TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

TrueCrypt must not die

207 pointsby joshcrewsalmost 11 years ago

14 comments

buddylwalmost 11 years ago
Also, it appears someone finally got a hold of a Truecrypt dev. The project was just shut down from lack of interest. No drama about auditing or, crazy NSA conspiracies after all: <a href="https://twitter.com/stevebarnhart/status/472203503478509568" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;stevebarnhart&#x2F;status&#x2F;472203503478509568</a><p>Edit: That tweet was deleted for some reason, but the rest of the thread is still there: <a href="https://twitter.com/stevebarnhart/status/472192457145597952" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;stevebarnhart&#x2F;status&#x2F;472192457145597952</a>
评论 #7820026 未加载
评论 #7820827 未加载
评论 #7820333 未加载
评论 #7820885 未加载
评论 #7820469 未加载
评论 #7820090 未加载
评论 #7820148 未加载
评论 #7821275 未加载
tptacekalmost 11 years ago
It would be nice if the people who pick up and run with the &quot;reboot&quot; of Truecrypt&#x27;s project management had a background in cryptography. Do these people?
评论 #7820171 未加载
评论 #7820591 未加载
callahadalmost 11 years ago
I don&#x27;t believe the TrueCrypt license allows this kind of redistribution, does it?<p>Then again, with anonymous developers and unknown jurisdiction, it may be moot.
评论 #7820004 未加载
评论 #7819897 未加载
评论 #7820530 未加载
评论 #7819905 未加载
bitJerichoalmost 11 years ago
My opinion, the fact that some security researcher was going to be getting more money than the actual developer ever made off the project must have been infuriating. I think that&#x27;s good enough reason to burn the project to the ground.
评论 #7822473 未加载
voltagex_almost 11 years ago
The signatures and binaries are not served over HTTPS. It would be prudent to compare them to other sources.
评论 #7819868 未加载
评论 #7820535 未加载
评论 #7821056 未加载
nhaydenalmost 11 years ago
This looks like a bootstrap site that was thrown together in an hour by two guys with twitter accounts and $10 for a domain name. I really doubt they&#x27;re going to be doing any dev work.
评论 #7820129 未加载
评论 #7820231 未加载
100rsaalmost 11 years ago
Still have no idea what&#x27;s the &quot;unfixed security issues&quot;, and few guys mention about it. I image there the &quot;security issues&quot; will be (if it exist): 1. because key are easy to stolen by coolboot or trojan. 2. because it has backdoor, will save key to a hidden place. 3. because it will leave some information in other place, like 2 but it&#x27;s implantation problem. 4. because it use a vulnerable algorithm to generate key. 5. because pbkdf2 or aes256 is <i>broken</i> but nobody known it. exclude 2 and 3, change to other software it&#x27;s not help at all, algorithm almost same.
评论 #7821337 未加载
Istofalmost 11 years ago
if the developers of Truecrypt are anonymous and the license doesn&#x27;t allow something like this, would this allow us to find out who the developers are if they sue?
评论 #7820155 未加载
评论 #7823513 未加载
throwaway7767almost 11 years ago
Honestly, I was hoping this drama would result in the implementation of hidden containers for other crypto solutions (dm-crypt, etc).<p>Hopefully that may still happen.
评论 #7821238 未加载
Sir_Cmpwnalmost 11 years ago
This is a bad idea. TrueCrypt should be put to bed for good. An event of this magnitude is easy justification for dropping TrueCrypt. It serves an extremely delicate purpose and this raises far too many red flags to ignore.<p>Place your energy in the alternatives. I wish you could downvote things on HN, if only because this is downright dangerous and needs to be read by as few people as possible.
评论 #7820200 未加载
评论 #7820188 未加载
评论 #7820191 未加载
Paul12345534almost 11 years ago
I would love to see it live on with no new unneeded features, no changes made unless they are to fix bugs. Keep a stable long-term product and get as many people as possible looking over that code for flaws.
christianbryantalmost 11 years ago
Search off the phrase &quot;TrueCrypt Developers Association. All rights reserved.&quot; and you will find many other projects that include embedded TrueCrypt code. Food for thought...
readalmost 11 years ago
<i>Anonymous development on a security relevant Project is no longer an option.</i><p>Why not?
评论 #7821229 未加载
thought_alarmalmost 11 years ago
Why don&#x27;t you send TrueCrypt.org a few dollars then?
评论 #7820372 未加载