Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

TrueCrypt inspired confidence in me because the way the dev team operated displayed true expertise and professionalism. Maybe I perceived that incorrectly, but that's how I felt.

VeraCrypt has always seemed like someone swooped down and forked TrueCrypt the moment it became abandoned, to grab all its faithful users.

Now, that's a bit dramatic, and probably not entirely true. But that's how it always felt to me -- ANYONE can just fork TrueCrypt. Why should I trust these guys in particular?



TrueCrypt went belly up in May,2014[1]

VeraCrypt 1.0 was released in May,2013[2]. One year prior.

[1] http://truecrypt.sourceforge.net

[2] https://sourceforge.net/u/yanpas/veracrypt/ci/VeraCrypt_1.0b...


VeraCrypt is currently maintained by Mounir Idrassi, which is like a real person with a name. VeraCrypt is also actively developed, the big issue solved in version 1.8 being to add support for UEFI GPT drives, which is actually a big deal.

TrueCrypt was developed by an anonymous developer that vanished, abandoning the project. Funny how trust works.


The way in which TrueCrypt "became abandoned" does not inspire confidence as well. Considering they left a cryptic and very strange exit note that many perceived as a notice of law enforcement activity.


The strongest evidence I have seen is that the developer was arrested by the DEA on unrelated charges.[0]

The full story about him is fascinating and well worth the read.[1]

[0] http://www.newyorker.com/news/news-desk/the-strange-origins-...

[1] https://mastermind.atavist.com/


It's not a developer of TrueCrypt but of E4M. At the time TrueCrypt was developed Le Roux was busy with doing crimes.

https://en.wikipedia.org/wiki/E4M

https://en.wikipedia.org/wiki/Paul_Le_Roux

Although TrueCrypt existed since 2004 he ordered his employees around 2007 to use E4M (which would be improbable if he really developed TrueCrypt). The developer (or developers) of TrueCrypt isn't publicly known.


If anything that cryptic abandonment actually gave me more confidence in TrueCrypt. Was it so hard to crack that the government shut it down?


I meant confidence in what came after it. Meaning the likelihood of a backdoored and/or weak software was likely.


Ah I get what you meant now, I agree. If some entity already had their eye on TrueCrypt and had shut it down, you wouldn't expect them to let a copycat pop up unless it was less secure.


This is the "NSAKEY" of open source crypto conspiracy theories.


As far as I recall, there are 8 bytes set to zero in the TC header at a very curious location.


That's always how these worst backdoors begin... with curious patterns of zeroes. How better to zero out a key than with actual zeroes. Nobody will ever suspect!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: