TrueCrypt no longer supported?

Do you think they would actually disclose this?


Chances you'd be on the NSA list to have your volume cracked in the first place is low.


We do know the FBI has tried and failed.


http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/


With a proper random password of 20+ characters with mixed upper, lower, numbers, and symbols, I'd like to see the NSA try it with every computer on earth. The formula doesn't lie and we can break down a single computers potential on a local machine. There are really only 3 ways to break it before the end of the world:

1) Weakness in the algorithm
2) Flaw in the software implementing the algorithm
3) Flaw in the operating system

Of course there are many other parts in the chain that can theoretically leave open vulnerabilities, but those are the 3 big ones that every user must trust.
 
Considering that Edward Snowden was advising journalists to use TC, I would think that the NSA cannot "crack a TC volume in 5 minutes".

But hey, who knows more about NSA capabilities - Snowden or Red Squirrel?
 
Chances you'd be on the NSA list to have your volume cracked in the first place is low.


We do know the FBI has tried and failed.


http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/


With a proper random password of 20+ characters with mixed upper, lower, numbers, and symbols, I'd like to see the NSA try it with every computer on earth. The formula doesn't lie and we can break down a single computers potential on a local machine. There are really only 3 ways to break it before the end of the world:

1) Weakness in the algorithm
2) Flaw in the software implementing the algorithm
3) Flaw in the operating system

Of course there are many other parts in the chain that can theoretically leave open vulnerabilities, but those are the 3 big ones that every user must trust.

You're joking, right?

You do realize that if seen as a big enough threat to even warrant cracking (i.e. national security), you'd just be picked up and drugged/tortured? Need I even post this, when there are so many examples in the past few years of the government's abuse of power in instances such as these? One that comes to mind immediately is when the FBI was allowed to interview one of the Boston Bombers without reading him his Miranda Rights. Like any government superpower (and like Steven Seagal), the Law is Above The Law

security.png
 
Oh, lets not try at all. Got it.

I never said that, did I?

I was just trying to dispel the notion that there's ever a thing such as creating something which cannot be cracked. There are more ways to get someone's TC password & keyfiles than just brute forcing with rainbow tables, and if you're too naïve to realize that a system is only as protected as its weakest link, then that's on you.

TC, like any encryption solution, should be seen as a deterrent not as some sort of savior incapable of being cracked just because you picked some magical password length/complexity. Same goes for having bars on your windows or a security door. If someone wants in, there's always a way (and it's usually extremely simple, like waiting for you to open your door).
 
When there are so many examples in the past few years of the government's abuse of power in instances such as these? One that comes to mind immediately is when the FBI was allowed to interview one of the Boston Bombers without reading him his Miranda Rights
The government has no requirement to give you a lawyer and cease questioning you when there's a threat to public safety.

You have no idea what you're talking about.
 
The government has no requirement to give you a lawyer and cease questioning you when there's a threat to public safety.

You have no idea what you're talking about.

As if justification was needed, when anything can be seen as a threat to public safety, such as classified information on an encrypted HDD?

I had no idea how brainwashed some people have become.
 
I work for a company that recovers data on a large scale, and it's pretty rare we can't crack a truecrypt volume (and we don't have the NSA's budget lol).

If you are brute-forcing passwords then your statement is very believable. Most users use a password less than 8 characters that consists of lowercase letters and numbers and in the majority of cases, just lowercase letters. With the right computing power, which on a company budget is easily attainable, your brute-forcing duration is probably 24-48 hours at most (and I'm being very conservative with that guess).

Are all users of Truecrypt technical users? No. Are all technical users using complex passwords like they should? Haha, no, absolutely not. I've worked with engineers long enough to know just how lazy you people really are. That should again show you why your statement is so believable. Throw in a password (like mine) which is 8 characters or longer consisting of special characters, upper and lowercase letters and numbers and you're looking at years to crack it even with clustered brute-forcing.
 
Considering that Edward Snowden was advising journalists to use TC, I would think that the NSA cannot "crack a TC volume in 5 minutes".

But hey, who knows more about NSA capabilities - Snowden or Red Squirrel?

Encryption is still better than no encryption so obviously he would suggest that. There is probably a lot of red tape involved in actually cracking it so while the actual cracking may only take a very short time (I just said 5 minutes, it could be several hours or days, maybe even months) it's probably a huge deal for them to free up that much computing resources to do it. Some encryptions probably have flaws that make it easier for them to do it, but TC may be so secure that the only way to do it for them is brute force. That's a huge royal pain in the ass for them. Depending on how much stuff they crack the cluster could also be so back logged that it takes years before a file can be processed.

Just speculating, but I think it's ignorant to think that encryption makes you 100% safe from the government. If they want to get in, they'll find a way. Either way, you are probably going to die if they physically find you because they'll just force you to give the key at gun point and if you do they'll just put you in jail based on what they found. I rather just die than go to jail.

