or "dev rage quit".

      Also: https://twitter.com/0xabad1dea...

      Personally I'm more inclined to believe the devs calling it than any NSA scheme, but again.

      No. Evidence.

    4. Re:still speculation by AmiMoJo · · Score: 1

      Problem is that there's nothing else for Windows. BitLocker can't be trusted, FreeOTFE is dead too... All we can do is hope that the last good version of TrueCrypt remains secure for a long time yet, or that someone forks it.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    5. Re:still speculation by Anonymous Coward · · Score: 0

      It does matter why. It matters if the USA government is bullying legitimate companies into destroying their own products and forcing them to stay quiet about it.

    6. Re:still speculation by Ken_g6 · · Score: 1

      Actually it could be both. TFA doesn't say "warrant canary"; it says "duress canary". Duress could be anything from NSA to Russian Mob to simply getting sick of working on the project.

      Furthermore, if the "duress canary" was set up right, inaction would cause it to appear. So it would be the default result of a "rage quit". And maybe they were too sick of the project to bother with anything better.

      --
      (T>t && O(n)--) == sqrt(666)
    7. Re:still speculation by tero · · Score: 5, Interesting

      Two guys - working working over a decade without funding etc.

      Ennead was 29 in 2005 (http://www.wolfmanzbytes.com/windows/70-truecrypt-encryption.html) and they obviously developed it on their freetime.

      Fast forward from that to today and you got couple of middle-aged devs, probably with more demading careers and perhaps even families and maybe with young kids.

      They started it as a Windows project, when Windows was...a completely different beast than it is today.

      It's no wonder TrueCrypt didn't get very many (any?) releases in the past couple of years.

      It's certainly a very interesting way to exit stage.

    8. Re:still speculation by Anonymous Coward · · Score: 0

      As I suspected as well.

      The devs used a very old library for compiling due to many reasons, and they can no longer support it.
      Could they do it another way? Almost certainly, but it would be considerably harder for them and they likely already don't have much time to work on it otherwise it wouldn't be dead. (unless it was those damned spies)

      The source is already out there, but they already caution people not to use it because they will try to compile it on things that are very likely not secure, with things that are very likely not secure (the reason they were using old things to develop it on in the first place)
      So that is most likely the reason they straight up said that it isn't secure and to use other stuff.
      The Bitlocker thing is a little odd though.

    9. Re:still speculation by Anonymous Coward · · Score: 0

      You need to do a little more research...

      https://diskcryptor.net/

    10. Re:still speculation by BitZtream · · Score: 2, Interesting

      Reality check: TrueCrypt for Windows could never be trusted, even if you aren't knowledgeable enough to understand that.

      TrueCrypt was a nothing more than a block device driver for Windows, it was a kernel module. Any other kernel module or the kernel itself could hook into the chain between TrueCrypt and the rest of the system and read the clear text data.

      Because of the reality of working with Windows, TrueCrypt is no more trustworthy than BitLocker on Windows. They don't need to back door the BitLocker system itself, they can just bypass it OR TrueCrypt.

      --
      Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
    11. Re:still speculation by Anonymous Coward · · Score: 0

      TrueCrypt was a nothing more than a block device driver for Windows, it was a kernel module. Any other kernel module or the kernel itself could hook into the chain between TrueCrypt and the rest of the system and read the clear text data.

      That requires that the key has been entered after the system has been compromised. I don't think there even is a theoretical system that can protect against that.
      The argument is pretty much that Windows is compromised at installation.

    12. Re:still speculation by AmiMoJo · · Score: 5, Insightful

      TrueCrypt never claimed to protect you from a compromised system. The point of it was offline security. Once unmounted the contents of an encrypted container are inaccessible to anyone without the key.

      Once you understand what TrueCrypt is for you can see why it is so valuable.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  19. Re:Nonsence by PPH · · Score: 1

    Back door != Keys

    The TC devs hold no keys, but could conceivably build a back door into future versions. Or perhaps there already is one, or a weakness overlooked. Its also possible that the NSA has known about the TC devs for some time, has possibly been leaning on one or more of them and this has only recently become evident to the entire team.

    --
    Have gnu, will travel.
  20. The project needs to be given away... by Karmashock · · Score: 1

    Literally give the source code and rights to continue development to anyone and everyone.

    A new project will pick it up and continue development without breaking the law. And at that point its unlikely the NSA will be able to do anything to it.

    --
    I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
    1. Re:The project needs to be given away... by Karmashock · · Score: 1

      I don't see how it could... and even if it did... just leak it.

      --
      I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
    2. Re:The project needs to be given away... by Anonymous Coward · · Score: 0

      Maybe someone's computer should get "hacked" and source stolen and distributed on the net.

    3. Re:The project needs to be given away... by Anonymous Coward · · Score: 0

      All the TC source code has been freely available for years. So there's no need to "leak it".

      Look up "tc-play" for the most popular (so far) rebuild of it.

    4. Re:The project needs to be given away... by Anonymous Coward · · Score: 0

      You can download the source - no need to leak it.

    5. Re:The project needs to be given away... by Jane+Q.+Public · · Score: 1

      Literally give the source code and rights to continue development to anyone and everyone.

      It's already underway. The auditors said they plan to fork the Truecrypt codebase if it passes the audit. Possibly even it if doesn't but any issues are fixable.

  21. I Voted This Submission Down by NotSanguine · · Score: 5, Interesting

    No evidence is presented. The reference to a "canary" is suspect, as it isn't discussed what that canary was.

    Some semi-random tweeter is reposted on some random blog? I don't think so.

    It's possible that this is accurate, but without evidence, why bother? As I asked in the original discussion about the shuttering of TrueCrypt, who stands to benefit?

    --
    No, no, you're not thinking; you're just being logical. --Niels Bohr
    1. Re:I Voted This Submission Down by Anonymous Coward · · Score: 0

      The reference to a "canary" is suspect, as it isn't discussed what that canary was.

      The canary is the fact that the "explanation" of the EOL of XP is inconsistent with the stated goals and roadmap for the product as of recently.

      If they'd wanted people to believe they'd gotten tired of the product, they'd have said "We're tired of working on this, we've changed our licensing terms, and releasing the code to everyone for future development."

      If you can't say why you're taking the product down, you have two alternatives: either say nothing, fueling suspicion, or lie so poorly that everyone's suspicions are raised even higher.

      The government can compel you to neither confirm nor deny any secret orders from any secret courts. (This also ought to be intolerable in a free society, but we're well past that tipping point.) What it cannot do is require that you be a sufficiently good liar that anyone believes your explanation. They can't charge you for not mentioning the secret court's secret letter because to do so would expose said letter's existence, which is precisely what the government wants hidden in the first place. Warrant canaries are a legal catch-22 of the government's own making.

    2. Re:I Voted This Submission Down by NotSanguine · · Score: 3, Insightful

      The reference to a "canary" is suspect, as it isn't discussed what that canary was.

      The canary is the fact that the "explanation" of the EOL of XP is inconsistent with the stated goals and roadmap for the product as of recently.

      If they'd wanted people to believe they'd gotten tired of the product, they'd have said "We're tired of working on this, we've changed our licensing terms, and releasing the code to everyone for future development."

      If you can't say why you're taking the product down, you have two alternatives: either say nothing, fueling suspicion, or lie so poorly that everyone's suspicions are raised even higher.

      The government can compel you to neither confirm nor deny any secret orders from any secret courts. (This also ought to be intolerable in a free society, but we're well past that tipping point.) What it cannot do is require that you be a sufficiently good liar that anyone believes your explanation. They can't charge you for not mentioning the secret court's secret letter because to do so would expose said letter's existence, which is precisely what the government wants hidden in the first place. Warrant canaries are a legal catch-22 of the government's own making.

      Yes, it's suspicious. Yes, the suggestions make little or no sense to anyone with technical knowledge.

      As I said, the report might be accurate.

      However, extraordinary claims require extraordinary evidence. I see no evidence. At all. It's all supposition and guesswork. Present me with actual evidence, and I can be convinced. Until then, it's all noise and hand waving, IMHO.

      --
      No, no, you're not thinking; you're just being logical. --Niels Bohr
    3. Re:I Voted This Submission Down by Anonymous Coward · · Score: 0

      Don't worry man, you obviously don't need secure volume protection from anyone more hostile than the guy next door.

      This is not an extraordinary claim. It is the most plausible explanation. This is simply someone posting their observation to bring a little light to people with their heads too buried in the sand to realize.

      For the rest of us, an NSL was pretty obvious from the start. And a good reason to toss the last version and move on to something else.

    4. Re:I Voted This Submission Down by NotSanguine · · Score: 2

      Don't worry man, you obviously don't need secure volume protection from anyone more hostile than the guy next door.

      This is not an extraordinary claim. It is the most plausible explanation. This is simply someone posting their observation to bring a little light to people with their heads too buried in the sand to realize.

      For the rest of us, an NSL was pretty obvious from the start. And a good reason to toss the last version and move on to something else.

      My requirements are irrelevant. And, as I've said twice now (I guess reading comprehension isn't required for ACs?), the claim about an NSL or some other sort of government involvement is certainly possible. However, I'm not going to go off half-cocked without actual, verifiable information.

      You'll note that I most certainly did not say "Oh, everything is perfectly fine. Nothing to see here. Go on about your business, citizen.

      Given the product involved and the current environment, some paranoia is certainly justified. And just because some of us (me included) are paranoid, doesn't mean that "they" aren't out to get us.

      All that said, if by some freak occurrence, if you actually read what I wrote, I merely pointed out that the claims made on the site linked to by TFS were unsubstantiated by any real evidence.

      [Rant]Why is it that some people have such a hard time understanding simple English on an English language website? Sheesh![/Rant]

      --
      No, no, you're not thinking; you're just being logical. --Niels Bohr
    5. Re:I Voted This Submission Down by fustakrakich · · Score: 1

      When it comes to authority, the mere suspicion of abuse should be sufficient to start an investigation. People in power must always be treated as suspect in an adversarial manner. In other words, always treat those with power as a hostile witness. History is full of events that justify action against them.

      --
      “He’s not deformed, he’s just drunk!”
    6. Re:I Voted This Submission Down by NotSanguine · · Score: 1

      When it comes to authority, the mere suspicion of abuse should be sufficient to start an investigation. People in power must always be treated as suspect in an adversarial manner. In other words, always treat those with power as a hostile witness. History is full of events that justify action against them.

      An excellent point. I'd love to find out what really happened. I suppose I could write my congressman. That always works. :( :( :(

      --
      No, no, you're not thinking; you're just being logical. --Niels Bohr
    7. Re:I Voted This Submission Down by fustakrakich · · Score: 1

      Getting anything from a congress person requires a subpoena at least. They only get away with this crap because the population is so submissive.

      --
      “He’s not deformed, he’s just drunk!”
    8. Re:I Voted This Submission Down by Anonymous Coward · · Score: 0

      However, extraordinary claims require extraordinary evidence. I see no evidence. At all. It's all supposition and guesswork. Present me with actual evidence, and I can be convinced. Until then, it's all noise and hand waving, IMHO.

      Have you lived in a closet for the last five years? I don't see any extraordinary claims here. What I see is claims that the government is doing business as usual. The opposite would be extraordinary.

    9. Re:I Voted This Submission Down by NotSanguine · · Score: 1

      Getting anything from a congress person requires a subpoena at least. They only get away with this crap because the population is so submissive.

      Do you actually have a suggestion? Or are you just tilting at windmills?

      Perhaps we should buy a US Attorney. I've got a jar full of silver change. A pretty big one too.

      --
      No, no, you're not thinking; you're just being logical. --Niels Bohr
    10. Re:I Voted This Submission Down by fustakrakich · · Score: 1

      Do you actually have a suggestion?

      No, only observation..

      Wait, yes, stop reelecting crooks.

      --
      “He’s not deformed, he’s just drunk!”
    11. Re:I Voted This Submission Down by Prune · · Score: 2

      In fact, Alyssa Rowan (quoted in TFA and a known persona in the crypto community) detailed the canary in the previous ./ article, posting as an AC: http://it.slashdot.org/comment...

      --
      "Politicians and diapers must be changed often, and for the same reason."
    12. Re:I Voted This Submission Down by Prune · · Score: 1

      Sheesh, what's with people offering opinion on /. without having done a modicum of research? The canary was posted already on http://it.slashdot.org/comment... (it's pretty obvious the AC referenced is Alyssa Rowan from TFA, a known persona in the crypto community).

      --
      "Politicians and diapers must be changed often, and for the same reason."
    13. Re:I Voted This Submission Down by NotSanguine · · Score: 2

      In fact, Alyssa Rowan (quoted in TFA and a known persona in the crypto community) detailed the canary in the previous ./ article, posting as an AC: http://it.slashdot.org/comment...

      Mayhap it is, and mayhap it isn't. Either way, TrueCrypt is dead. Anything else, without documentary evidence (and that means independently verifiable evidence, not mysterious tweets and AC posts) is just speculation, IMHO. Feel free to disagree with me, I don't mind.

      --
      No, no, you're not thinking; you're just being logical. --Niels Bohr
    14. Re:I Voted This Submission Down by NotSanguine · · Score: 1

      (it's pretty obvious the AC referenced is Alyssa Rowan from TFA, a known persona in the crypto community).

      Really? And you have documentary evidence supporting this contention? What is your evidence based upon? Did you see this "person" type the message? Did you view /.'s logs and trace back the IP address used by that particular AC and confirm that it is the "persona" (you can't even confirm who "Alyssa Rowan" is, let alone whether or not that was the person who posted that comment as AC.) you think it is.

      You have no documentary evidence. Therefore your assertions are also just opinion. Sigh.

      Okay. I'll say it a fourth time. Maybe it's true and maybe it isn't. We don't know for sure. Anything else is speculation.

      --
      No, no, you're not thinking; you're just being logical. --Niels Bohr
    15. Re:I Voted This Submission Down by Kalriath · · Score: 1

      How is some giant government conspiracy the most plausible explanation? I bet you believe that commercial jetliners spray mind control chemicals when they take off as... fuck it, I'm off to go buy more shares in a tin foil manufacturer.

      --
      For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
    16. Re:I Voted This Submission Down by Bucky24 · · Score: 1

      That can be difficult when we don't get to choose the choices we make.

      --
      All the world's a CPU, and all the men and women merely AI agents
    17. Re:I Voted This Submission Down by fustakrakich · · Score: 1

      Yes, we do. Every person on the ballot was chosen by the voters.

      --
      “He’s not deformed, he’s just drunk!”
  22. Seems the answer is self evident by Anonymous Coward · · Score: 0

    Go with BL. What have you got to lose? Information, yours included, wants to be FREE! Set it FREE!

  23. AC in last thread mentioned a warranty canary by Anonymous Coward · · Score: 5, Informative

    An anonymous coward in the last thread said that a known warrant canary was seen:

    http://it.slashdot.org/comments.pl?sid=5212985&cid=47117051

    1. Re:AC in last thread mentioned a warranty canary by GrumpySteen · · Score: 1

      And you can trust everything an AC says, right?

      BTW, you owe me $500 for that bet you made with me the last time you were blackout drunk. You probably don't remember it, but you can trust me. I would never make shit up.

    2. Re:AC in last thread mentioned a warranty canary by CmdrTamale · · Score: 1

      A canary that is *widely* known is kind of dangerous to know, if you know what we mean.

      There is No Simple Alternative.
      --
      I didn't really want to moderate anyway.

    3. Re:AC in last thread mentioned a warranty canary by Anonymous Coward · · Score: 0

      I didn't make any claims regarding the veracity of the AC's statement, but I'm sure that won't stop you from finding something to argue about, retard.

  24. Re:The FBI is mostly entirely comprised of Mormons by wordsnyc · · Score: 1

    Yeah, absurdly non-true today. OTOH, Hoover did prefer Mormons in his inner circle, and the FBI agents I had occasion to meet in the 60s & 70s definitely came across as uptight and straitlaced Mormon types. Fun Fact: in the 60s, FBI agents helpfully drove AMC/Rambler sedans as undercover cars and used sturdy but crappy Beseler Topcon 35 mm cameras.

    --
    Sent from the iPad I found in your car.
  25. Speculation by Anonymous Coward · · Score: 3, Insightful

    This is Slashdot. No one cares whether something is true or not as long as it is negative towards the government. Sad really, since it diminishes any sort of real discussion about actual concerns about the government rather than made up fantasy.

  26. It has to be true! by MouseTheLuckyDog · · Score: 1

    Not only is this mercurial and virtually unknown Alyssa Rowan spotted a canaryu, but so has PeeWee Herman! He just tweeted.

    1. Re:It has to be true! by Anonymous Coward · · Score: 0

      Courtney Love confirms.

  27. Doesn't add up by Anonymous Coward · · Score: 0

    Truecrypt.sourceforge.net doesn't host confidential data. Therefore receipt of a letter from the government seems not only irrelevant but implausible. On the other hand, if the site or source were hacked, that would be cause for posting an explicit notice--with no need for a canary system.

  28. The project needs to be given away... by Anonymous Coward · · Score: 0

    Maybe the NS Letter already prohibits what you envision.

  29. If It Is Private, Keep It Private by DERoss · · Score: 2, Insightful

    I never use cloud resources. Too many users have been severely inconvenienced if not outright burned by cloud services that have been hacked, suppressed by some government, gone out of business, or gone down for several hours. I keep all my data where I can access it, either on my PC or on a removable hard drive that I store remotely from my PC but easily reached.

