TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

German BSI withholds Truecrypt security report

234 点作者 rffn超过 5 年前

11 条评论

60654超过 5 年前
Note, the title is no longer accurate. There&#x27;s an update at the end of the article, along with a download link:<p>&gt; Shortly before we published this article the BSI has allowed to publish the Truecrypt documents. They can be downloaded from the Frag den Staat web page. Update from December 16th 2019, 13:22
评论 #21803343 未加载
评论 #21803763 未加载
评论 #21803333 未加载
Grumbledour超过 5 年前
It is sad to see the state still making freedom of information requests so difficult and using copyright as a flimsy excuse to hinder citizens to share the information when they finally manage to get it out of them.<p>I find it especially sad to see something like this held back by an entity that claims to want to protect security in information technology and doubly so since this information would be relevant to the developers and many state entities that use the software and its successor.<p>The BSI is sadly often toothless when it comes to actually enforcing security standards on federal entities but to see them not even trying to educate on such matters, when they clearly know better, squanders a lot of trust one may have in them.
评论 #21803363 未加载
评论 #21808576 未加载
评论 #21803611 未加载
评论 #21803903 未加载
jmakov超过 5 年前
&quot;... in the simplest case a user can mount a Truecrypt volume that contains a file with suid root permission that will open a shell. Golem.de was able to replicate this scenario in a current version of Veracrypt.&quot;
评论 #21806424 未加载
评论 #21803830 未加载
评论 #21804131 未加载
评论 #21803784 未加载
评论 #21803647 未加载
cantrevealname超过 5 年前
The casual user stumbling on this article is going to think that TrueCrypt or VeraCrypt has been broken. There’s a big difference between attacks on a live system when a volume is being used, versus cases in which an encrypted volume is lost, stolen, or copied.<p>It needs to be firmly said that there is still <i>no known way</i> to recover plaintext from an unmounted TrueCrypt or VeraCrypt volume on a powered-off system without knowing the pass phrase. TrueCrypt and VeraCrypt are still totally secure for the standard use-case of protecting your powered-off laptop being stolen, or your backup drives being lost, or an encrypted volume that you’ve copied over to Dropbox being compromised.
评论 #21808164 未加载
chmod775超过 5 年前
&gt; As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...]<p>&gt; The BSI knew all that. [...]<p>&gt; The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn&#x27;t consider them to be relevant. BSI furthermore says that the results were not intended to be published.<p>This is looking pretty terrible for Truecrypt. It means they ignored a vulnerability report and kept the vulnerabilities around for five years.
评论 #21803391 未加载
评论 #21803532 未加载
评论 #21803566 未加载
EsssM7QVMehFPAs超过 5 年前
Why would they release an audit that effectively provides them with zero-days into encrypted suspect disks.<p>They release now because no one is using TrueCrypt any longer..
评论 #21803802 未加载
评论 #21804075 未加载
unnouinceput超过 5 年前
I use VeraCrypt and none of this are of my concern in my daily use of it. Can anyone tell me if my containers are still safe from prying eyes since I upload them to cloud? I need specific answers from anyone working on VeraCrypt, not general answers of &quot;yeah, they are unsafe&quot; that usually HN does.
评论 #21807334 未加载
评论 #21806702 未加载
pushedx超过 5 年前
Is there a solid alternative to TrueCrypt with most of the features that’s been implemented with a proof-checking system such as OcaML Mirage?
kjaftaedi超过 5 年前
If you&#x27;re going to comment, it&#x27;s highly preferable that you read the article where all of this is explained.
评论 #21804563 未加载
评论 #21803926 未加载
评论 #21803834 未加载
onetimemanytime超过 5 年前
Much safer to assume that a decent nation state can decrypt Truecrypt and a lot of other things. You can hide stuff from your wife, friends or banana Republic countries, but I wouldn&#x27;t bet against NSA with 30 years in jail.
评论 #21803977 未加载
intc超过 5 年前
FWIF: <a href="https:&#x2F;&#x2F;truecrypt.ch&#x2F;" rel="nofollow">https:&#x2F;&#x2F;truecrypt.ch&#x2F;</a>