mlts22 wrote:
What really worries me is that the TrueCrypt 7.2 files were not just signed by the Windows Authenticode key, but the PGP/gpg key as well. If this was a hacker, it was an extreme compromise, as private keys are usually kept offline.
Serious stuff here, be it a hacker or worse.
The
theregister.co.uk is also reporting that the new TrueCrypt 7.2 binaries posted have been altered, and only decrypt volumes. It's encryption capabilities removed. But could also possibly contain malware? They also report that although these files appeared to be digitally signed by the developers, that a "new and untrusted key was used"?
This mystery just gets better and better? :h