I don't see why people should spend money auditing it, instead of building maintainable alternatives
I don't see why people should spend money auditing it, instead of building maintainable alternatives
Bitlocker is great for enterprise-style encryption, in particular on machines with TPM chips. However many consumer machines do not include a TPM, even in 2015.
TrueCrypt allowed you to encrypt individual drives, even offline drives, with no Bitlocker overhead. You also weren't required to decrypt them upon each boot like Windows' Bitlocker insists upon.
Additionally TrueCrypt would also encrypt directories, USB drives, hidden volumes, various encryption algorithms, double encryption, and so on.
Plus it was cross-platform friendly (or at least more so than BitLocker). What are we meant to use to move encrypted data from Linux to Windows now? 7Zip w/AES 256?
https://news.ycombinator.com/item?id=8546524
Short story is that if you use Windows 8{.1} and have a Microsoft account then it will upload your BitLocker keys by default. Seems to me like a backdoor if ever I heard one.
OpenSSL is on every system and can encrypt files with aes-256-gcm if for whatever reasons libgcrypt can't be used http://stackoverflow.com/questions/12153009/openssl-c-exampl...
Tarsnap you can copy keys to any platform that will run Tarsnap http://www.tarsnap.com/man-tarsnap-keygen.1.html http://jamesoff.net/site/2009/09/10/tarsnap-under-cygwin/
If you want to move an encrypted file from Linux to Windows, though, you should use something like PGP.
What if my use case is different: keeping just a particular set of documents not in constant use secret? Perhaps stored on a removable drive? Truecrypt is great for this. It does have the risk of information leakage via tempfiles and swap, but it also makes you a lot harder to raid unless you've got the incriminating document open on your screen in a cafe (you fool).
(I was asked by someone I know who works in international human rights "How do I get my case files safely across borders?" and didn't have a good answer.)
Sector crypto can't do anything even approximating this without contortions like geli.
If I was trying to protect files from nation state adversaries, I would not consider Truecrypt.
That doesn't mean I think you shouldn't run something like Truecrypt. I think you're better off with whatever your OS provides, but some kind of sector-level crypto, be it Bitlocker, Truecrypt, or Filevault, is still useful.
But if you're serious about protecting a specific set of files, encrypt them manually, no matter what else you do.
* Sector-level crypto is cryptographically incapable of secure in-place editing; they can gradually leak information about the plaintext as edits happen. That's not a big deal for a PDF, which aren't on-line live real-time edited, but it can be a big deal for other kinds of files. I tend to err on the side of systems programming weaknesses rather than crypto weaknesses. We're better at dealing with them.
* No matter what kind of cryptography you're using, the assumption you should be making is that plaintext is at some point exposed to someone who owns up your live running system.
I think concern about unlinked plaintext-containing sectors is reasonable, and a good reason to use both sector-level crypto and file-level crypto. I use both, as does everyone at Matasano.
(TrueCrypt had a weird license that makes forking a little strange; more here: https://security.stackexchange.com/questions/58994/are-there... )
(Edit: just saw tptacek recommending against the forks. I guess this is uglier than I thought. https://news.ycombinator.com/item?id=9069708 )
There's no free full disk encryption for Windows users with modern (UEFI) boxes. The money would be better spent on that, but returning crowdfunded money... tricky.
Truecrypt manages to create virtual disks that look a lot like regular disks, so I assume it does some kernel-level stuff to make that work.
When someone builds a new one (as happens every other day), we'll have to start again, right back at the beginning, fixing all the bugs in it and auditing it. About halfway through that process, someone will come along and say "I don't see why people should spend money auditing it, instead of building maintainable alternatives"...
There will always be new projects doing things in different ways. That's no reason not to make sure that something we have now works properly.
Or you can start trusting forks of Truecrypt that base their code on the post-audit code for Truecrypt.
I don't think anything would be _drastically_ changing in Windows 11 and 12.