Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
The Mystery Of The TrueCrypt Encryption Software Shutdown
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
freewill78
freewill78,
User Rank: Apprentice
11/11/2014 | 5:50:21 PM
It is Obvious
Common, for me it is very clear; that government or security agents; could not find a hole and convience truecrypt guys to close it. I am sure microsoft has special holes for bitlocker. Everybody knows; apple, microsoft and big companies share information with national security agent. Gates also stated in an interveiw that they can share information for national benefits.

On the other hand; Me from outside of U.S.  I have no offense on these companies or national security agent; I love microsoft and its products; they are doing great things for the world development progress; and I can make money by help of their products.

 

 

 

 
AbeG
AbeG,
User Rank: Apprentice
6/16/2014 | 10:36:29 PM
Re: TruCrypt users
I can't imagine how any corporation with a responsible IT Department would be able to justify widescale use of truecrypt.  Assuming that no security issues are found with TrueCrypt, it's a great program.  However, it cannot be centraly managed, and for an Enterprise, that alone is usually a deal breaker.

It's hard to get upset with an open source project like this that is loved by many yet funded by few.  It seems as though software development is sharing the same fate as media organizations.  The trend being that high quality content/software should be funded by advertising, except when advertising interferes too much with the product.  In those cases, the product should be free with no advertising.
AbeG
AbeG,
User Rank: Apprentice
6/16/2014 | 10:15:57 PM
Re: TruCrypt users
@shakeeb.  There are a number of alternatives for TrueCrypt.  I ran a search on alternative.to (http://alternativeto.net/software/truecrypt/) and looks like everyone should consider switching over to DiskCryptor.

I thought this was a compelling argument:

"The only open-source alternative to DiskCryptor that has comparable features is TrueCrypt. However, because of the restrictive license under which TrueCrypt is provided — the TrueCrypt Collective License — TrueCrypt cannot be classified as a truly free software, as it places limits on the use and modification of its source code by developers. There are other alternatives with similar functionality, but they are fully proprietary ones, which makes them unacceptable to use for protection of confidential data."
securityaffairs
securityaffairs,
User Rank: Ninja
6/2/2014 | 2:54:51 PM
Re: Take it at face value
@gev

You wrote: 

"The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images."

What does it mean? Have any idea of the number of downloads collected by TrueCrypt?

 

Do you believe that TrueCrypt users are only XP users?

I believe that there is much more.

 
gev
gev,
User Rank: Moderator
6/2/2014 | 2:45:44 PM
Take it at face value
Right there at the top of the page, it says:

 

The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images.

 

How come the author ignores the simplest explanation?

Because then there would be mistery, and hence no article.
RyanSepe
RyanSepe,
User Rank: Ninja
5/31/2014 | 10:47:50 PM
Re: http://truecrypt.ch/
I agree, we need to understand that though its difficult to update encryption technologies its very necessary. Think of it as patching a security safeguard. Security tools need to evolve in hopes to combat volatile emergent threats. 
shakeeb
shakeeb,
User Rank: Apprentice
5/31/2014 | 2:47:07 AM
Re: http://truecrypt.ch/
@christianabryant- I feel that these encryption tools need to evolve. Some of them are still in the initial versions (no one has taken steps to upgrade them as the threats increase). 
shakeeb
shakeeb,
User Rank: Apprentice
5/31/2014 | 2:44:36 AM
Re: TruCrypt users
@theb0x – thanks for sharing, does this mean that hackers can't get through without having physical access to the system?
shakeeb
shakeeb,
User Rank: Apprentice
5/31/2014 | 2:42:18 AM
Re: TruCrypt users
It's scary to see how software encryption will no longer help us to protect our data. I wonder what TruCrypt users will do next to ensure their data is kept safe. 
RetiredUser
RetiredUser,
User Rank: Ninja
5/30/2014 | 6:26:47 PM
http://truecrypt.ch/
I've never used TrueCrypt, but have always been aware of it as a FOSS user and supporter.  I find it interesting how quickly http://truecrypt.ch/ was raised with the seeming intent to continue TrueCrypt as a forked project.  In the FOSS world there is absolutely nothing odd about this; I'm forking a codebase right now, in fact.  But because this is TrueCrypt, one wonders at the motivation for the Swiss team.  I suspect there is a money pile waiting for the right group that can support TrueCrypt as a service provider for those IT shops using the software that would rather stagnate than evolve.  I think the fork is the right thing to do, provided the new team has the needed skills to move the project forward. 

Note:  Search off the phrase "TrueCrypt Developers Association. All rights reserved." and you will find many other projects that include embedded TrueCrypt code.  Food for thought...
Page 1 / 2   >   >>


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Improving Enterprise Cybersecurity With XDR
Enterprises are looking at eXtended Detection and Response technologies to improve their abilities to detect, and respond to, threats. While endpoint detection and response is not new to enterprise security, organizations have to improve network visibility, expand data collection and expand threat hunting capabilites if they want their XDR deployments to succeed. This issue of Tech Insights also includes: a market overview for XDR from Omdia, questions to ask before deploying XDR, and an XDR primer.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-32284
PUBLISHED: 2022-07-04
Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet.
CVE-2022-33208
PUBLISHED: 2022-07-04
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sy...
CVE-2022-33948
PUBLISHED: 2022-07-04
HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.
CVE-2022-33971
PUBLISHED: 2022-07-04
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an ...
CVE-2022-34151
PUBLISHED: 2022-07-04
Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studi...