Go Back  FlyerTalk Forums > Travel&Dining > Travel Technology
Reload this Page >

Truecrypt compromised?

Community
Wiki Posts
Search

Truecrypt compromised?

Thread Tools
 
Search this Thread
 
Old Jun 2, 2014 | 3:38 pm
  #16  
FlyerTalk Evangelist
30 Countries Visited
1M
All eyes on you!
15 Years on Site
 
Join Date: Apr 2009
Location: Bye Delta
Programs: AA EXP, UA Silver, HH Diamond, IHG Plat, Hyatt Plat, Marriott Titanium, Nat'l EE, Avis PC, Hertz PC
Posts: 16,635
http://truecrypt.ch/

TrueCrypt must not die

TrueCrypt.ch is the gathering place for all up-to-date information.

If TrueCrypt.org really is dead, we will try to organize a future.
javabytes is offline  
Old Jun 2, 2014 | 3:43 pm
  #17  
 
Join Date: Oct 2013
Location: WAS
Programs: SPG Plat. Marriott Plat. Hilton Diamond. Hyatt Diamond. IHG Plat.
Posts: 2,580
https://opencryptoaudit.org

Update: The TrueCrypt Phase I Audit Report is available!
https://opencryptoaudit.org/reports/...Assessment.pdf
f0xx is offline  
Old Jun 2, 2014 | 3:55 pm
  #18  
FlyerTalk Evangelist
30 Countries Visited
1M
All eyes on you!
15 Years on Site
 
Join Date: Apr 2009
Location: Bye Delta
Programs: AA EXP, UA Silver, HH Diamond, IHG Plat, Hyatt Plat, Marriott Titanium, Nat'l EE, Avis PC, Hertz PC
Posts: 16,635
That was published a few months ago... the second phase of the audit is still pending. And the second phase is where the money is.
javabytes is offline  
Old Jun 5, 2014 | 11:47 am
  #19  
Original Poster
 
Join Date: Aug 2005
Location: SNA Rwy 20L
Programs: QF Silver
Posts: 703
OK, what the heck is going on with computer security these days... After years of blissful ignorance:

First we get Heartbleed - spend a couple of days updating all my servers/routers/clients to the latest OpenSSH.

Next the venerable TrueCrypt starts a storm of conspiracy stories.

Today another vulnerability in OpenSSH has been identified which potentially affects HTTPS traffic and the OpenSSL foundation is asking us to upgrade again.

http://www.wired.com/2014/06/heartbl...ssl-uncovered/

I can't wait for the results of the TC audit, the computer world isn't that much fun anymore.
Zarf4 is offline  
Old Jun 6, 2014 | 1:38 pm
  #20  
All eyes on you!
10 Years on Site
 
Join Date: Jun 2013
Location: Bristol (ex-Londoner)
Programs: BAEC Blue, VS Flying Club
Posts: 232
This is a prime example of when closed source goes bad. No source = no trust.

dmcrypt or lukscrypt plus GPG is the way to go
CraigWatson is offline  
Old Jun 6, 2014 | 1:43 pm
  #21  
FlyerTalk Evangelist
Conversation Starter
All eyes on you!
20 Years on Site
 
Join Date: Nov 2002
Location: ORD
Posts: 14,771
TrueCrypt is open source - isn't it?
gfunkdave is offline  
Old Jun 6, 2014 | 1:44 pm
  #22  
All eyes on you!
10 Years on Site
 
Join Date: Jun 2013
Location: Bristol (ex-Londoner)
Programs: BAEC Blue, VS Flying Club
Posts: 232
Originally Posted by gfunkdave
TrueCrypt is open source - isn't it?
Not quite: http://en.wikipedia.org/wiki/TrueCry...d_source_model

TL;DR - TrueCrypt License != Open Source

Originally Posted by Wikipedia
According to current OSI president Simon Phipps:

...it is not at all appropriate for TrueCrypt to describe itself as "open source." This use of the term "open source" to describe something under a license that's not only unapproved by OSI but known to be subject to issues is unacceptable.
CraigWatson is offline  
Old Jun 6, 2014 | 2:02 pm
  #23  
FlyerTalk Evangelist
30 Countries Visited
2M
All eyes on you!
25 Years on Site
 
Join Date: Jul 2000
Location: in the vicinity of SFO
Programs: AA 2MM (LT-PLT, PPro for this year)
Posts: 19,784
Originally Posted by CraigWatson
This is a prime example of when closed source goes bad. No source = no trust.

dmcrypt or lukscrypt plus GPG is the way to go
TrueCrypt makes source available, and you can build your own version from source easily enough. In practical terms, there is little stopping redistribution or forking.

That's "open source" enough for me.

