Tales from the Crypt: Burying Open-source Encryption

Two weeks ago TrueCrypt announced that it was ceasing work on its open source encryption solution. Much to the surprise of many, their web site updated with a notification that the product as unsecure and users should migrate to solutions like the native encryption found in Windows and Mac OS X.

It was an interesting turn of events. And nothing really gets people’s attention like a warning spread across a web site that states, “WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues.” While the impact on larger businesses and enterprises is likely minimal, it still highlights a key problem with security that is open source – there’s no accountability to make sure it’s secure.

We’ve regularly been asked about TrueCrypt as a solution for business customers and we typically raised the issues of security, support and ultimately, accountability. While ‘free’ always sounds good, there are always strings attached. If a user has problems with open source software, who do they call to get help? Who helps troubleshoot and fix the issue? This alone is enough reason for a larger business to steer clear from an open source security solution.

The good news is that TrueCrypt has done the right thing. They informed users and suggested alternatives, and very good alternatives at that. BitLocker and FileVault are excellent encryption solutions and can meet the needs of many customers. For the larger business/enterprise, they’ll likely need more and that comes with central management.

It’s exactly why we introduced the ability to manage BitLocker with SecureDoc in May. We can help organizations take advantage of great native encryption solution, but then add extra layers of security with more robust authentication and key management.

RIP TrueCrypt.

Previous Post
Ruggedly Secure
Next Post
Computer Forensics and Self-Encrypting Drives

Related Posts

What’s your P@ssw0rd?

I know I’m a little late to the party, but recently I’ve been giving more and more thought to the passwords I use to access the various sites and tools I use on a day to day basis. The main…
Read more
RSA Conference

Five Observations from RSA 2018

I once again had the pleasure and privilege to attend the RSA Security conference in San Francisco, CA. rsaconference.com/events/us18. The conference keynotes, sessions and sidebar conversations were a good opportunity to see what the hot topics in security are. I…

Keeping up with the Jones’

The evolution of technology goes at a breakneck pace. Whether it’s new products coming to market or updates to existing products – it’s a never-ending cycle. As a software company that supports multiple Operating Systems (OS), we’re no different and…
Read more

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.