Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Phase 2 of the TrueCrypt audit is completed
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Phase 2 of the TrueCrypt audit is completed

shivshiv Member

April 2, 2015: Phase II analysis is completed and, pending an executive summary, TrueCrypt is Audited.

Open Crypto Audit Project - https://opencryptoaudit.org/

Link to report in pdf - https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_OCAP_final.pdf

tl;dr from Matthew Green's blog

Based on this audit, Truecrypt appears to be a relatively well-designed piece of crypto software. The NCC audit found no evidence of deliberate backdoors, or any severe design flaws that will make the software insecure in most instances.

That doesn't mean Truecrypt is perfect. The auditors did find a few glitches and some incautious programming -- leading to a couple of issues that could, in the right circumstances, cause Truecrypt to give less assurance than we'd like it to.

Going to continue using Truecrypt although Veracrypt is promising.

Thanked by 2netomx KwiceroLTD

Comments

  • I wonder if the audit team got a National Security Letter.

    Thanked by 1netomx
  • 4n0nx4n0nx Member

    Gunter said: I wonder if the audit team got a National Security Letter.

    I wonder if the original author of truecrypt got a NSL

  • MaouniqueMaounique Host Rep, Veteran
    edited April 2015

    4n0nx said: I wonder if the original author of truecrypt got a NSL

    That is almost certain. Nobody would work on such a software, then say it is insecure and recommend closed source instead. If there were any doubts, now everyone knows bitlocker is backdoored, and where there is a government backdoor, there is a big chance, not only the government knows about it.
    Let's see what comes out from the fork at truecrypt.ch. If NSA sues for copyright infringement, we know who shut it down :P

Sign In or Register to comment.