Hacker News new | ask | show | jobs
by stblack 993 days ago
I always wonder what really happened with TrueCrypt. What’s the inside story, there?

I’m not interested in anybody’s guess. What happened? WTF actually happened?

4 comments

Paul Leroux was sentenced to 25 years in June 2020, appellate court confirmed the sentence in 2022.

https://law.justia.com/cases/federal/appellate-courts/ca2/20...

Oh I'd forgotten about this part:

> Le Roux was arrested on 26 September 2012 for conspiracy to import narcotics into the United States, and agreed to cooperate with authorities in exchange for a lesser sentence and immunity to any crimes he might admit to later. He subsequently admitted to arranging or participating in seven murders, carried out as part of an extensive illegal business empire.

https://en.m.wikipedia.org/wiki/Paul_Le_Roux

Didn't he consistently deny being involved in TrueCrypt? E4M is closely related, but is there any evidence showing that Paul == TrueCrypt? Just curious if there was.
There's no proof
That is wild. How did he have time to maintain TrueCrypt while doing all of that crime?
Paul was what people call a 10x programmer. He was highly prolific.

The book Mastermind goes into this a bit.

So do some old web posts straight from Paul himself, if you know where and if they are still up.

Has anyone looked up the details of all of this? The DEA has been notorious for arresting people overseas and indicting them for just participating(i.e. being in the same room) in conversations about drug trafficking even if those conversations were between DEA agents.

Just a quick glimpse at the Wikipedia page actually talks about 5 drugs that seem to me like over the counter medicine. What's kinda interesting to me skimming this and looking at the references is that the assassins and a lot of the operations were Israelis and the whole thing was run from Tel Aviv, but there's zero reference to any of those people. They are just called the Israeli business partners.

I noticed that US fed agencies work like that - use someone for their own games and make it looks like success job for own careers.

Some cops tried it in my country as well. These cops recieved a middle finger from the court.

Edit: The courts called it 'provocation by police' and everyone was freed.

I’m on mobile but there’s more info on the Israelis in the Mastermind book. Some of them still have public LinkedIn profiles.
He denies involvement with TrueCrypt. Is there any actual proof?
> The district court's decision that immediate video sentencing was in defendant's best interest was reasonable because defendant was asking for a time-served sentence …

Time served was 25 years!?!

Leroux has been in custody since 2012. If he was sentenced to 25 years in 2020... he would only have 17 years to serve. it's 2023 now, so he has 14 years left.
For anyone who wonders and can tolerate some guessing, here is an interesting starting point:

https://magazine.atavist.com/he-always-had-a-dark-side/

The the article may have something interesting to say, but it seems to spend paragraphs upon paragraphs on the amateur sleuthing that the article authour did, rather than come to the point quickly.
In other words what many of us would call an interesting article :-)
The article writer focusing on themselves rather than on their subject makes it less interesting for me.
I had no idea, that explains a lot. Thanks.
Absolutely wild. Thank you for contributing this!
I’ve always heard speculation that I believe of some sort of NSA involvement. When it was taken down back in the day (yes it was pretty much a takedown, the entire website got thrashed..) there was a lot of people on Reddit that were speculating that.
The way it was announced was suspicious. Purging the website rather than just posting an "unmaintained" notice is weird for any FOSS project, but recommending people just use Bitlocker sounded like a clear "canary". Like the authors were being coerced and decided to burn their reputation on purpose rather than comply
The "Not Secure Anymore" message likely refers to the weak password based key derivation function and verification steps. I suspect the NSA and other advanced computing groups had means to brute force it and it took the rest of us years to figure out the parameters weren't strong enough.
The alternate theory was that the NSA forced the project to shutdown or become backdoored because they couldn't break it, and that was deemed unacceptable, resulting in the author deciding to call it quits (lavabit style) rather than compromise the application. The question then becomes "why is VeraCrypt allowed to exist"
I'm not sure how you're insisting on more than "anybody's guess" when that's all the information that is out there