Truecrypt: A disappearance without much to explain

TrueCrypt question

A few days ago, the mysterious disappearance of Truecrypt, the famous disk encryption software, was reported. On their sourceforge page they say that it was not secure and that it could contain vulnerabilities and that they recommend the use of Bitlocker Drive Encryption, which is the encryption software that comes by default in Windows Vista, 7 and 8. They even mention that its development was stopped in May, after support for Windows XP ended.

Now some developers decided to forge the code and base it in Switzerland, while Gibson Research Corporation says "No, Truecrypt is still safe", at least until the Open Crypto Audit say the opposite. The Open Crypto Audit is a project to audit the Truecrypt code, and in April they reported that the first part of the audit was done and of the 11 vulnerabilities they found, there were none serious.

So what's up?

According to sharing Tweets Between Steven Barnhart and Matthew Green (who leads the Open Crypto Audit), Steven tried to contact someone involved and received a couple of emails from someone named "David."

What does David say ?: No interest. Arguably there is no interest in further developing Truecrypt. In another email he says that Bitlocker is "good enough" and that Windows (XP) was the original goal of the project. He also says there was no contact with the government. Steven asked him if he would be willing to re-license the code with another license or fork it. David responds that that would be harmful since only they (the Truecrypt developers) are familiar with the code.

Anyway, that's just a theory why it disappeared. There are other as they managed to break the encryption, that the identity of its developers is known (the brand is registered in the name of David Tesarík, perhaps it is the same one who sent the emails), that God exists and is on the side of the NSA, etc.

Meanwhile, for Linux users there are several alternatives (with less restrictive licenses than truecrypt): dm-crypt, LUKS, eCryptfs, EncFs, RealCrypt (it is nothing more than truecrypt with another brand), ZuluCrypt and others.


Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.

  1.   desikoder said

    I could already suspect it. Some time ago I read that truecrypt, although they said it was open source, had its source code obfuscated (illegible), in addition, it was difficult to compile, so they gave you binaries precompiled by the truecrypt team ... Anyway, I have never used truecrypt , Security is not only provided by encryption, but also by encryption software THAT IS FREE. Seriously, I don't understand why so many people are using truecrypt under linux or windows ... In linux you can encrypt the hard disk with LUKS (Linux Unified Key Setup), in fact I have the disk encrypted. In windows it does not make sense to encrypt something because windows is controlled by the nsa ...

    Come on, it doesn't surprise me in the least. In addition, I find it curious that they recommend switching to BitLocker, when it is proprietary, much more insecure, and also if you delete your username, even if you recreate it with the same name and password, since the NT user identifier (a registry roll de windows) is different, you cannot recover it, when in LUKS it is a simple passphrase with which you figure, decipher and point ball.

    regards

    1.    eliotime3000 said

      That is why I find it ironic that they excuse themselves that it was a solution for Windowsers who still used Windows XP, because as of Service Pack 3, it already came with the BitLocker system included, but it did not let you encrypt the drives.

      And by the way, it can also be done with other GNU / Linux utilities apart from LUKS.

      1.    desikoder said

        Yes, I know that it can be encrypted with other software, although of course, everything is going well on your site. LUKS to encrypt my hard drive, and gpg + enigmail + thunderbird for mail.

        regards

        1.    desikoder said

          Now it appears in my firefox user-agent under Ubuntu because it is what I am using, I am on a foreign PC.

          I have a nice debian on my powerpc laptop, with desktop openbox

          1.    eliotime3000 said

            Don't worry, because I'm using Debian + XFCE on my netbook, and on my desktop, Debian + KDE.

            With what I trolle is with the user agent, since I work with Windows if it only leaves me no alternative such as video editing or graphic design (my desktop PC has Windows Vista SP2 and my netbook has Windows 8, and both are dual -boot with Debian).

  2.   pepper said

    I think microsoft paid them

    1.    eliotime3000 said

      Or surely they realized that Windows XP was no longer going to have more maintenance and that only the embeddable versions are going to be the only ones that are going to receive this type of support.