    I encrypt my most sensitive data. No, I do not rely on some corporation's declaration: "Trust us. We are good. We will protect you." Instead, I use an OpenPGP application that has been reviewed by outside experts and that I have installed on my PC. The data on my removable hard drive are encrypted. Some of my PC files are also encrypted. My pass-phrase, without which my private key is useless for decryption, exists only in my head and in an envelope in my safe deposit box at a bank. My private key is on my PC in a non-standard location. If somehow someone else were to access my private key, I have a much greater problem than the compromise of my sensitive data.

    See my http://www.rossde.com/PGP

    1. Re:If It Is Private, Keep It Private by Anonymous Coward · · Score: 0

      Therapy would be a hell of a lot less complicated.

    2. Re:If It Is Private, Keep It Private by Anonymous Coward · · Score: 0

      > burned by cloud services

      This! Last week I had a Debian upgrade fail on my vm at DreamHost. When I contacted support, they erased all of my files. I guess that's the punishment I get for expecting to be able to login to my own damn server. I should have been suspicious when adding new users to the vm took over two weeks. They aren't competent enough to automate even simple tasks like adding users.

    3. Re:If It Is Private, Keep It Private by Anonymous Coward · · Score: 0

      You can trust banks to keep it safe for you.

    4. Re:If It Is Private, Keep It Private by SuperTechnoNerd · · Score: 2
      Interesting:

      envelope in my safe deposit box at a bank

      That the government can legally get a search warrant for.
      However the one your head it's protected by the 5th amendment.

      Think about it.

    5. Re:If It Is Private, Keep It Private by Anonymous Coward · · Score: 0

      You know nothing about mother rape. Most of the apartments I've lived in the past twenty-five years have been biased against open source. You open source morons want rape over honest confrontation. That is your way. You racists are Republicans. Fuck you. I got arrested Sunday night for supporting your kind. The Seattle PD is smart enough to understand that my kind represents rape. That is our way. Fuck you for pointing that out.

    6. Re:If It Is Private, Keep It Private by DERoss · · Score: 0

      I have accounts at four different financial institutions. To serve a search warrant, they would have to know which branch of which institution houses the particular safe deposit box containing the "magic" envelope. If such a search warrant were successfully served, they would still have to find my external hard drive or serve another search warrant on my house to access my files. Since none of my files contain evidence of a crime, such warrants could easily be challenged.

      As for keeping my master pass-phrase in my head, the 5th Amendment protects me in the U.S. I understand that in the U.K., however, failure to give the police your master OpenPGP pass-phrase can result in a lengthy prison term.

    7. Re:If It Is Private, Keep It Private by Anonymous Coward · · Score: 0

      Yes, I admit that, but I also want my VPSs to run. DreamHost has broken our contract by investigating how we treat our mothers. Mine was a whore so DreamHost punishes my and mine kind. Those morons believe in genetics while no liberal does. I am a free man according to the Democrats while my crimes against my own kind indict me as far as Republicans are concerned. They and thier kind hates freedom. Just because I raped a girl doesn't make me a bad person.

    8. Re:If It Is Private, Keep It Private by epyT-R · · Score: 1

      So would less ad hominem and more critical thinking. If people of your sort hadn't elected the past two administrations into power, we wouldn't have this problem in the first place.

    9. Re:If It Is Private, Keep It Private by dave420 · · Score: 1

      That was not an ad-hominem, as it was pertinent to the discussion. If he'd said he was wrong because his trousers were green, you'd have a point. I'm not entirely surprised a racist misogynist like yourself has difficulty using these concepts accurately, as you clearly prefer to operate outside of logic, in order to preserve your twisted world-view.

  30. Ars Scholae Palatinae by westlake · · Score: 5, Informative
    There is nothing I think worth adding to "Marlor's" post to Ars:

    I can't comprehend the conspiracy theories flying around about this.

    [TrueCyrpt] is a barely-maintained Open Source project (no updates in the past two years), with an outdated, messy code-base, serious build dependency problems, and lacking in full support for the newest Windows release. It likely only has a small development team - perhaps only one or two people.

    The developers are absurdly secretive, and when they do come out of hiding to make a statement, they are confrontational (take, for example, their response to Fedora's queries over the clause in their license that reserves the right to sue for copyright infringement).

    If this was any other project, we'd all just assume the developers had decided to call it a day. However, because of the nature of the software, everyone assumes security agencies or reptilians are involved.

    Maybe the developer was a security researcher who has decided to retire to a tropical island. Or maybe there were two developers, and they have had a dispute. Maybe the primary developer took a job offer at a security firm, with a clause prohibiting him from working on external projects. There are an almost infinite range of possibilities... assuming that the cause was the devious acts of state-sponsored actors is leaping to a pretty big conclusion.

    If I developed a piece of security software, and wanted to cease development, I'd make a similar statement.

    "Don't use this anymore. It's not maintained, and should therefore be considered insecure".

    Otherwise, if a vulnerability is discovered, everyone will scream: "Fix it now! Nobody told us to stop using it!"

    ''TrueCrypt is not secure,'' official SourceForge page abruptly warns

    [Ars stats for Marlor: 1279 posts > registered Oct 3, 2003 > 0.01% of all posts > 0.33 posts per day]

    1. Re:Ars Scholae Palatinae by Anonymous Coward · · Score: 0

      "Ars Scholae Palatinae".. What, you think mentioning some pretentious faux-latin forum tag is going to make us take your post seriously? Get lost. Or as we say in latin, "gettus lostus".

    2. Re:Ars Scholae Palatinae by duke_cheetah2003 · · Score: 2

      This all makes sense to me, until you add in a few strange parts:

      1) Why did they nuke all previous versions of the software? The disclaimer is there. There's was no need to nuke the old versions.
      2) Why neuter v7.2 so it can't encrypt? Heck, why even release a neutered version? The disclaimer is there. If I was ending my work on a project, I wouldn't end it on 'here's a broken version, and I erased all the good versions.'
      2) Why the unprofessional webpage, with screen shots? Screen shots take time to get, so if they spent time on this, why not spent a few extra minutes to make the page look nice as well?
      3) Why nuke the TC forum on SourceForge? That makes ZERO sense.. I can't even begin to guess why ANYONE wanted the forum obliterated.

      I personally don't know what to make of TrueCrypt's state... There's a lot of conflicting information and it's proving very hard to decide which parts are true and which are fabrications or speculations.

      FWIW, I'm inclined to buy into the devs threw in the towel because they're just sick of dealing with it. But even that isn't a sure thing in my mind, it's just highest probability. Sick of it explains the abruptness of the site's change, as well. Doesn't really explain the other anomalies though.

      But a close second is they the devs were some how coerced into removing their product from public availability. I'm not sure to what end, because obviously there's mirrors of the software, and already lots of talk about forking or developing something to do the same thing. TrueCrypt is currently the ONLY cross platform encryption solution that works so delightfully transparently on entire devices, or on file containers. TrueCrypt is also still the only crypto package with the built in 'plausible deniability' feature of hidden volumes. Yeah I know it's been shown to be fairly easy to prove the existence of a hidden volume, but you have to know to look and how to look. These features do make it uniquely positioned in the crypto software sphere.

    3. Re:Ars Scholae Palatinae by epyT-R · · Score: 1

      Considering the current political and social climate is ruled by politicians that clueless fucktards like this 'marlor' voted for, it's best practice to assume an NSL compromise.

    4. Re:Ars Scholae Palatinae by Anonymous Coward · · Score: 0

      What's so funny about "Gettus Lostus?"

  31. TC developer used hidden message!!! by Anonymous Coward · · Score: 5, Funny

    Haha. Frankly, usable crypto kits need security audits.

  32. COUNTERMEASURE by Anonymous Coward · · Score: 1

    Take

    1.) small Atmel/ATMega CPU
    2.) LCD display
    3.) a small keyboard (26 keys suffice) suitable for said CPU
    4.) three 1.2V rechargeable batteries
    5.) symmetric Cipher of your choice that fits into 4K of RAM. E.g. 3DES, GOST,...

    Then implement
    A) ENIGMA/SIGABA-style cipher machine on said hardware using said ciphers
    B) Publish pcbs and source code via strongly anon means, sign using gpg if needed.

    This machine can be used via ANY crap comms channel from NSAbook to NSAdroid phones. Or POTS, CB radio, shortwave links. Machine should in later releases not be bigger than a cigarette box. Carry it everywhere.

    1. Re:COUNTERMEASURE by Anonymous Coward · · Score: 0

      Will you take the responsibility for all the hard work required to create that?

