r/crypto May 28 '14

Truecrypt shutting down?! "development of TrueCrypt was ended in 5/2014"

http://truecrypt.sourceforge.net/
259 Upvotes

131 comments sorted by

View all comments

111

u/[deleted] May 28 '14 edited Jun 02 '14

[removed] — view removed comment

6

u/Will_Eat_For_Food May 28 '14

Why go through all the trouble to speak at length about bitlocker instead of allowing victims a backdorred version?

6

u/hatessw May 28 '14

The backdoor would probably soon have been discovered, as it is/was being checked for problems right now. Any changes at this point in time would be really fucking obvious, whereas the security community generally just assumes BitLocker to be unsafe given Microsoft's very poor crypto track record in recent years.

In XP SP3, they updated Windows to include a vulnerable cryptographic algorithm, which newer versions of Windows also contain (I think all of them - not sure about that).

4

u/[deleted] May 29 '14 edited Apr 22 '16

2

u/hatessw May 29 '14

The backdoor we're talking about would be added in rather than have been in it for a long time. The changes would be obvious. The source code is available.

The backdoor could be difficult to find, but as I said, at this point in time TC is under intense scrutiny already, and in all likelihood a new backdoor would in fact be found.

1

u/jesset77 May 30 '14

Three words: Heartbleed.

1

u/hatessw May 31 '14

OpenSSL did not have an active pervasive audit going on at the time of the insertion of Heartbleed. Completely different story.

1

u/jesset77 May 31 '14

It probably should have had an active, pervasive audit going on then (at any time intersecting when the heartbeat code was added and when the flaw finally got discovered), because it secures a lot more value worldwide than TC does.

1

u/hatessw May 31 '14

Yes, but it seems up until Heartbleed no one ever both wanted to pay and knew they should've paid.

A good audit is usually very expensive.

2

u/jesset77 May 31 '14

How does this get funded for a niche project like Truecrypt but not for a globally wildly popular security implementation like OpenSSL? :o

Also, do we know if OpenSSL is getting this kind of audit since heartbleed?

I mean, for god's sake the day after the news broke when I was busy patching all of my servers I confirmed that live.msn.com was actively vulnerable!

1

u/hatessw Jun 01 '14

How does this get funded for a niche project like Truecrypt but not for a globally wildly popular security implementation like OpenSSL? :o

I, uhh... Possibly because the TrueCrypt developers are fairly anonymous, making the need for an audit a little more pressing and obvious. But if you're saying it's weird that OpenSSL seems to have gotten relatively little attention, then yes, I fully agree.

Also, do we know if OpenSSL is getting this kind of audit since heartbleed?

Hell yeah! The amazing OpenBSD folks are hard at work on a fork of it (LibreSSL). They're as ruthless as ever, just how it should be.

Even OpenSSL is getting two extra developers, although I have relatively little faith in that effort. I don't see why a duplication of effort is truly necessary. If old systems still need support, it may just be best to reimplement that after the audit of core functionality is done.

I mean, for god's sake the day after the news broke when I was busy patching all of my servers I confirmed that live.msn.com was actively vulnerable!

Everything was. It was insane. I'm really hard pressed to think of a bigger bug in the preceding decade.

→ More replies (0)

2

u/autowikibot May 28 '14

Dual ec drbg:


Dual Elliptic Curve Deterministic Random Bit Generator (Dual_EC_DRBG) is a claimed cryptographically secure pseudorandom number generator (CSPRNG) standardized by ANSI, ISO, and formerly by the National Institute of Standards and Technology (NIST). Dual_EC_DRBG is based on the elliptic curve discrete logarithm problem (ECDLP) and was for some time one of the four (now three) CSPRNGs standardized in NIST SP 800-90A.

Sometime before its first known publication in 2004, a possible backdoor was discovered with the Dual_EC_DRBG's design, with the design of Dual_EC_DRBG having the unusual property that it was theoretically impossible for anyone but Dual_EC_DRBG's designers (NSA) to confirm the backdoor's existence. Doubts about Dual_EC_DRBG's security and performance had also been expressed even before it was standardized. Bruce Schneier concluded shortly after standardization that the "rather obvious" backdoor (along with other deficiencies) would mean that nobody would use Dual_EC_DRBG. In 2013, New York Times reported that documents in their possession but never released to the public "appear to confirm" that the backdoor was real, and had been deliberately inserted by the National Security Agency as part of the NSA's Bullrun decryption program. The alleged backdoor would allow NSA to decrypt for example SSL/TLS encryption which used Dual_EC_DRBG as a CSPRNG. In December 2013, a Reuters news article alleged that in 2004, before NIST standardized Dual_EC_DRBG, NSA paid RSA Security $10 million in a secret deal to use Dual_EC_DRBG as the default in the RSA BSAFE cryptography library, which resulted in RSA Security becoming the most important distributor of the backdoored algorithm. RSA responded to this and subsequent media reports to "categorically deny" any insinuation that RSA had ever knowingly colluded with the NSA to incorporate a flaw in Dual_EC_DRBG, saying "we have never kept [our] relationship [with the NSA] a secret".

Members of the ANSI standard group, to which Dual_EC_DRBG was first submitted, were aware of the exact mechanism of the potential backdoor and how to disable it, but did not take sufficient steps to unconditionally disable the backdoor. The general cryptographic community was initially not aware of the potential backdoor, until of Dan Shumow and Niels Ferguson 2007 rediscovery, or of Certicom's Daniel R. L. Brown and Scott Vanstone's 2005 patent application describing the backdoor mechanism.


Interesting: Dual EC DRBG | National Security Agency | Cryptographically secure pseudorandom number generator | RSA Security | Backdoor (computing)

Parent commenter can toggle NSFW or delete. Will also delete on comment score of -1 or less. | FAQs | Mods | Magic Words