Hacker News new | ask | show | jobs
by 100rsa 4400 days ago
Still have no idea what's the "unfixed security issues", and few guys mention about it. I image there the "security issues" will be (if it exist): 1. because key are easy to stolen by coolboot or trojan. 2. because it has backdoor, will save key to a hidden place. 3. because it will leave some information in other place, like 2 but it's implantation problem. 4. because it use a vulnerable algorithm to generate key. 5. because pbkdf2 or aes256 is broken but nobody known it. exclude 2 and 3, change to other software it's not help at all, algorithm almost same.
1 comments

If we believe the person I was in contact with (big IF, I know), there are no current issues, but it is by definition "harmful" to continue use because it is no longer being maintained. In fact, the person requested I tell Steve Gibson to not distribute or include a notice telling people not to use it.