    2. Re:COUNTERMEASURE by plover · · Score: 1

      The Mooltipass http://hackaday.io/project/86-... meets almost all of your requirements. You'll have to supply your own code mods.

      --
      John
  33. Truecrypt guys actually can receive NSA letters? by Anonymous Coward · · Score: 0

    I thought that you need to be a USA citizen with a business. And IIRC the truecrypt guys are very secretive about their identities, so much that in the past people have speculated about who they actually are (kind of like with satoshi from bitcoin). Isn't it jumping too far from "random unknown people on the internet" to "USA citizens known by the NSA?" just to justify the recent website changes?

  34. Any *good* recommendations? by Anonymous Coward · · Score: 1

    DiskCryptor seems fine, but doesn't seem like it supports mounting a virtual hard disk (correct me if I'm wrong); only actual full disk encryption.

    1. Re:Any *good* recommendations? by Hypotensive · · Score: 1

      Since with loopback you can make any file into a virtual block device, there's no reason you can't use LUKS/cryptsetup with files.

    2. Re:Any *good* recommendations? by Anonymous Coward · · Score: 0

      Just install Windows and use BitLocker. It's the easy-to-use, robust, professional and properly maintained solution, instead of these open source hobbyist toys.

      Yeah, thanks for repeating the NSA 'party line' but we've heard it already.

  35. Re:Truecrypt guys actually can receive NSA letters by Anonymous Coward · · Score: 0

    There's no real anonymity on the internet. If they operate their own website for downloads, then the authorities just go after their host and registrar to find out who they are. If they instead use something like GitHub, they just go after GitHub.

    Who knows. Maybe the leader of the project, whoever he or she may be, was from the US, and that's why an NSL was able to shut them down.

  36. More speculation by Lost+Race · · Score: 3, Interesting

    There's nothing in TFA that hasn't been speculated in great detail already.

    No explanation totally makes sense. Here's my working model of what happened (all speculation of course):

    The project has been gradually disintegrating over the last few years -- developers leaving and not being replaced, remaining developers having less time to spend on the project for whatever reason, and the perceived reward for fixing increasingly difficult bugs is not enough to keep people interested. It's just not fun any more.

    The to-do list has some really nasty bugs that are difficult to fix and could potentially compromise all TC containers. The remaining developers in the project have been grinding away at these bugs, but haven't made much progress for reasons outlined above. They realized that the project was going to fizzle out before they got anything fixed. A cursory look at the 7.2 code suggests that they had committed to some major rewriting of the code, and bit off more than they could chew.

    At this point, what can they do? Reporting the vulnerabilities would be irresponsible since no fixes are forthcoming. Lives depend on some of the secrets their software keeps. Best to push people gently away from TC until the problems can be fixed, if ever, while keeping the details of the vulnerabilities as secret as possible, and giving people realistic expectations about the future of TC development (i.e. none).

    They probably had a plan for creating a migration plan that actually made sense, but ran out of resources before finishing, and decided to go with what they had on hand. At this point they were probably down to one very part-time developer and maybe a few unreliable volunteers. ("Hey Jim, where's that page you were writing about Linux FDE? Jim? Hello? Anybody there?")

    There was really no good way forward with the resources remaining, so they did the best they could.

    Why didn't they find someone else to take over the project? I guess they tried, but couldn't find anyone in their immediate circle of trust who was willing and able. Perhaps they felt that expanding their circle of trust would jeopardize their anonymity.

    On the other hand....

    "WARNING: Using TrueCrypt is *not *secure *as ..."

    1. Re:More speculation by Anonymous Coward · · Score: 0

      -Why did they pull down the site then?
      -They could have GPL'd (or any other license, really) their software, no one understands their license, so no one can really take it over or fork it without being in danger of being sued
      -They could have communicated it in some way. "Hey, we don't have time for this anymore, future bugs will not be fixed, get other software ASAP, here's how you migrate to BitLocker.", that would have been easier for everyone and not this mess we have now.

    2. Re:More speculation by Anonymous Coward · · Score: 1

      Eh.. if what you said is true, why don't they just say they will shut it down due to lack of interest and state that people should just find alternatives because of the bugs, etc., etc. Its not like they have a reputation to uphold given they're anonymous. Whats the point of an ambiguous warning without much explanation, if they care enough like you suggested, they should care enough to give a good and simple explanation.

      Btw, are you a govie shill? Just checking.

    3. Re:More speculation by Anonymous Coward · · Score: 0

      BTW, are you an arrogant asshole? Just checking, seeing has how anyone with the temerity to have an opposing view from yours must make them a "govie shill."

  37. Re:Nonsence by Anonymous Coward · · Score: 0

    Not likely. The NSA has tried and failed to break into truecrypt volumes in the past. Now, whether or not they were giving it their all is up for speculation, but that was after the 7.1 version was released. So, it's unlikely that there was a backdoor or other weakness at that point.

    7.2 is a different matter, that's a much more recent version and it's probably technically possible that it's been compromised.

  38. Continued development by ArchieBunker · · Score: 1

    If the last current build is secure why should we need continued development? The tool is out there and it works. I don't see that as a problem.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
    1. Re:Continued development by fnj · · Score: 1

      In the long run at a minimum there needs to be security patch maintenance. Buffer overflow discoveries, etc.

    2. Re:Continued development by myowntrueself · · Score: 1

      If the last current build is secure why should we need continued development? The tool is out there and it works. I don't see that as a problem.

      Possibly some service pack for windows will make truecrypt stop working on that platform. This could easily be engineered and 'requested' in an NSL to MS.

      For Linux, less likely but perhaps some changes to the kernel could do it, less likely to be from an NSL though.

      --
      In the free world the media isn't government run; the government is media run.
  39. Where is the Kickstarter to re-implement it? by swb · · Score: 3, Interesting

    I'm surprised there hasn't been a Kickstarter setup to re-implement TrueCrypt from the ground up.

    What would be the dollar cost to hire a team of developers to do it?

    1. Re:Where is the Kickstarter to re-implement it? by fnj · · Score: 1

      How do you propose that donations work when the thugs come down on Visa, Mastercard and PayPal to stop payments?

      I'm actually serious. This is a matter that does need to be dealt with in general.

    2. Re:Where is the Kickstarter to re-implement it? by swb · · Score: 4, Interesting

      I think it would be great for the EFF and the ACLU to sponsor it. It would immediately cause problems for someone to get ham-handed about it.

    3. Re:Where is the Kickstarter to re-implement it? by ufoman · · Score: 0

      Bitcoin?

      --
      The following statement is false.
      The previous statement is true.
      Welcome to my world.
    4. Re:Where is the Kickstarter to re-implement it? by epyT-R · · Score: 1

      Yes. It would be started by the NSA and use a few bought developers as a honey pot to draw 'open participation.' Who would know?

    5. Re:Where is the Kickstarter to re-implement it? by westlake · · Score: 2

      I'm surprised there hasn't been a Kickstarter setup to re-implement TrueCrypt from the ground up. What would be the dollar cost to hire a team of developers to do it?

      We know the cost of the audit:

      Since September 2013, a handful of cryptographers have been discussing new problems and alternatives to the popular security application. By February 2014, the Open Crypto Audit Project---a new organization based in North Carolina that seeks formal 501(c)3 non-profit status---raised around $80,000 toward this goal on various online fundraising sites.

      TrueCrypt audit finds ''no evidence of backdoorsâ or malicious code.''

      It's reasonable to assume that any attempt to resurrect TrueCrypt would fail without an independent audit on the same scale.

      We don't know the size of the TrueCrypt team or the man-hours invested in its development, but we do know it took ten calendar years to take TrueCrypt to version 7.1,

    6. Re:Where is the Kickstarter to re-implement it? by Charliemopps · · Score: 1

      I'm surprised there hasn't been a Kickstarter setup to re-implement TrueCrypt from the ground up.

      What would be the dollar cost to hire a team of developers to do it?

      Hundreds of thousands at least. This stuff doesn't seem expensive until you actually get started. I once had a very small project that did nothing more than produce a single line of (rather clever) SQL code. It only took the developer 10min to write but all the testing, meetings, etc... involved made the project hit $25k pretty quickly.

    7. Re:Where is the Kickstarter to re-implement it? by Anonymous Coward · · Score: 0

      improved TrueCrypt version, Veracrypt : http://www.idrix.fr/Root/content/category/7/32/46/
      not sure how much of the code the cleaned up tho....

  40. Hello by Anonymous Coward · · Score: 0

    Let me tank you a lot
    http://playgame02.blogspot.com

  41. It was a government takeover by jigawatt · · Score: 0

    The new site was clearly designed by the Obamacare people.

  42. Re:Nonsence by TechyImmigrant · · Score: 2

    The signing keys you dolt.

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
  43. So... by ledow · · Score: 1

    Ignoring the rumour-based article with zero facts:

    What we really need then is a distributed, peer-to-peer, anonymised source-control system.

