EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS


Truecrypt Cannot be Audited Because It’s Proprietary Software

Posted in Free/Libre Software, Security at 8:37 am by Dr. Roy Schestowitz


Summary: Why nobody should trust Truecrypt (or any other piece of proprietary software for that matter), even if it claims to have been “audited”

THE other day we alluded to Truecrypt in this post, not quite mentioning the holes in the argument that Truecrypt can be “audited” [1-3]. Unless everyone can view the code and compile it independently (or rely on others to do so independently), we must assume that Truecrypt is not secure and that it might contain back doors (either unidentified or deliberately planted). This whole Internet ‘debate’ about Truecrypt “audit” should remind us that Free software is vital for dodging surveillance.

The NSA has used corporations to facilitate snooping and it may not be alone [4]. This is happening at many levels [5-7] based on new leaks and revelations, so rather than look for evidence of insecurity (e.g. back door) we should pursue real assurance of security. You know what the spies like to tell us: if you have nothing to fear, you have nothing to hide, right? So come on, Truecrypt, share your source code. What have you got to hide?

Related/contextual items from the news:

  1. Should Truecrypt be audited?

    Truecrypt is a cross-platform, free disk encryption software for Windows and Unix-like operating systems. It is generally considered a good disk encryption software, and not too long ago, I wrote a tutorial that showed how to encrypt the Windows installation of a Windows-Linux dual-boot setup (see Dual-boot Fedora 18 and Windows 7, with full disk encryption configured on both OSs).

  2. New effort to fully audit TrueCrypt raises $16,000+ in a few short weeks
  3. Can you trust ‘NSA-proof’ TrueCrypt? Cough up some dough and find out

    The source code for the Windows, Linux and Mac OS X utility is publicly available for people to inspect and verify, but this has not been enough to convince every cryptography guru that it’s entirely secure.

  4. After Snowden’s leaks, China’s Huawei calls for more transparency in the tech industry

    With all of the recent revelations about the US National Security Agency’s surveillance programs, it must be hard for the Chinese telecom equipment manufacturer Huawei not to gloat a little bit.

    After all, the leaks from former contractor Edward Snowden showed that the NSA enlisted US technology companies to enable its snooping on global telecommunications networks—which is exactly what US intelligence officials have accused Huawei of doing on behalf of the Chinese government.

  5. Europe Moves to Shield Citizens’ Data

    Lawmakers here have introduced a measure in the European Parliament that could require American companies like Google and Yahoo to seek clearance from European officials before complying with United States warrants seeking private data.

  6. Dutch Telcos Used Customer Metadata, Retained To Fight Terrorism, For Everyday Marketing Purposes

    One of the ironies of European outrage over the global surveillance conducted by the NSA and GCHQ is that in the EU, communications metadata must be kept by law anyway, although not many people there realize it.

  7. NSA Harvesting Contact Lists

    A new Snowden document shows that the NSA is harvesting contact lists — e-mail address books, IM buddy lists, etc. — from Google, Yahoo, Microsoft, Facebook, and others.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New

  1. Links 23/10/2016: Alcatel's New Android Smartphones, Another Honorary Doctorate for Stallman

    Links for the day

  2. Open Letter Exposing the Farce Which Was Battistelli's 'Social Conference' Coinciding With Further (New) Attacks on EPO Staff Representatives

    A detailed letter reveals legitimate concerns expressed by staff representatives at the EPO ahead of the so-called Social Conference, in which we have highlighted severe factual flaws

  3. Translation of Latest Rant From French MP Philip Cordery About Benoît Battistelli's Abuses at the EPO

    Philip Cordery crosses horns with Benoît Battistelli, who has become a source of embarrassment for France with his autocratic tendencies and misguided policies that rapidly ruin the European Patent Office (EPO)

  4. Battistelli-Commissioned PwC ‘Study’: Leaked Document Shows PwC's Dishonesty and Misrepresentation of EPO Staff

    An in-depth analysis (but not comprehensive, just preliminary) of the so-called 'study' from PwC, which basically did what it was paid for (pay to say)

  5. Links 22/10/2016: Deus Ex for GNU/Linux, Global DDoS (DNS)

    Links for the day

  6. Battistelli-Commissioned PwC ‘Study’: Survey Comparison Shows Serious Deterioration and Efforts by PwC to Disguise the Truth

    The latest output from PwC turns out to be even worse than initially thought, indicating that not only did it find a degradation in the EPO but also attempted to hide/obscure it

  7. EPO Teaser - The "Iberian Connection" - Some Photos of García-Escudero and His Royal/Government Connections

    A look at the undeniably close connections between Mr. García-Escudero and the most powerful people in Spain

  8. Disruption to Site's Service

    A technical note about why Techrights has not been publishing many articles recently

  9. Links 21/10/2016: MPV 0.21, Mad Max for GNU/Linux

    Links for the day

  10. EPO Caricature: Battistelli's High Five

    Another cartoon about the sad state of the EPO

  11. Battistelli Ruins Not Only the EPO But Also the Whole of Europe By Ushering in Software Patents That Patent Trolls Love So Much

    Battistelli's bad leadership at the EPO threatens to bring to Europe all the ills and menaces of the patent system in the United States

  12. EPO Spokesman Lies to IP Watch in Order to Save Face and Save the King (Battistelli)

    Rewriting history (revisionism) regarding Battistelli and what was demanded amidst abusive behaviour from him

  13. Unitary Patent (UPC) is Dead, But 'Managing IP' and Selfish Patent Law Firms Still Try to Resurrect It

    The latest attempts to shore up the Unitary (or Unified) Patent Court and who's behind it other than the usual suspects

  14. Links 20/10/2016: Linux 4.10 Preview, ONF and ON.Labs to Merge

    Links for the day

  15. Battistelli-Commissioned PwC 'Study': The Raw Outcome Shows Distortion of the Facts at the EPO's Notorious 'Social Conference'

    Results of the Staff Survey carried out by PwC, in order to provide some propaganda for Battistelli's expensive Social Conference

  16. Addendum: EPO's Alberto Casado Cerviño, WIPO's Francis Gurry, and EUIPO's Archambeau

    Photos taken as part of an IP event which took place in Riga (Latvia) in March 2015

  17. Worrisome Connections Between EPO VP2 Alberto Casado Cerviño and Patricia García-Escudero Márquez

    Exploring the potential conflicts of interests implicating the EPO's Boards of Appeal Committee

  18. Site's Infrastructure Under Attack and Upgrades Ahead of Major New Publications

    Protections for the Web site have been improved and capacity increased in order to avoid or at least prepare for another week of abusive/spam traffic

  19. Team Battistelli's Conspiracy Theory: SUEPO is Behind Everything, EPO Management is Trying to Tell the Media

    Attempts to blame SUEPO, the staff union of the EPO, even though SUEPO has nothing to do with articles that are critical of the EPO while many thousands of EPO employees are disgruntled

  20. Links 19/10/2016: Canonical Livepatch Service, Plasma Plans

    Links for the day

  21. The 'Sarah Sharps' of Microsoft: Not the Kind of Scandal the Media Cares Enough to Write About

    Another example of the large (industrial) scale of sexual discrimination at Microsoft -- a company that tries to advertise itself as diverse or tolerant and stigmatise Free/Open Source software (FOSS) as intolerant and/or not diverse

  22. EPO Caricature: EQE Questions

    The latest EPO cartoon, this time about European qualifying examination (EQE)

  23. The Long History or Seeds of Control by Fear and Punishment at the EPO

    The latest hogwash from Team Battistelli (Pinocchio), the latest instance of software patents promotion by EPO Principal Director, and an old (decade-old) nugget of information from the Forum for Principal Directors

  24. Subject of the European Patent Office's Abuses Raised in European Parliament by Ulrike Müller (ALDE)

    A local copy of a bunch of questions asked less than a month ago by Ulrike Müller at the European Parliament, regarding the unacceptable state of affairs at the European Patent Office (EPO)

  25. French Article About the EPO "Crisis"

    Le Monde, which covered EPO suicides and nervous breakdowns a year and a half ago, revisits the subject

  26. Battistelli Wants Us to Believe a Patent Office in a Freefall (EPO) is “Stronger and More Sustainable”

    Still in denial (or self-deluding for self indulgence), Battistelli writes about the EPO as though everything is rosy and people are happy

  27. Leaked Documents Shed More Light on What Happened to Alison Brimelow and How Battistelli Rose to Power

    How Battistelli's (almost) all-male (and all-white, mostly French) management came into being, not too long after Ms Alison Brimelow got elbowed out the Office

  28. Leaked: Outcomes of 149th Administrative Council's Meeting at the European Patent Organisation

    The raw details or a summary thereof, based on the above which serves to confirm what we wrote about several days ago, right after the quarterly meeting had ended

  29. Danish Press Coverage of the European Patent Office and the Problems Explored by Techrights

    Jesper Kongstad does virtually nothing to deny the arguments (or "accusations") and instead alludes to the style of the writings about him

  30. Links 18/10/2016: Release Candidate of Leap 42.2, Looking Ahead at GTK4

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time


Recent Posts