+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

Snowden's Favorite Encryption Tool Is 'Not Secure'

Jun 1, 2014, 04:32 IST

screenshotEdward Snowden during a recent interview on German television

A popular encryption tool used and endorsed by ex-NSA contractor Edward Snowden abruptly shut down on Wednesday, with its website telling users the tool is "not secure" but failing to provide additional details.

Advertisement

The decade-old tool - called TrueCrypt - allowed users to encrypt sensitive files and hard drives and was a favorite of security-minded individuals. One of those people was Edward Snowden, who hosted a "Crypto Party" in Dec. 2012 to teach a group of people how it to encrypt hard drives and USB sticks, while still working as a contractor for the NSA in a Hawaii.

But the sudden closure of TrueCrypt has led some to speculate the anonymous developers behind it had aroused the eye of the U.S. government and they decided to just throw in the towel. (Snowden's encrypted email service, Lavabit, suffered a similar fate).

The "advisory comes as a shock to the security community, though no one has been able to confirm its authenticity so far," wrote Runa Sandvik, a developer of the Tor anonymous web browser, in Forbes.

Interestingly, the shut down came as a full-scale professional security audit of the TrueCrypt software was underway, led by Matthew Green, a cryptographer and professor at Johns Hopkins University, journalist Brian Krebs reported.

Advertisement

So far, the audit had not found anything suspicious in the code, but Green told Brian Krebs the fact TrueCrypt has been taken down could lead some to believe there's some "big evil vulnerability in the code."

"I was starting to have warm and fuzzy feelings about the code, thinking [the developers] were just nice guys who didn't want their names out there," Green told Brian Krebs. "But now this decision makes me feel like they're kind of unreliable. Also, I'm a little worried that the fact that we were doing an audit of the crypto might have made them decide to call it quits."

You are subscribed to notifications!
Looks like you've blocked notifications!
Next Article