Hacker News new | past | comments | ask | show | jobs | submit login

Why would they release an audit that effectively provides them with zero-days into encrypted suspect disks.

They release now because no one is using TrueCrypt any longer..




Because there weren't any real zero days in the report in the first place. The article mentions that it's mainly minor things like failing to clear memory, which is only helpful in rare circumstances.


They did not publish publicly but did report their findings to the true crypt foundation so that it could be fixed (but they in return didn't agree that those were flaws worth thinking)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: