Skip to content

Comment on TrueCrypt, the final release, archive

Comments

The writing style in this letter is completely different from that on the TrueCrypt page. If this letter had been posted originally, the whole episode would have been viewed much differently. And why does the author of this letter assure readers that "As far as we know, TrueCrypt is utterly uncrackable", while the TrueCrypt.org page (or rather, the truecrypt.sourceforge.net page to which it redirects) screams (in red at the very top), "WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues"?

EDIT: Sorry - as brazzy and NickSharp kindly point out below, the letter was imagined and written by Steve Gibson. As the HN title at the moment is "One of the TrueCrypt Devs Responded", I missed that.

Misunderstanding aside, these two statements are not really incompatible:

-"As far as we know, TrueCrypt is utterly uncrackable"

-"WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues"

It makes sense to post such a warning to a product with no known vulnerabilities, if it's to remain unsupported. What if a bug becomes public tomorrow? Are you going to keep current with the news and analyze allegations, despite having given up supporting the tool? These crypto attacks are often pretty hard to understand...

Are you talking about the imagined letter that is, uh, not actually from the Truecrypt devs?

Sorry - completely missed that. The title of the HN post at the moment is "One of the TrueCrypt Devs Responded".

I believe you are referring to the "imaginary letter" linked to in that post. As stated, that link is speculation, not an actual response from the devs.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.