There are really only three angles to explore here:
* The guy flipped. Open and shut case. This implies the world is boring. It's more fun to assume this isn't the case.
* Truecrypt has some fundamental state-planted problem. Though the post-closing audits found nothing particularly damning [1]. We really need a non-technical audit of Truecrypt though. Certainly something happened there with a three letter agency. They wouldn't just shut down without any actual reason. Who is a tech-journalist I can send an email to? I'd like to reach out and ask them to try to get in contact with all of the Truecrypt top contributors. At least some of them have to be outside US jurisdiction. I feel like someone has to have already explored this angle, though. Can someone kindly link me to a full history of their VCM? A 5 minute google turned up short for me-- I could find a lot of mirrors of the latest source and binaries but none with the full history. Perhaps we're looking at the wrong place. Another angle is that Truecrypt itself was cryptographically sound (and thus an audit wouldn't find anything) but instead the developers found evidence that Windows itself was undermining encryption done through it. They privately reached out and got gagged.
* We collectively have underestimated the cracking abilities of the FBI/NSA. They hire amazing cryptographers. I'm too lazy to look up anything to back this up, but I would wager they even employ the majority of people in the US working on quantum computing (and thus quantum-crackers). Excluding universities this is almost certainly true. I was asking on ##crypto a few months ago about what was going on with bleeding-edge quantum computing and the people in the channel seemed to think that we weren't even close to 1024 qubbit quantum computers. But given that so much of the talent is under security clearances, I can't imagine we have a great idea of what's really going on in that field. Perhaps they can crack everything we currently do. An interesting project idea is for someone to implement some of the post-quantum algorithms [2]. Even if your implementation is faulty or the theory is incorrect, it would not hurt to use these and encrypt on top of what we're already doing. They probably won't make sense for day-to-day encryption for boring folk, but performance concerns are secondary for our journalists and whistleblowers.
My real guess on what happened here? A mix of the three. I would guess our sysadmin messed up somewhere and left incomplete evidence of his keys, or that truecrypt itself did this. I would guess FBI/NSA was able to use this and their supercomputers to put the pieces together.
I want to read more about what is physically impossible with regards to cryptography. When I took my discrete mathematics class a few years ago we got into this, but I've honestly forgotten a lot of the details. Eg: If every atom in the universe could hold 1tb and we had boundless computational power, could we generate rainbow tables to defeat our current cryptography. Etc.
[1]: http://istruecryptauditedyet.com/
[2]: https://en.wikipedia.org/wiki/Post-quantum_cryptography#Algo...