geekhack

geekhack Community => Other Geeky Stuff => Topic started by: osi on Wed, 28 May 2014, 21:21:58

Title: Truecrypt is dead
Post by: osi on Wed, 28 May 2014, 21:21:58
Check their source forge page for more info.

It was good while it lasted at least!
Title: Re: Truecrypt is dead
Post by: SpAmRaY on Wed, 28 May 2014, 21:25:23
for those who don't want to look it up

Quote
WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues

This page exists only to help migrate existing data encrypted by TrueCrypt.

The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform.

http://truecrypt.sourceforge.net/ (http://truecrypt.sourceforge.net/)

-the intererwebs seem to think this could be a hoax or hack however....
Title: Re: Truecrypt is dead
Post by: osi on Wed, 28 May 2014, 21:28:24
Thank you sir for the extra info!
Title: Re: Truecrypt is dead
Post by: Techno Trousers on Wed, 28 May 2014, 22:45:22
I'm dubious about this, but if it turns out to be true, it's a dark day indeed for the security of the little guy. I can't even remember how many people I've recommended TrueCrypt to.
Title: Re: Truecrypt is dead
Post by: osi on Wed, 28 May 2014, 22:58:47
I'm dubious about this, but if it turns out to be true, it's a dark day indeed for the security of the little guy. I can't even remember how many people I've recommended TrueCrypt to.

Indeed. Truecrypt was the goto for open source encryption.

Time to checkout some other technologies

Title: Re: Truecrypt is dead
Post by: katushkin on Thu, 29 May 2014, 04:18:07
Goddamit. Looks like I'm going to have to encrypt my porn important files some other way.
Title: Re: Truecrypt is dead
Post by: osi on Thu, 29 May 2014, 06:53:10
This morning the truecrypt page is as it was last night. Will do some more reading today but it seems as if it IS true.

I wonder if the truecrypt audit turned up anything in terms of weakness in the implementation and that's why they shut it down??
Title: Re: Truecrypt is dead
Post by: jdcarpe on Thu, 29 May 2014, 09:57:19
In my opinion, this is a signal. It's almost certainly a result of the NSA issuing a shutdown order to the TrueCrypt team. They first issue a statement that the software is insecure, to deter people from using the previous, secure version. Then they recommend BitLocker, which most likely has an NSA backdoor built in, so as to be easily broken by Big Brother. Why would Windows XP EOL make strong crypto insecure all of a sudden? It wouldn't.
Title: Re: Truecrypt is dead
Post by: esoomenona on Thu, 29 May 2014, 09:59:52
A statement? Like destroying their lives bit by bit until they finally cave and lie to the people?
Title: Re: Truecrypt is dead
Post by: hjkl_over_wasd on Thu, 29 May 2014, 10:01:10
I agree with jdcarpe. 

The last report from the security audit, showed that the software was very promising, but further tests had to be made in order to be completely certain of the implemented security standards.
Title: Re: Truecrypt is dead
Post by: osi on Thu, 29 May 2014, 10:24:33
It also bothers me that the newly found vulnerability is not described yet. A possible explanation would be to allow a grace period to allow users to migrate existing encrypted data to other means.

The EOL of XP statement is really odd. JD like you said, this shouldn't be a factor here. My guess is it is simply ANY (not a good reason) reason just to announce the discontinuation of the product. Who knows what type of gag order the Truecrypt team may have applied against them.

The all of a sudden nature of this reminds me of the lavabit shutdown. Software can't be physically destroyed so the abruptness to move users away from Truecrypt may have been the best way for that team to get the message out to STOP USING THE PRODUCT!

Trust no one...

[attach=1]
Title: Re: Truecrypt is dead
Post by: blackbox on Thu, 29 May 2014, 10:37:56
If this turns out to be true, its very sad. I just read this article:
http://boingboing.net/2014/05/29/mysterious-announcement-from-t.html (http://boingboing.net/2014/05/29/mysterious-announcement-from-t.html)
Title: Re: Truecrypt is dead
Post by: Kayla on Thu, 29 May 2014, 10:55:15
Bitlocker? nope nope nope nope nope

The whole thing is way too fishy for me.
Title: Re: Truecrypt is dead
Post by: D01 on Thu, 29 May 2014, 11:05:03
Bummer.
Title: Re: Truecrypt is dead
Post by: TheSoulhunter on Thu, 29 May 2014, 11:50:30
In my opinion, this is a signal. It's almost certainly a result of the NSA issuing a shutdown order to the TrueCrypt team. They first issue a statement that the software is insecure, to deter people from using the previous, secure version. Then they recommend BitLocker, which most likely has an NSA backdoor built in, so as to be easily broken by Big Brother. Why would Windows XP EOL make strong crypto insecure all of a sudden? It wouldn't.

+1
Title: Re: Truecrypt is dead
Post by: SpAmRaY on Thu, 29 May 2014, 11:59:39
What if the NSA was really behind truecrypt all along?
Title: Re: Truecrypt is dead
Post by: blackbox on Thu, 29 May 2014, 12:18:09
What if the NSA was really behind truecrypt all along?
And now it is trying to migrate it to the newest product bitlocker?
Title: Re: Truecrypt is dead
Post by: SpAmRaY on Thu, 29 May 2014, 12:24:48
What if the NSA was really behind truecrypt all along?
And now it is trying to migrate it to the newest product bitlocker?

Just a smokescreen so people don't realize what's been going on this entire time. :eek:
Title: Re: Truecrypt is dead
Post by: blackbox on Thu, 29 May 2014, 12:27:09
What if the NSA was really behind truecrypt all along?
And now it is trying to migrate it to the newest product bitlocker?

Just a smokescreen so people don't realize what's been going on this entire time. :eek:

Of course, why didnt I realize that?
Title: Re: Truecrypt is dead
Post by: jdcarpe on Thu, 29 May 2014, 12:31:31
That's the beauty of open source encryption versus closed source. With open source, independent reviewers can audit the software to look for vulnerabilities. With closed source, a backdoor could be hidden easily, with no way of users knowing or being able to discover it, until it is too late.
Title: Re: Truecrypt is dead
Post by: osi on Thu, 29 May 2014, 12:38:45
What if the NSA was really behind truecrypt all along?

Eeek, I hope not!

Conspiracy theory : While NIST was deciding on a standard for AES, they happened upon a bug in either the twofish or serpent implementations. This information got swept under the rug and the public was told they simply weren't qualified to be used as a standard. NSA happily looked under the rug and grabbed the details that were hidden from view.

</theory>

Yes, I know the review was fully public ☺
Title: Re: Truecrypt is dead
Post by: IvanIvanovich on Thu, 29 May 2014, 12:42:06
I also suspect the NSA is behind it's shutdown... but the nice thing about opensource is after further code audits, and any needed fixes forks will appear shortly and NSA can play cat and mouse with those releasing them.
Title: Re: Truecrypt is dead
Post by: jdcarpe on Thu, 29 May 2014, 13:21:15
Information is power, people. Don't let government bullies take your power. Make them respect the people they are supposed to serve.
Title: Re: Truecrypt is dead
Post by: James35 on Thu, 29 May 2014, 14:03:34
I agree.  TrueCrypt's open source has been examined by so many people for so long, there has never been any security holes found. I suspect pressure from the outside has made them close down the site.
Title: Re: Truecrypt is dead
Post by: Kayla on Thu, 29 May 2014, 15:19:27
Information is power, people. Don't let government bullies take your power. Make them respect the people they are supposed to serve.
Easier said than done.
Title: Re: Truecrypt is dead
Post by: Coreda on Thu, 29 May 2014, 15:33:38
(http://i.imgur.com/nMxtJiH.jpg)

From everything I've been keeping up with it's obvious they were contacted by the government and forced to make changes, so they decided to make it obvious to everyone. Still pretty shocking, and as the license is strict it makes things more difficult for forking, apparently.

As for the audits I'm glad they'll continue (of the previous 7.1a version) according to Matthew Green, who confirmed it. After all they still have the money people raised for it.
Title: Re: Truecrypt is dead
Post by: tbc on Thu, 29 May 2014, 15:51:33
I also suspect the NSA is behind it's shutdown... but the nice thing about opensource is after further code audits, and any needed fixes forks will appear shortly and NSA can play cat and mouse with those releasing them.

sorta.  OSS doesn't work quite as well with security provider applications.

there really aren't that many people qualified to do an audit and to implement the code changes necessary.  especially as standards get updated.

the prime rule of software programming is to never write your own security, you're just not good enough to do it right.  you're going to do it wrong, and then your false confidence will screw everyone over.
Title: Re: Truecrypt is dead
Post by: Techno Trousers on Thu, 29 May 2014, 16:29:30
I don't really understand the conspiracy theory that the NSA was forcing them to put in a backdoor. Under what authority could something like that happen? We don't even know if the authors are within U.S. jurisdiction.

Of the conspiracy theories I've seen, my favorite is that TrueCrypt has been stolen from the original authors by some nefarious spook agency, and they are trying to convince some person or persons to unencrypt their stuff, ostensibly to convert it to a "safer" encryption solution.

I think this appeals to me since there's no evidence of any backdoors or weaknesses so far. I'm hoping I can safely keep using v. 6x until a good open source alternative for Windows is available. Hopefully they will continue with the in-depth code audit this summer as planned, so we'll know for sure one way or the other.
Title: Re: Truecrypt is dead
Post by: jdcarpe on Thu, 29 May 2014, 16:33:33
I don't really understand the conspiracy theory that the NSA was forcing them to put in a backdoor. Under what authority could something like that happen? We don't even know if the authors are within U.S. jurisdiction.

Of the conspiracy theories I've seen, my favorite is that TrueCrypt has been stolen from the original authors by some nefarious spook agency, and they are trying to convince some person or persons to unencrypt their stuff, ostensibly to convert it to a "safer" encryption solution.

I think this appeals to me since there's no evidence of any backdoors or weaknesses so far. I'm hoping I can safely keep using v. 6x until a good open source alternative for Windows is available. Hopefully they will continue with the in-depth code audit this summer as planned, so we'll know for sure one way or the other.

No one is saying that TrueCrypt had a backdoor. Quite the contrary - I believe TrueCrypt was secure. Which is why the NSA forced the TrueCrypt team to shut the project down. The NSA likely has backdoors into closed source encryption technologies, such as Microsoft's BitLocker.
Title: Re: Truecrypt is dead
Post by: James35 on Thu, 29 May 2014, 16:41:27
Exactly.  There is no back door.  The source was open for examination by anyone.
Title: Re: Truecrypt is dead
Post by: Kayla on Thu, 29 May 2014, 16:49:02
TrueCrypt has been contacted by authorities countless times before and has refused to work with them and kept their methods a secret. If it was NSA from the start then this stunt wouldnt be necessary. There is a story we're missing here and I have a feeling it will turn up eventually. We just have to sit tight and let the internet detectives detect. :p
Title: Re: Truecrypt is dead
Post by: jwaz on Thu, 29 May 2014, 16:55:30
Quote
We are considering several scenarios, including potentially supporting a fork under appropriate free license, w/ a fully reproducible build.

Quote
We are continuing forward with formal cryptanalysis of TrueCrypt 7.1 as committed, and hope to deliver a final audit report in a few months.

Quote
We will be making an announcement later today on the TrueCrypt audit and our work ahead.

via https://twitter.com/OpenCryptoAudit
Title: Re: Truecrypt is dead
Post by: Techno Trousers on Thu, 29 May 2014, 16:59:57
Thanks jwaz, I just came here to post that. Great news, because they would certainly have revealed if they'd found a serious bug found in TrueCrypt that they'd already reported and the TrueCrypt team threw in the towel on the project rather than fix it (one of the conspiracy theories out there). I'm going to continue to use it until it's been proven to be compromised.
Title: Re: Truecrypt is dead
Post by: James35 on Thu, 29 May 2014, 17:01:43
I would bet money that it hasn't been compromised.
Title: Re: Truecrypt is dead
Post by: davkol on Thu, 29 May 2014, 17:20:20
TC isn't open source, it's "source available". Anyway, the source is still on Github: https://github.com/DrWhax/truecrypt-archive

The weird part is that the site is blocked at Archive.org. Three-letter organization indeed.

