EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

05.31.14

TrueCrypt Too Proprietary to be Secure and Corporate Media Should Stop Blaming Free/Open Source Software (FOSS)

Posted in Free/Libre Software, Security at 4:36 am by Dr. Roy Schestowitz

TrueCrypt was never worth trusting in the first place

Telecommunication

Summary: Analysis of the whole TrueCrypt fiasco and response to the blaming of FOSS (where the licences are clearly not FOSS)

PROPRIETARY software should be assumed insecure by design, as it often contains back doors and one simply cannot prove otherwise. Based on experience alone, a lot of proprietary software comes with back doors, sometimes accidentally but not always. A lot has been written about this before, both here and elsewhere, so we are not going to write so much on this subject. Instead we wish to focus on the news that TrueCrypt development is moving to Switzerland (the first article we found about this is [1] and there is also some analysis [2]). The PATRIOT Act comes to mind and also the experiences of secure mail services in the United States, including Edward Snowden’s E-mail provider. When Groklaw shut down, citing concerns over NSA spying, it recommended that people adopt Kolab, which is based in Switzerland. It should be emphasised that Switzerland harbours privacy not because of humanitarian interests but because of national interests. For domestic prosperity it facilitates international crime (tax evasion from all nations) and wishes to guard the criminals.

The problems with TrueCrypt are not new to us; I very much predicted what the news insinuates and I had received flack for saying so. TrueCrypt has been thoroughly and even successfully openwashed based on some odd kind of marketing angle; those close to the project know better how it works and if an audit which is not transparent is needed for TrueCrypt, then we should quickly realise that the build process and some components are wrapped in a riddle/mystery. The very core of the problem, including its build process, are very crucial. The announcement from TrueCrypt was as vague — not transparent — as the project itself.

Now it is widely known that TrueCrypt gave an illusion of privacy, which is in many ways worse than having no privacy at all because there is impact on users’ behaviour. We may never know how many people have gone to jail or were killed because of TrueCrypt’s false promise.

FOSS-hostile sites try to spin that as an issue with FOSS even though it’s not FOSS. One source states: “The abrupt announcement that the widely used, anonymously authored disk-encryption tool Truecrypt is insecure and will no longer be maintained shocked the crypto world–after all, this was the tool Edward Snowden himself lectured on at a Cryptoparty in Hawai’i.”

Snowden uses Debian GNU/Linux (Tails) and the main reporter he worked with, Glenn Greenwald, only recently dumped Microsoft Windows and moved to GNU/Linux.

There has been a lot more coverage about it [1, 2], including the usual scaremongering by Mr. Goodin, who wrote about it not once but twice, saying: “One of the official webpages for the widely used TrueCrypt encryption program says that development has abruptly ended and warns users of the decade-old tool that it isn’t safe to use.”

Goodin’s colleague wrote about it as well. They are really milking this cow and the best known CIA-linked news site asked: “Is this the end of popular encryption tool TrueCrypt?”

The plutocrats’ press, Forbes, called it “Open Source” (in the headline), so it can’t even get its basic facts right:

Over the past 24 hours the website for TrueCrypt (a very widely used encryption solution) was updated with a rather unusually styled message stating that TrueCrypt is “considered harmful” and should not be used. If you have not come across TrueCrypt and why it has become so popular see the below section ‘why do people use TrueCrypt’.

Better coverage came from the expected sources, not playing to the tune of FOSS smears (TrueCrypt is proprietary).

Knowing that Microsoft is an NSA partner, Gordon in our IRC channels felt baffled because TrueCrypt is “now recommending bitlocker for windows”, to which Ryan replied: “Proprietary encryption from Microsoft that was designed in partnership with the NSA…”

Microsoft is talking to British police about encryption. When I wrote about this nearly a decade ago Microsoft staff were using personal insults against me, only later (much later) to realise that I was right. Sean Michael Kerner calls TrueCrypt “Open-Source” (with a dash) when he writes: “The other challenge facing TrueCrypt is the simple fact that there are many other disk-encryption technologies now available. On Microsoft’s Windows operating system in particular, which was a key target platform for TrueCrypt, versions of Windows after Windows XP include support for Bitlocker, which performs a similar function. In addition, there are multiple file-encryption technologies available, including, FileVault for Mac, DiskCryptor for Windows and Luks for Linux.”

Proprietary operating systems are not compatible with encryption for the same reason that proprietary hypervisors are not. If the NSA can infiltrate the lower layer (e.g. VM host, OS, BIOS) through back doors, then the rest (what’s above) is almost automatically compromised. No sane developer would recommend anything that’s proprietary for security and privacy. Don’t forget Microsoft's COFEE and CIPAV. Microsoft is very much in bed with spooks and police. Microsoft is an informant without conciousness. Privacy in Windows is not a goal; the contrary is true. One Linux/BSD site thinks that TrueCrypt is now “dead” and there is the following statement about the software licence:

Based on the wording of its license, there was always a question mark surrounding the open source-ness of Truecrypt. But that’s not the topic of this brief article. What prompted me to write this is an article that appeared in the Washington Post suggesting that TrueCrypt may have seen its last days as an (“open source”) software project.

