Author Topic: Something really strange is up with TrueCrypt  (Read 1676 times)

0 Members and 2 Guests are viewing this topic.

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Something really strange is up with TrueCrypt
« on: May 29, 2014, 01:04:52 am »
Apparently, they've officially announced that development is over and that people should migrate to BitLocker (Microsoft's integrated full disk encryption).

http://truecrypt.sourceforge.net/

Of course, nothing is as it seems.

Some insight from the /r/netsec thread:

Quote
TL;DR: Assumption #1 The website is presumed hacked, the keys are presumed compromised, the binary on the website is capable only to decode encrypted data, not encode, and may contain trojan (although I didn't find any, but don't believe me). The binary is signed with the valid (usual) key. All old versions are wiped, the repository is wiped too. Please do not download or run it. And please don't switch to bitlocker.

Latest working version is 7.1a. Version 7.2 is a hoax, although it's signed by a valid key and seems like was built on the usual developer PC (there are some paths like c:\truecrypt-7.2\driver\obj_driver_release\i386\truecrypt.pdb, which were the same for 7.1a).

On the SourceForge, the keys were changed before any TrueCrypt files uploaded, but now they are deleted and the old keys got reverted back.

Why I think so: strange key change, DNS record changed, why bitlocker?

Assumption #2 Something bad happened to TrueCrypt developers (i.e. take down or death) or to TrueCrypt itself (i.e. found the worst vulnerability ever) which made them do such a thing.

Why I think so: all files are with valid signatures, all the releases are available (Windows; Linux x86, x86_64, console versions, Mac OS, sources).

SourceForge sent emails on 22 May, they said they changed password algorithms and everybody should change their passwords.

TrueCrypt developers are unknown and currently there is no way to know who is who and who should we listen to.

From wikileaks twitter https://twitter.com/wikileaks/status/471769936038461440:

    (1/4) Truecrypt has released an update saying that it is insecure and development has been terminated http://truecrypt.sf.net

    (2/4) the style of the announcement is very odd; however we believe it is likely to be legitimate and not a simple defacement

    (3/4) the new executable contains the same message and is cryptographically signed. We believe that there is either a power conflict..

    (4/4) in the dev team or psychological issues, coersion of some form, or a hacker with access to site and keys.

From Matthew Green (one of TrueCrypt auditor) twitter https://twitter.com/matthew_d_green/status/471752508147519488:

    @SteveBellovin @mattblaze @0xdaeda1a I think this is legit.

TrueCrypt Setup 7.1a.exe:

    sha1: 7689d038c76bd1df695d295c026961e50e4a62ea
    md5: 7a23ac83a0856c352025a6f7c9cc1526

TrueCrypt 7.1a Mac OS X.dmg:

    sha1: 16e6d7675d63fba9bb75a9983397e3fb610459a1
    md5: 89affdc42966ae5739f673ba5fb4b7c5

truecrypt-7.1a-linux-x86.tar.gz:

    sha1: 0e77b220dbbc6f14101f3f913966f2c818b0f588
    md5: 09355fb2e43cf51697a15421816899be

truecrypt-7.1a-linux-x64.tar.gz:

    sha1: 086cf24fad36c2c99a6ac32774833c74091acc4d
    md5: bb355096348383987447151eecd6dc0e

Diff between latest version and the hoax one: https://github.com/warewolf/truecrypt/compare/master...7.2

Screenshot: http://habrastorage.org/getpro/habr/post_images/da1/1bf/6a5/da11bf6a5225fa718987ba4e54038fc1.png

See also the HN thread: https://news.ycombinator.com/item?id=7812133

Either this is a full compromise, a false flag psyop to undermine encryption, the developers found a critical security bug and decided to go out with a bang so as to avoid disclosing it and potentially threatening lives, or they got sick of developing the software and so are going out with a bang.

There's also some really interesting speculation that the TrueCrypt devs use a very old Visual C++ version and build system to compile TrueCrypt that is now fully obsoleted with the EOL of Windows XP, and after their inability to port it, decided to just end it all.

Whatever it is, this will be fascinating to watch.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

Offline Zesh

  • Royal Highness
  • ****
  • Posts: 699
  • Cookies: 42
    • View Profile
Re: Something really strange is up with TrueCrypt
« Reply #1 on: May 29, 2014, 01:17:34 am »
Very interesting. Thanks for the share +1.

Offline lucid

  • #Underground
  • Titan
  • **
  • Posts: 2683
  • Cookies: 243
  • psychonaut
    • View Profile
Re: Something really strange is up with TrueCrypt
« Reply #2 on: May 29, 2014, 04:52:54 am »
I knew there was a reason I dropped TrueCrypt.
"Hacking is at least as much about ideas as about computers and technology. We use our skills to open doors that should never have been shut. We open these doors not only for our own benefit but for the benefit of others, too." - Brian the Hacker

Quote
15:04  @Phage : I'm bored of Python

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Something really strange is up with TrueCrypt
« Reply #3 on: May 29, 2014, 05:15:31 am »
Yeah I switched to LUKS full disk encryption a long time ago.
Too many threat models using TrueCrypt.

Offline Oni

  • /dev/null
  • *
  • Posts: 5
  • Cookies: 1
    • View Profile
    • Sinisterly
Re: Something really strange is up with TrueCrypt
« Reply #4 on: May 29, 2014, 05:43:18 am »
Incredibly worrying, considering many people I know rely on Truecrypt. I sure as hell wouldn't trust Bitlocker or anything managed by Microsoft. Like Architect, I think LUKS is much more reliable. Unfortunately, most of the people I know that rely on Truecrypt are using Windows.
« Last Edit: May 29, 2014, 05:44:23 am by Oni »
"We're all mad here. I'm mad. You're mad."


Skype: oni_sl
XMPP: oni-sensei@riseup.net

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: Something really strange is up with TrueCrypt
« Reply #5 on: May 29, 2014, 07:24:43 am »
Damn this is really interesting. If they did decide to drop it all then it's friggin' funny.

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Something really strange is up with TrueCrypt
« Reply #6 on: May 29, 2014, 07:33:21 am »
Either way it looks like the devs officially don't care about maintaining TrueCrypt source. Why? We may never know.

Offline rasenove

  • Baron
  • ****
  • Posts: 950
  • Cookies: 53
  • ಠ_ಠ
    • View Profile
Re: Something really strange is up with TrueCrypt
« Reply #7 on: May 29, 2014, 08:06:57 am »
The fact that TrueCrypt is suggesting people to migrate to BitLocker and the odd nature of their announcement makes me think, NSA is behind this?
My secrets have secrets...

Offline voodoo

  • Serf
  • *
  • Posts: 42
  • Cookies: 4
  • Try Harder
    • View Profile
    • Security Voodoo
Re: Something really strange is up with TrueCrypt
« Reply #8 on: May 29, 2014, 08:32:37 am »
Somewhat of an unexpected event that had some of my coworkers shooting different conspiracy theories back and forth today.  The format of the announcement is what makes it seem odd to me.  Gonna keep my eye on this one.  *puts tin foil hat on*
keep it simple

Offline flowjob

  • Knight
  • **
  • Posts: 327
  • Cookies: 46
  • Pastafarian
    • View Profile
Re: Something really strange is up with TrueCrypt
« Reply #9 on: May 29, 2014, 08:41:05 pm »
Two good comments I found on the reddit thread:
http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_development_has_ended_052814/chtuusa
http://www.reddit.com/r/netsec/comments/26pz9b/truecrypt_development_has_ended_052814/chtm4xp

Changing the "English (U.S.)" to "English (United States)" seemed pretty weird to me too when looking through the diff...
Why would someone do that, when abandoning the project anyway?
Quote
<phil> I'm gonna DDOS the washing machine with clothes packets.
<deviant_sheep> dont use too much soap or youll cause a bubble overflow

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Something really strange is up with TrueCrypt
« Reply #10 on: May 30, 2014, 01:23:25 am »
I guess now we wait for a some type of "This domain has been seized because we're huge cocks over here at NSA" banner.

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Re: Something really strange is up with TrueCrypt
« Reply #11 on: May 30, 2014, 02:00:15 am »
I guess now we wait for a some type of "This domain has been seized because we're huge cocks over here at NSA" banner.

Intelligence agencies aren't responsible for domain seizures.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Something really strange is up with TrueCrypt
« Reply #12 on: May 30, 2014, 03:41:25 am »
Jokes aren't responsible for your interpretation of the humor inside.

Offline Pussy

  • NULL
  • Posts: 3
  • Cookies: 0
  • Content Blocked!
    • View Profile
Re: Something really strange is up with TrueCrypt
« Reply #13 on: May 31, 2014, 07:01:42 am »
Nsa Holds all big companies facebook, yahoo, apple, twitter, etc. and now they wanted to get hold of Truecrypt to hook public encrypted data. The only flaw in truecrypt is NSA, so now Devs are making people aware to of this issue, and yes we should stop using it until further Upgrades.
--------

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: Something really strange is up with TrueCrypt
« Reply #14 on: June 16, 2014, 12:51:51 pm »
Quote
The message on TrueCrypt's new website got me thinking:
Using TrueCrypt is not secure as it may contain unfixed security issues
 
Let's isolate the first letter of each word:
(U)sing (T)rueCrypt (i)s (n)ot (s)ecure (a)s (i)t (m)ay (c)ontain (u)nfixed (s)ecurity (i)ssues
 
Result?
utinsaimcusi
 
Let's spread that!
uti nsa im cu si
 
That is latin for
"If I wish to use the NSA"
 
Stay away from future Truecrypt releases. This is clearly a warning from the developers.
~Factionwars