Newly found TrueCrypt flaws
itworld.com
itworld.com
They didn't.
> VeraCrypt has been licensed under the Apache License 2.0 since 28 June 2015.
> VeraCrypt inherited a substantial amount of code from its TrueCrypt predecessor and thus is also subject to the terms of version 3.0 of the "TrueCrypt License" which is unique to the TrueCrypt software.
http://lists.freedesktop.org/archives/distributions/2008-Oct...
On the forms they have, there is a space you can fill out for claimant name, and one for author name. There is also a pseudonym checkbox.
They will happily let you register it only in the name of the pseudonym.
See: http://www.copyright.gov/fls/fl101.pdf
For more interesting fun, read the last sentence of that PDF, where it goes on to explain that you get different years of protection for distributing under a pseudonym vs if your identity is revealed.
In actual legal practice? Probably not if they want to retain anonymity.
Which may be tricky.
In the civil system, which is where copyright resides, you can simply be represented by counsel and never appear at all :)
This happens all the time.
Here are the pull requests that fix the bugs.
https://veracrypt.codeplex.com/SourceControl/changeset/cf4794372e5dea753b6310f1ca6912c6bfa86d45
https://veracrypt.codeplex.com/SourceControl/changeset/0d9239178bab3332d0f9c911de89f6f80b65d2d1
The first version of truecrypt that is vulnerable to the accessToken bug was 6.1a, which is roughly 4 years ago. I didn't look into the other bug though....4 years was enough for me....If you want to do the digging into release dates, I would check this repo. This was the only archive of truecrypt code I could find. https://github.com/DrWhax/truecrypt-archive
If you ask me, a much more serious bug would be going from an encrypted hard drive to an unencrypted hard drive... Local Privilege Escalation is definitely a bad bug, but it's not anywhere as bad as it could be.
There'a also https://github.com/AuditProject/truecrypt-verified-mirror (maintained by opencryptoaudit.org)
They are lot shorter that I expected
I'd like to see Microsoft allow more drivers to run in user-mode, but this is just the risk you take when installing drivers. Microsoft has been tightening driver signing requirements, so you can at least be sure they're from a known source.
I did not realize how poorly the general "tech savvy" public apparently misunderstands software security.
Auditing is closer to an art than a science. For any real software, no two auditors will find the same set of bugs.
Think of it as similar to QA. If you write some complex software from scratch, and give it to 1 tester to do one pass on it, do you expect every bug was found and fixed?
Like security audits, you'll still be finding bugs for years, or in some cases even decades, that were sitting there all along.
I don't even have non privileged users on my windows machine. Most end users don't. This could only really matter in some corporate environments but even my windows machine at work has full admin privileges.
This is a major, major vulnerability, no doubt about it. Shame TC has a hackey Windows driver to make its pseudo-drive features work. Anything that installs a driver is dangerous in the world of Windows as it has high level permissions. I imagine organizations with strong security policies wouldn't run this and instead just run some PGP variant that doesn't use any customized Windows drivers.
>I don't even have non privileged users on my windows machine.
Technically, you do if you have the UAC enabled. You're only really an admin after UAC runs, at least in most cases. From what I'm reading this should work around he UAC if the driver is running at SYSTEM level.
Interesting. Makes sense.
Ok, we shortened it.