[liberationtech] Emergency: Has TrueCrypt.org been Hijacked?

2014-05-28 Thread Brad Beckett
Truecrypt.org now redirects to: http://truecrypt.sourceforge.net/ with a warning to use Bitlocker and not Truecrypt. Something seems off. - Brad -- Liberationtech is public archives are searchable on Google. Violations of list guidelines will get you moderated:

Re: [liberationtech] Emergency: Has TrueCrypt.org been Hijacked?

2014-05-28 Thread KheOps
On Wed, May 28, 2014 at 01:44:12PM -0700, Brad Beckett wrote: Truecrypt.org now redirects to: http://truecrypt.sourceforge.net/ with a warning to use Bitlocker and not Truecrypt. Hard to tell whether it's a hijack or an actual warning message. Does it make sense that TrueCrypt development could

Re: [liberationtech] Emergency: Has TrueCrypt.org been Hijacked?

2014-05-28 Thread Nighat Dad
That warning on TrueCrypt's website has been there since a while. AFAIK, iSEC did a security audit of TrueCrypt and found various weaknesses and issues in it. opencryptoaudit.org/reports/iSec_F… https://t.co/FEXS8JkSnZ On Wed, May 28, 2014 at 10:58 PM, KheOps khe...@ceops.eu wrote: On Wed,

Re: [liberationtech] Emergency: Has TrueCrypt.org been Hijacked?

2014-05-28 Thread Bernard Tyers
Hi Nighat, When you say a while, how long do you mean? There is a thread on the Twitters at the moment about this: https://twitter.com/runasand/status/471740622031032320 - The the signature of the .exe still verifies. - The key seems to be legit:

Re: [liberationtech] Emergency: Has TrueCrypt.org been Hijacked?

2014-05-28 Thread Andrew Lewis
The new exe is apparently signed with the same cert as the old one, and people say that the only changes so far in comparing diff's is the warning message and turning it into remove-only. (I haven't had a chance to verify myself, but these are claims from the twittersphere) -Andrew On May 28,

Re: [liberationtech] Emergency: Has TrueCrypt.org been Hijacked?

2014-05-28 Thread Tom O
If your bored https://github.com/warewolf/truecrypt/compare/master...7.2 On Thursday, May 29, 2014, Andrew Lewis m...@andrewlew.is wrote: The new exe is apparently signed with the same cert as the old one, and people say that the only changes so far in comparing diff's is the warning message