Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

All of the files available here: http://truecrypt.ch/ have the same hashes as provided by this person.


Don't just trust my SHA1s, verify with the sigs and the TrueCrypt Foundation public key. Ensure the key has the fingerprint shown in the great-great-great grandparent of this comment, independently verified by others in this thread.

  gpg --import TrueCrypt-Foundation-Public-Key.asc
  gpg --fingerprint F0D6B1E0
  gpg --verify truecrypt-7.1a-linux-x64.tar.gz.sig
You should see:

  gpg: Signature made Tue 07 Feb 2012 12:45:26 PM PST using DSA key ID F0D6B1E0
  gpg: Good signature from "TrueCrypt Foundation <contact@truecrypt.org>"
  gpg: WARNING: This key is not certified with a trusted signature!
  gpg:          There is no indication that the signature belongs to the owner.
  Primary key fingerprint: C5F4 BAC4 A7B2 2DB8 B8F8  5538 E3BA 73CA F0D6 B1E0


Thanks!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: