Encryption Site TrueCrypt Shuts Down Amid Speculation and Conspiracy Theoriesby Sabina Laska @ 2014-05-29 03:29 PM
Open-source encryption program TrueCrypt appears to have been compromised, with a strange website update warning users that the product was no longer secure and distributing a new version of the software that some analysts called suspicious.
“WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues,” an update posted on the encryption suite’s site said, followed by instructions to help users migrate data encrypted by TrueCrypt to BitLocker, another full-disk encryption program that comes included with current Windows operating systems .
The termination was apparently triggered after Microsoft ended support for Windows XP, as the developers’ statement implied the change instigated security problems with the TrueCrypt program.
“The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP,” the message on the program’s homepage at sourceforge.net read. “You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform.”
The TrueCrypt site is now offering downloads of a new version of the software, 7.2, but journalists have noted irregularities about the source code.
British IT news site The Register reported:
“A binary TrueCrypt 7.2 installer for Windows, downloaded from the TrueCrypt SourceForge site, contained the same text found on the rewritten homepage – confirming the download has also been fiddled with amid today’s website switcheroo.”
The story also linked to “an eyebrow-raising list of changes” between the source code of version 7.2 and the previous release, 7.1a.
The new software did not appear to contain malware, however, with some experimenting users saying the program only opened a warning not to use TrueCrypt and refused to encrypt data – only decrypt it.
Still, software developer Jonathan Zdziarski, who worked as a cryptographer on the TrueCrypt project warned against using the new version – or the old ones, for that matter.
Zdziarski wrote on Twitter:
“If TrueCrypt.org is compromised, it’s likely been compromised a good while. I wouldn’t trust any recent downloads of the software.”
TrueCrypt statement and software still unconfirmed
The authenticity of the statement on the TrueCrypt site, as well as the new software, has not yet been confirmed, though the developers of the encryption suite have still yet to come forward with more detail about the change.
Kenn White, of the crowdfunded project that has been working on auditing on TrueCrypt’s code, said that the audit project had no new information on the shutdown.
“No one on the TC audit project has anything to do with its development or the TC site,” he tweeted. “We will share any credible updates with the community.”
White added that the audit project had contacted the TrueCrypt development team and were waiting for a response. The audit team, tweeting under the handle @OpenCryptoAudit, also said it would make an announcement Thursday on their work and the future of the audit.
Public reaction largely of disbelief
The Internet community, meanwhile, quickly expressed incredulity about the announcement, with Reddit users exclaiming it “just reeks of fishiness” and that the “wording and vagueness” of the statement raised red flags.
Speculation in the Reddit thread on the reasons for the shutdown range from a simple hack attack to conspiracy theories that the developers have been served with a subpoena from the US government to enable a back door into the program.
Lavabit, a security-minded email provider that was a favorite of former security contractor Edward Snowden, was forced to shut down in a similar manner last August, citing pressure from the US government to provide information about its clients.
Until more detail comes through about the nature of and reasons for the shutdown, however, the rumors and speculation will remain just that.
- 2014-10-28 03:44 PM
‘It is Impossible to Technically Ban Decentralized Cryptocurrencies Due to the Nature of the Internet’ – Evgeny Volovik. Evgeny Volovik is the head of the Information and Communication Department at Russia’s Federal Financial Monitoring Service Resource Center. By Allen Scott
- 2014-10-28 12:58 PM
4 Reasons Why Economists Should Love Bitcoin. I studied economics and this doesn’t make sense to me. From an academic standpoint all I see is vast potential for this technology. Here are the top 4 reasons why economists should love Bitcoin: By Kenny Spotz
- 2014-10-28 01:33 PM
IRS Seizes Assets on Suspicion Only: Bitcoin could be Next. The law, known as “civil asset forfeiture” was structured to not only track deposits made by suspected criminals but to seize them as well. But anyone who knows how bureaucracies operate knows that la By Carlo Caraluzzo
- 2014-10-29 01:53 AM
Bittrex To Drop BlackCoin and Litecoin Pairs. Popular exchange Bittrex was experimenting with Blackcoin pairs, but today they announced they will be dropping both BlackCoin and Litecoin pairs. By Ian DeMartino
- 2014-10-28 10:12 AM