# TrueCrypt question

**URL:** https://boards.straightdope.com/t/truecrypt-question/807065
**Category:** Factual Questions
**Created:** [January 20, 2018, 6:29pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065 "2018-01-20T18:29:56Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![Daylate](https://avatars.discourse-cdn.com/v4/letter/d/9dc877/32.png) [@Daylate](https://boards.straightdope.com/u/Daylate)
#### Post date: [January 20, 2018, 6:29pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065/1 "2018-01-20T18:29:56Z")

</div>

As most of you know, the encryption program TrueCrypt is no longer supported. Is there anything out there that you would consider the equivalent or better? I’ve got some files (financial, etc.) that I would like to protect, but am unsure it TrueCrypt is still satisfactory for that.

I’ve looked at BitLocker, but am not sure if that would do the job as easily or safely as TC.

Thanks in advance for any advice.

---

<div class="post-metadata">

### Author: ![DPRK](https://avatars.discourse-cdn.com/v4/letter/d/4491bb/32.png) [@DPRK](https://boards.straightdope.com/u/DPRK)
#### Post date: [January 20, 2018, 6:33pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065/2 "2018-01-20T18:33:53Z")

</div>

They replaced it by VeraCrypt.

If you just want to encrypt individual files, programs like GPG can do that.

---

<div class="post-metadata">

### Author: ![Duckster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duckster/32/1244_2.png) [@Duckster](https://boards.straightdope.com/u/Duckster)
#### Post date: [January 20, 2018, 7:39pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065/3 "2018-01-20T19:39:31Z")

</div>

TrueCrypt is just fine to keep using. You want the last version before they crippled it.

Get it here: [GRC's&nbsp;|&nbsp;TrueCrypt, the final release, archive&nbsp;&nbsp;](https://www.grc.com/misc/truecrypt/truecrypt.htm)

I use TrueCrypt all of the time.

---

<div class="post-metadata">

### Author: ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)
#### Post date: [January 21, 2018, 1:37am UTC](https://boards.straightdope.com/t/truecrypt-question/807065/4 "2018-01-21T01:37:52Z")

</div>

It depends what you are trying to defend against. I use VeraCrypt to encrypt USB memory keys which need to be read on both Macs and PCs. In that case, I’m defending against some random person finding the USB key and trying to read the data. I’ve not seen anything to suggest that VeraCrypt is not suitable for this.

For encrypting the hard disk on Macs and PCs I use FileVault and BitLocker, which are included with the OS. I trust these will protect the data from a laptop thief. I am _not_ convinced these will protect against the government, but that’s not who I’m worried about accessing the data.

CPUs made in the last 10 years or so have hardware accelerated encryption ([AES-NI](https://en.wikipedia.org/wiki/AES_instruction_set)), so I think it is almost always wise to use full disk encryption. The performance penalty is negligible, and it will leave the disk unreadable if, for example, you return it for a warranty replacement.

If your threat model is protecting against another user of the computer, then VeraCrypt virtual images should be fine. Create one, put your sensitive data in it, and then only open it when you need the data.

---

<div class="post-metadata">

### Author: ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)
#### Post date: [January 21, 2018, 12:35pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065/5 "2018-01-21T12:35:13Z")

</div>

[VeraCrypt](https://veracrypt.codeplex.com/) is nothing other than a continued development of TrueCrypt.

It’s a new and better incarnation of TrueCrypt. It’s based on the same code, but with all the vulnerabilities fixed, and with various improvements, and ongoing development.

**VeraCrypt can now _open existing TrueCrypt volumes_ and (optionally) _convert_ them to VeraCrypt format.**

It takes a few seconds longer to mount a volume encrypted with VeraCrypt, due to the increased security, but once it’s open, it functions exactly like TrueCrypt.

---

<div class="post-metadata">

### Author: ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)
#### Post date: [January 21, 2018, 2:57pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065/6 "2018-01-21T14:57:35Z")

</div>

VeraCrypt Portable:

> **[VeraCrypt Portable (free disk encryption) | PortableApps.com](https://portableapps.com/apps/security/veracrypt-portable)**
>
> VeraCrypt is a free disk encryption software based on TrueCrypt 7.1a. It allows secure encryption of full disks as well as virtual volumes that can be mounted on the fly. VeraCrypt has support for various encryption algorithms (AES, Serpent,...

