I do like the algorithms options (there are 15 available) and being able to combine them, while also having the option to choose from 4 different hash algorithms. Veracrypt is open-source, which is for me a marker of trust (reducing the chance of backdoors). Even if the cloud backup company has a breach, we feel assured that our data is not accessible. Now, all our data is secured in safe containers, and backed online. You never know when one day your data ends up in the wrong hands. In addition to patches for these two flaws, the program also has other security improvements over its predecessor.I used to have private data all around my hard drives. Users who still use TrueCrypt should switch to VeraCrypt as soon as possible. Microsoft's BitLocker is not available on Home editions of Windows, which come pre-installed on many consumer laptops, and most other programs that can encrypt the system partition require a paid license. There are still many users of TrueCrypt or VeraCrypt, because it's one of the few free options they have for encrypting their entire hard disks, including the Windows system partition. The program's developer only flagged the CVE-2015-7358 flaw as critical and said that it can be exploited by "abusing drive letter handling." VeraCrypt 1.15 that was released Saturday, contains patches for the two vulnerabilities, identified as CVE-2015-7358 and CVE-2015-7359, as well as for other bugs. However, they have been fixed in VeraCrypt, an open-source program based on the TrueCrypt code that aims to continue and improve the original project. Since TrueCrypt is no longer actively maintained, the bugs won't be fixed directly in the program's code. The Google researcher hasn't disclosed details about the two bugs yet, saying that he usually waits seven days after a patch is released to open his bug reports. The first phase of the TrueCrypt audit project, performed by security engineers from iSEC Partners, a subsidiary of information assurance company NCC Group, covered the driver code, but "Windows drivers are complex beasts" and it's easy to miss local elevation of privilege flaws, Forshaw said on Twitter. It's impossible to tell if the new flaws discovered by Forshaw were introduced intentionally or not, but they do show that despite professional code audits, serious bugs can remain undiscovered. The auditors found no high-severity issues or evidence of intentional backdoors in the program. The first phase, which analyzed the TrueCrypt driver and other critical parts of the code, had already been completed when TrueCrypt was discontinued. The original authors of TrueCrypt, who have remained anonymous, abruptly shut down the project in May 2014 warning that "it may contain unfixed security issues" and advised users to switch to BitLocker, Microsoft's full-disk encryption feature that's available in certain versions of Windows.Īt that time a crowd-funded effort was already underway to perform a professional security audit of TrueCrypt's source code and its cryptography implementations. The flaws, which were apparently missed in an earlier independent audit of the TrueCrypt source code, could allow attackers to obtain elevated privileges on a system if they have access to a limited user account.
0 Comments
Leave a Reply. |