I’m sad because this is great and the answer to much but stands no chance when you move past the “single user who is IT literate” user group.
I’m sad because this is great and the answer to much but stands no chance when you move past the “single user who is IT literate” user group.
Comparing with Bitlocker is silly - its source is closed, and that's almost an automatic "untrustworthy" for many. It also is Windows only.
“Many” is probably overstating things relative to the full audience for Bitlocker
I never realized there was so much history - just thought the app had been orphaned for the usual mundane reasons. I've got to read that book!
Almost by definition, corporations will sell their souls to MS if that means "accountability", that means someone to blame when things go wrong. Not if, when.
Just the fact Veracrypt exists and can be used by that 0.01% is enough. It is already useful beyond expectations.
It's possible that whatever vulnerability the TrueCrypt developers were alluding to still lurks in the VeraCrypt codebase, but the chances seem pretty low. VeraCrypt uses much stronger encryption methods, it has addressed all the issues raised in the original TrueCrypt audit as well as a separate audit of its own code, and the latest version isn't even backward-compatible with TrueCrypt volumes.
The obvious recommendation back then was LUKS. And even if there were no alternatives they're not going to recommend you a proprietary solution with a high chance of being backdoored. They'll just say to use "other software".
Recommending BitLocker might have been a signal to hackers in the aftermath of the Snowden revelations, but IIRC the announcement also included a detailed tutorial for setting up BitLocker that was actually quite helpful to anyone whose threat model mostly concrerned thieves, corporate spies, and non-Five Eyes intelligence agencies.
Of course, it would be the binaries that are problem, if there is one. If you vet the source code and compile it yourself, there shouldn't be any issue. Note that the French government has long history of being anti-cryptography for end-consumers.
I personally wouldn't even touch Veracrypt with a long pole. But that's just my personal opinion.
Are you sure? I thought it could open them in read-only mode. Here's a 2023 post suggesting it's supposed to still be able to open TC 6.0+ files, though the user in question is having trouble: https://sourceforge.net/p/veracrypt/discussion/technical/thr...
Since then truecrypt was carefully reviewed, some bugs were found, but no backdoors. It was forked and veracrypt is one of those forks. It has enhanced security which makes it annoying to use. For example to disconnect the drive one needs to enter admin's password. That's done because veracrypt doesn't store it. On one hand it makes it more secure, on the other entering passwords many times in public makes it less.
What? For me, VeraCrypt can mount and unmount volumes (on Windows 11) without ever prompting for UAC. It could also do the same on my other, Windows 10 PC.
I believe they incorporated the recommendations from TrueCrypt's own audit, and then went through an additional external audit that came up clean.
That's was the time the other Truecrypt contributors learned that Paul le Roux was in federal custody[1]. Most likely they nukes encryption & gave dire warnings as a scorched earth play to avoid the possibility of an FBI-authored binary release of TrueCrypt, since Paul controlled the website and the infrastructure, IIRC.
1. Warning: linked story is a 3-part longform story that can cause 30-60m to vanish from your day. https://magazine.atavist.com/he-always-had-a-dark-side/
No way in hell would I recommend it to less technical people (except default settings, which works fine but offers near zero security against extremely common things like theft). Bitlocker is by far the least user-friendly OS-provided I've ever seen - it's so bad I have to assume it's being intentionally ruined.