You can run both VeraCrypt and TrueCrypt on the same computer - there is no conflict.

---

<div class="post-metadata">

### Author: ![CurtC](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@CurtC](https://boards.straightdope.com/u/CurtC)
#### Post date: [January 22, 2018, 4:46pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065/7 "2018-01-22T16:46:07Z")

</div>

> [@Duckster](#):
>
> TrueCrypt is just fine to keep using. You want the last version before they crippled it.

My wife got a new Windows 10 machine a couple of years ago, and TrueCrypt wasn’t able to do its whole-disk encryption with Win10.

Also at that time, VeraCrypt was not yet able to do whole-disk encryption, but I believe that’s been added since.

---

<div class="post-metadata">

### Author: ![erysichthon](https://avatars.discourse-cdn.com/v4/letter/e/d07c76/32.png) [@erysichthon](https://boards.straightdope.com/u/erysichthon)
#### Post date: [January 22, 2018, 10:44pm UTC](https://boards.straightdope.com/t/truecrypt-question/807065/8 "2018-01-22T22:44:54Z")

</div>

> [@Duckster](#):
>
> TrueCrypt is just fine to keep using. You want the last version before they crippled it.
> 
> Get it here: [GRC's&nbsp;|&nbsp;TrueCrypt, the final release, archive&nbsp;&nbsp;](https://www.grc.com/misc/truecrypt/truecrypt.htm)
> 
> I use TrueCrypt all of the time.

I’m still using TrueCrypt too. It has been thoroughly audited, and the audit found no backdoors and no significant vulnerabilities (I do not have the expertise to interpret the audit report, but prominent security bloggers like [Bruce Schneier](https://www.schneier.com/blog/archives/2015/04/truecrypt_secur.html) and [Matthew Green](https://blog.cryptographyengineering.com/2015/04/02/truecrypt-report/) have pronounced the program safe to use).

However, I realize it will probably stop working in some future version of Windows. I am still on Windows 7, and I don’t use the whole-disk encryption feature (which was noted above as not working in Windows 10).

---

<div class="post-metadata">

### Author: ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)
#### Post date: [January 23, 2018, 3:26am UTC](https://boards.straightdope.com/t/truecrypt-question/807065/9 "2018-01-23T03:26:36Z")

</div>

> [@CurtC](#):
>
> My wife got a new Windows 10 machine a couple of years ago, and TrueCrypt wasn’t able to do its whole-disk encryption with Win10.
> 
> Also at that time, VeraCrypt was not yet able to do whole-disk encryption, but I believe that’s been added since.

The built-in full-disk encryption in Windows (called Bitlocker) is unbroken, fast and perfectly fine to use. For full-disk encryption, I’d recommend using the OS’ version as it’ll be less likely to have compatibility issues.

---

<div class="post-metadata">

### Author: ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)
#### Post date: [January 23, 2018, 7:33am UTC](https://boards.straightdope.com/t/truecrypt-question/807065/10 "2018-01-23T07:33:46Z")

</div>

For what it’s worth, the usage scenarios between file/folder vs full-disk encryption are a bit different.

With full disk encryption, if somebody steals your laptop while it’s on and you’re logged in, your file will be completely unencrypted even if the whole drive was protected by Bitlocker. Once you log in, Bitlocker provides no security.

But if you had separately encrypted your most critical files with a different key, they can’t do anything with the encrypted files even if they stole them right off your unlocked desktop. You would need to encrypt the folder with something else (usually, a distinct passphrase) that’s not tied to your Windows login identity, which automatically unlocks Bitlocker and the built-in Windows file/folder encryption.

As for whether to use VeraCrypt, TrueCrypt, or PGP, or some other widely-available tool (7zip’s AES encryption?), it’s largely an academic question. Generally open-source is considered safer, audited is even better but no promise of anything, all are considered questionable/potentially insufficient against determined state actors, but all are generally “good enough” against just about anybody else, like casual identity thieves. Encryption is just a very good lock, used to encourage hackers to move on to easier targets (of which there are millions) or at least easier methods (call up your bank directly using a spoofed phone number or a fake ID). Just encrypt it with a relatively popular program, a password you’ll remember, and put it in a bank vault or bury it under your grandma’s house or something.
