Hacker Newsnew | past | comments | ask | show | jobs | submit | pig's commentslogin

Googlebot evaluates Javascript.


If you are paranoid^, you wouldn't use TrueCrypt. http://brianpuccio.net/excerpts/is_truecrypt_really_safe_to_...

^ good sense of the word


If you toss out the GUI stuff and the boilerplate encryption algorithms, the amount of important code in TrueCrypt is fairly small. It has, naturally enough, been subjected to attempts to break it:

http://www.zdnet.co.uk/news/security-management/2008/07/17/s...

Writing a sentence like "Some folks claim it has a backdoor" is painfully dishonest, manipulative, and scummy.


> If you toss out the GUI stuff and the boilerplate encryption algorithms, the amount of important code in TrueCrypt is fairly small.

First of all, even if you use "boilerplate" encryption algorithms, crypto is ridiculously easy to get wrong, especially in a very demanding setting of disk encryption. Second, TrueCrypt's ability to present its volumes as virtual drives/mountable images is no small feat (both in Linux and NT).


I can't speak for early 2009 when that article was published, but does any of this stand true today still?

They have a changelog here: http://www.truecrypt.org/docs/?s=version-history Their contact page says they're registered in the US and gives an address: http://www.truecrypt.org/contact

OK, can't speak for their forum banning as I'm not familiar with that situation and correct I cannot find any public repositories - but that's not too rare for some open source projects.

The reasons for being partially anonymous are pretty clear, I doubt various governments are a great fan of TrueCrypt especially with its plausible deniability.


Did you wonder why they have their address in that page as an image?

Apparently it is also near an air force base http://news.ycombinator.com/item?id=1533674


While I agree that we should not blindly place trust in security tools and assume we are safe, this link [1] gives me some optimism about TC's security (if it is to be believed... that's the problem with paranoia).

[1] http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto...


Yikes! I am going to go bury my head in some nice sandy hole for a while and pretend the world is a nicer place than it really is. :(



I made a question on Quora [1] for this in case anyone wants to contribute. I've seen alot of conflicting discussion on Hacker News as to the authenticity of TrueCrypt. Hopefully we can continue the dialogue and organize the response over there, as it may go beyond the scope of the discussion here, where it arguably only has a tenuous connection to amazon cloud storage or other web storage services.

[1] http://www.quora.com/Is-TrueCrypt-safe


Whoa! 100 to 200? How do you manage? How do you choose? Any tips / suggestions? I'd like to do it but I have no idea how I can without making it my full time job.


Having a train or bus ride be a significant part of your commute would help significantly. I plowed through books when I used to ride the bus to work (and that was only a 20-25 minute ride), but now that I bike I haven't been reading nearly as much.


Have you tried Favbot? http://www.favbot.com/ I like it a lot.



52 comments. tptacek has made 48 of them.


How about messing with your friends?


Do you see a causation there?


People who complain about a product that they have no intention of becoming a customer of are really annoying, especially in a startup focused community. Invite method is needed to ensure smooth rollout and scaling. Bugs can be fixed as reports come in, without getting the same bug report from 1000 people.


Why are they annoying? Don't you want to be able to acquire customers who originally had no intention of joining/buying/etc.? To do this, you'd be well-advised to at least take non-customers' opinions at face value without rejecting them out of hand. Reasons why people won't give you business can be just as useful as reasons why they will. Perhaps more.


Farmers work whenever they want.


And people haven't been using farm schedules to justify DST for several decades. It's now supposedly about electricity use.


It's about continuing to justify what has always been a bad idea of which the powers that be refuse to let go.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: