Originally Posted by
GUWonder
VeraCrypt has some critical vulnerabilities. It will be interesting to see how quickly all of those identified (at this point) get fixed.
http://www.zdnet.com/article/veracry...ritical-flaws/
Note that some flaws in TrueCrypt were actually fixed with/by/for VeraCrypt.
That article is very badly written. VeraCrypt had actually released an update addressing the audit two day prior to that article going live. And unlike what that article hints at, the remaining issues are not high-priority, but rather low risk bugs that require significant work to correct. Also, I don't believe anything the audit found would meet the industry-accepted definition of "Critical"; again another issues I have with that piece.
If anything, the fact that VeraCrypt is being audited is a good thing. TrueCrypt went years without an audit. Having critical crypto projects regularly audited is the only way to have any confidence in its security.