小时候的天空 写了:想找一款加密软件。奇怪truecrype是开源软件,为什么没有进入ubuntu的源
还有安装系统时选择加密主目录,如果换系统,真么办?
那个Truecrypt还是 真有可疑的地方
http://en.wikipedia.org/wiki/Truecrypt#Controversy)
Reasonable paranoia
If relying on TrueCrypt encryption for life and death matters, it is worth noting that TrueCrypt (or any other software) is only as trustworthy as the people writing and reviewing the code.[38][39][40] Also, when using distributed binaries instead of compiling from the source code, a user may be running code that was inserted during packaging and that is not available in the open source repository (possible backdoors, etc.).[41][42][43] It is challenging to create binaries from source code that match the official binaries for purposes of verifying their integrity due to compiler options, etc.[44][41][42]
Various observers have noted some characteristics of TrueCrypt that extremely security conscious users may want to consider:[45][46][47][48]
The developers of TrueCrypt have been only anonymously referred to on the site as “The TrueCrypt Foundation” since 2010,[45] though there are potentially good reasons related to privacy why they might have chosen to remain thus.
There has been no known comprehensive review of the source code by a qualified cryptographer.[49][44] Thorough security code review and testing is hard, tedious, and painstaking work, and very few people have the skills to do it. There was, however, a functional evaluation of the deniability of hidden volumes in an earlier version of TrueCrypt by Schneier et al. that found security leaks.[46]
The "TrueCrypt License" is unique and contains distribution and copyright-liability restrictions.[50]
Various other open source projects including Fedora[51] and the Tails[52] live CD have removed or forbidden TrueCrypt from their distributions due to the closed fashion in which development is performed.