TrueCrypt audit code review: no evulz, low source code quality
Back in October, Kenneth White and Matthew Green kicked off the idea to do a full and complete audit of TrueCrypt, the most popular disk encryption package out there. They raised over $60,000 dollars and 33BTC to this end, and got underway.
The first part of the audit, the in-depth source code review was performed by a security firm and completed April 14 ( report ).
No bogeys found so far (11 medium-to-minor items). The next stage (cryptanalysis) is currently underway.
I'm sure plenty of people are thinking "how about OpenSSL?". At one point: sure. Right now? I'd personally prefer to see this sort of effort going into improving the OpenSSL software.
The first part of the audit, the in-depth source code review was performed by a security firm and completed April 14 ( report ).
No bogeys found so far (11 medium-to-minor items). The next stage (cryptanalysis) is currently underway.
I'm sure plenty of people are thinking "how about OpenSSL?". At one point: sure. Right now? I'd personally prefer to see this sort of effort going into improving the OpenSSL software.