Notice: You have been identified as a bot, so no internal UID will be assigned to you. If you are a real person messing with your useragent, you should change it back to something normal.
Anonymous B joined in and replied with this 12 years ago, 13 minutes later[^][v]#482,102
Surely, Minichan is the best place for all of your encryption and security questions.
Anonymous A (OP) replied with this 12 years ago, 1 minute later, 15 minutes after the original post[^][v]#482,103
@previous (B)
yeah actually, this forum is filled with high-quality nerds.
r04r joined in and replied with this 12 years ago, 32 minutes later, 47 minutes after the original post[^][v]#482,109
I think so :( From what I gather the most likely theories, sorted by my opinion of likelihood, are:
1) The truecrypt developers gave up on the project. They've been at it for 10 years with no significant changes in the past 2 years, and also no signficant donations. Now an audit of their hard work has brought in like $70k, so it's likely they mad. They also anonymous, so there's that too. Since they will no longer be maintaining the project, it can be seen as insecure as new bugs will not be fixed by them.
2) They got hardcore haxxed and someone defaced the project for some insane lulz. This is getting less and less likely as more time passes, since someone should have noticed by now and reverted it with the amount of coverage this received. A sourceforge employee also commented that the access patterns to their account have been consistent.
3) A goverment agency tracked them down and got involved, either wanting to shut them down or for a backdoor to be implemented. This could be the result, or their refusal.
4) A truly critical bug was found in truecrypt, which shamed the developers into quitting. This seems unlikely, as a security advisory and a fix would be much more appreciated by everyone instead of abandoning the project and letting the bug live in all existing versions.
It is "open source" to the point where the source is available, and the latest license (which they changed in the latest update) allows for redistribution as long as none of the artwork or TrueCrypt name is used. Hopefully we'll see a nice fork, since afaik it's the only cross platform encryption tool that lets you mount file volumes as disks which is quite convient.
(Edited 4 minutes later.)
Anonymous A (OP) replied with this 12 years ago, 19 minutes later, 1 hour after the original post[^][v]#482,113
@previous (r04r)
:( #1 seems the most likely to me too. The message on their site is weird though, surely they would know "WARNING: Using TrueCrypt is not secure" would just scare people. Is the audit going to continue?
(Edited 56 seconds later.)
r04r replied with this 12 years ago, 2 minutes later, 1 hour after the original post[^][v]#482,114
@previous (A)
I think the audit will continue, according to a tweet by one of the auditors. They may have issues with getting any more funding now, which could be the goal of this release. But yeah, I have no idea. I'm sure they know it would scare people, but with cryptography you should be scared if the software you use is unmaintained.
Btw their advice for other platforms is utterly laughable. Check this out: http://truecrypt.sourceforge.net/OtherPlatforms.html The encryption type for OSX is set to 'none', and for linux they tell you to search your package manager and just use whatever. Like, the fuck?
(Edited 19 seconds later.)
Anonymous A (OP) replied with this 12 years ago, 38 minutes later, 1 hour after the original post[^][v]#482,117
@previous (r04r)
Good thing the audit is continuing, and good point.
I lol'd at 'none', maybe they're secretly trying to tell us they're doing this under coercion in a very subtle way. :D
r04r replied with this 12 years ago, 13 minutes later, 2 hours after the original post[^][v]#482,121
@previous (A)
Lol maybe, or they simply put like no care in the screenshot or it's a stock image. Weird tho.
Anonymous D joined in and replied with this 12 years ago, 5 hours later, 7 hours after the original post[^][v]#482,195
@482,109 (r04r)
why would an audit bringing in $70k rustle their jimmies?
Anonymous A (OP) replied with this 12 years ago, 16 minutes later, 7 hours after the original post[^][v]#482,198
@previous (D)
$70k for an audit versus what little donations they likely received. They might have felt their hard work went somewhat underappreciated.
Anonymous E joined in and replied with this 12 years ago, 2 hours later, 10 hours after the original post[^][v]#482,209
The developers were kidnapped by the FBI
Triptych !IupsXZPnnU joined in and replied with this 12 years ago, 21 minutes later, 10 hours after the original post[^][v]#482,211
Ohp. This is strange.
Anonymous C replied with this 12 years ago, 7 hours later, 18 hours after the original post[^][v]#482,245
Keep in mind the audit is performed by a third party, and it's basically checking if the truecrypt devs didn't fuck up anywhere in the past 10 years while never giving them any money. Seems likely they are no longer interesting in the project, especially if they primarily use windows and bitlocker does what they want. It's still very weird they'd use a propieretary product tho.
Anonymous G joined in and replied with this 12 years ago, 1 hour later, 19 hours after the original post[^][v]#482,259
@previous (C)
i like how they recommend bitlocker :D
Ash !bbKEtchUp. joined in and replied with this 12 years ago, 10 minutes later, 19 hours after the original post[^][v]#482,261
Does this mean that they spent 70k on this audit, that the audit revealed they have had 70k in donations or that people donated 70k for an audit whilst donating nothing to the project?
Killer Lettuce !!iNo3FkiZx joined in and replied with this 12 years ago, 2 minutes later, 19 hours after the original post[^][v]#482,263
r04r replied with this 12 years ago, 8 minutes later, 20 hours after the original post[^][v]#482,270
@previous (TTEH !JXsxEkDBLs)
Yep. People who know crypto well and are employed in such a field can charge a pretty penny because there aren't many of them.