Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
The Mystery Of The TrueCrypt Encryption Software Shutdown
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
freewill78
50%
50%
freewill78,
User Rank: Apprentice
11/11/2014 | 5:50:21 PM
It is Obvious
Common, for me it is very clear; that government or security agents; could not find a hole and convience truecrypt guys to close it. I am sure microsoft has special holes for bitlocker. Everybody knows; apple, microsoft and big companies share information with national security agent. Gates also stated in an interveiw that they can share information for national benefits.

On the other hand; Me from outside of U.S.  I have no offense on these companies or national security agent; I love microsoft and its products; they are doing great things for the world development progress; and I can make money by help of their products.

 

 

 

 
AbeG
50%
50%
AbeG,
User Rank: Apprentice
6/16/2014 | 10:36:29 PM
Re: TruCrypt users
I can't imagine how any corporation with a responsible IT Department would be able to justify widescale use of truecrypt.  Assuming that no security issues are found with TrueCrypt, it's a great program.  However, it cannot be centraly managed, and for an Enterprise, that alone is usually a deal breaker.

It's hard to get upset with an open source project like this that is loved by many yet funded by few.  It seems as though software development is sharing the same fate as media organizations.  The trend being that high quality content/software should be funded by advertising, except when advertising interferes too much with the product.  In those cases, the product should be free with no advertising.
AbeG
50%
50%
AbeG,
User Rank: Apprentice
6/16/2014 | 10:15:57 PM
Re: TruCrypt users
@shakeeb.  There are a number of alternatives for TrueCrypt.  I ran a search on alternative.to (http://alternativeto.net/software/truecrypt/) and looks like everyone should consider switching over to DiskCryptor.

I thought this was a compelling argument:

"The only open-source alternative to DiskCryptor that has comparable features is TrueCrypt. However, because of the restrictive license under which TrueCrypt is provided — the TrueCrypt Collective License — TrueCrypt cannot be classified as a truly free software, as it places limits on the use and modification of its source code by developers. There are other alternatives with similar functionality, but they are fully proprietary ones, which makes them unacceptable to use for protection of confidential data."
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
6/2/2014 | 2:54:51 PM
Re: Take it at face value
@gev

You wrote: 

"The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images."

What does it mean? Have any idea of the number of downloads collected by TrueCrypt?

 

Do you believe that TrueCrypt users are only XP users?

I believe that there is much more.

 
gev
50%
50%
gev,
User Rank: Moderator
6/2/2014 | 2:45:44 PM
Take it at face value
Right there at the top of the page, it says:

 

The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images.

 

How come the author ignores the simplest explanation?

Because then there would be mistery, and hence no article.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/31/2014 | 10:47:50 PM
Re: http://truecrypt.ch/
I agree, we need to understand that though its difficult to update encryption technologies its very necessary. Think of it as patching a security safeguard. Security tools need to evolve in hopes to combat volatile emergent threats. 
shakeeb
50%
50%
shakeeb,
User Rank: Apprentice
5/31/2014 | 2:47:07 AM
Re: http://truecrypt.ch/
@christianabryant- I feel that these encryption tools need to evolve. Some of them are still in the initial versions (no one has taken steps to upgrade them as the threats increase). 
shakeeb
50%
50%
shakeeb,
User Rank: Apprentice
5/31/2014 | 2:44:36 AM
Re: TruCrypt users
@theb0x – thanks for sharing, does this mean that hackers can't get through without having physical access to the system?
shakeeb
50%
50%
shakeeb,
User Rank: Apprentice
5/31/2014 | 2:42:18 AM
Re: TruCrypt users
It's scary to see how software encryption will no longer help us to protect our data. I wonder what TruCrypt users will do next to ensure their data is kept safe. 
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
5/30/2014 | 6:26:47 PM
http://truecrypt.ch/
I've never used TrueCrypt, but have always been aware of it as a FOSS user and supporter.  I find it interesting how quickly http://truecrypt.ch/ was raised with the seeming intent to continue TrueCrypt as a forked project.  In the FOSS world there is absolutely nothing odd about this; I'm forking a codebase right now, in fact.  But because this is TrueCrypt, one wonders at the motivation for the Swiss team.  I suspect there is a money pile waiting for the right group that can support TrueCrypt as a service provider for those IT shops using the software that would rather stagnate than evolve.  I think the fork is the right thing to do, provided the new team has the needed skills to move the project forward. 

Note:  Search off the phrase "TrueCrypt Developers Association. All rights reserved." and you will find many other projects that include embedded TrueCrypt code.  Food for thought...
Page 1 / 2   >   >>


Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7227
PUBLISHED: 2020-01-18
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, ...
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.