Re: [OT][Update] VeraCrypt 1.26.29
Shadow <[email protected]>
| Newsgroups | alt.comp.freeware |
|---|---|
| Organization | A noiseless patient Shadow |
| Message-ID | <[email protected]> |
On Fri, 12 Jun 2026 01:07:00 +0000, "p-0 0-h the cat (coder) <[email protected]>" wrote: >On 11/06/2026 22:59, Shadow wrote: >> On Thu, 11 Jun 2026 15:09:51 -0500, "Allan Higdon" >> <[email protected]> wrote: >> >>> "VeraCrypt is a free open source disk encryption software for Windows, Mac OSX and Linux. Brought to you by IDRIX ( https://www.idrix.fr/ ) and based on TrueCrypt 7.1a." >>> >>> Features: >>> >>> Available for Linux, MacOSX (10.7+) and Windows >>> Increased security and many vulnerabilities fixed compared to TrueCrypt >> >> Interesting. What are Truecrypt 7.1.1's (AKA 7.1a) >> vulnerabilities? > >Hi, Shit the cat says "Thanks for asking" > >First of all 7.1.1 has a bit of a history. The actual version audited >was 7.1a. Seriously, don't go there. Someone squirted open sauce all >over it. Terrible mess. > >Anyway, Veracrypt used the audited 7.1a I'm told > >The vulnerabilities identified in the OCAP audit were fixed says AI but >all I can tell ya is the version history has no mention of the Open >Crypto Audit post 5/4/2015 but a ton of work has been done since then. > >Also the key derivation security was overhauled making brute force >attacks way harder. > >You can find Phase 1 and Phase 2 of the OCAP report on your favorite >repository GitHub if you weren't a dinosaur that is but I'm sure someone >will find them for you. > >iSEC Partners / NCC Group Publications is allegedly the spell that your >old friend Google will magically use to transport you there. I really >cannot be arsed to check because .... see below > >btw fun fact the TrueCrypt developers buggered off and recommended >people use Bitlocker. There was an encoded message in the readme (in Latin)saying that all the alternatives were NOT safe. Strangely, that completely disappeared from the Wiki page. Bitlocker, Veracrypt and something called CipherShed were recommended by the TLAs as viable alternatives. ALL of them have had multiple vulnerabilities(the CVEs are full of them). CipherShed was abandoned as a bad joke. Bitlocker? //According to Microsoft sources,BitLocker does not contain an intentionally built-in backdoor// - 2006 //Starting with Windows 8 and Windows Server 2012, Microsoft removed the Elephant Diffuser from the BitLocker scheme for no declared reason. Dan Rosendorf's research shows that removing the Elephant Diffuser had an "undeniably negative impact" on the security of BitLocker encryption against a targeted attack. Microsoft later cited performance concerns, and noncompliance with the Federal Information Processing Standards (FIPS), to justify the diffuser's removal.// And the FIPS isn't even a TLA, it's a FLA. LOL. > > >> But it's good to know "many" were fixed.... > >Four dots is that like super skeptical inferring your usual conspiracy >innuendo or are you being generally supportive? I hope it's the latter. > >AI reckons it's had another couple of audits since. Veracrypt that is. Yes, in 2016 and 2020, and they found multiple vulnerabilities, "which were fixed". Sounds about right. And early this year Microsoft refused to sign the Veracrypt executable. But they "negociated" with the developers. And the latest version is signed again. And if it's signed you can trust it, right? > >Thanks YW []'s -- Don't be evil - Google 2004 We have a new policy - Google 2012 Google Fuchsia - 2021