    Publish a hash and that hash corresponds to a certain "official" branch of the code and can't be retracted. Do it right and any fork can publish their hash and maintain their own branch even if the original project goes under. Source-code verification - that's no harder than today, but you could set up code verification of, say, the most popular hash the same way you do TrueCrypt audits.

    However, before that, we really need a bunch of people to be pushing out patches to TC and be shown to still be developing it, anonymous or not. I don't particularly care about TC being taken down - to me that just proves it's usefulness and effectiveness, if that's true. What I care about is, whether the project died or was taken down, we need people to develop on it - and at least start adding UEFI etc. support.

    1. Re: So... by Anonymous Coward · · Score: 0

      Something like git?

    2. Re: So... by Anonymous Coward · · Score: 0

      git is neither peer-to-peer nor anonymized.

      While every clone of a git repository is equal and can be used to serve it to others over the Web, you still need someone known to you to run a server so you can clone your own copy.

      I don't think that's what GP meant.

      It would be more like Freenet - network of nodes serving as distributed storage of blocks identified by hashes and relayed from node to node as needed.

      You could probably build something like that as a Freenode plugin, actually.

  44. Maybe the developers took a paying job... by bhlowe · · Score: 1

    Or the devs were encouraged to take a paid vacation from coding... Courtesy of the NSA or Microsoft. My guess the link to www.truecrypt.org/donations/ was not often visited.

  45. Re:The explanation. by Anonymous Coward · · Score: 0

    Or, it could be a NSA front, pretending to be a legitimate crypto developer, pretending to be a NSA front.

    ... pretending to be the People's Front of Judea?

  46. Sad by beefoot · · Score: 2

    It is a sad truth. NSA / USA government will only drive innovation underground or out of the country.

    1. Re:Sad by Anonymous Coward · · Score: 0

      Out of the country where? Every country has their own equivalent of the NSA.

    2. Re:Sad by Anonymous Coward · · Score: 0

      For certain definitions of "equivalent".

  47. Steve Gibson by Anonymous Coward · · Score: 4, Insightful

    Because nobody on Slashdot would intentionally visit a link to grc.com. If you want us to visit the land of raw sockets and falling skies, you're going to have to mask the destination.

    1. Re: Steve Gibson by bill_mcgonigle · · Score: 4, Funny

      If you ever tried listening to one of his podcasts you could make some informed comments. I dare you to go listen to the two recent ones on certificate revocation protocols and not come away better informed. But an informed commenter on Slashdot? My goodness that would be like the bad old days.

      --
      My God, it's Full of Source!
      OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    2. Re: Steve Gibson by MouseTheLuckyDog · · Score: 3, Funny

      Yep. THey are right up thjere with Lucy's podcasts on how to kick a football.

    3. Re:Steve Gibson by Anonymous Coward · · Score: 0

      Mind clarifying your comment a bit. I always found grc interesting, if a bit.... old fashioned in their outlook. But I've never really worked on networking or security, at least at a low level.

    4. Re:Steve Gibson by duke_cheetah2003 · · Score: 4, Interesting

      Steve has made some mistakes in the past and over-hyped some things, but all in the all, the man means well and is genuinely interested in the welfare of computer users. If you write him off just because he's made a few poor judgments in the past, well, that's your loss. He does have generally useful information and it's presented in a non-nerdy fashion so any bonehead can make sense of it. Usually.

    5. Re:Steve Gibson by hubie · · Score: 1

      What is his track record? Whether one chooses to write him off depends upon how often he has cried wolf before, and the details of his mistakes (were they due to fundamental lack of understanding of a technical topic, or something more benign?). It has been many, many years since I've gone to his web site, and I do not doubt that he cares about computer security in general, but (back then, at least) I recall his site being very self-promotional in the sense that he'd warn you of the security issues you (may) have, and sell you a solution. That might be what the parent comment was referring to.

    6. Re:Steve Gibson by cant_get_a_good_nick · · Score: 1

      The raw sockets deal - Windows added raw sockets, or more simply said the ability to manipulate Internet packets at a very low level. Mr Gibson acted as if the entire Internet was about to collapse. In theory it was a bit easier to make fake packets and try to mess with other computers, in practice malware that is embedded in the kernel could already do this, and the bad machines could only mess with poorly configured machines anyway. If you know networking, fake packets don't help TCP that much anyway, mostly fun to mess with UDP. There is a lot of damage you can do without raw sockets.

      The knock against Steve on this wasn't so much the initial panic about raw sockets, but that he stuck to his guns once people explained how this wasn't a big deal. Either he Just Didn't Get It, or he wanted to fearmonger, or both. He sounded a bit chicken little here, and never really seemed to get why he was wrong.

      Winders XP Steve hates 8, fine, we all do. But instead of going to 7, for a long time he wanted to stick with XP. His reasoning, i don't go to any bad websites, i have a firewall, etc. This is shortsighted. Malware advertising on random ad networks is a big deal now, can Steve vet EVERY ad that he sees on the net? Can he vet that every website that he visit has never been pwned and had malware inserted? Can he vet that every machine on his LAN is clean? The worse thing is that he keeps talking about how he runs XP over and over on his podcast. He kind of implies "this is safe for me to do" but never really says "nobody else in their right mind should do this".

      Assembly for a long time he was crazy about assembly, kind of showing how cool he was by using it. I learned assembly/machine code from a book when i was in 7th grade or so. I think it's cool in theory to write some assembly code now. in practice I'd never use it for a real app. Why not? Partially because of time; most libraries and tools are for C or other higher-than-assembly-level languages - you'd need to reinvent a lot of wheels and hope you did them right. And partially for static checking tools which would have a much harder time with assembly checks.

      Mr Gibson's podcast has some good factual info, but his opinions are occasionally off and sometimes even dangerous. It's like the story of the broken watch - a broken watch is right twice a day, but you'd need another watch to tell you when. Steve's right a lot of times, but you need to know enough already to know when he's not right, and when he's not right RUN.

    7. Re:Steve Gibson by duke_cheetah2003 · · Score: 1

      Well, off the top of my head, I know there was the raw sockets in Windows thing. My brain wants to say something about documents and Microsoft embedding something in them, or something like that, the memory of this is a bit foggy. It was a long time ago. It was also rather silly.

      I do find it a little goofy he's still pushing Spinrite so much. It's not that it's a bad piece of software, many a year ago, it was pretty darn useful.. today though, using this thing is probably an epic waste of time with current drive technology.

      That's all I can recall that is questionable about the guy. I think he's published a lot of useful utilities over the years and seems to be interested in spreading useful information. I certainly have no problem with him. I think others bash on him a little too hard over a few mistakes / overhype.

    8. Re:Steve Gibson by MrNiceguy_KS · · Score: 1

      Steve has made some mistakes in the past and over-hyped some things...

      Kind of interesting, since the linked article is basically the exact opposite of over-hype. I think the really relevant point is this:

      TrueCrypt's formal code audit will continue as planned. Then the code will be forked, the product's license restructured, and it will evolve. The name will be changed because the developers wish to preserve the integrity of the name they have built. They won't allow their name to continue without them. But the world will get some future version, that runs on future operating systems, and future mass storage systems.

      If we assume that the TrueCrypt announcement is a NSL warrant canary, then the question is "Why now?" "Why?" is a stupid question - of course the government would like a backdoor into TrueCrypt. But why the NSL now?

      Option A is that, since the TC developers are anonymous, their identities have only recently been discovered by the government agencies that issued the warrant. I'll admit this is possible, but it seems unlikely.

      Option B: Version 7.1a of TrueCrypt has a flaw that is known to government agencies, but has not yet been discovered by the community. The government is worried that the ongoing code audit will discover and remove this flaw, and they issued a NSL requiring that if the flaw is discovered, the updated version include a government-approved backdoor. TC devs made the warrant canary announcement rather than agree to comply.

      Option C: At some point after the release of Version 7.1a, the TrueCrypt devs received a NSL requiring a backdoor in the next released version. TC dev team technically complied by not releasing a new version, since there were no known weaknesses in 7.1a. The code audit has uncovered a flaw and informed dev team, leading dev team to shut down the project and invoke warrant canary.

      It will be interesting to see what happens with the code audit. Hopefully the audit team had the foresight to set up a warrant canary themselves. At any rate, Steve Gibson does have a point - the code is out there, and the audit will continue. TrueCrypt will be forked, and work will continue.

      --
      Redundancy is good And also good.
  48. Re:The explanation. by Gibgezr · · Score: 1

    The Judean People's Front crack suicide squad would like a word with you.

  49. Freedom no longer applies in the USA by Anonymous Coward · · Score: 0

    All interesting developments in these areas are going to move offshore and become decentralized.
    I don't believe that anyone considers the Streisand Effect when the government pushes to end fourth amendment protections.

