5 ms·
Call me paranoid but this just looks like really good evidence that Truecrypt was secure.
by harrystone 12y ago
Call me paranoid but this just looks like really good evidence that Truecrypt was secure.
- alextgordon 12y ago...or that BitLocker isn't.
- lelandriordan 12y agoI know everyone likes to bash MS around here but is there any actual proof of Bitlocker's insecurity that is more recent than 2008? If you look at wikipedia it seems like the only known real vulnerability requires someone with physical access to boot via USB into another OS within a few minutes of turning the computer off. When is this a real risk for anyone? I am not a security expert but unless you are doing things shady enough to get raided by the FBI, it seems like Bitlocker is pretty secure. The same problem occurs in other encryption programs on Linux and OSX. Also, it may not be open source like what we want, but MS lets its partners and enterprise customers audit the code subject to an NDA. http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption#Security_concerns http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption#Secu...
- nacs 12y agoIt's not open source so who knows what's lurking in there? It's not like anyone has been able to audit the source of Bitlocker.
- pfg 12y agoIt's really not that hard to imagine scenarios where this might happen. Simply leaving your notebook unattended after a shutdown might leave you compromised. Besides, government agencies in other countries might have a slightly different view on what constitutes "shady behaviour" (think regime critics).
- alextgordon 12y agoPut it this way. There's no proof that BitLocker is any more effective than rot13.
- rflig 12y agoDon't forget that M$ gives you the great 'service' to store your BL-key in your M$-account (on their servers) as soon as a) your machine is not connected to a domain and b) you're [...] enough (most are!) to log on with an M$-account to Win8.x.
- Shorel 12y ago...and that BitLocker isn't.