Skip to main content

标 题: NSA避免再爆丑闻,停止了加密软件Truecrypt的开发
发信人: mitbbs2715 (好吃不懒做), 信区: Military
标  题: NSA避免再爆丑闻,停止了加密软件Truecrypt的开发
发信站: BBS 未名空间站 (Thu May 29 11:36:19 2014, 美东)


Several readers sent word that the website for TrueCrypt, the popular disk
encryption system, says that development has ended, and Windows users should
switch to BitLocker. A notice on the site reads, "WARNING: Using TrueCrypt
is not secure as it may contain unfixed security issues. ... You should
migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk
images supported on your platform." It includes a link to a new version of
TrueCrypt, 7.2, and provides instructions on how to migrate to BitLocker.
Many users are skeptical of a site defacement, and there's been no
corroborating post or communication from the maintainers. However, the
binaries appear to be signed with the same GPG key that the TrueCrypt
Foundation used for previous releases. A source code diff of the two
versions has been posted, and the new release appears to simply remove much
of what the software was designed to do. It also warns users away from
relying on it for security. (The people doing an audit of TrueCrypt had
promised a 'big announcement' soon, but that was coincidental.) Security
experts are warning to avoid the new version until the situation can be


Popular posts from this blog

CKA Simulator Kubernetes 1.22 Pre Setup Once you've gained access to your terminal it might be wise to spend ~1 minute to setup your environment. You could set these: alias k = kubectl                         # will already be pre-configured export do = "--dry-run=client -o yaml"     # k get pod x $do export now = "--force --grace-period 0"   # k delete pod x $now Vim To make vim use 2 spaces for a tab edit ~/.vimrc to contain: set tabstop=2 set expandtab set shiftwidth=2 More setup suggestions are in the tips section .     Question 1 | Contexts Task weight: 1%   You have access to multiple clusters from your main terminal through kubectl contexts. Write all those context names into /opt/course/1/contexts . Next write a command to display the current context into /opt/course/1/ , the command should use kubectl . Finally write a second command doing the same thing into ...

OWASP Top 10 Threats and Mitigations Exam - Single Select

Last updated 4 Aug 11 Course Title: OWASP Top 10 Threats and Mitigation Exam Questions - Single Select 1) Which of the following consequences is most likely to occur due to an injection attack? Spoofing Cross-site request forgery Denial of service   Correct Insecure direct object references 2) Your application is created using a language that does not support a clear distinction between code and data. Which vulnerability is most likely to occur in your application? Injection   Correct Insecure direct object references Failure to restrict URL access Insufficient transport layer protection 3) Which of the following scenarios is most likely to cause an injection attack? Unvalidated input is embedded in an instruction stream.   Correct Unvalidated input can be distinguished from valid instructions. A Web application does not validate a client’s access to a resource. A Web action performs an operation on behalf of the user without checkin...