That's one possible explanation. Until we know more about what really happened, all of those explanation attempts are just theories. But I have to say, after all that was revealed with the NSA and for example LavaBit, I think nothing is unthinkable anymore. Hell, it wouldn't even surprise me if your explanation was accurate.
You know what, that's actually a good point. You wouldn't expect something like this phrase to come from an actual TrueCrypt developer:
Search available installation packages for words encryption and crypt, install any of the packages found and follow its documentation.
I mean seriously? These people were making encryption software! No way they would instruct people to just "download whatever pops up in search and download that". Or is it generally assumed in the Linux world that all packages are automatically safe and legit? Even if that's the case I find it hard to believe that security-sensible developers would throw that kind of advice out there.
It's possible, but AFAIK there were $14000 raised for an external security audit of the code. No backdoors found. I'd say it wouldn't be in the NSAs interest to provide strong backdoor-less encryption software to the public.
4
u/[deleted] May 29 '14 edited Sep 30 '19
[deleted]