Yes, I can confirm that F0D6B1E0 was on the Truecrypt web site about a year or two ago, since it's been on my keyring for at least that long. I've installed Truecrypt multiple times over the past few years, and have always used this key to verify (or its signing subkey, I suppose).
Don't just trust my SHA1s, verify with the sigs and the TrueCrypt Foundation public key. Ensure the key has the fingerprint shown in the great-great-great grandparent of this comment, independently verified by others in this thread.
gpg: Signature made Tue 07 Feb 2012 12:45:26 PM PST using DSA key ID F0D6B1E0
gpg: Good signature from "TrueCrypt Foundation <contact@truecrypt.org>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: C5F4 BAC4 A7B2 2DB8 B8F8 5538 E3BA 73CA F0D6 B1E0
Comments
Same key as the previous binaries? I doubt it, given that the keys were replaced mere 3 hours before the new binaries were published:
http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...
Anyone have key fingerprints for pub keys used for the 7.1a vs 7.2 signing? Preferably pub key from a while ago I guess.
This looks like the previous key: https://github.com/DrWhax/truecrypt-archive/blob/master/True...
Besides the different file name, the contents of the files match: http://www.diffchecker.com/szpb500v
Yes, I can confirm that F0D6B1E0 was on the Truecrypt web site about a year or two ago, since it's been on my keyring for at least that long. I've installed Truecrypt multiple times over the past few years, and have always used this key to verify (or its signing subkey, I suppose).
There's a "TrueCrypt Foundation" key on the keyservers from 2004, the ID is E3BA73CAF0D6B1E0.
The time stamp on key servers can not be trusted. Anyone can spoof keys in anyone elses name, with any timestamp they want.
The only way to verify is if you have the previous key stored somewhere, or can find a trustpath to it.
I have the key stored in my local keychain:
E3BA73CAF0D6B1E0 C5F4 BAC4 A7B2 2DB8 B8F8 5538 E3BA 73CA F0D6 B1E0
Checks out.
I have 7.1a binaries, source, sigs and pub key from September 2013.
My version from September is identical to the pub key at http://sourceforge.net/projects/truecrypt/files/TrueCrypt/Ot... .Could you post the SHA1s of those? I'm failing to use GPG properly.
Can you please make these available for download, the Linux ones at least?
All of the files available here: http://truecrypt.ch/ have the same hashes as provided by this person.
Don't just trust my SHA1s, verify with the sigs and the TrueCrypt Foundation public key. Ensure the key has the fingerprint shown in the great-great-great grandparent of this comment, independently verified by others in this thread.
You should see:Thanks!