Long story short: that change does not matter much.
https://cryptoservices.github.io/fde/2014/12/08/code-executi...
With the diffuser, we have ~9 years of conjecture and speculation, with no one overly certain that attacks are possible. Without it, we have calc.exe fairly quickly after someone got the idea to try. You can't say these are roughly the same in practical terms.
WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues.
The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform.
[1] Discussed here:
* https://news.ycombinator.com/item?id=7828107
They don't owe anyone on HN or anywhere else any kind of "ownership of statements" or explanation. The published some source code. They got sick of it. They've moved on. It's over.
I understand the urge people have to synthesize a soap opera narrative out of things on message boards --- that's fun, after all, and the alternative is boring. But that's all the conversation about the TC project abandonment really is: a synthesized soap opera.
The circumstances were fishy - in a way that says don't trust the software to anyone that has anything to hide.
Using TrueCrypt is not secure as it may contain unfixed security issues.
I don't think the developers owe anyone anything, in terms of supporting this project or even justifying their decision not to support it. But they did make this claim, which they didn't need to, which casts the entire project in doubt. You're saying they are refusing to elaborate on this claim? Or has no-one asked them to? Because I think this thread is evidence enough that plenty of people want to know.However, I still use TrueCrypt because I'm familiar with it, don't believe it has been compromised, and I trust a random pickpocket will be unable to break it.
(Also to clarify, when I said 'take ownership of this statement' I was referring to the earlier conjecture that the message was written by people other than the original developers.)
My particular curiosity is about that announcement, and whether or not it was a government attempt to discredit a likely very effective product.