Could VeraCrypt become the next TrueCrypt?

Advertisement

VeraCrypt is an encryption software that is a fork of TrueCrypt. What is meant by that is that it is based on TrueCrypt source without being a mere clone of the program.

Since it is based on the popular application, it offers pretty much the same feature set that TrueCrypt makes available. This includes creating encrypted containers on hard drives and encrypting entire partitions or drives including the system partition.

According to IDRIX, the company behind VeraCrypt, it adds security enhancements to the algorithm that "makes it immune to new developments in brute-force attacks".

For example, when the system partition is encrypted, TrueCrypt uses PBKDF2-RIPEMD160 with 1000 iterations whereas in VeraCrypt we use 327661. And for standard containers and other partitions, TrueCrypt uses at most 2000 iterations but VeraCrypt uses 655331 for RIPEMD160 and 500000 iterations for SHA-2 and Whirlpool.

The downside to those changes is that it takes longer to open (read mount) encrypted partitions. The actual performance of mounted drives is however not affected by this.

Another downside is that the storage format is not compatible with TrueCrypt's storage format which means that you will still have to find a way to convert TrueCrypt partitions to VeraCrypt format.

The stop of TrueCrypt development affects VeraCrypt. Since it is based on TrueCrypt source,it is now up to IDRIX to continue development of the application. Previously, the company could use new features introduced by the TrueCrypt team which is not an option anymore at the time of writing.

veracrypt

The "TrueCrypt is insecure" message may also affect user perception or at least doubt when it comes to VeraCrypt. While the -- ongoing -- audit has not found any major security issues in its first stage, it may still keep some users from giving VeraCrypt a true, considering that it is based on the same source as TrueCrypt.

Mounir Idrassi, IDRIX founder and developer behind VeraCrypt on the other hand does not seem devastated by TrueCrypt's end of life statement. Quite the contrary; he told us that he had big plans for the application and believes that development could continue more quickly than before.

A Mac OS X and Linux version will be released this summer for instance, and there is development ongoing to implement SHA-2 key derivation for the encryption of system partitions.

Idrassi believes that VeraCrypt will benefit from TrueCrypt's security audit to correct any weaknesses or issues found by the audit. While this may require lots of work, he hopes that other developers may contribute to the VeraCrypt project to speed these things up.

It will be interesting to see how VeraCrypt evolves in the coming months. If things to as planned, it could rise to become a very popular TrueCrypt alternative.

Summary
Author Rating
4
Software Name
VeraCrypt
Operating System
Windows
Landing Page
Please share this article

facebooktwittergoogle_plusredditlinkedinmail

Advertisement

Responses to Could VeraCrypt become the next TrueCrypt?

  1. Nebulus June 8, 2014 at 9:54 pm #

    Until that TrueCrypt audit will be finished, there are too many questions and very few answers... All we can do now is wait. In other words, if I am willing to trust a TrueCrypt fork, why not continue to use the old TrueCrypt?

    • Martin Brinkmann June 8, 2014 at 10:02 pm #

      Makes sense.

    • sades June 9, 2014 at 5:33 am #

      Conversely if you're willing to trust TrueCrypt why not use the better supported and more advanced fork?

  2. steven June 8, 2014 at 11:21 pm #

    https://www.grc.com/misc/truecrypt/truecrypt.htm

  3. Marc F June 9, 2014 at 12:04 am #

    Well, TrueCrypt.ch will also be working on an OSS fork.
    So there's plenty of choices

  4. TheRube June 9, 2014 at 10:29 pm #

    Mr. Brinkmann.

    Thank you for this VC review as I (we) was in eager anticipation of it!

    TR

  5. Hawk June 12, 2014 at 4:32 pm #

    Don't have a portable version?

  6. mida June 14, 2014 at 4:57 pm #

    i think i know why the new format isnt compatible with this from old truecrypt, but if trucrypt.ch make a second fork of tc than cooks all developers there own little soup. it should be better if developers there want work one fork. combine manpower...

  7. Man in the winter June 23, 2014 at 6:07 am #

    Hi I agree.We had better to integrate all the compiler into one team on one platform .
    And who build a google talk account (group talk) in order to let us talk about the TC/VC instantly.

Leave a Reply