At least we still have EncFS.
Title: Re: Truecrypt is dead
Post by: madhias on Fri, 30 May 2014, 04:32:08
That's new: http://truecrypt.ch/ (http://truecrypt.ch/)

Also some interesting read about the name, creators, etc (russian translation):
https://translate.google.com/translate?hl=en&sl=ru&tl=en&u=http%3A%2F%2Fnews.softodrom.ru%2Fap%2Fb19702.shtml (https://translate.google.com/translate?hl=en&sl=ru&tl=en&u=http%3A%2F%2Fnews.softodrom.ru%2Fap%2Fb19702.shtml)
Title: Re: Truecrypt is dead
Post by: osi on Fri, 30 May 2014, 07:13:28
That's new: http://truecrypt.ch/ (http://truecrypt.ch/)

Also some interesting read about the name, creators, etc (russian translation):
https://translate.google.com/translate?hl=en&sl=ru&tl=en&u=http%3A%2F%2Fnews.softodrom.ru%2Fap%2Fb19702.shtml (https://translate.google.com/translate?hl=en&sl=ru&tl=en&u=http%3A%2F%2Fnews.softodrom.ru%2Fap%2Fb19702.shtml)

This is interesting and I see it is based out of Switzerland. But can we really trust this application now considering the past week? My body want's to trust it as I've been using truecrypt for some years now but my mind is still confused.

: patiently waits for the 2nd phase of public audit to finish:

Title: Re: Truecrypt is dead
Post by: Techno Trousers on Fri, 30 May 2014, 08:21:09

I think it would be prudent to wait until the OpenCryptoAudit group talks about their future plans. Personally, I'd be more likely to trust a new project started by or spun off from them. I'm sure we will be seeing a lot of new forks popping up in the coming weeks, and the problem with cryptography implentations is that they are about the most difficult software to get right.
Title: Re: Truecrypt is dead
Post by: katushkin on Sat, 31 May 2014, 03:53:50
Can't trust the Swiss.

Well you can, but you will never know who else they are working with...
Title: Re: Truecrypt is dead
Post by: Eszett on Sat, 31 May 2014, 04:27:10
Let's think about it. The developers of the most secure encryption software on earth warn about their own software, and recommend the software of their competitor, which is known to come with a backdoor to the NSA. And you take this serious? Kiddin'? It stinks to high heaven. Use TrueCrypt 7.1a or DiskCryptor.

Anyway, you know that the warning is bull, when it comes
-- with red letters and block writing.
-- without specific reasons.
-- without the author's name.
-- with a surreptitious advertising


Title: Re: Truecrypt is dead
Post by: roaduck on Mon, 02 June 2014, 22:52:40
There are alternatives out there.

http://alternativeto.net/software/truecrypt/

General Net Privacy Advice

https://www.wefightcensorship.org/article/fifteen-minutes-online-anonymityhtml.html




I am also considering the following : secure cloud storage / secure email / secure webmail /secure social media etc :

Protonmail

https://protonmail.ch/

Tresorit

https://tresorit.com/

Lavaboom

https://lavaboom.com/en/

Wuala

http://wuala.com/en/pricing/

Vole

http://vole.cc/

Getsync

http://getsync.com/

BitTorrent Chat

http://labs.bittorrent.com/experiments/bittorrent-chat.html

Maidsafe

http://maidsafe.net/overview


--------------------------------------------------------------------------------------------------------------------------------------
Here are some Encryption Links
__________________________

http://www.snuko.com/en/gb
http://www.robotronic.de/elevate.html
http://www.hbgary.com/products/responder_pro
http://www.gwebs.com/mailcloak/mailcloak_for_mail_clients.html
http://www.washingtonpost.com/blogs/wonkblog/wp/2013/06/14/nsa-proof-encryption-exists-why-doesnt-anyone-use-it/
https://play.google.com/store/apps/details?id=org.thoughtcrime.redphone
http://www.forbes.com/sites/jonmatonis/2012/07/19/5-essential-privacy-tools-for-the-next-crypto-war/
http://allfacebook.com/encrypt-your-facebook-postings-with-uprotect-it_b30477
http://www.hermetic.ch/eee/eee.htm
http://www.badphorm.co.uk/e107_plugins/forum/forum_viewforum.php?25
http://www.badphorm.co.uk/e107_plugins/forum/forum_viewtopic.php?14983
http://gimfmedia.com/tech/en/download-mobile-encryption/
http://www.propublica.org/article/the-nsas-secret-campaign-to-crack-undermine-internet-encryption
http://news.cnet.com/2300-1029_3-6230933.html?tag=ne.gall.pg
https://en.wikipedia.org/wiki/Deniable_encryption
https://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software
http://aluigi.freeforums.org/post11991.html
http://www.valeso.com/
https://www.infoencrypt.com/
http://www2.rpost.com/encrypt_with_rmail
https://www.sendinc.com/
http://www.mxcsoft.com/
http://www.bytefusion.com/products/ens/cryptoanywhere/whatiscryptoanywhere.htm
http://www.mailvelope.com/
http://free.antivirus.com/us/email-encryption-service/index.html
http://www.secureaction.com/encryption_free/
http://www.nchsoftware.com/encrypt/index.html
http://www.safehousesoftware.com/SafeHouseExplorer.aspx
http://www.cbc.ca/news/technology/anti-nsa-blackphone-commendable-but-will-consumers-buy-it-1.2544562
http://www.skycrypt.com/
https://torrentfreak.com/how-nsa-proof-are-vpn-providers-131023/
https://lockbin.com/
http://thenextweb.com/apps/2014/04/18/tresorit-opens-end-end-encryption-file-sharing-service-public/
https://tresorit.com/
https://help.ubuntu.com/community/FullDiskEncryptionHowto
http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software

___________________________________________________________________________________________________________
Free PGP Resources
--------------------

http://www.pa.msu.edu/reference/pgp-readme-1st.html - probably the best version - Illegal for use in USA
http://www.bytefusion.com/products/ens/cryptoanywhere/whatiscryptoanywhere.htm - CryptoAnywhere
http://www.heureka.clara.net/sunrise/pgp.htm
https://www.wefightcensorship.org/article/sending-encrypted-emails-using-thunderbird-and-pgphtml.html - Sending encrypted emails using Thunderbird and PGP
https://www.mailvelope.com/ - OpenPGP for Webmail
http://www.pgpguide.20m.com/ - An Unauthorised Guide to PGP Cryptography
___________________________________________________________________________________________________________
Secure Browsers Proxies and Anonymous Surfing
--------------------------------------------------

https://www.whitehatsec.com/aviator/ - Whitehat Security - Aviator Browser
http://www.deepnetsecurity.com/products/dualtrust/ - Deepnet Security - DualTrust
http://download.sirrix.com/content/pages/bbdl-en.htm - Sirrix AG security technologies - Browser in the Box
http://anonymous-proxy-servers.net/en/jondofox.html - Anonymous Surfing with JonDoFox
https://anonymous-proxy-servers.net/wiki/index.php/Censorship-free_DNS_servers - Censorship-free DNS servers
http://dnslookup.me/dynamic-dns/ - Free Dynamic DNS Providers
http://www.noip.com/free/ - No-IP Free Dynamic DNS
http://www.dnsexit.com/Direct.sv?cmd=ipClients - Dynamic DNS Clients - Software, Specifications and Guidelines
https://github.com/castleproject/Core/blob/master/src/Castle.Core/DynamicProxy/ProxyGenerator.cs - Castle.DynamicProxy
http://www.mousematrix.com/ - Mousematrix

https://ultrasurf.us/ - Ultrasurf
http://www.internetfreedom.org/GPass - GPass
http://darknet.se/about-darknet/?lang=en - Darknet
http://null-byte.wonderhowto.com/inspiration/anonymity-darknets-and-staying-out-federal-custody-part-one-deep-web-0133455/ - Darknet Tutorial part 1
http://mute-net.sourceforge.net/ - Simple, Anonymous File Sharing
https://freenetproject.org/download.html - Freenet
http://www.cyberghostvpn.com/en_gb - CyberGhost
http://alternativeto.net/software/hidemyass-vpn/ - HideMyAss! - Alternative To
https://uwnthesis.wordpress.com/2012/12/02/the-amnesic-incognito-live-system-linux-base-anonymous-os/?preview=true&preview_id=1685&preview_nonce=9bed3b4cca - TAILS – The Amnesic Incognito Live System – Anonymous OS
___________________________________________________________________________________________________________
Title: Re: Truecrypt is dead
Post by: noisyturtle on Tue, 03 June 2014, 02:31:03
Let us all don out tinfoil hats and dance around our bunkers shouting at cans of beans!
Title: Re: Truecrypt is dead
Post by: angelic_sedition on Wed, 04 June 2014, 13:13:52
There's tcplay (https://github.com/bwalex/tc-play). I'm still using truecrypt for now.