Thread: Computers Truecrypt may be compromised
View Single Post
Old 05-30-2014, 12:06 PM   #24
planetdoc planetdoc is offline
Veteran
 

Join Date: Apr 2012
Casino cash: $9995865
Quote:
Originally Posted by htismaqe View Post
Then don't use open source software.
With open source software at least people have the opportunity to audit code which one does not have with closed source software. Using closed source software requires trust.

Quote:
Originally Posted by htismaqe View Post
You're stance on this, and multiple threads, seems to border on total paranoia rather than anything even remotely practical.
please clarify.

My stance on Truecrypt is that it may be compromised. That is not paranoia.

What you suggest (that people should independantly audit code for each version) is not practical.

Quote:
Originally Posted by htismaqe View Post
What would your proposed solution be?
proposed solution to truecrypt possibly being compromised?

The Audit of truecrypt has already been paid for, and stage 1 has been completed. Its worthwhile to see what vulnerabilities are found after a complete audit of version 7.1a.

Auditers need to implement a warrant canary in case they receive a NSL to prevent them from disclosing vulnerabilities in 7.1a.

If Truecrypt is found to be vulnerable, than the project should be forked and patched. Till more information is known, users should investigate alternatives.

Last edited by planetdoc; 05-30-2014 at 12:18 PM..
Posts: 2,174
planetdoc has disabled reputation
    Reply With Quote