TrueCrypt inspired confidence in me because the way the dev team operated displayed true expertise and professionalism. Maybe I perceived that incorrectly, but that's how I felt.
VeraCrypt has always seemed like someone swooped down and forked TrueCrypt the moment it became abandoned, to grab all its faithful users.
Now, that's a bit dramatic, and probably not entirely true. But that's how it always felt to me -- ANYONE can just fork TrueCrypt. Why should I trust these guys in particular?
VeraCrypt is currently maintained by Mounir Idrassi, which is like a real person with a name. VeraCrypt is also actively developed, the big issue solved in version 1.8 being to add support for UEFI GPT drives, which is actually a big deal.
TrueCrypt was developed by an anonymous developer that vanished, abandoning the project. Funny how trust works.
The way in which TrueCrypt "became abandoned" does not inspire confidence as well. Considering they left a cryptic and very strange exit note that many perceived as a notice of law enforcement activity.
Although TrueCrypt existed since 2004 he ordered his employees around 2007 to use E4M (which would be improbable if he really developed TrueCrypt). The developer (or developers) of TrueCrypt isn't publicly known.
Ah I get what you meant now, I agree. If some entity already had their eye on TrueCrypt and had shut it down, you wouldn't expect them to let a copycat pop up unless it was less secure.
That's always how these worst backdoors begin... with curious patterns of zeroes. How better to zero out a key than with actual zeroes. Nobody will ever suspect!
VeraCrypt has always seemed like someone swooped down and forked TrueCrypt the moment it became abandoned, to grab all its faithful users.
Now, that's a bit dramatic, and probably not entirely true. But that's how it always felt to me -- ANYONE can just fork TrueCrypt. Why should I trust these guys in particular?