I have an encrypted TrueCrypt volume on an old 8GB USB stick that's held my tax stuff and a backup of my thesis drafts since maybe 2012. I check it twice a year, tops, usually right before I get paranoid about losing the drive on a train. So when I opened Twitter this afternoon and saw people asking "wait, is TrueCrypt dead?" I actually felt a little jolt of dread.
Here's what happened, as far as anyone can piece together. Sometime today the TrueCrypt.org page and the project's SourceForge listing both got swapped out for a giant red warning: "WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues." Underneath that, instructions for migrating your volumes to BitLocker if you're on Windows, and vague hand-waving for everyone else. There's also a new build, 7.2, that will only decrypt existing volumes now. It won't let you create new ones or re-encrypt anything.
That's the whole announcement. No blog post explaining why. No warning on the mailing list beforehand. No names attached, because nobody's ever known exactly who runs TrueCrypt to begin with, it's been maintained by anonymous or pseudonymous developers this whole time, which honestly is part of why so many of us trusted it (a weird kind of trust, when you actually stop and think about it, and I say that as someone who's relied on it for years).
The timing is what makes this feel off rather than just sad. Barely two weeks ago the independent security audit of TrueCrypt, the one that got funded through that crowdfunding drive after all the Snowden stuff had everybody nervous about backdoors, finished its first phase and turned up nothing catastrophic. A handful of bugs, nothing screaming "NSA plant." People, me included, took that as a decent sign. And then out of nowhere the people behind the software torch the whole thing and tell everyone to go use BitLocker, a closed-source Microsoft product, which is a genuinely bizarre recommendation if your entire reason for existing for a decade was "don't trust encryption software you can't audit yourself."
I've already seen three theories going around. One: the devs got some kind of legal order and this is their version of shouting into the void without technically saying anything (people keep bringing up Lavabit shutting down rather than hand over its keys). Two: the site got compromised and someone's messing with everybody, though the new build is apparently still signed with the legitimate TrueCrypt key, which makes a simple hack less likely. Three: the maintainers are just burned out after a decade of unpaid, anonymous work and picked maybe the most alarming possible way to say so. None of the three feel satisfying to me. I don't think anyone outside the project actually knows, and I'd bet we won't find out for a long while, if ever.
Practically speaking, I'm not migrating my little USB stick to BitLocker tonight. The old builds still work fine, they just won't get updates going forward, and there's no proven exploit sitting around waiting to be used against my thesis drafts from 2011. But I'll be watching what the audit team does next, because if they go ahead and finish auditing the actual source code regardless of this warning page, that tells you something. If they quietly drop it too, that tells you something else entirely.
Unrelated aside, but Google showed off its own self-built driverless car prototype yesterday, the little two-seater pod with no steering wheel or pedals, and I keep getting mentally derailed comparing "software I have to trust with my files" to "a car I'd have to trust with my actual body." Not a useful comparison, probably, but my brain won't drop it.
Back up whatever you've got encrypted, hang onto your old TrueCrypt installer somewhere safe in case you need it down the line, and don't panic-migrate to something new just because an anonymous warning page told you to today. We've all had enough of taking security advice from a webpage nobody can even identify the author of.