Two serious flaws found in TrueCrypt by James Forshaw, a member of Google's Project Zero team
Lucian Constantin / ITworld.com :
Context & Ripple Effects
In April, an independent audit of TrueCrypt came back largely reassuring: minor issues, no deliberate backdoors, no severe design flaws. Today James Forshaw of Google's Project Zero discloses two serious flaws in the same code — a direct challenge to the audit's headline verdict, landing on a tool many enterprises treat as verified.
The timing matters because the argument over TrueCrypt isn't settled: six weeks later a detailed analysis concluded it was safer than previously reported. Forshaw's findings sit at the center of that tug-of-war between formal audit sign-off and adversarial bug hunting, and they show how two credible reviews of the same software can reach opposite conclusions about its severity.
First-order effects
- Anyone who adopted or certified TrueCrypt on the strength of the April audit's 'no severe design flaws' finding now has to reconcile that sign-off with two serious flaws found by a different method.
- Forshaw's disclosure hands defenders concrete vulnerability detail for a widely relied-on encryption tool, while putting immediate pressure for fixes on the project's maintainers.
Second-order effects
- The conflicting verdicts raise the bar for what counts as assurance: a single clean audit no longer settles a crypto tool's reputation once a team like Project Zero re-examines it, so reviewers' methods become as scrutinized as the code itself.
- Other vendors of security-critical software should expect the same treatment — Project Zero's model of private reporting followed by timed disclosure, seen in its 90-day disclosure to Malwarebytes, makes any widely deployed tool fair game regardless of prior audit status.
Third-order effects
- If aging, trusted crypto code keeps yielding serious flaws under expert review, the industry's assurance model shifts from one-time paid audits toward continuous adversarial testing by well-resourced teams.
- Google is already productizing that shift: Project Wycheproof's open-source tests for known attacks on cryptographic libraries turn individual bug discoveries into reusable testing infrastructure, changing how third-party crypto gets vetted.
The trend: Long-trusted encryption tools are being re-litigated by elite bug-hunting teams, displacing one-time audits with continuous adversarial review as the standard of assurance.