Skip to content

Comment on TrueCrypt suggesting migration to BitLocker?parent

Comments

We don't know much about the TC developers, do we? It's also possible that they're just really cavalier about this stuff, and that this is their response to the TC audit process ("stop bothering us about it and use something that's maintained").

True. Security announcements have been botched in the past, for all sorts of reasons, not that you have any experience with that, of course. But what does XP being EOL'd have to do with anything? That and the blithe recommendation to use other solutions, even though they don't have hidden volume functionality which is a main selling point of TC, is what changed my mind, from thinking this is probably a legit mishandled disclosure, to thinking it's probably fake.

On the other hand, as pointed out in other subthreads, if the devs are tired of maintaining it, this could be a legit, unappreciated-developer version of a temper tantrum. Nobody seems to know (yet).

But what does XP being EOL'd have to do with anything?

Every version of Windows after XP has a native disk encryption utility. TrueCrypt was built to bring full disk encryption to Windows, which didn't exist at the time - this is the developers way of saying "you don't need us anymore, Windows now does what we did"

Not every version... In case of Vista and 7 only Enterprise and Ultimate editions have it and in case of 8/8.1 you need to have Pro or Enterprise edition.

True, but if you need disk encryption you probably use one of those already.

I mean, a normal use case is a corporate laptop used when traveling or similar. Normal home users certainly have no need of it, for them it's just something else that can go wrong and destroy all their data.

FDE was available from different vendors (I bought DriveCrypt PlusPack more than 15 yr ago and tried CompuSec (free) more than 10 yr ago, Comodo FDE is around since ~2k8). So availability of FDE software can hardly be the reason. Neither the credibility of M$, in matters of quality of code as well as especially being an US based company.

Certainly possible, although this from the audit web page doesn't sound like that would be a big problem:

"Wed, Oct 24, 2013: We have made contact with the TrueCrypt development team. They have stated a commitment to a thorough, independent security audit and cryptanalysis of the code."

Since TC developers were unknown for a long time. Perhaps the audit effort, or someone involved with it, intentionally or not, somehow opened some clue that allowed some 3-letters agency go after the developers and they receive those weird proposals like Lavabit ??

Or the NSA was maintaining it the whole time, and they've just sent everyone to the next best thing for them, because of the coming audit.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.