Skip to content

Comment on "Forensics for Prosecutors" mentions backdoor in TrueCrypt (page 15) [pdf]

Comments

Truecrypt is open source. Can anyone find the backdoor?

"Reflections on trusting trust" [1] may be necessary here. When you install Truecrypt, do you download a packaged binary app? Or do you compile it from source? Do you trust your compiler?

Until you know what the backdoor actually _is_, please don't stop just because you audited the source code.

[1] a good summary is at http://en.wikipedia.org/wiki/Backdoor_%28computing%29#Reflec...

A bit of Googling got me:

"Is Truecrypt A CIA honeypot" http://www.privacylover.com/encryption/analysis-is-there-a-b...

Seems like paranoia is looking just in general more plausible today.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.