I suppose they could be approached by someone to plant backdoor into the software, but I wonder if that can be done without someone noticing it...
EDIT: I normaly don't care. But this time I'd be glad if who downmoded this post explained why.
I'm not going to jump the gun just yet but after snowden it's not out of the question.
edit: Confirmed Microsoft stores your recovery key on their servers if you're not connected to a domain: http://windows.microsoft.com/en-AU/windows-8/bitlocker-recov...
Whether or not they superstitiously store it anyway is a different question.
http://sourceforge.net/p/truecrypt/activity/?page=0&limit=10...
Besides the different file name, the contents of the files match: http://www.diffchecker.com/szpb500v
The only way to verify is if you have the previous key stored somewhere, or can find a trustpath to it.
E3BA73CAF0D6B1E0 C5F4 BAC4 A7B2 2DB8 B8F8 5538 E3BA 73CA F0D6 B1E0
Checks out.
pub 1024D/F0D6B1E0 2004-06-06
Key fingerprint = C5F4 BAC4 A7B2 2DB8 B8F8 5538 E3BA 73CA F0D6 B1E0
uid TrueCrypt Foundation <contact@truecrypt.org>
sub 4077g/6B136ECF 2004-06-06
My version from September is identical to the pub key at http://sourceforge.net/projects/truecrypt/files/TrueCrypt/Ot... . tc/linux$ sha1sum *
c2a8c78a23f97ffb17bf47448c9f2daa3c8f80cd truecrypt-7.1a-linux-console-x64.tar.gz
078cdd4a58f0342cb872d7456c0ba49e310fcad9 truecrypt-7.1a-linux-console-x64.tar.gz.sig
a53a7a609a25d9a1e33f720ce5c0265ddd4e8b25 truecrypt-7.1a-linux-console-x86.tar.gz
66060f9444d5df70b4fcdeb655dc60131fce5ad1 truecrypt-7.1a-linux-console-x86.tar.gz.sig
086cf24fad36c2c99a6ac32774833c74091acc4d truecrypt-7.1a-linux-x64.tar.gz
45f65bf755d9481d8afa0d17de6a034062b7a7bd truecrypt-7.1a-linux-x64.tar.gz.sig
0e77b220dbbc6f14101f3f913966f2c818b0f588 truecrypt-7.1a-linux-x86.tar.gz
9efcd79e963126d6d8ef242857b4fafb06eb8ff0 truecrypt-7.1a-linux-x86.tar.gz.sig
d43e0dbe05c04e316447d87413c4f74c68f5de24 TrueCrypt 7.1a Source.tar.gz
caeb2bb1d5605d1fc960e936a06e52611033788c TrueCrypt 7.1a Source.tar.gz.sig
c871f833d6c115f4b4861eed859ff512e994b9fc TrueCrypt-Foundation-Public-Key.asc
tc/windows$ sha1sum *
06961d83e39c7248df09c132cb6e9b9f528ce69a Configuration.xml
88b323b416290924621901a10da3f4f7482e3f77 License.txt
4c4891f5eafcf9b96be01e31031992d9e98d39c3 TrueCrypt.exe
34442e400e6cb2534f33a0b1599defe36eefef2a TrueCrypt Format.exe
7689d038c76bd1df695d295c026961e50e4a62ea TrueCrypt Setup 7.1a.exe
e1e3efaeac2fbcdbff0c2c62ac33233bd356edfa TrueCrypt Setup 7.1a.exe.sig
62fc4f76540740e63c7f0a33e3a1b66411f0a303 truecrypt.sys
17249d979b3bc52d0a33821cc7f810337ddea2b6 TrueCrypt User Guide.pdf
17c46ebc6f4977afbcf4aa11eccee524fd95b1c8 truecrypt-x64.sys gpg --import TrueCrypt-Foundation-Public-Key.asc
gpg --fingerprint F0D6B1E0
gpg --verify truecrypt-7.1a-linux-x64.tar.gz.sig
You should see: gpg: Signature made Tue 07 Feb 2012 12:45:26 PM PST using DSA key ID F0D6B1E0
gpg: Good signature from "TrueCrypt Foundation <contact@truecrypt.org>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: C5F4 BAC4 A7B2 2DB8 B8F8 5538 E3BA 73CA F0D6 B1E0Even if it's a legit announcement, I wouldn't run that 7.2 binary. Anyone running truecrypt already has truecrypt, right? I don't know why they'd release a new version at the same time as such a dire and panic-inducing announcement.
[1] http://sourceforge.net/blog/sourceforge-net-global-password-...
I frequently reformat my boot volumes—but I've had a .tc file laying around on an external HD since forever, with my websites' X.509 private keys and such inside.
I'm probably going to do exactly as this announcement says: download the export-only binary, create a loop-mounted LUKS volume, and migrate everything over.
Just quickly scroll through the diff (better version here: https://gist.github.com/anonymous/e5791d5703325b9cf6d1) and you will immediately see that all that was done is disable/remove a majority of the functionality.
AbortProcess ("INSECURE_APP");
Print ("WARNING: Using TrueCrypt is not secure");
They added exceptions/rose errors/printed warnings everywhere where you could possibly encrypt and all of it reflects their intent at the Sourceforge page.Anyway, it was a joke.
edit: But I'm not touching that binary with a 10 foot pole, thank you. There isn't even any guarantee yet that that source compiles into the given binary.