TrueCrypt 'decrypted' by FBI to nail doc-stealing sysadmin?
theregister.co.uk
theregister.co.uk
TrueCrypt like many other FDE's has 2 keys, your Data Encryption Key which is generated by the software using random values, and your Key Encryption Key which is generated from a pass phrase and no random data since it has to be generated every time.
The KEK is generated using a key derivation function most commonly PBKDF2, this is by far the easiest vector to attack because this vector is vulnerable to 2 fairly easy attacks.
Brute force against the KDF which generated the KEK and brute force against the user which generated the pass phrase.
Bad entropy or not the FBI will not be breaking AES anytime soon heck if AES can be broken atm with entropy as bad as some rolling a D20 the US government won't use it because you can be sure that some implementations of it in use by the USG have probably even shittier pseudo random number generators than that...
Why no one is wrapping their sensitive hardware in termite or booby trapping them, I cannot understand.
There are really only three angles to explore here:
* The guy flipped. Open and shut case. This implies the world is boring. It's more fun to assume this isn't the case.
* Truecrypt has some fundamental state-planted problem. Though the post-closing audits found nothing particularly damning [1]. We really need a non-technical audit of Truecrypt though. Certainly something happened there with a three letter agency. They wouldn't just shut down without any actual reason. Who is a tech-journalist I can send an email to? I'd like to reach out and ask them to try to get in contact with all of the Truecrypt top contributors. At least some of them have to be outside US jurisdiction. I feel like someone has to have already explored this angle, though. Can someone kindly link me to a full history of their VCM? A 5 minute google turned up short for me-- I could find a lot of mirrors of the latest source and binaries but none with the full history. Perhaps we're looking at the wrong place. Another angle is that Truecrypt itself was cryptographically sound (and thus an audit wouldn't find anything) but instead the developers found evidence that Windows itself was undermining encryption done through it. They privately reached out and got gagged.
* We collectively have underestimated the cracking abilities of the FBI/NSA. They hire amazing cryptographers. I'm too lazy to look up anything to back this up, but I would wager they even employ the majority of people in the US working on quantum computing (and thus quantum-crackers). Excluding universities this is almost certainly true. I was asking on ##crypto a few months ago about what was going on with bleeding-edge quantum computing and the people in the channel seemed to think that we weren't even close to 1024 qubbit quantum computers. But given that so much of the talent is under security clearances, I can't imagine we have a great idea of what's really going on in that field. Perhaps they can crack everything we currently do. An interesting project idea is for someone to implement some of the post-quantum algorithms [2]. Even if your implementation is faulty or the theory is incorrect, it would not hurt to use these and encrypt on top of what we're already doing. They probably won't make sense for day-to-day encryption for boring folk, but performance concerns are secondary for our journalists and whistleblowers.
My real guess on what happened here? A mix of the three. I would guess our sysadmin messed up somewhere and left incomplete evidence of his keys, or that truecrypt itself did this. I would guess FBI/NSA was able to use this and their supercomputers to put the pieces together.
I want to read more about what is physically impossible with regards to cryptography. When I took my discrete mathematics class a few years ago we got into this, but I've honestly forgotten a lot of the details. Eg: If every atom in the universe could hold 1tb and we had boundless computational power, could we generate rainbow tables to defeat our current cryptography. Etc.
[1]: http://istruecryptauditedyet.com/
[2]: https://en.wikipedia.org/wiki/Post-quantum_cryptography#Algo...
I always wonder about this: in order to decrypt a file/volume encrypted by TrueCrypt, user just need to type their NOT-SO-LONG password. With today's capability such as EC2 or quantum computing as you mentioned, isn't that just minutes away to crack a 12 digi password?
>>> (126-31)**12
540360087662636962890625
How many years would this take if you could test each password in .0000000000001s? >>> (((126-31)**12)*.0000000000001)/60/60/24/7/365
244.78151394444308True Crypt also implements xor-encrypt-xor which means you don't only need to know where the data is but also to which blocks it was written to and what as int the adjacent blocks. Later versions of TrueCrypt implemented XTS which even made this more "complicated" to guess, especially when you tried intentionally to attack the block cipher by flooding it with data that you expect to be padded in a predictable manner.
I'm sorry but i for once would be really surprised if the US government or any other entity has actual cryptographic attacks against modern encryption standards that do not involve engineered back doors (And things like the ECC fiasco doesn't count since it's pretty unlikely that even with knowing the seed values the NSA could actually decrypt anything) into the cryptography software or the system in general.
They can and do of course attack the weak links and go after the users and their keys and password when they are vulnerable to be stolen.