Urban75 Home About Offline BrixtonBuzz Contact

Heads Up on Hushmail - Not secure

an audit is pretty standard. It doesn't mean they expect it to be dodgy.. Just that they want to prove it isn't

There is a bit of specific code they are concerned about......

For one thing, researchers have been unable to prove that the downloadable Windows executable, built by the TrueCrypt team, can be constructed purely from the published source code, for reasons based on unusual decisions by the developers – as explained by cryptographer Matthew Green here. (In short, the Windows binary appears to save a block of unexplained bytes with the encrypted data. Some fear this is a key to a backdoor, which would allow people in-the-know to decrypt the data without the user's password.)

http://www.theregister.co.uk/2013/10/15/truecrypt_security_audit/
 
Back
Top Bottom