ISEC Completes TrueCrypt Audit
isecpartners.github.io
isecpartners.github.io
> "iSEC did not identify any issues considered "high severity" during this testing. iSEC found no evidence of backdoors or intentional flaws. Several weaknesses and common kernel vulnerabilities were identified, including kernel pointer disclosure, but none of them appeared to present immediate exploitation vectors. All identified findings appeared accidental."
Classic. Taking a dig at the developers while telling the rest of the world TrueCrypt is ok to use.
This seems matter-of-factish to me as long as they can defend it. (Hey, some of the code tha I've written to save people time and money does not have a very polished style, -that is a matter of fact and I'm fine with that.)
Couldn't your pointing out that it might be disinfo also be disinfo in itself?
Oh crap, infinite loop!
At some point, you have to trust someone, even if they are out to get you.