top | item 37734021

(no title)

stblack | 2 years ago

I always wonder what really happened with TrueCrypt. What’s the inside story, there?

I’m not interested in anybody’s guess. What happened? WTF actually happened?

discuss

order

etc-hosts|2 years ago

Paul Leroux was sentenced to 25 years in June 2020, appellate court confirmed the sentence in 2022.

https://law.justia.com/cases/federal/appellate-courts/ca2/20...

e12e|2 years ago

Oh I'd forgotten about this part:

> Le Roux was arrested on 26 September 2012 for conspiracy to import narcotics into the United States, and agreed to cooperate with authorities in exchange for a lesser sentence and immunity to any crimes he might admit to later. He subsequently admitted to arranging or participating in seven murders, carried out as part of an extensive illegal business empire.

https://en.m.wikipedia.org/wiki/Paul_Le_Roux

icelancer|2 years ago

Didn't he consistently deny being involved in TrueCrypt? E4M is closely related, but is there any evidence showing that Paul == TrueCrypt? Just curious if there was.

jandrese|2 years ago

That is wild. How did he have time to maintain TrueCrypt while doing all of that crime?

hosteur|2 years ago

He denies involvement with TrueCrypt. Is there any actual proof?

pyuser583|2 years ago

> The district court's decision that immediate video sentencing was in defendant's best interest was reasonable because defendant was asking for a time-served sentence …

Time served was 25 years!?!

eitland|2 years ago

For anyone who wonders and can tolerate some guessing, here is an interesting starting point:

https://magazine.atavist.com/he-always-had-a-dark-side/

billfruit|2 years ago

The the article may have something interesting to say, but it seems to spend paragraphs upon paragraphs on the amateur sleuthing that the article authour did, rather than come to the point quickly.

wkat4242|2 years ago

I had no idea, that explains a lot. Thanks.

ThePowerOfFuet|2 years ago

Absolutely wild. Thank you for contributing this!

perth|2 years ago

I’ve always heard speculation that I believe of some sort of NSA involvement. When it was taken down back in the day (yes it was pretty much a takedown, the entire website got thrashed..) there was a lot of people on Reddit that were speculating that.

didntcheck|2 years ago

The way it was announced was suspicious. Purging the website rather than just posting an "unmaintained" notice is weird for any FOSS project, but recommending people just use Bitlocker sounded like a clear "canary". Like the authors were being coerced and decided to burn their reputation on purpose rather than comply

goalieca|2 years ago

The "Not Secure Anymore" message likely refers to the weak password based key derivation function and verification steps. I suspect the NSA and other advanced computing groups had means to brute force it and it took the rest of us years to figure out the parameters weren't strong enough.

lucb1e|2 years ago

I'm not sure how you're insisting on more than "anybody's guess" when that's all the information that is out there