{"id":30163,"date":"2015-04-03T09:40:44","date_gmt":"2015-04-03T13:40:44","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/truecrypt-doesnt-contain-nsa-backdoors.php"},"modified":"2015-04-03T09:40:44","modified_gmt":"2015-04-03T13:40:44","slug":"truecrypt-doesnt-contain-nsa-backdoors","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/truecrypt-doesnt-contain-nsa-backdoors.php","title":{"rendered":"TrueCrypt doesn&#8217;t contain NSA backdoors"},"content":{"rendered":"<p><p>    A security audit of TrueCrypt has determined that the disk    encryption software does not contain any backdoors that could    be used by the NSA or other surveillance agencies. A report    prepared by the NCC Group for Open Crypto Audit Project found    that the encryption tool isnot vulnerable to being    compromised.  <\/p>\n<p>    However, the software was found to contain a few other security    vulnerabilities, including one relating to the use of the    Windows API to generate random numbers for master encryption    key material. Despite this, TrueCrypt was given a relatively    clean bill of health with none of the detected vulnerabilities    considered sever enough to lead \"to a complete bypass of    confidentiality in common usage scenarios\".  <\/p>\n<p>    NCC's     report reveals a total of four vulnerabilities in    TrueCrypt, with two of them being marked as severe. The most    worrying -- although it must be stressed that the report does    not suggest that there is real cause for concern -- stems from    the fact that random numbers are generated based on values from    a Windows API. Should this API fail for any reason, TrueCrypt    may continue to generate keys with the possibility of an    element of predictability -- clearly not ideal for encryption    software.  <\/p>\n<p>    Moving forward, the report stresses the importance of improving    error handing in the software:  <\/p>\n<p>      Because TrueCrypt aims to be security-critical software, it      is not appropriate to fail silently or attempt to continue      execution in unusual program states. More than simply      aborting the application, attempt to gather relevant      diagnostic information and make it available for submission      to developers to diagnose root-causes. This is especially      important as it is difficult to fully test code on multiple      operating systems and configurations.    <\/p>\n<p>    With an increased interest in the activities of the NSA, and    particularly in the suggestion that hardware and software    should have backdoors built in by default, the report will    comes as good news overall for TrueCrypt users.  <\/p>\n<p>    Photo Credit: Lightspring    \/ Shutterstock  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/betanews.com\/2015\/04\/03\/truecrypt-doesnt-contain-nsa-backdoors\" title=\"TrueCrypt doesn't contain NSA backdoors\">TrueCrypt doesn't contain NSA backdoors<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> A security audit of TrueCrypt has determined that the disk encryption software does not contain any backdoors that could be used by the NSA or other surveillance agencies. A report prepared by the NCC Group for Open Crypto Audit Project found that the encryption tool isnot vulnerable to being compromised. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-30163","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/30163"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=30163"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/30163\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=30163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=30163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=30163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}