Re: [OT][Update] VeraCrypt 1.26.29
"p-0 0-h the cat (coder) <[email protected]>"
| Newsgroups | alt.comp.freeware |
|---|---|
| Organization | To protect and to server |
| Message-ID | <[email protected]> |
On 12/06/2026 13:00, Shadow wrote: > On Fri, 12 Jun 2026 01:07:00 +0000, "p-0 0-h the cat (coder) > <[email protected]>" wrote: >> btw fun fact the TrueCrypt developers buggered off and recommended >> people use Bitlocker. > > There was an encoded message in the readme (in Latin)saying > that all the alternatives were NOT safe. It's BS just search for "Uti NSA" > Strangely, that completely > disappeared from the Wiki page. What Wiki page? Did you check the history or was it a full blown Black OPs, pull out by the root, cover up by the TLAs? <snip> > > Bitlocker? > > //According to Microsoft sources,BitLocker does not contain an > intentionally built-in backdoor// - 2006 Yes, Dan Rosendorf confirmed that. > //Starting with Windows 8 and Windows Server 2012, Microsoft removed > the Elephant Diffuser from the BitLocker scheme for no declared > reason. Dan Rosendorf's research shows that removing the Elephant > Diffuser had an "undeniably negative impact" on the security of > BitLocker encryption against a targeted attack. Microsoft later cited > performance concerns, and noncompliance with the Federal Information > Processing Standards (FIPS), to justify the diffuser's removal.// [Pooh] Dan Rosendorf who is he [Gemini] Dan Rosendorf is a Czech cybersecurity professional and IT executive who wrote a highly cited academic research paper on BitLocker's architectural flaws back in 2012 which was titled "The BitLocker Schema: An Analysis of Microsoft's Full Disk Encryption." In 2012, Rosendorf was an academic researcher who presented his findings at a technical defense university conference (Security and Protection of Information). Today, he's a senior tech executive in the Czech Republic (he actually became the CEO of the ICZ Group, a major Central European enterprise technology and defense software provider). What did his research actually prove? Rosendorfs paper looked at exactly what happens to standard AES-CBC encryption if you strip away the Elephant Diffuser. He proved that without that diffuser layer, an attacker with sophisticated laboratory equipment could theoretically modify specific encrypted blocks on a hard drive without knowing the key. In the conclusions of his own presentation, Rosendorf explicitly clarified that removing the diffuser only matters if you are defending against a highly targeted, nation-state attack where someone steals your drive, modifies the binary bits in a lab, and boots it back up. [Pooh] So, to be clear someone has to have physical possession of the drive, modify it in a lab, what does that exactly mean, you can't just boot up with a windows cd and use HxD to modify the drive then you need a lab, is that something to do with the TPM chip [Gemini] Yes, you can't just slide in a live Windows USB stick or a bootable CD and start poking around with a hex editor like HxD. This is where the TPM (Trusted Platform Module) chip completely shuts down the attack vector. Here is exactly what "modifying it in a lab" means in this context On a properly configured modern machine, the TPM chip handles the encryption keys. During boot, the TPM does what is called an Integrity Measurement. Before it releases the key to decrypt the drive, the TPM checks the system's "state": Is the motherboard firmware untouched? Is the bootloader exactly the same? Has the partition table changed? If you boot the machine using a Windows installation CD or a Linux live USB to run HxD, the system's boot path changes completely. The TPM chip instantly detects this, locks down, and refuses to release the encryption key. Your drive remains an unreadable brick of scrambled data. You can't use HxD to intelligently modify something if you can't read what's on the disk to begin with. What "Modifying it in a Lab" Actually Means Because the TPM prevents software-level tampering on the machine itself, an attacker cannot use standard software tools. To bypass this, a nation-state adversary has to perform a highly advanced hardware-level physical attack. To exploit the missing Elephant Diffuser via Rosendorf's method, an attacker has to do the following: Desolder the Storage: Physically desolder the NVMe or flash memory chip directly off the laptop's motherboard. Hardware Programmer: Place the bare chip into a specialized hardware chip programmer connected to a separate forensics workstation. Bit-Flipping Manipulation: Because the data is encrypted via standard AES-CBC without a diffuser, changing a bit in sector A predictably scrambles sector A, but it also alters sector B in a mathematically predictable way. The attacker uses this quirk to precisely inject malicious code into a specific system file (like a login screen driver) without knowing the encryption key. Resolder and Boot: Solder the modified flash chip back onto the original motherboard perfectly, press power, and hope the TPM doesn't flag the modified system file before the injected code executes. > And early this year Microsoft refused to sign the Veracrypt > executable This was just clerical shit which affected others. > And if it's signed you can trust it, right? No. Pay attention. You are playing with the big cats now. Stay sharp Doc. We are hungry. Frankly Doc, you are insulting people backed with zero credible evidence and complete BS innuendo. The developer of VeraCrypt, what has he done to you and Allan for posting it who does a damn sight better due diligence than you Doc. No Hugs this time. Please stop. Post some real research and perhaps Shit will join in. Cat's lives matter! p-0.0-h the cat, the number one influencer on the Usenet Social! Live everyday like you're a really cool cat! Sent from my iFurryUnderbelly. -- p-0.0-h the cat Internet Terrorist, Mass sock puppeteer, Agent provocateur, Gutter rat, Devil incarnate, Linux user#666, BaStarD hacker, Resident evil, Monkey Boy, Certifiable criminal, Spineless cowardly scum, textbook Psychopath, the SCOURGE, l33t p00h d3 tr0ll, p00h == lam3r, p00h == tr0ll, troll infâme, the OVERCAT [The BEARPAIR are dead, and we are its murderers], lowlife troll, shyster [pending approval by STATE_TERROR], cripple, sociopath, kook, smug prick, smartarse, arsehole, moron, idiot, imbecile, snittish scumbag, liar, total ******* retard, shill, pooh-seur, Pooh Dendum, scouringerer, jumped up chav, punk ass dole whore troll, no nothing innumerate religious maniac, lycanthropic schizotypal lesbian, professional bully and stalker, the most complete ignoid, joker, and furball. NewsGroups Numbrer One Terrorist Honorary SHYSTER and FRAUD awarded for services to Haberdashery. By Appointment to God Frank-Lin. Signature integrity check md5 Checksum: be0b2a8c486d83ce7db9a459b26c4896 I mark any messages from trolls »Q« and 'Arlene' Holder as stinky