Release of VeraCrypt 1.24, a fork of TrueCrypt

After a year of development has been published project release VeraCrypt 1.24, a fork of the TrueCrypt disk encryption system, which has ceased to exist. VeraCrypt is notable for replacing the RIPEMD-160 algorithm used in TrueCrypt with SHA-512 and SHA-256, increasing the number of hashing iterations, simplifying the build process for Linux and macOS, and addressing issues, identified during the audit of TrueCrypt's source code. Additionally, VeraCrypt provides compatibility mode for TrueCrypt partitions and contains tools for converting TrueCrypt partitions to VeraCrypt format. The code developed by the VeraCrypt project is distributed is licensed under the Apache 2.0 license, while borrowings from TrueCrypt updates for the project continue to are provided under the TrueCrypt License 3.0.

In the new release:

  • For non-system partitions, the maximum password length has been increased to 128 characters in UTF-8 encoding. To ensure compatibility with older systems, an option has been added to restrict the maximum password size to 64 characters;
  • As an alternative to the CPU RDRAND instructions, support for the Jitterentropy, which utilizes jitter-based hardware generation of pseudo-random numbers, based on the timing variance of executing a specific set of instructions on the CPU (CPU execution time jitter), which is dependent on numerous internal factors and unpredictable without physical control over the CPU;
  • Performance optimization has been implemented for XTS mode on 64-bit systems supporting SSE2 instructions. The optimizations have, on average, increased performance by 10%;
  • Code has been added to detect the presence of RDRAND/RDSEED instruction support in CPUs and Hygon processors. Issues with detecting AVX2/BMI2 support have been resolved;
  • For Linux, the CLI has been updated with the ‘—import-token-keyfiles’ option compatible with non-interactive mode;
  • For Linux and macOS, a check for available filesystem space to create the file container has been added. A flag ‘—no-size-check’ is provided to disable this check;
  • For Windows, a mode has been implemented for storing keys and passwords in memory in an encrypted form, using the ChaCha12 cipher, t1ha hash, and a CSPRNG based on ChaCha20. By default, this mode is disabled, as it leads to an approximate 10% increase in overhead and prevents the system from entering sleep mode. For Windows, protection against certain data extraction attacks from memory has also been added, based on what has been implemented in KeePassXC the method of restricting memory access for users without administrator privileges. Key cleanup has been added before shutdown, before rebooting, or (optionally) when connecting a new device. Enhancements have been made to the UEFI bootloader. Support for using CPU instructions RDRAND and RDSEED as an additional source of entropy has been added. A mount mode has been added without assigning a drive letter to the partition.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster