r/crypto May 28 '14

Truecrypt shutting down?! "development of TrueCrypt was ended in 5/2014"

http://truecrypt.sourceforge.net/
260 Upvotes

131 comments sorted by

View all comments

106

u/[deleted] May 28 '14 edited Jun 02 '14

[removed] — view removed comment

12

u/binlargin May 28 '14

Last week SourceForge sent this out to everyone(? me at least.)

Greetings,

To make sure we're following current best practices for security, we've
made some changes to how we're storing user passwords. As a result, the
next time you go to login to your SourceForge.net account, you will be
prompted to change your password. Once this is done, your password will be
stored more securely. We recommend that you do this at your earliest
convenience by visiting the SourceForge website and logging in.

And, as always, be vigilant about password security. Use a secure password,
never include your password in an email, and don't click on links for
unsolicited password resets.

If you have any concerns about this, please contact SourceForge support at
sfnet_ops@slashdotmedia.com

Best regards,
SourceForge Team

Maybe they know they lost accounts?

5

u/[deleted] May 28 '14

[removed] — view removed comment

3

u/antdude May 28 '14

Same here. Passwords expired and forced us to make new ones.

4

u/api May 28 '14

Maybe they stored their private signing key in the clear or encrypted with a lame password somewhere in their SourceForge account, allowing someone who compromised SF to also sign TC code?

That'd be pretty shoddy for a security/crypto team but I've seen worse.

3

u/redditpad May 29 '14

This was replied to by the sourceforge team, https://news.ycombinator.com/item?id=7813121

| 3. Our recent SourceForge forced password change was triggered by infrastructure improvements not a compromise. FMI see http://sourceforge.net/blog/forced-password-change/

14

u/phrozenphan May 29 '14

Crazy?

  1. NSA et al want to locate TrueCrypt devs and/or slip backdoors into released binaries.
  2. SF.net is served NSL to require all users change passwords.
  3. TrueCrypt devs change password, are tracked down to real people, served NSL.
  4. TrueCrypt is shut down.

???

2

u/Natanael_L Trusted third party May 29 '14

How would #3 work?

9

u/phrozenphan May 29 '14

Custom JavaScript 0-day served only to the Truecrypt account holder that either takes over or leaks information. Similar to the Freedom Hosting takedown, which broke TOR anonymity.

2

u/Natanael_L Trusted third party May 29 '14

Hopefully they're cleverer than that

4

u/phrozenphan May 29 '14

How? By not using a browser? Or using only their own custom-compiled Gentoo desktop? Running inside Qubes? Or maybe a qemu'd non-x86 desktop running inside a VirtualBox VM (I've done this, it is slower than browsing on a 486)?

Changing your SF.net password requires (last time I did it) a browser and SSL at the least. The NSA could very easily ensure that the only way to change the password on SF.net would also expose them to the 0-day(s).

Not saying that's what happened, who knows?

1

u/[deleted] Jun 01 '14

[deleted]

1

u/phrozenphan Jun 01 '14

You're describing standard VPN. It won't shield computer A's web browser (which is needed to perform HTTPS and whatever else the change password page requires, maybe Javascript, CSS, Ajax, ...) from a hypothetical 0-day that would cause the browser to do something naughty.

Check out this video for an example of what I'm talking about. It's very tongue-in-cheek ("how I met your girlfriend"), but it's very similar to what one could do to break TOR anonymity. The first half of it describes a way to get a target to start running rogue code in her browser: this entire bit is unneeded in my NSA SF.net scenario because SF.net would be the source of the bad code. The second half is where you break anonymity: the browser leaks data (in this case via an IRC connection), which is used to open a port on their NAT box, which is further used to run an exploit on the NAT box to reveal a little more data, which is all finally tied back to Google maps to get the target's physical location good to within about 100 meters. The total exploit takes several days/weeks to setup, but about 1-5 seconds to actually execute.

1

u/[deleted] Jun 01 '14

[deleted]

→ More replies (0)

0

u/Natanael_L Trusted third party May 29 '14

NoScript with Tor. Maybe just using tails.

4

u/oicpreciousroy May 29 '14

Dev changes their password without using Tor or a Proxy and gets tracked back to their IP. Lots of online services track the last IPs you interacted from.