Re: [OT][Update] VeraCrypt 1.26.29

Shadow <[email protected]>
Newsgroups alt.comp.freeware
Organization A noiseless patient Shadow
Message-ID <[email protected]>
On Fri, 12 Jun 2026 01:07:00 +0000, "p-0 0-h the cat (coder)
<[email protected]>" wrote:

>On 11/06/2026 22:59, Shadow wrote:
>> On Thu, 11 Jun 2026 15:09:51 -0500, "Allan Higdon"
>> <[email protected]> wrote:
>> 
>>> "VeraCrypt is a free open source disk encryption software for Windows, Mac OSX and Linux. Brought to you by IDRIX ( https://www.idrix.fr/ ) and based on TrueCrypt 7.1a."
>>>
>>> Features:
>>>
>>> Available for Linux, MacOSX (10.7+) and Windows
>>> Increased security and many vulnerabilities fixed compared to TrueCrypt
>> 
>> 	Interesting. What are Truecrypt 7.1.1's (AKA 7.1a)
>> vulnerabilities?
>
>Hi, Shit the cat says "Thanks for asking"
>
>First of all 7.1.1 has a bit of a history. The actual version audited 
>was 7.1a. Seriously, don't go there. Someone squirted open sauce all 
>over it. Terrible mess.
>
>Anyway, Veracrypt used the audited 7.1a I'm told
>
>The vulnerabilities identified in the OCAP audit were fixed says AI but 
>all I can tell ya is the version history has no mention of the Open 
>Crypto Audit post 5/4/2015 but a ton of work has been done since then.
>
>Also the key derivation security was overhauled making brute force 
>attacks way harder.
>
>You can find Phase 1 and Phase 2 of the OCAP report on your favorite 
>repository GitHub if you weren't a dinosaur that is but I'm sure someone 
>will find them for you.
>
>iSEC Partners / NCC Group Publications is allegedly the spell that your 
>old friend Google will magically use to transport you there. I really 
>cannot be arsed to check because .... see below
>
>btw fun fact the TrueCrypt developers buggered off and recommended 
>people use Bitlocker.

	There was an encoded message in the readme (in Latin)saying
that all the alternatives were NOT safe. Strangely, that completely
disappeared from the Wiki page.
	Bitlocker, Veracrypt and something called CipherShed were
recommended by the TLAs as viable alternatives. ALL of them have had
multiple vulnerabilities(the CVEs are full of them).
	CipherShed was abandoned as a bad joke.

	Bitlocker?

//According to Microsoft sources,BitLocker does not contain an
intentionally built-in backdoor// - 2006

//Starting with Windows 8 and Windows Server 2012, Microsoft removed
the Elephant Diffuser from the BitLocker scheme for no declared
reason. Dan Rosendorf's research shows that removing the Elephant
Diffuser had an "undeniably negative impact" on the security of
BitLocker encryption against a targeted attack. Microsoft later cited
performance concerns, and noncompliance with the Federal Information
Processing Standards (FIPS), to justify the diffuser's removal.//

	And the FIPS isn't even a TLA, it's a FLA. LOL.
>
>
>> 	But it's good to know "many" were fixed....
>
>Four dots is that like super skeptical inferring your usual conspiracy 
>innuendo or are you being generally supportive? I hope it's the latter.
>
>AI reckons it's had another couple of audits since. Veracrypt that is.

	Yes, in 2016 and 2020, and they found multiple
vulnerabilities, "which were fixed".
	Sounds about right.

	And early this year Microsoft refused to sign the Veracrypt
executable. But they "negociated"  with the developers. And the latest
version is signed again.
	And if it's signed you can trust it, right?
>
>Thanks

	YW
	[]'s
--
Don't be evil - Google 2004
We have a new policy  - Google 2012
Google Fuchsia - 2021
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.