That said the more security you use the better. You at least want to try to slow them down. Depending on the situation it could buy you time to act accordingly such as trash the data or flee the country.
 
Just speculating, but I think it's ignorant to think that encryption makes you 100% safe from the government. If they want to get in, they'll find a way. Either way, you are probably going to die if they physically find you because they'll just force you to give the key at gun point and if you do they'll just put you in jail based on what they found. I rather just die than go to jail.

QFT
 
You're joking, right?

You do realize that if seen as a big enough threat to even warrant cracking (i.e. national security), you'd just be picked up and drugged/tortured? Need I even post this, when there are so many examples in the past few years of the government's abuse of power in instances such as these? One that comes to mind immediately is when the FBI was allowed to interview one of the Boston Bombers without reading him his Miranda Rights. Like any government superpower (and like Steven Seagal), the Law is Above The Law

security.png


Like I said, the NSA isn't going to waste their time on something that isn't a threat. There are other agencies out there. Agencies like the NSA and CIA are built on fear. What you don't know can only hurt you. Cops use this tactic piss poorly all the time. It's called a fishing expedition.

We have a saying here about our local police. They shoot first and then they try to ask questions. When it comes to the FBI they have a track record of shooting first and I don't think hitting people is on their agenda. They are a law enforcement agency, not a military one like the NSA and a who-the-fuck-knows-where-their-power-comes-from CIA entity.

The minute we bring torture into the argument we get into some dark shit and only more violence as protection becomes the solution. For instance the counter argument could be, "Good luck torturing me. If I see the Feds at my door step one of us is going to die."
 
I see Steve Gibson has been following this pretty closely: Click here. Sounds like, at least with one developer, a lack of interest was one of the big reasons.

Shame...
 
It is legit and TrueCrypt is basically done with full functionality of version 7.1a. Let's hope the audit which is still going to be taking place doesn't find anything.

I will be testing DiskCryptor in the meantime.
 
It's odd they did not try to properly pass the torch down, and it's also odd they say it's no longer secure. To me this is still a bit fishy, we'll have to wait for a more official statement.
 
I'd consider them unsafe anyway if you're really that worried. I work for a company that recovers data on a large scale, and it's pretty rare we can't crack a truecrypt volume.


Must be a shitload of easy passwords and birthdays.

How long would it take to crack a seemingly random string of 16 characters?
 
Must be a shitload of easy passwords and birthdays.

How long would it take to crack a seemingly random string of 16 characters?

Most people probably don't use a 16 character password. you can probably start with lower case alpha, then lower/upper case alpha, then lower/upper alpha numeric and chances are you will crack most passwords. If there's special characters then it will start to add up to the time, but it's not a matter of if, but a matter of when. The more computers you have working on it the faster it goes. Essentially each computer doubles the time.

Ex: one computer can try AAAAAAAA, AAAAAAC, AAAAAAE, AAAAAAG and so on while the other computer does AAAAAAB, AAAAAAAD, AAAAAAAF, AAAAAAAH and so on.

Probably do a dictionary attack first though.
 
How long would it take to crack a seemingly random string of 16 characters?

Depends on the character set.for UTF 8 it would take
2^8 * 2^8 * ... * 2^8 = 2^128
guesses to exhaust the key space. So depends on the processor being used, but say you can do 1 megahash/second (remember that you need to hash the guess)
2^128/1000000 = 5316911983139663491615228241121378304/15625
or
3.40282366920938463463374607431768211456 × 10^32
so 3.4 * 10^32 seconds (ish)
roughly speaking a long ass time.
https://www.wolframalpha.com/input/?i=3.4*10^32+seconds+in+years
 
Depends on the character set.for UTF 8 it would take
2^8 * 2^8 * ... * 2^8 = 2^128
guesses to exhaust the key space.

Although, practically, nobody is going to use the full UTF-8 range to set a password.

If the person you are attacking is using an English keyboard, odds are good they are using 'regular' keys (IE., 26 lowercase, 26 uppercase, 10 numbers, 32 'special characters' - IE., only 94 unique characters to work from). It's not GUARANTEED, of course, but it'll cover 99% of the things you need to break into, and saves a LOT of work.
 
A 16-character password from 94 unique characters is still log(94^16)/log(2) = roughly 105 bits of entropy.
 
Come to think of it, do most systems even allow you to use extended ascii characters in passwords?

Ex: if I want to use char 254 or some oddball char like that. Even the simpler ones like tab can probably be left out, because chances are when entering the password when you hit tab it will actually tab to the next field. The system itself can probably handle the characters fine in back end but the GUI may not, so it's something to account for when writing a brute force script. There is probably also a way you could use ASICs to brute force encrypted files much faster than in software with PCs.

Chances are agencies like the NSA don't use regular PCs for this type of stuff, it's fully custom. ASICs today are usually related to bitcoin mining, but ASICs can be for anything they are designed for and are more efficient than doing the same thing with a regular PC using software.
 
Trying all combinations of 105 bits is 1286301978922607 years of work at 1 billion tries per second.

It just doesn't matter if you can accelerate the process by a factor of 1000 or 1000000 or even 1000000000.
 
man , and i use truecrypt all the time. steve gibson posted some interesting articles about it
 
Come to think of it, do most systems even allow you to use extended ascii characters in passwords?


This is actually one of the problems with implementation. For the last 10-15 years security and "good password strategies" have been talked up religiously, yet every single system is different. A good password generator, encryption program, and security implementation (Bank) will include at the very least all 95 common keyboard characters.

Unfortunately we have a lot of situations where this is a problem. A ton of password generators in manager software limit your character length. Websites and programs further limit you as do what characters you can use. Some will forbid you from using special characters at all. Others wont recognize the difference between capital and lower case, etc. The problem isn't just users and their passwords, but the lack of uniformity across the world. There is no standard it seems. To make matters worse, websites don't tell you what they accept as far as length and characters, so the user is in the dark.

I've seen some programs that support greater than 95 ASCII characters, but they're hard to come by. Some of those password testing sites load up dictionaries of 2,048+ characters using common ones you can do yourself like: é - whatever that term is called for those.
 
A 16-character password from 94 unique characters is still log(94^16)/log(2) = roughly 105 bits of entropy.

Except it's not, because *nobody* is going to use a combination of 16 literally random unique characters from that set of 94.

You start with your basic dictionary, do obvious character substitutions or insertions, simple phrases with various word combinations, non-space word breaks, etc using that 94 character set.

It's not a trivial problem, no, but it's also no 105 bits of entropy.
 
Although, practically, nobody is going to use the full UTF-8 range to set a password.

If the person you are attacking is using an English keyboard, odds are good they are using 'regular' keys (IE., 26 lowercase, 26 uppercase, 10 numbers, 32 'special characters' - IE., only 94 unique characters to work from). It's not GUARANTEED, of course, but it'll cover 99% of the things you need to break into, and saves a LOT of work.
Beyond that there are better attacks than brute force, but the question was how long does it take for a 16 character password. ACSII is 7 bit so 2^7 *... *2^7 = 2^(16*7) and the rest of the math is the same. Still a big ass number.
 
Beyond that there are better attacks than brute force, but the question was how long does it take for a 16 character password. ACSII is 7 bit so 2^7 *... *2^7 = 2^(16*7) and the rest of the math is the same. Still a big ass number.

Yeah, but as noted in the post right before that - 'strings of random characters' isn't a realistic thing to plan for. NOBODY is going to remember that, so nobody will use it (without posting a sticky note to their monitor, defeating the entire purpose).

You've only got so many words in the English language (and it's a big number!), so picking a password that is a single word, or short set of words, yet still amounting to 16 characters or less...seriously limits the degrees of entropy you need to worry about.
 
Yeah I really agree with the poster that said that we have trained ourselves to make passwords that are easy for a computer to break, but difficult to remember. Someone needs to implement colors and orientations into characters. For instance, if you use the basic 94 char set, and make it so each character can have 1 byte of grayscale color (adds 256 possible), and 8 possible easy orientations (represented by the characters 1,2,3,4,6,7,8,9 on a 10 key pad) and teach everyone to include at least one of these extra special characters then you have 192,512 possible "characters" and it will be easy for a regular person to remember 1 color value and 1 orientation, difficult for a computer to bruteforce.

If someone would just take the time to make a completely new extremely-stupidly-hard and complex character set specifically for encryption we could shut these bastards down.

8 character 140 bit passwords, and that's just the easy start!
 
What is encryption for 99.99999% of the time?

It's to cause enough hassle to stop the guy that stole or found your laptop from seeing whats on it before its wiped with a pirate copy of Windows 7.

Basically it needs to hold out for a few half hearted attempts at the password or 4 minutes, whichever is longer.

Thats about it.


As for Truecrypt...well it was obsolete going forward for full disk encryption on UEFI machines. That had not been fixed for three years so I guess they lost interest.
 
Tell this to all the cryptographers who are pissing away their lives developing secure encryption. Those fools...
 
Tell this to all the cryptographers who are pissing away their lives developing secure encryption. Those fools...

Well it surprises me how many 'ordinary' folks seem to think their data is worthy of Ethan Hunt slipping down a skylight on a wire to get it.

Trust me, no one is queuing up to crack open your triple encrypted holiday snaps.
 
Well it surprises me how many 'ordinary' folks seem to think their data is worthy of Ethan Hunt slipping down a skylight on a wire to get it.

Trust me, no one is queuing up to crack open your triple encrypted holiday snaps.

The danger is if they find MP3's or movies. The fines and jail time for that are simply beyond ridiculous. EVERYONE will have at least a few pirated content on their machine. It would be ignorant to think that some people don't do it.

Yet, it's one of the worse crimes you could ever do in the US and has the most harsh penalty of any other crime including violent crimes. You will have better luck being caught killing someone, you might get a few months of jail if you even get convicted.
 
Back
Top