Hacker News new | ask | show | jobs
by EsssM7QVMehFPAs 2372 days ago
Why would they release an audit that effectively provides them with zero-days into encrypted suspect disks.

They release now because no one is using TrueCrypt any longer..

2 comments

Because there weren't any real zero days in the report in the first place. The article mentions that it's mainly minor things like failing to clear memory, which is only helpful in rare circumstances.
They did not publish publicly but did report their findings to the true crypt foundation so that it could be fixed (but they in return didn't agree that those were flaws worth thinking)