Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The reason I knew Trucrypt was watertight was because the source code got fully audited and because the NSA got so squirmy about it.

Has there been any equivalent audit of Veracrypt? Or should we basically assume it’s been compromised/backdoored.



Veracrypt 1.18 was audited in 2016 by the Open Source Technology Improvement Fund [0]. It is incredibly unlikely that a random NSA backdoor is sitting around on a high profile open source project like Veracrypt. If you are still skeptical you are free to take a look at all of the source yourself [1].

[0] - https://ostif.org/the-veracrypt-audit-results/

[1] - https://github.com/veracrypt/VeraCrypt




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: