Skip to main content

Why TrueCrypt might not be so insecure after all

have i been pwned owner uncovers 13 million plaintext passwords leaked from free webhost is a safe password even possible we
guteksk7/Shutterstock
Reports of TrueCrypt’s flaws were greatly exagerated, if a 77-page report coming out of Germany’s Fraunhofer Institute is anything to go by. The intensive six-month study concludes that the encryption software is nowhere near as insecure as reported back in 2014.

“Our general conclusion is that TrueCrypt is safer than previous examinations suggest,” wrote professor Eric Bodden in a blog post announcing the study.

TrueCrypt was discontinued in the summer of 2014 — the developers said they didn’t want to maintain a standard with “unfixed security issues.” It’s still not clear exactly what those vulnerabilities were — they were never announced, in part to protect the project’s millions of users. Security researcher James Forshaw did find two flaws in September that could be used to compromise a machine (though not decrypt an encrypted hard drive), but it’s possible the vulnerability that led to the project being abandoned is something else entirely.

Whatever the problem is, the Fraunhofer Institute didn’t find anything they deemed a critical flaw during their six-month study — though they did state that encryption can’t solve all security concerns.

“From a security perspective, the fact that TrueCrypt is a purely software solution means that it cannot in principle protect against all relevant threats,” says the study.

Bodden added to this point in his blog post.

“It does not seem apparent to many people that TrueCrypt is inherently not suitable to protect encrypted data against attackers who can repeatedly access the running system,” wrote Bodden, adding that “TrueCrypt seems not better or worse than its alternatives” so far as encrypting data is concerned.

Basically, if someone already has access to your system in some way — be it physical access to the machine while it’s running, or the installation of Trojan horse malware — encryption of any kind won’t help. Keyloggers can be installed, and files can be accessed by malware while the user is accessing an encrypted drive — no encryption can prevent that. Encryption does, however, make it hard for someone who steals your hard drive to access the data on it.

Whatever flaw prompted the TrueCrypt developers to abandon the project — and even advise developers to not fork it — may not have shown up in any study, but it’s becoming harder to imagine what that flaw might be. A fork of the software, called VeraCrypt, includes patches for every bug that’s been found so far.

Editors' Recommendations

Justin Pot
Former Digital Trends Contributor
Justin's always had a passion for trying out new software, asking questions, and explaining things – tech journalism is the…
How to easily connect any laptop to a TV
An image-editor app being used to edit photos on a laptop.

If you’re using a laptop on a daily basis, you’ll know how tiring it can get to stare at a 13-inch screen for hours on end. This is why it’s great that most modern PCs can be connected to a TV. Not only does this give you a bigger display to work with, but you’ll still be able to use your laptop as you normally would. So no saying goodbye to those handy trackpad gestures!

Read more
The Asus ROG Ally just got a game-changing update
Asus ROG Ally handhelds side by side.

Asus' ROG Ally is one of the best handheld gaming PCs you can buy, and now it's getting even better. Asus is updating the handheld with AMD's Fluid Motion Frames (AFMF). This is a driver-level feature that adds frame generation to the majority of DirectX 11 and 12 games, which should vastly improve performance.

We've seen AFMF in action on AMD graphics cards previously. The feature launched late last year for desktop and mobile AMD graphics cards, but the ROG Ally oddly didn't support the feature. Asus' handheld uses the Ryzen Z1 chipset, which includes both an AMD processor and graphics card, but it uses its own specialized driver. Because of that, it didn't receive AFMF support right away.

Read more
How to delete a Discord server on desktop and mobile
Memrise bot in the Discord app directory.

Have you had enough of Discord for a while? We get it. It can be a little exhausting to say the least, especially if you’re running a jam-packed server, filled with multimedia and messages. Fortunately, if you’re in the mood to take a break, it’s not too hard to delete your Discord server.

Read more