Just remember that TrueCrypt is not FOSS.

There is another project whose software licence was blamed for lack of participation and oversight. The OSI’s President blamed the licence. That project was OpenSSL, which is now scrambling to get some more money. The Economist makes FUD out of it while other sites take a more objective approach [4-15]. Remember this: if the project is not quite as open or free as it wants people to believe, then it might not be worth trusting. We never trusted TrueCrypt.

Related/contextual items from the news:

  1. TrueCrypt Not Dead, Forked and Relocated to Switzerland

    The development of TrueCrypt, an open source piece of software used for on-the-fly encryption, has been terminated and users have been advised not to use it because it is not secure enough. Now, it seems that another team of developers have forked the software and rebased it in Switzerland.

  2. Death (?) And Rebirth!
  3. TrueCrypt, An Open-Source Whole-Disk Encryption System, Leaves Users High And Dry
  4. Tough Love for the Encryption Software That Was Compromised by Heartbleed
  5. CII announces 2 full-time devs and a security audit for OpenSSL
  6. Heartbleed: Linux Foundation hires dynamic duo to fix OpenSSL
  7. Linux Foundation throws money at OpenSSL staffing post-Heartbleed
  8. The Linux Foundation’s Core Infrastructure Initiative Announces New Backers, First Projects to Receive Support and Advisory Board Members

    The Core Infrastructure Initiative (CII), a project hosted by The Linux Foundation that enables technology companies, industry stakeholders and esteemed developers to collaboratively identify and fund open source projects that are in need of assistance, today announced five new backers, the first projects to receive funding from the Initiative and the Advisory Board members who will help identify critical infrastructure projects most in need of support.

  9. The Linux Foundation Assigns Two Full-Time Developers to Work on OpenSSL
  10. LF Announces New Backers, Projects For Core Infrastructure
  11. Linux Foundation adds more Internet protocols to its protection list
  12. Everyone uses OpenSSL, but nobody’s willing to fix it — except the Linux Foundation
  13. Linux Foundation flings two full-time developers at OpenSSL

    The Linux Foundation’s new elite tech repair team has named its initial areas of focus as it works to find and seal holes in widely-used open source software.

    The Linux Foundation announced on Thursday that members of the “Core Infrastructure Initiative” (CII) will dedicate resources to working on the Network Time Protocol, OpenSSH, and OpenSSL to hunt down and fix flaws in the tech that helps tie the internet together.

    “All software development requires support and funding. Open source software is no exception and warrants a level of support on par with the dominant role it plays supporting today’s global information infrastructure,” said Jim Zemlin, the executive director of the Linux Foundation.

  14. Corporations put their cash where their open source security is

    OpenSSL and Open Crypto Audit Project are the first open source projects to receive funding from the Core Infrastructure Initiative.

  15. The Linux Foundation Draws Backers and Funds to Tackle Tech Problems
Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 21/2/2017: KDE Plasma 5.9.2 in Chakra GNU/Linux, pfSense 2.3.3

    Links for the day



  2. EPO Caricature: Battistelli's Wall

    Battistelli's solution to everything at the EPO is exclusion and barriers



  3. The 'New' Microsoft is Still Acting Like a Dangerous Cult in an Effort to Hijack and/or Undermine All Free/Open Source Software

    In an effort to combat any large deployment of non-Microsoft software, the company goes personal and attempts to overthrow even management that is not receptive to Microsoft's agenda



  4. PTAB Petitioned to Help Against Patent Troll InfoGation Corp., Which Goes After Linux/Android OEMs in China

    A new example of software patents against Free software, or trolls against companies that are distributing freedom-respecting software from a country where these patents are not even potent (they don't exist there)



  5. Links 20/2/2017: Linux 4.10, LineageOS Milestone

    Links for the day



  6. No, Doing Mathematical Operations on a Processor Does Not Make Algorithms Patent-Eligible

    Old and familiar tricks -- a method for tricking examiners into the idea that algorithms are actual machines -- are being peddled by Watchtroll again



  7. Paid-for UPC Proponent, IAM 'Magazine', Debunked on UPC Again

    The impact of the corrupted (by EPO money) media goes further than one might expect and even 'borrows' out-of-date news in order to promote the UPC



  8. Lack of Justice in and Around the EPO Drawing Scrutiny

    The status of the EPO as an entity above the law (in Germany, the Netherlands, Switzerland and so on) is becoming the subject of press reports and staff is leaving in large numbers



  9. Links 19/2/2017: GParted 0.28.1, LibreOffice Donations Record

    Links for the day



  10. The EPO is Becoming an Embarrassment to Europe and a Growing Threat to the European Union

    The increasingly pathetic moves by Battistelli and the ever-declining image/status of the EPO (only 0% of polled stakeholders approve Battistelli's management) is causing damage to the reputation of the European Union, even if the EPO is not a European Union organ but an international one



  11. Patent Misconceptions Promoted by the Patent Meta-Industry

    Cherry-picking one's way into the perception of patent eligibility for software and the misguided belief that without patents there will be no innovation



  12. As the United States Shuts Its Door on Low-Quality Patents the Patent Trolls Move to Asia

    Disintegration of Intellectual Ventures (further shrinkage after losing software patents at CAFC), China's massive patent bubble, and Singapore's implicit invitation/facilitation of patent trolls (bubble economy)



  13. Links 17/2/2017: Wine 2.2, New Ubuntu LTS

    Links for the day



  14. Bad Advice From Mintz Levin and Bejin Bieneman PLC Would Have People Believe That Software Patents Are Still Worth Pursuing

    The latest examples of misleading articles which, in spite of the avalanche of software patents in the United States, continue to promote these



  15. Patents Are Not Property, They Are a Monopoly, and They Are Not Owned But Temporarily Granted

    Patent maximalism and distortion of concepts associated with patents tackled again, for terminology is being hijacked by those who turned patents into their "milking cows"



  16. SoftBank Group, New Owner of ARM, Could Potentially Become (in Part) a Patent Troll or an Aggressor Like Qualcomm

    SoftBank grabbed headlines (in the West at least) when it bought ARM, but will it soon grab headlines for going after practicing companies using a bunch of patents that it got from Inventergy, ARM, and beyond?



  17. Technicolor, Having Turned Into a Patent Troll, Attacks Android/Tizen/Linux With Patents in Europe

    Technicolor, which a lot of the media portrayed as a patent troll in previous years (especially after it had sued Apple, HTC and Samsung), is now taking action against Samsung in Europe (Paris, Dusseldorf and Mannheim)



  18. Michelle Lee is Still “in Charge” of the US Patent System

    Contrary to a malicious whispering campaign against Lee (a coup attempt, courtesy of patent maximalists who make a living from mass litigation), she is still in charge of the USPTO



  19. Our Assessment: EPO Wants a Lot of Low-Quality Patents and Low-Paid Staff With UPC (Prosecution Galore)

    The European Patent Office seems to be less interested in examination and more interested in facilitating overzealous prosecution all across Europe and beyond; The Administrative Council has shown no signs that it is interested in profound changes, except those proposed by Battistelli in the face of growing resistance from staff and from ordinary stakeholders



  20. Links 16/2/2017: HITMAN for GNU/Linux, Go 1.8

    Links for the day



  21. Yet More Complaints About the European Patent Office in the Bavarian Regional Government

    Some German politicians do care about the welfare of EPO staff, a lot more so than the EPO's management that is actively crushing this staff



  22. EPO Staff Representatives to Escalate Complaint About Severe Injustices to the EPO's Secretive Board 28

    In a new letter to President Benoît Battistelli it is made abundantly apparent -- however politely -- that Battistelli's gross abuses could further complicate things for Battistelli, who is already embroiled in a fight with his predecessor, Roland Grossenbacher



  23. New Survey Reveals That High Patent Quality, or Elimination of Bad Patents, is Desirable to Patent Holders

    A new survey from Bloomberg BNA and AIPLA reveals that the Patent Trial and Appeal Board (PTAB), which still grows in prominence, is supported by people who have themselves gotten patents (not those who are in the bureaucracy of patents and self-serving politics)



  24. Open Patent Office is Not the Solution; Ending Software Patents is the Solution

    Our remarks about the goals and methods of the newly-established Open Patent Office and what is instead needed in order to combat the menace that threatens software development



  25. New Scholarly Paper Says “UK’s Withdrawal From the EU Could Mean That the Entire (Unitary Patent) System Will Not Go Into Effect”

    A paper from academics -- not from the patent microcosm (for a change) -- provides a more sobering interpretation, suggesting quite rightly that the UPC can't happen in the UK (or in Europe), or simply not endure if some front groups such as CIPA somehow managed to bamboozle politicians into it (ratification in haste, before the facts are known)



  26. Patent Trolls Update: Rodney Gilstrap Maintains His Support for Trolls, MPEG-LA Goes Hunting in China, and Blackberry Hits Nokia

    A roundup of the latest news about patent trolls and what they are up to in the United States, Europe, and Asia



  27. Guest Post: EPO, an Idyllic Place to Work

    The true face of the EPO as explained by an insider, recalling the history that led to the negative image and toxic work atmosphere



  28. Links 15/2/2017: Linux 4.9.10 and Linux 4.4.49

    Links for the day



  29. Claude Rouiller (ILOAT) and ILO Rulings Effectively Disregarded by the European Patent Office

    The compositions of kangaroo courts at the EPO continue to be absurd, in spite of a ruling from the International Labour Organisation (ILO), which insisted that change must be made following a lot of mistrials



  30. National Law Journal Believes That Gorsuch as Supreme Court Justice Would be Opponent of Patent Reform

    Whispering campaign surrounds Neil Gorsuch's alleged or perceived views on patents, and in particular the America Invents Act (AIA) which brought the Patent Trial and Appeal Board (PTAB), a serial invalidator of software patents, owing to Alice (a Supreme Court decision)


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts