SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Audit Reveals Significant Vulnerabilities for TrueCrypt and Successor VeraCrypt
Date    Tuesday October 25 2016, @10:09PM
Author    cmn32480
Topic   
from the decrypt-this dept.
https://soylentnews.org/article.pl?sid=16/10/25/0310243

"exec" writes:

VeraCrypt security audit reveals many flaws, some already patched [Zeljka Zorz/Helpnet Security]

VeraCrypt, the free, open source disk encryption software based on TrueCrypt, has been audited by experts from cybersecurity company Quarkslab.

The researchers found 8 critical, 3 medium, and 15 low-severity vulnerabilities, and some of them have already been addressed in version 1.19 of the software, which was released on the same day as the audit report.

The code auditing effort analyzed VeraCrypt 1.18 and its bootloaders.

"A first step consisted in verifying that the problems and vulnerabilities identified by iSec and NCC Group in TrueCrypt 7.1a for the Open Crypto Audit Project had been taken into account and fixed," the Quarkslab researchers involved in the effort explained.

"Then, the remaining study was to identify potential security problems in the code specific to VeraCrypt. Contrary to other TrueCrypt forks, the goal of VeraCrypt is not only to fix the public vulnerabilities of TrueCrypt, but also to bring new features to the software."

A short overview of the issues found (fixed and still not fixed) can be found here. The audit report, with mitigations for still unpatched vulnerabilities, can be downloaded from here.

Are any Soylentils using Veracrypt and/or other forks of Trucrypt?

The full audit report: TrueCrypt Cryptographic Review[PDF] [Alex Balducci, Sean Devlin, Tom Ritter/Open Crypto Audit Project]

Previously:
Independent Audit: Newly Found TrueCrypt Flaw Allows Full System Compromise
No Backdoors Found in TrueCrypt
TrueCrypt Site Encodes Warning about NSA Infiltration
TrueCrypt Discontinued, Compromised?

-- submitted from IRC


Original Submission

Links

  1. "VeraCrypt security audit reveals many flaws, some already patched " - https://www.helpnetsecurity.com/2016/10/18/veracrypt-security-audit/
  2. "version 1.19" - https://veracrypt.codeplex.com/
  3. "identified" - https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_OCAP_final.pdf
  4. "here" - http://blog.quarkslab.com/security-assessment-of-veracrypt-fixes-and-evolutions-from-truecrypt.html
  5. "here" - https://ostif.org/the-veracrypt-audit-results/
  6. "TrueCrypt Cryptographic Review" - https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_OCAP_final.pdf
  7. "Independent Audit: Newly Found TrueCrypt Flaw Allows Full System Compromise" - https://soylentnews.org/article.pl?sid=15/09/30/0137229
  8. "No Backdoors Found in TrueCrypt" - https://soylentnews.org/article.pl?sid=15/04/03/0245239
  9. "TrueCrypt Site Encodes Warning about NSA Infiltration" - https://soylentnews.org/article.pl?sid=14/06/17/0511216
  10. "TrueCrypt Discontinued, Compromised?" - https://soylentnews.org/article.pl?sid=14/05/29/0243223
  11. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=16577

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Audit Reveals Significant Vulnerabilities for TrueCrypt and Successor VeraCrypt on 2024-03-29 09:26:09