Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Who is Alyssa Rowan, and why should I care that she thinks the TrueCrypt post is a warrant canary?


Just an old, slightly jaded reverser who hung around the right places, and you don't really _need_ to care: it doesn't tell me what happened, just that a 'something bad happened' whistle was blown. It could just be as simple as one dev leaving it for if another dev went nuts.

Does it actually change the response, at all, I wonder? 7.1a is known, and being independently audited anyway. (It looked pretty good back when I took a look at it, although that wasn't 7.1a and that was a more cursory look than this thorough audit process.) No duress can change the fact of what the code does (although it could change what the site serves, what the 1024-bit DSA signing key signs...). 7.2 really isn't useful for that, at all.

Be interesting to see what ultimately comes of all this mess; maybe someone will fork it from 7.1a (won't be me: build process is way too hairy and licence is troublesome even from back when it was a EFTM fork), or maybe people will move to Diskcryptor or something and improve/audit that (it _is_ under a better licence).

No matter what actually happened - or happens - it's a huge shame. TrueCrypt was practical, effective, easy-to-use, and strong when used properly (as far as I know), with some (now sadly-removed) good documentation on how to use it correctly and what it can and can't protect against well. I really hope this débâcle doesn't drive people to switch to weaker crypto.

As many have pointed out, BitLocker - even if it's faithful - isn't available on many editions of Windows, isn't cross-platform, and only really supports the equivalent of keyfiles if you're not packing a TPM. It's a poor substitute for the ways many people use TrueCrypt.

LUKS is much better, although OS support isn't anywhere near as easy-to-use, and I'd say broadly equivalent with aes-128-xts/aes-256-xts, except that LUKS has an clear-identifiable header (dm-crypt doesn't have to) and TrueCrypt (unless you have the passphrase) doesn't. (Whether that's important is doubtful: a disk full of random data looks 'probably encrypted' to anyone who'd care to look and to the guy with the 5$ wrench or jackboots, that's good enough.)

I can't comment on the Mac one, never really taken a long look.

It would also be interesting to see similarly close audits of the OS built-ins. I know I'm curious about the exact changes Windows 8 made to BitLocker, because they were fairly extensive internally. Maybe I'll take a look. Maybe you should, too.



What does an MLP chan have to do with Truecrypt?


Bugger all, it's just a random site I happen to host.


Could you verify that you are who you really say you are? And sorry for not knowing what you're associated with, a Google search for your name isn't very helpful in find out who you are. What relation do you have with the TrueCrypt devs?

EDIT: I also didn't realize that you had replied to my original comment, sorry about that.


No relation with the devs. Just a decade-old conversation about PGPdisk, IVs and trouble export laws might cause, so it's perfectly OK to not put _too_ much stock in it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: