> As Truecrypt got no further releases the software is still vulnerable for all those weaknesses. [...]
> The BSI knew all that. [...]
> The results were communicated to the Truecrypt foundation, however the Truecrypt developers didn't consider them to be relevant. BSI furthermore says that the results were not intended to be published.
This is looking pretty terrible for Truecrypt. It means they ignored a vulnerability report and kept the vulnerabilities around for five years.