Okay so I need to write about the weirdest tech story of the week, because it's Saturday night, I've got an external hard drive sitting on my desk that I don't trust anymore, and I still haven't decided what to actually do about it.
Three days ago, out of absolutely nowhere, the TrueCrypt website changed to a giant red warning: "WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues." No explanation. No names attached (the devs have always been anonymous, which is part of what made this so unnerving). Just a blunt statement and a recommendation to migrate to BitLocker if you're on Windows. The new version they pushed, 7.2, doesn't even let you encrypt new volumes anymore, only decrypt existing ones. It's like the software equivalent of a note taped to a locked office door telling you to go rent somewhere else.
For anyone who doesn't keep up with this stuff, TrueCrypt has been the go-to free, open-source disk encryption tool for close to a decade. After all the Snowden leaks last year I got genuinely paranoid about my backups and finally set up a TrueCrypt volume on the WD drive I use for photos and old project files, back around November. It took me an evening of fumbling with hidden volumes and passphrase settings I didn't fully understand, but it worked, and I felt vaguely responsible about my digital life for the first time in years. Now I've got no idea if that decision was smart or naive.
Here's what makes it extra strange: just last month, the crowdfunded independent audit of TrueCrypt's code (the one a bunch of security researchers started after everyone got spooked in 2013) published its first phase results and found nothing alarming. No backdoors, a handful of minor issues, nothing close to "stop using this immediately." So either something happened in the last few weeks that nobody's talking about, or the anonymous devs just decided they were done and picked the weirdest possible way to say it. Telling people to switch to BitLocker, which is closed-source and made by the same company that was named in the PRISM slides, is the part that really has people on forums convinced something's off. Some folks think it's a hack, some think it's a warrant canary situation where the devs got hit with a legal order and this is their way of signaling it without technically saying anything, some think it's just burnout after a decade of unpaid, anonymous, thankless work. Honestly that last one wouldn't shock me at all. I can barely keep this blog updated some months and nobody's threatening me over it.
I spent about an hour last night reading through comment threads instead of doing literally anything productive, which is a pretty normal way for me to spend a Friday if I'm being honest. Nobody agrees on anything. The general advice floating around seems to be: don't panic, don't delete your existing volumes, but also don't start anything new with it, and wait to see if someone forks the last trusted version before it locks itself down further. There's already chatter about people mirroring the old 7.1a installer since it's the last version widely considered fine.
So what am I actually doing with my drive? Nothing yet, honestly. I backed up the important stuff a second time onto a different drive that isn't encrypted at all, which feels like a step backward but at least means I won't lose the photos if this all turns out to be some kind of compromise. I'm holding onto the encrypted volume as-is for now rather than touching anything, since apparently even opening it with 7.2 to add files could be a bad idea depending on who you ask. I've also got three browser tabs open comparing alternatives like DiskCryptor, and I keep almost bookmarking a Reddit thread and then closing it because everyone in it is arguing in circles.
What gets me is how quietly this happened. No press release, no interview, no farewell post explaining a decade of work. One page changed color and a piece of software millions of people relied on effectively stopped existing in its old form, all in the space of a Wednesday. I don't think we're getting a real answer to what happened here anytime soon, and maybe we never do. I'll update this if the fork situation sorts itself out into something I actually trust enough to move my files onto. Until then my drive just sits there, encrypted, unopened, and slightly ominous looking on my desk.