    I blame a two party system backed by lazy and uninformed people whose information is fed by the five corporations who now run the government.

    RIPUSA

  50. Re:Nonsence by cheater512 · · Score: 1

    Correct, they have no keys.

    However 7.2 doesn't encrypt at all. Does that not qualify?
    If they got a valid legal letter saying they must release a version that can be read by law enforcement then they have complied.

  51. So by Anonymous Coward · · Score: 0

    It has come to this

  52. Old code still available by mysidia · · Score: 4, Informative

    It appears grc has created page where the last final version of TrueCrypt and all source code could be downloaded.

    My hope would be that someone will fork the project and continue development for Linux, and Windows XP/2003, at least, AND preferably work on new Version of Windows.

    Bitlocker is REALLY not good enough, for most users won't have access to it -- since it is only in the ENTERPRISE version of Windows 7; in particular... Windows 7 Standard and Professional do not have the feature.

    1. Re:Old code still available by OhPlz · · Score: 1

      Windows 7 Ultimate has it as well.

    2. Re:Old code still available by mysidia · · Score: 1

      Windows 7 Ultimate has it as well.

      So it does, but at $240 a pop, and unlike Enterprise Ultimate is not restricted to Volume license customers; however, ultimate is 'for enthusiasts' and actually more expensive per unit than Enterprise.

      Most home users either have the $60 Home premium edition, OR perhaps they got Pro bundled with their $500 PC, and the retail upgrade edition is $300..... in other words, cheaper to go buy Ultimate OEM bundled with a $1 piece of hardware.

      The value proposition of 'switch to Bitlocker' is nothing like "Download truecrypt to use for free with your Windows XP system".

    3. Re:Old code still available by petermgreen · · Score: 1

      Bitlocker is REALLY not good enough, for most users won't have access to it -- since it is only in the ENTERPRISE version of Windows 7; in particular... Windows 7 Standard and Professional do not have the feature. .

      It's also in the ultimate edition.

      --
      note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
    4. Re:Old code still available by v1 · · Score: 2

      I don't understand the confidence in bitlocker. If you assume TC got NSL'd, how would MS react in the same situation? Do you honestly believe that MS hasn't already been handed several NSL's over the years? And it's not open source, anything could be in there, including a back door. If you're paranoid about security, a closed-source product run by a big company based in the USA is the last place you'd be looking for a security product.

      I don't think an NSL can (legally) require you to actively DO anything besides turn over property or information. (in addition to the obligitory gag) If MS put a back door in bitlocker, the NSL could demand the keys. I don't think they'd be legally able to either demand such a back door be put in, or be left in though. But then again, this is MS and they'd have good reason to think twice about trying to drag an NSL through the legal mud. An NSL with "it would be nice if you woud..." followed by vague suggestions of consequences could be enough to get more out of them than is legally required.

      This isn't just to bash MS. Mac OS X is no different. Most of it is closed-source, and there's no chance of them releasing the source to their security API. There are already know back doors. if you have a fat wallet and a badge you can buy software to read the entire contents of an unlocked keychain on a mac, without knowing the user's password. Same for getting around a password-locked or disabled iphone. This is just the stuff we know about. You have to assume there's more with any company that has to comply with the insane national security laws of late.

      What it ALL boils down to is that you simply cannot trust any company (or group, or individual) that operates in the jurristiction of a government that has "secret laws". If I could add one ammendment to our constitution, that'd be it. Three words. No Secret Laws.

      --
      I work for the Department of Redundancy Department.
    5. Re:Old code still available by Anonymous Coward · · Score: 0

      Well, as most people here are pro-piracy anyway, I suggest you download the Digital River image of Windows 7 Ultimate and crack it with the Daz loader.

    6. Re:Old code still available by dave420 · · Score: 2

      Don't assume just because something is open source that it doesn't have backdoors. That is terrible logic.

    7. Re:Old code still available by ray-auch · · Score: 1

      It's in Pro edition as of Windows 8.

    8. Re:Old code still available by Anonymous Coward · · Score: 0

      I don't understand the confidence in bitlocker.

      By using Windows one is trusting Microsoft with their data anyway.

    9. Re:Old code still available by v1 · · Score: 1

      Don't assume just because something is open source that it doesn't have backdoors. That is terrible logic.

      I never spoke in such absolutes. It's been shown with great regularity however that open source products have far fewer security holes in them. The common phrase used is "many eyes make for shallow bugs". This is of course NOT always the case. The recent heartbleed bug is a good example of how a bug can remain hiding in plain sight for a long time. In instances like that, it's not a case of the code not getting audited, it's a case of the code being so old that it's expected to be bug-free simply due to the number of years it's been auditable.

      But I'll take open-source security over closed-source any day. Back doors are very hard to disguise in open source. The best you can do is what the NSA did recently with getting those weak crypto methods put into a standard. And look how fast that got noticed. Or put in an exploitable bug (like heartbleed) that wasn't obvious, that didn't necessarily just give access away, but that made breaking it much easier to do. The real beauty of heartbleed is that attacks didn't get logged. Someone could beat on your server for weeks if necessary to get lucky and fish out something useful, and all the while nothing would show up on the logs. And if you found youd been hacked, you'd have nothing useful (from the initial compromise anyway) to help you.

      --
      I work for the Department of Redundancy Department.
  53. Letter headed "imagined conversation." by Anonymous Coward · · Score: 0

    As the page clearly states, this is not a genuine letter. It is a work of fiction, presented as such by its author, Steve Gibson.

  54. Re:Nonsence by gweihir · · Score: 1

    Dead wrong. They hold the release signing keys.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  55. bad headline, not "explained" by Anonymous Coward · · Score: 0

    This is a hypothesis, not an explanation. Nowhere near an explanation.

    Geez.

    And this is why I read slashdot only once every few months now....

  56. Warning by Anonymous Coward · · Score: 0

    I think people should put a picture of a caged canary on their website's homepage. If they get an NSA letter, change it to a dead canary.

  57. The Truth by Anonymous Coward · · Score: 0

    The truth is the developers of TrueCrypt all got high-paying jobs at Microsoft, where they get to work on bitlocker instead.

  58. Their code, their rules by jphamlore · · Score: 1

    For those complaining that the TrueCrypt developers did not release the code under some other license such as the GPL: Their code, their rules. Given that some want to fork the code, obviously there is some expertise that was poured into the code that is not easily replicable. If they don't want to give away their expertise for free, it's their right.

  59. Billion dollar NSA FUD was against Truecrypt by Anonymous Coward · · Score: 0

    We all know that if, as an individual, you are targeted by the filth that runs the USA, UK etc, nothing will protect you against their surveillance methods. They will break into your home, and modify your computers directly, if you are a high enough value target. Cameras, key-loggers, EMF sniffers etc will eliminate the usefulness of ANY encryption method.

    We are NOT talking about these scenarios in this case. We ARE talking about FULL SURVEILLANCE NSA/GCHQ projects that seek to slurp up every piece of electronic information about every Human on the planet. And such obscene goals need very clear black propaganda psy-ops to increase their effectiveness.

    Witness the FUD one sees constantly on sites like Slashdot encouraging people NOT to properly erase their files (by promoting fairytales of 'magic' methods used by forensic scientists to surface scan magnetic media). Truecrypt has been in the cross-hairs of the NSA and GCHQ for years.

    One consequence of Snowden's revelations has been a massive reduction in the confidence ordinary people have in the so-called security products from major American tech companies. Microsoft, Oracle, Google, Apple and IBM fight amongst themselves to be the most useful to the NSA, and place back-doors in every one of their products. Truecrypt, which has NEVER been know to have been broken by any security agency, is an extraordinary thorn in the side of the NSA.

    While sites like Slashdot attempt to confuse the sheeple about the reliability of Truecrypt, informed people know that Truecrypt simply implements known SECURE encryption algorithms, and allows these mathematically validated algorithms to be conveniently applied to user data, creating blocks of encoded data indistinguishable from random noise. A simple driver model allows the file system of Windows to 'see' into the encrypted block when a correct password is provided, but no encrypted version of the password is stored, so reverse table attacks (the common method of 'breaking' password protected encryption) are not useful.

    Truecrypt is as trustworthy as it gets, because Truecrypt does almost nothing. And again, we are talking about useful against FULL SURVEILLANCE attacks, not useful against NSA programs against individuals, when all kinds of methods can be used to gain the password, or access to the data before encryption or after decryption.

    The NSA doesn't expect to prevent tech-savvy people from removing themselves from the full-surveillance grid. That is an impossible goal. They want to ensure that the 99% never use, or think about using tools like Truecrypt. And then, they want the 99% to automatically demonise anyone from the 1% who does take their privacy seriously.

    In a world where a monster like Bill Gates can deploy inBloom, Common Core and the Kinect2 in the same time frame, and spend billions propagandising for the acceptance of all three (inBloom has now been moved to the covert batch of NSA full surveillance projects, and gathers its data on American children by directly accessing the electronic databases of US schools), we should expect those in power to become every more emboldened, and ever more determined to inflict the worst police state methods against the population.

  60. Re:Nonsence by fnj · · Score: 3, Insightful

    Mod parent up. Grandparent AC is a moron. It's the signing keys, not some nonexistant master decrypt key.

    If the thugs have the signing keys, they could have a couple of months from now themselves brought out a new "improved" (but completely compromised) 7.3 masquerading as an improved, updated, security patched TrueCrypt.

  61. Re:Nonsence by fnj · · Score: 1

    Pssst, the keys they have are the SIGNING keys, not some nonexistant master decrypt key.

  62. Re:Nonsence by The+Snowman · · Score: 1

    7.2 is a different matter, that's a much more recent version and it's probably technically possible that it's been compromised.

    lolwut? Version 7.2 cannot encrypt anymore. I would say that is "compromised" even if the TrueCrypt developers did it themselves.

    --
    24 beers in a case, 24 hours in a day. Coincidence? I think not!
  63. Re:Nonsence by AHuxley · · Score: 1

    Yes the NSL gets them a/the trusted build server and web connections and allows the gov to become the 'project' with their own tame/turned staff over time.
    Over time the next tame builds have the classic trapdoor/key/backdoor. The applications still looks the same, all the sites look the same, no 3rd party can get to your data just one extra entity will have a way in too. The new feature over the life of a project after a NSL is the control of the site, server, code, staff and later an extra US/UK gov key is built in over an expected update cycle.

    --
    Domestic spying is now "Benign Information Gathering"
  64. Ready to join the TEA Party? by Anonymous Coward · · Score: 0

    It cracks me up to know how many people on this site detest the TEA Party, yet then express outrage at the federal government in situations like this. Are you ready to join the cause, or are you still hoping for change?

    1. Re:Ready to join the TEA Party? by Anonymous Coward · · Score: 0

      Really? It cracks you up that people detest a group of wack-job, racist, anti-science, fundamentalist, but they still hate governmental intrusion?

    2. Re:Ready to join the TEA Party? by Anonymous Coward · · Score: 0

      Oh goody, your subscription to the talking points is still active! Hillary is going to need you.

    3. Re:Ready to join the TEA Party? by Anonymous Coward · · Score: 0

      Oh goody, you can't even think for yourself. I subscribe to no one's talking points, not the dems, not the repubs. You, on the other hand, appear to have a nice, tall glass of the kool-aide. I find it insanely funny that you think because I don't buy one into one wacko group's BS, that I must automatically buy into the anther, diametrically opposed, wacko group's BS. You know, you should really start using your own brain, and get out of the group-think.

    4. Re:Ready to join the TEA Party? by Anonymous Coward · · Score: 0

      What koolaid? I think we are taxed too much, and that money is used against us by an endless list of government agencies. I don't see anything nuts about that.

      People who post frequently here tend to be liberal and tend to support the very folks that are in charge of those who are violating our rights. You're not, congrats. Not sure why you replied though, my comment clearly wasn't targeted to the fringe.

    5. Re:Ready to join the TEA Party? by Anonymous Coward · · Score: 0

      And so rather than joining the Libertarian party, you're going to stick with the Republican version of Hope'n'Change? Enjoy your neocon endless war on foreigners, drugs, gays, porn, etc etc etc. A government just big enough to watch you every second and tell you how to live your life.

      There's a reason a lot of us don't like the tea party. It's not because we're Democrats.

  65. Re:Nonsence by cheater512 · · Score: 1

    That is what I meant when I said they had no keys.

  66. Interesting... by Kythe · · Score: 3, Insightful

    ...that everyone seems to assume the Truecrypt developer(s) were in the U.S.

    --

    Kythe
    1. Re:Interesting... by Anonymous Coward · · Score: 0

      That quote "There is no longer interest" from alleged developer "David" is not idiomatic English.

    2. Re:Interesting... by Shatrat · · Score: 1

      If they were in the UK, France, or Israel their local cloak and dagger types would be just as likely to try and sneak something into the binaries. The NSA have plenty of contemporaries.

      --
      09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
  67. Re:Nonsence by TechyImmigrant · · Score: 1

    With FIPS140-2 4.9.2, SP800-90 10.3, Limiting the block size of AES to 128 bits, limiting the rounds of AES to 10, while misdirecting people to think key size was the important thing, along with effectively blocking progress on DNS security, IP security and other security tracks, the NSA has shown itself able to limit security and put backdoors out there which persist in the wild for many years before discovery.

    We should not think they couldn't slip a back door into Truecrypt without being caught. It just requires some crypto knowledge they have which we don't and they employ more cryptographers than the private sector and universities do.

    The recent string of results against DLP in prime power fields is an example of knowledge they may well have known before we did. what else is there that they are leaving the public at risk by keeping it a secret?

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
  68. NSA doesn't do NSLs by Anonymous Coward · · Score: 0

    But I don't want to interrupt y'all misinformation carry on...idiots

  69. Re:Nonsence by philip.paradis · · Score: 0

    The TC devs hold no keys, nothing to seize/request.

    As others have noted, you've just handily demonstrated that you have absolutely no business commenting on issues like these. Failure to grasp the significance of signing keys in this context is breathtakingly stupid.

    --
    Write failed: Broken pipe
  70. Re:Nonsence by philip.paradis · · Score: 1

    The TC devs hold no keys

    They hold signing keys. Are you aware of the purpose of those keys?

    --
    Write failed: Broken pipe
  71. TrueCrypt Audit is complete by Anonymous Coward · · Score: 0

    The audit of TrueCrypt is complete and the anonymous authors of TrueCrypt is the n.....ack.....help.....choking...... ...... ......
    nobody. Thank you for your cooperation.

  72. Re:Nonsence by philip.paradis · · Score: 1

    Although you have acknowledged the existence of signing keys, you have still failed to express understanding of the utility of those keys.

    --
    Write failed: Broken pipe
  73. NSA by countach · · Score: 1

    It doesn't seem likely that even the NSA could get a court order, when there doesn't actually exist any "master key" that would benefit them. This isn't like other cases where some central authority has the power to decrypt stuff if only they are willing to hand over the master key. Maybe I'm naive, but I don't think the court would order them to deliberately break the distributed code for the NSA's benefit.

  74. Where is the Kickstarter to re-implement it? by Anonymous Coward · · Score: 0

    why re-implement it.. just import the code into github and become the new maintainer... have fun with that..

  75. Retards by Anonymous Coward · · Score: 0

    You retards. The NSA does not send national security letters.

    1. Re:Retards by philip.paradis · · Score: 1

      Typically, the FBI or Secret Service send NSLs. It should be noted that such letters may be generated based on cooperation with other agencies, however.

      --
      Write failed: Broken pipe
  76. Please upmod parent. by hitchhacker · · Score: 2

    Trying to bring attention to this thread whether it turns out true or false.

    -metric

  77. Truecrypt - Based in the US? by Zelucifer · · Score: 3, Interesting

    Is there any proof that the contributors are even in the US and thus subject to a NSL? At least one of them seems to be from the Czech Republic (David Tesaík).

    --
    The corner of a round room
  78. Is the truth even possible? by duke_cheetah2003 · · Score: 3, Interesting

    Given the anonymous nature of the TrueCrypt developers, would we even believe someone who claimed to be a dev and gave us an explanation?

    Not sure I would. I've read a lot of different articles and comments about this ordeal and I'm frankly not sure what to believe. I'm not sure if I'd believe someone if they said they were a dev.

    I know we'd all laugh if the NSA came out publicly and said "we had nothing to do with it."

  79. Screw you slashdot by Anonymous Coward · · Score: 0

    Hire some proper fucking editors, please.

  80. Re:Nonsence by AHuxley · · Score: 0

    Re what else is there that they are leaving the public at risk by keeping it a secret?
    Think of classic home network traffic and DES like 'home' isp protections still in use.
    Some very low quality efforts floating around many nations networking telco systems.
    Long term and short term the idea might be catch and release, a vast cadre of informants and people who have to vouch for 'new' friends of friends.
    Projects are started, friendships formed, trust built. Over years that project gains trust and is built in free, open or commercial products.
    People move onto other projects, work, study ... that inner core of 'new' friends of friends now owns the project.
    The consumer crypto landscape will be like Engima or what embassies used in the 1950-80's - back to plain text everytime, in realtime.
    We know the software and hardware past, we have a tiny view global data grab of the present.

    --
    Domestic spying is now "Benign Information Gathering"
  81. Where is the Kickstarter to re-implement it? by Anonymous Coward · · Score: 0

    Oh, hell yeah! I see a way to scoop some easy money from the NSA! Do a kickstarter to re-implement TC, then just wait for them to show up to offer you money to put in a backdoor. If you make the code messy as a plate of spaghetti, their backdoor could easily wind up in some dead code.

  82. No master key by Todd+Knarr · · Score: 2

    Unlike with Lavabit, there's no single master key for TrueCrypt that can be gotten from the developers that'll decrypt any TC partition. The best the NSA could get is the ability to create their own signed binary package with their own modifications and have it appear as the official package on TC's site. The problem with that is that the TC code's open so anybody can build from source and compare with the official build and see that they aren't the same. And any compromise of the source (eg. weakening the cryptography) would be instantly revealed in the diffs. The whole NSL thing sounds dodgy, and doesn't quite fit. It seems more likely that, with Win7 and later moving to supporting only GPT disks, the TC developers found they can't add that support and decided to throw in the towel.

    In any case, the version of TC from before this change is still available and as far as anyone can tell is still secure. I'd be leery of switching to other encryption software that's known to be less secure until someone comes up with a definitive vulnerability in 0.71.

  83. Kennedy's words seem apt by MrKaos · · Score: 1

    "Those who make peaceful revolution impossible will make violent revolution inevitable." - John F. Kennedy

    --
    My ism, it's full of beliefs.
  84. Re:Nonsence by wonkey_monkey · · Score: 1

    Not likely. The NSA has tried and failed to break into truecrypt volumes in the past.

    Which you know for a fact, because if they had succeeded, they'd definitely tell us. Right?

    --
    systemd is Roko's Basilisk.
  85. just my 0.02$ by Anonymous Coward · · Score: 0

    I think that the Audit itself (or the result) made NSA pull the plug, or the authors refused to oblige in the Lavabit style. Till now, the truecrypt project was quite a border matter, but with auditing it may take attention of commercial sphere and thus became a threat. I wonder if there is any crypto software without a backdoor or a serious vulnerability problem. For example PGP at my work pc uses a "password" which changes once in three months without recrypting the content, and when you take the machine to the it department, they decrypt it without need of knowing this password.

  86. The solution by bl968 · · Score: 1

    The question is why should truecrypt or anyone else hold a master encryption key to your data. The software should generate a signing key on installation, and that key should be then used for signing. It could then be sent to the provider for them to store in case the original is lost. But truecrypt would not have a master key that automatically unlocks all of their customers data if subpoenaed by the government. Your key will unlock only your data and no one elses.

    --
    "GET / HTTP/1.0" 200 51230 "-" "Mozilla/4.0 (compatible; Setec Astronomy)"
  87. Re:The explanation. by TheCarp · · Score: 1

    Splitters!

    (would slashdot make Brian Himself wait this long to his submit?)

    --
    "I opened my eyes, and everything went dark again"
  88. Not enough evidence. by Anonymous Coward · · Score: 0

    I am usually one of those "conspiracy theorist" with the foil hat. But the fact is, most of us under that label, are very focussed on gathering evidence and scrutinizing it. Observe.

    I have heard that Aliens are actually controlling the world governments, but I have not seen enough evidence to convince me of that.
    I have seen enough evidence to convince me that Snowden is actually a spy working for Mr. Obama.
    I am not convinced the WTC was taken down by explosives on every floor, but I am convinced it was an inside job of sorts.

    This case is no different. Yes I know the New World Order is doing everything they can to seize control of communications and the Internet (Net neutrality), but I need to see some more evidence than just the theory. It's a little, but not enough.

  89. Alyssa Rowan is an anagram by Anonymous Coward · · Score: 0

    Alyssa Rowan is an anagram for "also warns ya"

  90. Things really are this bad by Anonymous Coward · · Score: 0

    I can't comprehend the conspiracy theories flying around about this.

    However, because of the nature of the software, everyone assumes security agencies or reptilians are involved.

    You're in denial about how bad things have gotten in the USA. "Conspiracy theory" doesn't imply untrue anymore. We know that the NSA is conspiring against us, it's just a matter of how. It's completely reasonable to assume security agencies are involved, despite your attempt to mock everyone who thinks so by equating it with an assumption of "reptiles".

  91. Re:The explanation. by Anonymous Coward · · Score: 0

    You mean the People's Front of Judea. Or is it the Popular Front?

  92. Accountability by Anonymous Coward · · Score: 0

    ...in a word why I won't go anywhere near such open source projects when no-one is in charge, the maintenance and governance processes are as clear as mud and when the key players are anonymous.
    BitLocker has proved secure enough but if NSA cane sniffing, at least I know who I'm dealing with

  93. Rooftop Voting! Coming soon! by TrentTheThief · · Score: 1

    "As nightfall does not come all at once, neither does oppression. In both instances, there is a twilight when everything remains seemingly unchanged. And it is in such twilight that we all must be most aware of change in the air — however slight — lest we become unwitting victims of the darkness."

    This sure sounds like the scenario that Justice Douglas was talking about.

    Maybe it's about time to dig up the rifles?

  94. So where can I download the last trusted version? by Anonymous Coward · · Score: 0

    Is this authoritative?
    https://www.grc.com/misc/truecrypt/truecrypt.htm

    Are these hashes correct?
    https://defuse.ca/truecrypt-7.1a-hashes.htm

  95. Re:Nonsence by dunkindave · · Score: 1

    I understand that if they acquired the signing keys they could sign their own package and, presuming the loss of the signing keys was not known, have people accept the new packages as legit. But can possession of the keys allow them to create a fake and apparently correctly signed version 7.1a? If so, then the reason for wanting the keys seems obvious to me, to create a fake version which they can send to targeted people/entities, either through a trojaned download site, or by playing man-in-the-middle and changing what is sent from a legitimate mirror. The target gets the fake version and it passes all the tests so uses it, and the government now has their backdoor in place.

    I haven't studied how packages are signed, and am too busy at the moment to go read up on it, so maybe I am just naive. (I am sure there are plenty of posters on Slashdot that will let me know if I am :).

  96. Not really definitive enough by Anonymous Coward · · Score: 0

    I would still say that the conclusion is speculative. There's also another possibility that nobody (that I've seen at least) has brought up. The TrueCrypt authors attempt to be anonymous, which could mean a number of things, such as they are government spies, demand the upmost privacy, or possibly they are affiliated with organized crime, as well as others (aliens maybe?). It seems odd that they would voluntarily want anonymity, as most of the security field is obsessed with getting their name out there because it bolsters their career. I'd like to throw my personal speculation into the ring, which is the organized crime angle. What better way to provide security for sketchy people doing sketchy things than to release a totally free and readily distributed public facing program that provides strong encryption. You get a number of advantages by doing this, the two primary being: ease of access and non-attribution. It could be the whole effort was really bankrolled and promoted by organized crime in order to provide tools that will in the end save them money and reduce their risk. This is also my opinion on the genesis of Bitcoin. It all goes towards solving some of the unique problems they have. Just my $.02, so please feel free to flame away :)

    1. Re:Not really definitive enough by Anonymous Coward · · Score: 0

      Yeah Mr INSCOM. Whatever you and your 3 million friends at the government suspect must be true.

  97. Would an older version be better? by Anonymous Coward · · Score: 0

    I have downloads of older versions of TrueCrypt that I have been using for years. Since some of these could potentially be pre-NSA versions, would they be safe, or has TrueCrypt given over their algorithms used for all versions?

  98. Re:Nonsence by PPH · · Score: 1

    You mean app signing keys? If TC has been compromised by an insider, or may be in the future, that signature will mean nothing.

    --
    Have gnu, will travel.
  99. NSA by koan · · Score: 1

    The message on TrueCrypt's new website got me thinking:
            Using TrueCrypt is not secure as it may contain unfixed security issues

            Let's isolate the first letter of each word:
            (U)sing (T)rueCrypt (i)s (n)ot (s)ecure (a)s (i)t (m)ay (c)ontain (u)nfixed (s)ecurity (i)ssues

            Result?
            utinsaimcusi

            Let's spread that!
            uti nsa im cu si

            That is latin for
            "If I wish to use the NSA"

            Stay away from future Truecrypt releases. This is clearly a warning from the developers.

    --
    "If any question why we died, Tell them because our fathers lied."
  100. Re:Nonsence by philip.paradis · · Score: 1

    The concern isn't compromise of TC by an insider. The concern is forced conveyance of signing keys to an intelligence agency. Are you aware of the consequences of such a scenario? I suspect you're feigning ignorance at this point in an attempt to minimize perceived risk. Why would you do that?

    --
    Write failed: Broken pipe
  101. Re:Nonsence by philip.paradis · · Score: 1

    Why haven't you replied to my last question?

    --
    Write failed: Broken pipe