/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Two serious flaws found in TrueCrypt by James Forshaw, a member of Google's Project Zero team

Lucian Constantin / ITworld.com :

ITworld.com Lucian Constantin

Context & Ripple Effects

In April, an independent audit of TrueCrypt came back largely reassuring: minor issues, no deliberate backdoors, no severe design flaws. Today James Forshaw of Google's Project Zero discloses two serious flaws in the same code — a direct challenge to the audit's headline verdict, landing on a tool many enterprises treat as verified.

The timing matters because the argument over TrueCrypt isn't settled: six weeks later a detailed analysis concluded it was safer than previously reported. Forshaw's findings sit at the center of that tug-of-war between formal audit sign-off and adversarial bug hunting, and they show how two credible reviews of the same software can reach opposite conclusions about its severity.

First-order effects

  • Anyone who adopted or certified TrueCrypt on the strength of the April audit's 'no severe design flaws' finding now has to reconcile that sign-off with two serious flaws found by a different method.
  • Forshaw's disclosure hands defenders concrete vulnerability detail for a widely relied-on encryption tool, while putting immediate pressure for fixes on the project's maintainers.

Second-order effects

  • The conflicting verdicts raise the bar for what counts as assurance: a single clean audit no longer settles a crypto tool's reputation once a team like Project Zero re-examines it, so reviewers' methods become as scrutinized as the code itself.
  • Other vendors of security-critical software should expect the same treatment — Project Zero's model of private reporting followed by timed disclosure, seen in its 90-day disclosure to Malwarebytes, makes any widely deployed tool fair game regardless of prior audit status.

Third-order effects

  • If aging, trusted crypto code keeps yielding serious flaws under expert review, the industry's assurance model shifts from one-time paid audits toward continuous adversarial testing by well-resourced teams.
  • Google is already productizing that shift: Project Wycheproof's open-source tests for known attacks on cryptographic libraries turn individual bug discoveries into reusable testing infrastructure, changing how third-party crypto gets vetted.

The trend: Long-trusted encryption tools are being re-litigated by elite bug-hunting teams, displacing one-time audits with continuous adversarial review as the standard of assurance.