6 ms·
If those companies wanted to subvert your TrueCrypt installation, they would have an easy time of it.
by sdevlin 11y ago
If those companies wanted to subvert your TrueCrypt installation, they would have an easy time of it.
- mafribe 11y agoCould you sketch how, so we can think about countermeasures?
- tedunangst 11y agoMITM the http connection you used to download truecrypt?
- Buge 11y agoI assume MITM your https connection by manipulating CAs. Or use one of their 0days to breaking into your machine and get your data while it is decrypted in memory or just steal your password.
- Lawtonfogle 11y agoI would assume both Windows and Mac are compromised to the level of C&C by the NSA. In a threat model that includes them I would not use either. But I would still think Windows + TrueCrypt is better than Windows + BitLocker.
- tptacek 11y agoDo you mean "NSA has stockpiled vulnerabilities they've discovered in Win8 that would enable them to quickly enroll a networked Win8 box into a C&C"? If so: sure, I agree. Do you mean "NSA has implanted backdoors into Win8 that would enable them to directly enroll a Win8 box into a C&C"? If so: virtually nobody who does professional vulnerability research, myself included, agrees. The distinction matters here, because if all you're saying is the former thing, that impacts Truecrypt just as much as Bitlocker, because it's equally true of every operating system, including Linux, FreeBSD and OpenBSD.
- Lawtonfogle 11y agoDoes it have an implanted back door? I don't know. Can it give one to Microsoft and say push it out as an update for these individuals and if you say anything you'll end up in prison? That is the problem with secret courts.
- mapt 11y agoThis seems silly, but Microsoft appears, on the surface, to have purchased Skype with the intention of selling surveillance to the NSA. They immediately replaced the whole network architecture and encryption setup with something that had weaker security and was subject to compromise of Microsoft. That's the sort of player we're dealing with, and that's why Bitlocker is not just improvably secure, it is best to simply assume that there are deliberate backdoors, whether any particular employee knows of them or not.
- astrange 11y agoSkype's peer-to-peer networking was entirely unsuitable for running on mobile devices, the new default market. I was never able to leave it logged in on my phone before, or else I'd only have half the usual battery life.
- sliken 11y agoAnd that's a justification for changing the way non-mobile devices handled skype?
- Lawtonfogle 11y agoEasy, but not as easy. I'm not saying that something is 100% secure, I'm saying that option A is better than option B.