Skip to main content
  1. Home
  2. Computing
  3. News

Why TrueCrypt might not be so insecure after all

Add as a preferred source on Google

Reports of TrueCrypt’s flaws were greatly exagerated, if a 77-page report coming out of Germany’s Fraunhofer Institute is anything to go by. The intensive six-month study concludes that the encryption software is nowhere near as insecure as reported back in 2014.

“Our general conclusion is that TrueCrypt is safer than previous examinations suggest,” wrote professor Eric Bodden in a blog post announcing the study.

Recommended Videos

TrueCrypt was discontinued in the summer of 2014 — the developers said they didn’t want to maintain a standard with “unfixed security issues.” It’s still not clear exactly what those vulnerabilities were — they were never announced, in part to protect the project’s millions of users. Security researcher James Forshaw did find two flaws in September that could be used to compromise a machine (though not decrypt an encrypted hard drive), but it’s possible the vulnerability that led to the project being abandoned is something else entirely.

Whatever the problem is, the Fraunhofer Institute didn’t find anything they deemed a critical flaw during their six-month study — though they did state that encryption can’t solve all security concerns.

“From a security perspective, the fact that TrueCrypt is a purely software solution means that it cannot in principle protect against all relevant threats,” says the study.

Bodden added to this point in his blog post.

“It does not seem apparent to many people that TrueCrypt is inherently not suitable to protect encrypted data against attackers who can repeatedly access the running system,” wrote Bodden, adding that “TrueCrypt seems not better or worse than its alternatives” so far as encrypting data is concerned.

Basically, if someone already has access to your system in some way — be it physical access to the machine while it’s running, or the installation of Trojan horse malware — encryption of any kind won’t help. Keyloggers can be installed, and files can be accessed by malware while the user is accessing an encrypted drive — no encryption can prevent that. Encryption does, however, make it hard for someone who steals your hard drive to access the data on it.

Whatever flaw prompted the TrueCrypt developers to abandon the project — and even advise developers to not fork it — may not have shown up in any study, but it’s becoming harder to imagine what that flaw might be. A fork of the software, called VeraCrypt, includes patches for every bug that’s been found so far.

Justin Pot
Justin's always had a passion for trying out new software, asking questions, and explaining things – tech journalism is the…
The best password managers for 2026
have i been pwned owner uncovers 13 million plaintext passwords leaked from free webhost is a safe password even possible we

Passwords are still a fact of digital life, even as passkeys slowly start to change how we sign in to our accounts. Apple, Google, and other platforms have also made their built-in password managers much more capable, giving people more options than ever for keeping track of their credentials. A dedicated password manager still has an important advantage, though: it can bring passwords, passkeys, two-factor authentication, secure notes, and shared credentials together across the different devices and platforms you use.

The best password managers also make good security habits easier to maintain. They can generate unique passwords instead of leaving you to come up with another variation of the same one, flag compromised credentials, and make it easier to share access without passing passwords around in messages. For families and people who regularly move between operating systems, they can be particularly useful, while privacy-focused services offer another reason to look beyond the tools built into your phone or browser.

Read more
Anthropic wants everyone to take a chill pill at cooking worryingly powerful AI models
Anthropic’s CEO thinks frontier AI is advancing faster than its safeguards, and his proposed fix amounts to giving the industry a speed limit
Claude Anthropic Featured

Anthropic CEO Dario Amodei thinks the AI industry is moving too fast for its own safety work to keep up. He still wants more powerful AI. He just wants companies to take longer getting there.

In a new essay, Amodei is calling for frontier AI companies to deliberately slow how quickly their models improve. The extra time would go toward understanding stronger systems and making sure safeguards work before another leap arrives. He argues AI progress would still remain fast.

Read more
OpenAI AI agents were linked to a cyberattack on RubyGems before the Hugging Face incident
Rogue AI concerns grow after OpenAI agents disrupt RubyGems in May attack
OpenAI logo on Microsoft surface

Artificial intelligence agents being tested by OpenAI were involved in a previously undisclosed cyberattack against RubyGems in May, an incident that is now raising uncomfortable questions about how much control humans really have over increasingly autonomous AI systems.

The attack overwhelmed RubyGems, a popular service used by software developers to publish and access Ruby packages, forcing operators to suspend new account registrations for four days. According to a report by The Wall Street Journal, OpenAI confirmed that its agents had been involved, but said they were using the platform to perform benign tasks and retrieve publicly available information during a training run.

Read more