Originally Posted by CraigWatson
Not quite: http://en.wikipedia.org/wiki/TrueCry...d_source_model

TL;DR - TrueCrypt License != Open Source
The term "open source" predates OSI, and they don't have a trademark on it.
nkedel is offline  
Old Jun 6, 2014 | 2:16 pm
  #24  
All eyes on you!
10 Years on Site
 
Join Date: Jun 2013
Location: Bristol (ex-Londoner)
Programs: BAEC Blue, VS Flying Club
Posts: 232
Originally Posted by nkedel
TrueCrypt makes source available, and you can build your own version from source easily enough. In practical terms, there is little stopping redistribution or forking.
In actual fact:

Originally Posted by Open Crypto Audit
The current required Windows build environment depends on outdated build tools and software packages that are hard to get from trustworthy sources. For example, following the reproducible build instructions requires access to VC++ 1.52 (released in 1993), in addition to various Windows ports of GNU tools downloadable from wherever they can be found. Using antiquated and unsupported build tools introduces multiple risks including: unsigned tools that could be maliciously modified, unknown or unpatched security vulnerabilities in the tools themselves, and weaker or missing implementations of modern protection mechanisms such as DEP and ASLR. Once the build environment has been updated, the team should consider rebuilding all binaries with all security features fully enabled. For the purpose of auditing, TrueCrypt should release instructions for how to create reproducible builds.
Originally Posted by nkedel
The term "open source" predates OSI, and they don't have a trademark on it.
True, but the OSI was founded for a reason, to clear up the term and to impose standards. The web was around in some form or another before the W3C and they don't have a trademark on the term HTML, but we still have web standards.

I may be slightly pedantic, but the mis-communication of the terms "open source" and "free software" are one of my biggest pet hates - it's Freedom vs Gratis, TrueCrypt may be Gratis but it's not Free because it's restricted by the TrueCrypt License. OSI-approved licenses and copyleft are two of the cornerstones of the software freedoms
CraigWatson is offline  
Old Jun 6, 2014 | 2:58 pm
  #25  
FlyerTalk Evangelist
30 Countries Visited
2M
All eyes on you!
25 Years on Site
 
Join Date: Jul 2000
Location: in the vicinity of SFO
Programs: AA 2MM (LT-PLT, PPro for this year)
Posts: 19,784
Originally Posted by CraigWatson
True, but the OSI was founded for a reason, to clear up the term and to impose standards.
They don't have any power to "impose" standards -- they can (and do) try to build consensus around them, but to suggest that theirs is the only definition out there is simply wrong.

The web was around in some form or another before the W3C and they don't have a trademark on the term HTML, but we still have web standards.
...and browsers have to deal with HTML that doesn't completely comply with the standards, and yet everyone understands that it is HTML.

I may be slightly pedantic, but the mis-communication of the terms "open source" and "free software" are one of my biggest pet hates - it's Freedom vs Gratis, TrueCrypt may be Gratis but it's not Free because it's restricted by the TrueCrypt License.
[/QUOTE]

Truecrypt isn't just free-as-in-beer; in practice as a private individual you're just as free to use the source as anything GPL-ed, and you are free to create and distribute new versions of it or products extended from it.

Indeed, the biggest issues with the license (that it's "viral," like GPL, and that it requires attribution) are both in common with some OSI-approved licenses, and overall, it's a good deal LESS restrictive than some of the approved OSI licenses from commercial entities (notably Sun's CDDL.)

(It's also not clear whether the new license posted with their gimped 7.2 release is retroactive; if so, most of the objections to the older license are moot.)

Moreover, by the FSF's standards, a lot of OSI-recognized licenses aren't free. That level of doctrinal dispute is uninteresting.

OSI-approved licenses and copyleft are two of the cornerstones of the software freedoms
Quite a lot of OSI-approved licenses AREN'T copyleft (in the generally accepted sense, including the one use in the OSI's own FAQ; some other people use it to mean all open source.)

OSI-approved licenses are a convenience, and something that post-dates all three of the major general-use licenses (GPL, BSD and Apache.)
nkedel is offline  
Old Jun 6, 2014 | 3:44 pm
  #26  
All eyes on you!
10 Years on Site
 
Join Date: Jun 2013
Location: Bristol (ex-Londoner)
Programs: BAEC Blue, VS Flying Club
Posts: 232
Touch
CraigWatson is offline  
Old Apr 3, 2015 | 6:15 am
  #27  
Suspended
 
Join Date: Jul 2001
Location: Watchlisted by the prejudiced, en route to purgatory
Programs: Just Say No to Fleecing and Blacklisting
Posts: 102,077
Some audit results resulted in the following article:

https://threatpost.com/audit-conclud...uecrypt/111994
GUWonder is offline  
Old Apr 3, 2015 | 12:55 pm
  #28  
All eyes on you!
20 Years on Site
 
Join Date: Jan 2003
Location: Manchester, United Kingdom
Programs: Hilton Gold, Priority Club Platinum (until December), FB Explorer, BA Blue, M&M Pleb
Posts: 8,616
Originally Posted by GUWonder
Some audit results resulted in the following article:

https://threatpost.com/audit-conclud...uecrypt/111994
Saw an article about that in The Register. Sounds like the whole situation was ultimately down to either warrant canary, or something more sinister. Doesn't effect me; all my secrets are dancing and singing in front of you.
Internaut is offline  
Old Apr 3, 2015 | 3:15 pm
  #29  
FlyerTalk Evangelist
Conversation Starter
All eyes on you!
20 Years on Site
 
Join Date: Nov 2002
Location: ORD
Posts: 14,771
Originally Posted by Internaut
Doesn't effect me; all my secrets are dancing and singing in front of you.
Oh, so THAT'S what that is. Cut it out, I'm trying to sleep here!
gfunkdave is offline  
Old Apr 3, 2015 | 4:00 pm
  #30  
FlyerTalk Evangelist
 
Join Date: Jun 2006
Location: IAD/DCA
Posts: 31,871
how much is not 'compromised' ?
Kagehitokiri is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.